Article 50 formalises something that good practice has long treated as obvious:
people are entitled to know when they are dealing with a machine
This weekend, a piece of European law that most UK businesses and website owners have never read will begin to govern how their chatbots greet customers, how their marketing images are marked, and how their AI-written marketing text is disclosed. Article 50 of the EU AI Act becomes enforceable on 2nd August 2026. The European Commission only finalised its guidance on how to apply it two weeks before the deadline. For a rule that has been on the statute book since 2024, its practical shape has arrived remarkably late, leaving so many businesses in Britain trying to work out what it requires of them.
Article 50 is not the part of the AI Act that gets the most attention. A “high-risk” regime of rules governing Artificial Intelligence used in hiring, credit scoring or law enforcement have been pushed back to December 2027 and August 2028 under a political deal reached in Brussels earlier this year. However, instead of falling under risk-management, Article 50 is a transparency rule with a very simple idea: if a person is dealing with a computer, or looking at something generated by a computer, they should be told.
The four requirements of Article 50
Strip away the legal drafting and Article 50 imposes four distinct asks, falling on two different kinds of actor. A provider is whoever builds or supplies the AI system. A deployer is whoever puts it to use in their own business.
Many websites will find themselves in the deployer category even when the AI itself was bought in from elsewhere. Therefore using a third-party chatbot, image generator or personalisation engine does not exempt a business from its own obligations under the Act.
The first duty falls on providers of any system designed to autonomously interact with a person, like a customer service chatbot or a voice agent. These tools must make it clear to those on the other end that they are talking to a machine (unless that would already be obvious to a reasonably attentive user). The second duty, also on providers, concerns any system generating synthetic audio, image, video or text. Its output must carry a machine-readable marker showing that it was artificially produced. This marker, however, is meant to work invisibly in the file itself, rather than as something a viewer sees. The third applies to deployers of emotion-recognition or biometric-categorisation tools, who must tell the people being scanned that this is happening. The fourth, and the one most likely to catch marketing and content teams off-guard, requires deployers to visibly disclose two specific things: deepfake imagery, audio or video, and AI-generated text published to inform the public on a matter of public interest.
The EU Commission interprets content that resembles a real person, place or event convincingly enough to pass as authentic, as a deepfake regardless of any intent to deceive. A “before and after” using a synthetic model, or an AI-altered product demonstration, can qualify even with no deception in mind. And “informing the public on matters of public interest” has been worded broadly enough to cover a good deal of everyday commercial content, such as commentary on financial, political, scientific or cultural developments.
Legal commentators reviewing the draft Code have noted that its reach extends well beyond companies that think of themselves as being in the AI business, taking in media and entertainment firms, advertisers, agencies and any brand running an active social presence.
Who this actually applies to, and why Brexit won’t save you
The Act’s territorial reach was deliberately built to mirror the GDPR’s, and it produces the same result: geography of incorporation is irrelevant. A UK company is in scope if it places an AI system on the EU market, or, the wider and more commonly overlooked trigger, if the output of its AI system is simply used within the EU. One EU customer interacting with a UK site’s chatbot, or one EU visitor served AI-written content, is enough to bring that interaction within the Act’s reach, regardless of where the company is registered, where its servers sit, or whether it has ever opened an EU office. A retailer shipping across the Channel, a SaaS platform with European sign-ups, or a content site with EU readers all clear that bar without trying to.
The penalties attached are real enough to matter at board level: up to €15 million or 3% of global annual turnover, whichever is higher, with a lower cap built in for SMEs. Enforcement sits with national market-surveillance authorities in the member states where the harm occurs, and not with any UK regulator, which is why so many British businesses have been slow to register the risk.
What this looks like in practice
Translated into the daily running of ecommerce sites or content-driven businesses, four categories of practical exposure stand out.
Customer-facing chatbots and virtual assistants need to identify themselves as AI at first contact, unless a shopper would obviously already know. A text bubble labelled “AI Assistant” clears this easily, but a conversational agent styled to sound like a named human staff member does not. Product and marketing imagery generated or manipulated by AI, such as model shots, virtual try-on visuals or video adverts need machine-readable marking under the provider-side rule, and if the generated content would pass as a real photograph of a real scene, the deployer-side deepfake disclosure applies too, meaning something a human visitor can actually see, not just metadata buried in the file.
AI-drafted blog posts, buying guides or comparison content published without meaningful human editing fall within the public-interest text obligation and need a visible label. The same content, if it goes through genuine editorial review with a named person or team taking responsibility for it, can rely on the human-review exemption instead. But the Commission’s guidance has clearly pointed out that a cursory skim does not count, the review has to be real and the responsibility has to be assignable to a real person. Content that is evidently artistic, satirical or fictional gets a lighter touch: disclosure is still required but only in a form that doesn’t get in the way of the work itself.
The most useful first step is for businesses to sort out where AI touches anything that ends up in front of a customer and clarify existing workflows. Disclosure design (where a label sits, how visible it is, whether it survives being cropped or shared) is worth treating as a genuine design problem rather than a compliance afterthought. The Commission’s own Code of Practice sets out preferred approaches to placement and wording. It is worth noting that generative AI systems already on the market before 2nd August 2026 have until 2nd December 2026 to implement the machine-readable marking specifically, and content published before the deadline does not need retroactive labelling.
Is this just the beginning?
It is no secret that the EU and many countries are seeking to regulate the spread of AI in our daily lives. In Britain, a comprehensive UK AI bill has been promised, deferred, and promised again since before the 2024 election; the government confirmed in mid-2025 that it would not appear before the following King’s Speech, and when that speech arrived in May 2026, it contained no comprehensive AI legislation at all. The government’s broader posture, reinforced by letters sent to nineteen sector regulators in January 2026, is that AI should mostly be regulated at the point of use by existing bodies rather than through a single cross-cutting AI law, a stance that has drawn criticism in the Lords, where peers have noted that a majority of the public favours a dedicated AI regulator instead.
For the time being, the sensible planning assumption is not that a UK equivalent will eventually simplify things, but that the two regimes will keep evolving independently, on their own timetables, indefinitely.
This article is intended as a general guide to a fast-moving area of regulation and does not constitute legal advice. Businesses with specific compliance questions should consult a qualified lawyer familiar with both the EU AI Act and UK regulatory law.