Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Technology»What AI deploying organizations need to comply with and govern under  Article 50 of the AI Act (Page 15)
Technology

What AI deploying organizations need to comply with and govern under  Article 50 of the AI Act

August 4, 20266 Mins Read
European Union flag with twelve yellow stars surrounding a white AI circuit icon at the center.

The European Commission has published guidelines clarifying the transparency duties of providers and deployers of AI systems under Article 50 of the AI Act. The obligations took effect on 2 August 2026 and address deception, impersonation, and manipulation. A deployer is an organization using an AI system under its authority, including systems operated on its behalf.

Deployers must inform people exposed to emotion-recognition or biometric-categorisation systems, whether used in real time or retrospectively. They must visibly or audibly disclose AI-generated or manipulated imagery, audio or video that constitutes a deepfake; relying solely on embedded machine-readable marking is insufficient. AI-generated text published to inform the public about matters of public interest must also be labelled unless it has undergone substantive human review or editorial control and a person or organization accepts editorial responsibility.

According to the European Commission, the intention behind the requirements are “To foster trust and integrity in the information ecosystem. People should know when they are interacting with AI or exposed to AI-generated content. This will help them make informed decisions, calibrate their trust and reliance on AI and avoid mis information or deception.”

For organizational AI governance, this requires an inventory identifying systems, outputs, audiences and deployment contexts; ownership; documented decisions on whether content falls within scope; and controls ensuring disclosures are accessible and retained when content is republished. Policies should distinguish genuine human review from superficial proofreading, cover third-party creators, and include procurement checks on providers’ technical marking. Adopting the Code of Practice may simplify evidence of compliance; otherwise equivalent measures must be demonstrated.

Article 2 of the EU AI Act makes it clear that Article 50 applies to:

  • Providers placing AI systems on the EU market, regardless of where they are established.
  • Deployers established in the EU.
  • Providers and deployers established outside the EU where AI-generated output is intended to be used within the EU.

Industry comment

Veeam’s Senior Vice President and General Manager EMEA, Tim Pfaelzer shared his thoughts with Resilience Forward on the deadline and what organizations must do to meet these standards...

“The deadlines for elements of the EU AI Act have become a set of shifting goalposts, but despite the pushback, the August 2nd deadline still marks a major turning point for European organizations. While on the surface, the transparency requirements for AI governance and operational accountability might seem an easier ask than the delayed high-risk requirements, it’s far trickier to solve in practice. Something that enterprises will realise when they attempt to align their AI deployments with these requirements. It’s not about ticking a compliance checkbox; it’s about rethinking their entire data estate to create the audit trails, governance policies, and effective foundations needed to support AI at scale.

“While much of the conversation has been about the lack of clarity around the Act, the focus is on the wrong thing. Regulations could well be clearer, but transparency and explainability cannot be achieved through policy alone. To gain that visibility into data to see where it resides, how it’s used, who has access, and how it’s being used in AI decisions, most organizations will need a fundamental rethink of their data estate. Taking this proactive action to establish transparency, governance frameworks, and resilience strategies will be crucial, ensuring that the data powering AI is secure, governed, available and recoverable. Because AI outcomes are only as trustworthy as the data behind them.

“To invest successfully in AI tools, organizations must first unlock the transparency and explainability that is required from August 2nd for compliance through a fuller restructuring of their data estate. Without a strong, foundational trust layer, organizations risk creating new governance, security, and compliance challenges as quickly as they create business value. With AI, the greatest competitive advantage doesn’t necessarily come from the fastest deployment, but from the most trusted one. So this regulatory deadline should be viewed not as the finish line, but as a starting point for the resilient data infrastructure needed for confident AI innovation.”


AI agents and Article 50

Resilience Forward prompted ChatGPT (5.6 Sol) to consider how Article 50 applies to AI agents. The response was as follows:

AI agents are expressly contemplated by the guidance, but the EU AI Act does not treat them as a separate legal category. They remain ‘AI systems’; the applicable duties depend on what they do, whom they interact with and whether the organization is their provider or deployer.

Agent useArticle 50 implication
Customer-facing chatbot, avatar or service agentPeople must be clearly informed that they are interacting with AI from the beginning, unless this is already obvious. The Commission specifically identifies AI agents as directly interactive systems.
Background agent communicating only with systems or other agentsThe interaction disclosure generally does not apply because no person interacts directly with it.
Agent generating deepfake audio, video or imageryThe deployer must provide a clear human-visible or audible disclosure; embedded metadata alone is insufficient.
Agent publishing public-interest informationAI-generated text must be labelled unless it receives substantive human review or editorial control and someone accepts editorial responsibility.
Agent using emotion recognition or biometric categorisationPeople exposed to the system must be informed, including where analysis occurs retrospectively.

The important complication is organizational status. An organization simply using a third-party agent will normally be a deployer. If it develops or commissions an agent and puts it into service under its own name, it may be the provider. For high-risk systems, rebranding, substantially modifying the agent or changing its purpose can also transfer provider responsibilities under Article 25.

Article 50 nevertheless addresses only transparency — not the central risks created by agency. An agent may autonomously access data, call tools, communicate externally, alter systems or initiate transactions without creating AI-generated ‘content’ covered by Article 50.

Agent governance therefore needs to go further:

  • Define the agent’s permitted objectives, systems, data and actions.
  • Give it a distinct identity and minimum privileges.
  • Require human approval for consequential or irreversible actions.
  • Preserve logs showing prompts, tool calls, decisions and outputs.
  • Establish spending, communication and operational limits.
  • Monitor behavioural drift and unexpected agent-to-agent delegation.
  • Provide suspension, rollback and incident-response mechanisms.
  • Train staff supervising agents, reflecting the Act’s AI-literacy obligation.

In short, Article 50 requires people to know when AI is involved; good agent governance must additionally control what authority the AI has once it becomes involved.

Europe
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleZero Networks launches Least Agency Enforcement to help organizations safely deploy AI agents
Next Article People risks: the traveller you cannot locate

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
The word Glossary surrounded by letter tiles to illustrate The International Resilience Glossary.

DRI International publishes updated International Glossary for Resilience

February 27, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?