The European Commission has published guidelines clarifying the transparency duties of providers and deployers of AI systems under Article 50 of the AI Act. The obligations took effect on 2 August 2026 and address deception, impersonation, and manipulation. A deployer is an organization using an AI system under its authority, including systems operated on its behalf.
Deployers must inform people exposed to emotion-recognition or biometric-categorisation systems, whether used in real time or retrospectively. They must visibly or audibly disclose AI-generated or manipulated imagery, audio or video that constitutes a deepfake; relying solely on embedded machine-readable marking is insufficient. AI-generated text published to inform the public about matters of public interest must also be labelled unless it has undergone substantive human review or editorial control and a person or organization accepts editorial responsibility.
According to the European Commission, the intention behind the requirements are “To foster trust and integrity in the information ecosystem. People should know when they are interacting with AI or exposed to AI-generated content. This will help them make informed decisions, calibrate their trust and reliance on AI and avoid mis information or deception.”
For organizational AI governance, this requires an inventory identifying systems, outputs, audiences and deployment contexts; ownership; documented decisions on whether content falls within scope; and controls ensuring disclosures are accessible and retained when content is republished. Policies should distinguish genuine human review from superficial proofreading, cover third-party creators, and include procurement checks on providers’ technical marking. Adopting the Code of Practice may simplify evidence of compliance; otherwise equivalent measures must be demonstrated.
Article 2 of the EU AI Act makes it clear that Article 50 applies to:
- Providers placing AI systems on the EU market, regardless of where they are established.
- Deployers established in the EU.
- Providers and deployers established outside the EU where AI-generated output is intended to be used within the EU.
Industry comment
Veeam’s Senior Vice President and General Manager EMEA, Tim Pfaelzer shared his thoughts with Resilience Forward on the deadline and what organizations must do to meet these standards...
“The deadlines for elements of the EU AI Act have become a set of shifting goalposts, but despite the pushback, the August 2nd deadline still marks a major turning point for European organizations. While on the surface, the transparency requirements for AI governance and operational accountability might seem an easier ask than the delayed high-risk requirements, it’s far trickier to solve in practice. Something that enterprises will realise when they attempt to align their AI deployments with these requirements. It’s not about ticking a compliance checkbox; it’s about rethinking their entire data estate to create the audit trails, governance policies, and effective foundations needed to support AI at scale.
“While much of the conversation has been about the lack of clarity around the Act, the focus is on the wrong thing. Regulations could well be clearer, but transparency and explainability cannot be achieved through policy alone. To gain that visibility into data to see where it resides, how it’s used, who has access, and how it’s being used in AI decisions, most organizations will need a fundamental rethink of their data estate. Taking this proactive action to establish transparency, governance frameworks, and resilience strategies will be crucial, ensuring that the data powering AI is secure, governed, available and recoverable. Because AI outcomes are only as trustworthy as the data behind them.
“To invest successfully in AI tools, organizations must first unlock the transparency and explainability that is required from August 2nd for compliance through a fuller restructuring of their data estate. Without a strong, foundational trust layer, organizations risk creating new governance, security, and compliance challenges as quickly as they create business value. With AI, the greatest competitive advantage doesn’t necessarily come from the fastest deployment, but from the most trusted one. So this regulatory deadline should be viewed not as the finish line, but as a starting point for the resilient data infrastructure needed for confident AI innovation.”
AI agents and Article 50
Resilience Forward prompted ChatGPT (5.6 Sol) to consider how Article 50 applies to AI agents. The response was as follows:
AI agents are expressly contemplated by the guidance, but the EU AI Act does not treat them as a separate legal category. They remain ‘AI systems’; the applicable duties depend on what they do, whom they interact with and whether the organization is their provider or deployer.
| Agent use | Article 50 implication |
| Customer-facing chatbot, avatar or service agent | People must be clearly informed that they are interacting with AI from the beginning, unless this is already obvious. The Commission specifically identifies AI agents as directly interactive systems. |
| Background agent communicating only with systems or other agents | The interaction disclosure generally does not apply because no person interacts directly with it. |
| Agent generating deepfake audio, video or imagery | The deployer must provide a clear human-visible or audible disclosure; embedded metadata alone is insufficient. |
| Agent publishing public-interest information | AI-generated text must be labelled unless it receives substantive human review or editorial control and someone accepts editorial responsibility. |
| Agent using emotion recognition or biometric categorisation | People exposed to the system must be informed, including where analysis occurs retrospectively. |
The important complication is organizational status. An organization simply using a third-party agent will normally be a deployer. If it develops or commissions an agent and puts it into service under its own name, it may be the provider. For high-risk systems, rebranding, substantially modifying the agent or changing its purpose can also transfer provider responsibilities under Article 25.
Article 50 nevertheless addresses only transparency — not the central risks created by agency. An agent may autonomously access data, call tools, communicate externally, alter systems or initiate transactions without creating AI-generated ‘content’ covered by Article 50.
Agent governance therefore needs to go further:
- Define the agent’s permitted objectives, systems, data and actions.
- Give it a distinct identity and minimum privileges.
- Require human approval for consequential or irreversible actions.
- Preserve logs showing prompts, tool calls, decisions and outputs.
- Establish spending, communication and operational limits.
- Monitor behavioural drift and unexpected agent-to-agent delegation.
- Provide suspension, rollback and incident-response mechanisms.
- Train staff supervising agents, reflecting the Act’s AI-literacy obligation.
In short, Article 50 requires people to know when AI is involved; good agent governance must additionally control what authority the AI has once it becomes involved.






