For years, the question “Might we actually be required to label this?” was a footnote in marketing meetings. Since 2 August 2026 it has been a compliance task: on that day the transparency obligations under Article 50 of the EU AI Regulation (EU AI Act) became generally applicable and enforceable by the national authorities.

That affects almost every marketing team working with AI today: chatbots on the website, generated images in ads, AI voices in commercials, automatically produced texts. We set out what Article 50 actually requires, what it expressly does not require – and the seven steps small and medium-sized enterprises can take to put their marketing on a sound footing.

AI disclosure obligations 2026: Article 50 EU AI Act in marketing – Grünberg.Digital. AI blog
Context

1. What Has Applied Since 2 August 2026

The AI Regulation enters into force in stages. For marketing and communications, 2 August 2026 is the stage with the greatest practical relevance: since that date the transparency and information obligations under Article 50 have been binding, and the supervisory powers and the sanctions regime apply as well.

One point matters for classification: Article 50 does not depend on a system’s risk class. It applies regardless of whether an application is classified as high-risk AI. What counts is solely what the system does – interact with people, generate or manipulate content, analyse emotions or biometric characteristics. That puts the classic marketing stack squarely within the scope.

Conversely, part of the regulation has been eased. For certain stand-alone high-risk applications under Annex III – in areas such as recruitment, creditworthiness assessment or education – the obligations were postponed to December 2027 as part of the so-called Digital Omnibus. The transparency obligations were expressly not affected by that postponement.

In short: the high-risk part has been deferred, the transparency part is live. Anyone betting in 2026 that “this only comes later” is confusing two completely different stages of the regulation.

Overview

2. The Four Transparency Obligations at a Glance

4
transparency obligations are set out in Article 50 – not one blanket “AI label”
15m
euros in fines – or 3% of worldwide annual turnover, whichever is higher
02/08
2026: since this day the obligations have been binding and enforceable by the authorities

In practice, Article 50 is often reduced to “AI content has to be labelled”. That is too crude. The provision contains four distinct obligations, each with different addressees and different triggers:

  • Paragraph 1 – disclose the interaction: systems that interact directly with people (typically chatbots and voice assistants) must make it recognisable that an AI is responding. Exception: it is obvious anyway from the context to a reasonably well-informed person.
  • Paragraph 2 – mark synthetic content: providers of generative systems must mark their outputs – image, video, audio, text – in a machine-readable format and make them detectable as artificially generated or manipulated.
  • Paragraph 3 – emotion recognition and biometric systems: anyone using emotion recognition or biometric categorisation must inform the people concerned about it.
  • Paragraph 4 – deepfakes and texts on matters of public interest: deployers must disclose when content consists of AI-generated or manipulated depictions of real people, places or events – and when AI texts are published in order to inform the public on matters of public interest.

The comparison below shows what has actually shifted for day-to-day marketing practice.

Marketing practice: until July 2026 vs. since 2 August 2026
AI Disclosure 2026: Article 50 AI Act in Marketing until July 2026 since 2 Aug 2026 notice voluntary, often in the imprint disclosure at first contact mandatory metadata usually stripped machine-readable marking (C2PA) realistic composites in a grey area deepfake disclosure by the deployer no AI-specific fine framework up to 15m euros or 3% of turnover Chatbot Image/video Deepfake Sanction

Schematic comparison of the marketing-relevant obligations. As at: August 2026. Not legal advice.

Customer dialogue

3. Chatbots and AI Assistants: Disclosure at First Contact

The most common use case in SMEs is the website chat. Anyone using an AI assistant for enquiries, appointment booking or initial qualification must ensure that users know they are talking to a machine. And they must know it before they share their concerns and possibly personal data – not only in the privacy policy.

3.1 What Sound Implementation Looks Like

In practice, a clear, visible notice at the point where the dialogue begins is usually sufficient: a label on the chat widget, a first message from the assistant, or both. Effective means legible, not hidden, in the users’ language and not watered down by design tricks. An “AI assistant” in the avatar name plus a greeting that states the role covers the core of it.

3.2 The Exception – and Why You Should Not Rely on It

Article 50(1) removes the need for a notice where the AI nature is obvious to a reasonably well-informed person. The problem: “obvious” is an assessment that, in a dispute, someone else will make. Since implementation costs you almost nothing, the notice is the cheaper route than the argument about whether it was dispensable.

A common mistake: the notice sits in the terms of use while the bot acts in the dialogue as if it were a member of staff – complete with a first name and “let me just check that for you”. It is precisely this humanisation that creates the misunderstanding Article 50 is designed to prevent.

Creatives

4. AI Images, Video and Audio: Marking and Deepfakes

With generated creatives, two obligations run in parallel, and separating them is the key to understanding the rules:

The machine-readable marking is owed by the provider. Whoever supplies the model must make the output technically detectable as synthetic. C2PA (Coalition for Content Provenance and Authenticity) has established itself as the technical reference standard – an open standard for cryptographically signed provenance records, supplemented by watermarks and secured metadata. As a marketing team, you do not have to generate this signature yourself.

The visible disclosure is owed by the deployer – but only for deepfakes. As soon as a creative depicts real people, places or events in a deceptively realistic way without things having happened that way, you must disclose that the content was artificially generated or manipulated. That covers campaigns with generated “testimonials”, AI voices of well-known people, or re-enacted scenes that come across as documentary footage.

4.1 The Quiet Pitfall: Your Own Workflow

The provider’s obligation comes to nothing if the signature is lost on the way to the ad. And that happens routinely: screenshots, resizing in older tools, aggressive image compression and some CMS pipelines strip metadata. So check the chain from generation to ad upload once – and keep the original files.

4.2 What the Platforms Are Now Doing Themselves

The major advertising platforms are following suit: Meta evaluates provenance signals and automatically adds a notice to the ads concerned, and Google displays information on how an ad was created in Search, YouTube and Discover. For you that means the label may appear without you setting it – and it looks more assured if you had planned for it anyway.

Content

5. AI Texts: When Blog, Newsletter and Landing Page Must Be Labelled

Here the relief is greater than many headlines suggest. The disclosure obligation for AI texts in Article 50(4) is tied to two conditions: the text must be published in order to inform the public and must concern matters of public interest – what is meant here is news, politics and public debate.

The second qualification is decisive: the obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. A specialist article that is reviewed, expanded and owned by a human therefore does not trigger the labelling requirement under Article 50.

For most SME content – service pages, product copy, newsletters, guide articles – the obligation therefore rarely bites in any case. But anyone who merely claims editorial responsibility and publishes raw output unchecked loses precisely the exception they are invoking. The documented sign-off step is therefore not red tape; it is your evidence.

The practical core: it is not “used AI” that triggers the obligation, but “published unchecked”. A documented human sign-off is both a compliance building block and quality assurance – and it has a positive effect on your E-E-A-T signals.

Roles

6. Provider or Deployer? Why This Question Decides Your Obligations

The AI Regulation allocates obligations by role. As a marketing department or agency you are normally the deployer (in the wording of the regulation: deployer) – you use a system that someone else provides. Providers are the model and tool manufacturers.

  • As a deployer you owe: disclosure for deepfakes, the information duty for emotion recognition and biometric systems, identifying your chatbot as AI and – outside the editorial exception – disclosure for AI texts on matters of public interest.
  • As a deployer you do not owe: the technical, machine-readable marking of the model output. That is the provider’s obligation. You should, however, sensibly preserve it rather than destroy it.
  • You become a provider if you place a system on the market under your own name or brand, or substantially modify a third-party system – for example with your own branded AI assistant as a product. The obligations then shift considerably.

For working with agencies and freelancers, one simple consequence follows: agree contractually who has used AI, which assets are generated and who ensures the labelling. Without that information you cannot meet your own obligation.

Sanctions

7. Fines, Supervision and the German Framework

Under Article 99(4) of the AI Regulation, breaches of Article 50 carry fines of up to 15 million euros or 3% of worldwide annual turnover – whichever amount is higher. For small and medium-sized enterprises the regulation provides for caps that take proportionality into account; the framework nevertheless remains uncomfortable.

In Germany the institutional framework is now in place: under the KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG, the German AI market surveillance and innovation promotion act), which the Bundestag passed on 11 June 2026 and which entered into force at the end of July 2026, the Bundesnetzagentur (Federal Network Agency) becomes the central market surveillance authority for enforcing the AI Regulation. It already runs an AI service desk and is building up coordination and supervision.

Realistically, the immediate risk for an SME is rarely the maximum fine – it is the second lever: competitors and industry associations. An unlabelled, deceptively realistic advertising depiction is at the same time a classic allegation of misleading advertising. Warning letters and injunction proceedings are the more likely route by which Article 50 becomes relevant in practice.

Please note: this article sets out the position as at August 2026 in practical terms and does not replace legal advice. Questions of interpretation around Article 50 – in particular the scope of the deepfake definition and the format and placement of notices – will be further specified through guidelines and a code of practice. For binding assessments, seek advice from a lawyer.

Your action plan

8. Checklist: Making Your Marketing AI-Act-Proof in 7 Steps

Immediate measures for your marketing
1
Create an AI inventory List every system that interacts with customers or generates content: chatbot, image generator, text assistant, voice tool, ad automation. For each system, note the provider, the purpose of use and the responsible person.
2
Review the chatbot notice and move it to the front The notice belongs at the start of the dialogue, not in the privacy policy. Check the label, the greeting text and the mobile view – and avoid human names without clear identification.
3
Sort creatives by deepfake risk Clearly separate obviously illustrative motifs from depictions that show real people, places or events in a deceptively realistic way. Only the latter trigger the visible disclosure obligation – there you place a notice in the creative or directly in the ad copy.
4
Secure the metadata chain Test whether C2PA signatures and provenance metadata survive your route from generation through image editing and the CMS to the ad upload. Archive the original files and avoid screenshot workflows.
5
Document editorial sign-off Define who reviews and takes responsibility for texts before publication, and record this traceably – in the editorial plan, in the CMS or via a sign-off step in the workflow. That is your evidence for the exception covering AI texts.
6
Update agency and supplier contracts Add a duty to disclose the AI used and the assets generated, plus clear responsibility for labelling. Without this information you cannot meet your deployer obligations.
7
Train the team and name a responsible person The regulation requires AI literacy within the company. A short, documented training session plus a named responsible person closes the most common gap: nobody knows who decides.

Would you like to set up your AI marketing cleanly and verifiably? Arrange a free initial consultation with our team.

The bigger picture

9. Conclusion: Transparency Is Cheaper Than Its Reputation

Article 50 requires less than the excitement in August 2026 suggested – but it requires it bindingly. No company has to attach a warning notice to every AI-assisted sentence. But anyone who deploys chatbots, produces deceptively realistic depictions or publishes raw text unchecked has specific obligations and a real risk of sanctions.

The pragmatic route runs through order rather than fear: an inventory, a visible chatbot notice, a tested metadata chain, a documented sign-off. That can be set up in a single morning and will hold up over time. And it pays twice over: transparency about the use of AI has become a trust argument – particularly in markets where customers have long since learned to spot generic AI content.

Our assessment: the companies that label properly in 2026 lose no conversions – they gain credibility. The competitive advantage does not come from hiding AI, but from owning it with confidence.

Read also: Ethics, Law & Psychology: The Compass for Modern AI Marketing in Germany and Cookieless and Consent Mode v2 2026: How SMEs Stay Measurable.

Frequently asked questions

10. FAQ: The Key Questions on the AI Disclosure Obligation

Do I have to label every text created with AI as AI content?

No. The disclosure obligation under Article 50(4) applies to texts published in order to inform the public on matters of public interest. It also does not apply where the content has undergone human review or editorial control and a person holds editorial responsibility for the publication. Typical marketing content such as service pages, product copy or reviewed specialist articles therefore does not normally trigger the obligation.

Is a note in the privacy policy enough for my chatbot?

No. Article 50(1) requires that people are able to recognise the AI interaction – and in good time, that is, at the start of the dialogue. A note that appears only in the privacy policy or in the terms of use does not meet this. What works in practice is a visible label on the chat widget combined with a first message that states the AI role.

Who has to mark AI images technically – me or the tool?

Machine-readable marking of synthetic outputs is an obligation of providers under Article 50(2), that is, the model and tool manufacturers; the technical reference standard is C2PA. As a deployer you do not have to generate this signature yourself. You should, however, preserve it in your workflow and additionally disclose it visibly wherever a creative depicts real people, places or events in a deceptively realistic way.

What fines apply for breaches of Article 50?

Article 99(4) of the AI Regulation provides for fines of up to 15 million euros or 3% of worldwide annual turnover for breaches of the transparency obligations – whichever amount is higher. Proportionate caps apply to small and medium-sized enterprises. In Germany, the Bundesnetzagentur (Federal Network Agency) has been the central market surveillance authority since the KI-MIG entered into force at the end of July 2026. In practical terms, competition-law warning letters for misleading advertising are also relevant.

Stephan Michalik
About the Author
Stephan Michalik
Founder Grünberg.Digital. · CEO Flio Germany GmbH

Maximum performance through the synergy of experience and innovation: As Founder of Grünberg.Digital. and CEO of Flio Germany GmbH – a leading business incubator and enabler – Stephan Michalik designs holistic online marketing strategies. Whether precise SEA, high-revenue email marketing, or high-converting landing pages: He seamlessly combines these core disciplines with cutting-edge AI. The result: highly efficient, AI-powered marketing ecosystems for maximum digital advantage.

LinkedIn