For years, the question “Might we actually be required to label this?” was a footnote in marketing meetings. Since 2 August 2026 it has been a compliance task: on that day the transparency obligations under Article 50 of the EU AI Regulation (EU AI Act) became generally applicable and enforceable by the national authorities.
That affects almost every marketing team working with AI today: chatbots on the website, generated images in ads, AI voices in commercials, automatically produced texts. We set out what Article 50 actually requires, what it expressly does not require – and the seven steps small and medium-sized enterprises can take to put their marketing on a sound footing.
1. What Has Applied Since 2 August 2026
The AI Regulation enters into force in stages. For marketing and communications, 2 August 2026 is the stage with the greatest practical relevance: since that date the transparency and information obligations under Article 50 have been binding, and the supervisory powers and the sanctions regime apply as well.
One point matters for classification: Article 50 does not depend on a system’s risk class. It applies regardless of whether an application is classified as high-risk AI. What counts is solely what the system does – interact with people, generate or manipulate content, analyse emotions or biometric characteristics. That puts the classic marketing stack squarely within the scope.
Conversely, part of the regulation has been eased. For certain stand-alone high-risk applications under Annex III – in areas such as recruitment, creditworthiness assessment or education – the obligations were postponed to December 2027 as part of the so-called Digital Omnibus. The transparency obligations were expressly not affected by that postponement.
In short: the high-risk part has been deferred, the transparency part is live. Anyone betting in 2026 that “this only comes later” is confusing two completely different stages of the regulation.
2. The Four Transparency Obligations at a Glance
In practice, Article 50 is often reduced to “AI content has to be labelled”. That is too crude. The provision contains four distinct obligations, each with different addressees and different triggers:
- Paragraph 1 – disclose the interaction: systems that interact directly with people (typically chatbots and voice assistants) must make it recognisable that an AI is responding. Exception: it is obvious anyway from the context to a reasonably well-informed person.
- Paragraph 2 – mark synthetic content: providers of generative systems must mark their outputs – image, video, audio, text – in a machine-readable format and make them detectable as artificially generated or manipulated.
- Paragraph 3 – emotion recognition and biometric systems: anyone using emotion recognition or biometric categorisation must inform the people concerned about it.
- Paragraph 4 – deepfakes and texts on matters of public interest: deployers must disclose when content consists of AI-generated or manipulated depictions of real people, places or events – and when AI texts are published in order to inform the public on matters of public interest.
The comparison below shows what has actually shifted for day-to-day marketing practice.
Schematic comparison of the marketing-relevant obligations. As at: August 2026. Not legal advice.
3. Chatbots and AI Assistants: Disclosure at First Contact
The most common use case in SMEs is the website chat. Anyone using an AI assistant for enquiries, appointment booking or initial qualification must ensure that users know they are talking to a machine. And they must know it before they share their concerns and possibly personal data – not only in the privacy policy.
3.1 What Sound Implementation Looks Like
In practice, a clear, visible notice at the point where the dialogue begins is usually sufficient: a label on the chat widget, a first message from the assistant, or both. Effective means legible, not hidden, in the users’ language and not watered down by design tricks. An “AI assistant” in the avatar name plus a greeting that states the role covers the core of it.
3.2 The Exception – and Why You Should Not Rely on It
Article 50(1) removes the need for a notice where the AI nature is obvious to a reasonably well-informed person. The problem: “obvious” is an assessment that, in a dispute, someone else will make. Since implementation costs you almost nothing, the notice is the cheaper route than the argument about whether it was dispensable.
A common mistake: the notice sits in the terms of use while the bot acts in the dialogue as if it were a member of staff – complete with a first name and “let me just check that for you”. It is precisely this humanisation that creates the misunderstanding Article 50 is designed to prevent.
4. AI Images, Video and Audio: Marking and Deepfakes
With generated creatives, two obligations run in parallel, and separating them is the key to understanding the rules:
The machine-readable marking is owed by the provider. Whoever supplies the model must make the output technically detectable as synthetic. C2PA (Coalition for Content Provenance and Authenticity) has established itself as the technical reference standard – an open standard for cryptographically signed provenance records, supplemented by watermarks and secured metadata. As a marketing team, you do not have to generate this signature yourself.
The visible disclosure is owed by the deployer – but only for deepfakes. As soon as a creative depicts real people, places or events in a deceptively realistic way without things having happened that way, you must disclose that the content was artificially generated or manipulated. That covers campaigns with generated “testimonials”, AI voices of well-known people, or re-enacted scenes that come across as documentary footage.
4.1 The Quiet Pitfall: Your Own Workflow
The provider’s obligation comes to nothing if the signature is lost on the way to the ad. And that happens routinely: screenshots, resizing in older tools, aggressive image compression and some CMS pipelines strip metadata. So check the chain from generation to ad upload once – and keep the original files.
4.2 What the Platforms Are Now Doing Themselves
The major advertising platforms are following suit: Meta evaluates provenance signals and automatically adds a notice to the ads concerned, and Google displays information on how an ad was created in Search, YouTube and Discover. For you that means the label may appear without you setting it – and it looks more assured if you had planned for it anyway.
5. AI Texts: When Blog, Newsletter and Landing Page Must Be Labelled
Here the relief is greater than many headlines suggest. The disclosure obligation for AI texts in Article 50(4) is tied to two conditions: the text must be published in order to inform the public and must concern matters of public interest – what is meant here is news, politics and public debate.
The second qualification is decisive: the obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. A specialist article that is reviewed, expanded and owned by a human therefore does not trigger the labelling requirement under Article 50.
For most SME content – service pages, product copy, newsletters, guide articles – the obligation therefore rarely bites in any case. But anyone who merely claims editorial responsibility and publishes raw output unchecked loses precisely the exception they are invoking. The documented sign-off step is therefore not red tape; it is your evidence.
The practical core: it is not “used AI” that triggers the obligation, but “published unchecked”. A documented human sign-off is both a compliance building block and quality assurance – and it has a positive effect on your E-E-A-T signals.
6. Provider or Deployer? Why This Question Decides Your Obligations
The AI Regulation allocates obligations by role. As a marketing department or agency you are normally the deployer (in the wording of the regulation: deployer) – you use a system that someone else provides. Providers are the model and tool manufacturers.
- As a deployer you owe: disclosure for deepfakes, the information duty for emotion recognition and biometric systems, identifying your chatbot as AI and – outside the editorial exception – disclosure for AI texts on matters of public interest.
- As a deployer you do not owe: the technical, machine-readable marking of the model output. That is the provider’s obligation. You should, however, sensibly preserve it rather than destroy it.
- You become a provider if you place a system on the market under your own name or brand, or substantially modify a third-party system – for example with your own branded AI assistant as a product. The obligations then shift considerably.
For working with agencies and freelancers, one simple consequence follows: agree contractually who has used AI, which assets are generated and who ensures the labelling. Without that information you cannot meet your own obligation.
7. Fines, Supervision and the German Framework
Under Article 99(4) of the AI Regulation, breaches of Article 50 carry fines of up to 15 million euros or 3% of worldwide annual turnover – whichever amount is higher. For small and medium-sized enterprises the regulation provides for caps that take proportionality into account; the framework nevertheless remains uncomfortable.
In Germany the institutional framework is now in place: under the KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG, the German AI market surveillance and innovation promotion act), which the Bundestag passed on 11 June 2026 and which entered into force at the end of July 2026, the Bundesnetzagentur (Federal Network Agency) becomes the central market surveillance authority for enforcing the AI Regulation. It already runs an AI service desk and is building up coordination and supervision.
Realistically, the immediate risk for an SME is rarely the maximum fine – it is the second lever: competitors and industry associations. An unlabelled, deceptively realistic advertising depiction is at the same time a classic allegation of misleading advertising. Warning letters and injunction proceedings are the more likely route by which Article 50 becomes relevant in practice.
Please note: this article sets out the position as at August 2026 in practical terms and does not replace legal advice. Questions of interpretation around Article 50 – in particular the scope of the deepfake definition and the format and placement of notices – will be further specified through guidelines and a code of practice. For binding assessments, seek advice from a lawyer.
8. Checklist: Making Your Marketing AI-Act-Proof in 7 Steps
Would you like to set up your AI marketing cleanly and verifiably? Arrange a free initial consultation with our team.
9. Conclusion: Transparency Is Cheaper Than Its Reputation
Article 50 requires less than the excitement in August 2026 suggested – but it requires it bindingly. No company has to attach a warning notice to every AI-assisted sentence. But anyone who deploys chatbots, produces deceptively realistic depictions or publishes raw text unchecked has specific obligations and a real risk of sanctions.
The pragmatic route runs through order rather than fear: an inventory, a visible chatbot notice, a tested metadata chain, a documented sign-off. That can be set up in a single morning and will hold up over time. And it pays twice over: transparency about the use of AI has become a trust argument – particularly in markets where customers have long since learned to spot generic AI content.
Our assessment: the companies that label properly in 2026 lose no conversions – they gain credibility. The competitive advantage does not come from hiding AI, but from owning it with confidence.
Read also: Ethics, Law & Psychology: The Compass for Modern AI Marketing in Germany and Cookieless and Consent Mode v2 2026: How SMEs Stay Measurable.
10. FAQ: The Key Questions on the AI Disclosure Obligation
Do I have to label every text created with AI as AI content?
No. The disclosure obligation under Article 50(4) applies to texts published in order to inform the public on matters of public interest. It also does not apply where the content has undergone human review or editorial control and a person holds editorial responsibility for the publication. Typical marketing content such as service pages, product copy or reviewed specialist articles therefore does not normally trigger the obligation.
Is a note in the privacy policy enough for my chatbot?
No. Article 50(1) requires that people are able to recognise the AI interaction – and in good time, that is, at the start of the dialogue. A note that appears only in the privacy policy or in the terms of use does not meet this. What works in practice is a visible label on the chat widget combined with a first message that states the AI role.
Who has to mark AI images technically – me or the tool?
Machine-readable marking of synthetic outputs is an obligation of providers under Article 50(2), that is, the model and tool manufacturers; the technical reference standard is C2PA. As a deployer you do not have to generate this signature yourself. You should, however, preserve it in your workflow and additionally disclose it visibly wherever a creative depicts real people, places or events in a deceptively realistic way.
What fines apply for breaches of Article 50?
Article 99(4) of the AI Regulation provides for fines of up to 15 million euros or 3% of worldwide annual turnover for breaches of the transparency obligations – whichever amount is higher. Proportionate caps apply to small and medium-sized enterprises. In Germany, the Bundesnetzagentur (Federal Network Agency) has been the central market surveillance authority since the KI-MIG entered into force at the end of July 2026. In practical terms, competition-law warning letters for misleading advertising are also relevant.