EU AI Act Transparency Duty Takes Effect: The December Extension Doesn’t Cover Deployers
Privacy & Compliance

EU AI Act Transparency Duty Takes Effect: The December Extension Doesn’t Cover Deployers

Article 50 of the EU AI Act, the regulation’s transparency obligation, became applicable today. The number attached to it is a fine of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Stated that way, it sounds like a blanket duty to label AI-generated content. That duty doesn’t exist. Article 50 defines four narrow scenarios, split across two different actors, and much of an ordinary marketing workflow, ad copy included, sits outside all of them.

What Article 50 actually splits into

Two of the four duties sit with providers, the companies that build a system and place it on the market, per artificialintelligenceact.eu’s rundown of Article 50. Providers must design systems so a user is told they’re interacting with an AI (50(1)), and providers of generative AI systems must mark their outputs in a machine-readable format that’s detectable as artificially generated (50(2)).

The other two sit with deployers. Bratby Law defines a deployer as “the legal person under whose authority the system is used,” distinct from the provider that designed the system. Deployers must tell people exposed to emotion-recognition or biometric-categorisation systems that they’re being read that way (50(3)), and must disclose when they use AI to create deepfakes, or to publish AI-generated text meant to inform the public on matters of public interest, unless that text underwent human review or editorial control (50(4)).

The article isn’t limited to high-risk systems. Its stated purpose is to cut transparency risks such as impersonation, deception, manipulation and misinformation, which the article may reach in chatbots, generative tools, emotion-recognition systems, biometric-categorisation tools or deepfake technologies.

Does AI-generated ad copy need a label under the EU AI Act?

Usually no. Article 50(4) covers AI-generated text only when it’s published to inform the public on matters of public interest and hasn’t undergone human review or editorial control, a description that doesn’t fit routine ad copy. Lewis Silkin’s briefing, published July 31, states that routine AI-drafted advertising copy generally sits outside that scenario, provided it avoids claims relating to matters such as health, consumer safety or sustainability.

Label likely required Label likely not required
Deepfake images, audio or video that resemble existing people, objects, places, entities or events, and would falsely appear authentic or truthful to a person exposed to them Routine AI-drafted advertising copy that generally sits outside the text scenario, provided it avoids health, consumer-safety or sustainability claims
AI-generated text published to inform the public on matters of public interest, when it hasn’t undergone human review or editorial control Background tidying, lighting and colour adjustments, cosmetic touch-ups, or aesthetic background replacements and product re-scaling, unlikely to require a label
AI-drafted ad copy carrying claims about health, consumer safety or sustainability sits outside the routine-copy carve-out, so it has to be tested against the text scenario rather than assumed either way.

The deepfake test needs two conditions, not one

Lewis Silkin’s read of the guidance sets a two-part test for what counts as a deepfake under 50(4), and both parts have to hold. The content must resemble an existing person, object, place, entity or event, and it must “falsely appear to a person to be authentic or truthful.” Content that clears the first bar but not the second, or the reverse, doesn’t qualify.

“Existing” is read broadly: it covers subjects that “could plausibly exist, or could plausibly have existed in reality.” What falls outside is “genuinely fantastical content,” and the guidance’s own examples of that category are dragons and elephants driving cars. Lewis Silkin puts minor interventions on the other side of that line: background tidying, lighting and colour adjustments, cosmetic touch-ups, aesthetic background replacements and product re-scaling are unlikely to require a label. And the duty doesn’t reach backward: Lewis Silkin states that deepfakes created before today don’t need to be marked or labelled retroactively.

The December date belongs to providers, not deployers

The other date in play is 2 December. The AI Omnibus package gives providers of generative AI systems already on the market until then to meet the 50(2) machine-readable marking duty. That’s a provider obligation, on one limb, for systems that predate the rule. The extension reaches providers on that one limb; deployer duties applied from today, with no equivalent grace period.

elsop covered a different provider track earlier: the GPAI model-provider obligations, which run on their own calendar. A brand publishing AI-generated content isn’t a GPAI provider. It’s a deployer, using systems other companies built, and the deployer clock started today, not in December.

Guidance is here, but neither document is binding

The European Commission published its final Guidelines on the Article 50 transparency obligations on 20 July: 51 pages, built with input from member states, the AI Board and stakeholders through public consultation. The Guidelines are non-binding, but they’re expected to be the primary reference national authorities use when interpreting the obligations.

A second document runs alongside it: the Code of Practice on Transparency of AI-generated Content, assessed as adequate by the Commission and the AI Board. It’s voluntary, a route to demonstrate compliance rather than a requirement to. By the end of July, roughly 190 companies and organisations had signed it. A provider that skips it isn’t out of options; it has to show compliance “through alternative equivalently adequate means.”

What isn’t optional is the fine, once a breach occurs. Lewis Silkin’s line on it: “Non-compliant deployers face fines of up to €15 million or 3% of global annual turnover, whichever is higher.” PPC Land and Bratby Law both report that the obligation and the legal standing to fine for breaching it arrive on the same date, today. There’s no window where the duty exists on paper but can’t yet be acted on.

elsop covered a parallel move in US state privacy law last month: Connecticut’s amended privacy act now requires a controller to state in its privacy notice whether it collects, uses, or sells personal data to train large language models, covering internal use, sale to third parties, and vendors acting on its behalf. Different legal system, different trigger, but the same instinct to make the AI supply chain say out loud what it is doing.

Alex Savich

Digital marketing journalist covering MarTech, AI, SEO, and analytics for Elsop Insights.