Since 2 August 2026, new transparency rules under the European AI Act have applied across the EU. Article 50 introduces labeling requirements for certain AI systems and AI-generated or manipulated content.
For many startups, Article 50 may be the first part of the EU AI Act that requires practical action. Companies don't need to build foundation models or develop high-risk AI to fall within its scope. Depending on how the technology is implemented, everyday uses — from customer-support chatbots to AI-generated marketing content — may trigger transparency obligations.
In this explainer, we break down what startup founders need to know about the EU AI Act’s new transparency rules, including who must comply, which AI systems and content are covered, what must be labelled, and which expectations may apply.
For a broader overview of the legislation and how companies have responded, read our guide to everything you need to know about the EU AI Act.
What do the new AI transparency and labeling rules cover?
Unlike the AI Act's high-risk rules, Article 50 doesn’t depend on an AI system’s risk classification. Instead, its transparency obligations are triggered by how technology is designed or used and whether a company acts as a provider or deployer.
Article 50 covers four main areas:
- AI systems that interact directly with people
Who’s responsible: the provider
What it requires: providers must ensure that people are informed when they're interacting with an AI system, unless it's already obvious from the context
Startup examples: a company offering an AI-powered customer-support chatbot, virtual assistant or sales agent
- AI-generated or manipulated content
Who’s responsible: the provider
What it requires: providers of systems that generate synthetic images, audio, video or text must ensure that their outputs are marked in a machine-readable format and can be detected as AI-generated or manipulated.
Startup examples: a startup offering an AI tool that generates product images, advertising materials, voice recordings or videos
- Emotion recognition and biometric categorisation
Who’s responsible: the deployer
What it requires: companies using these systems must inform people exposed to them. They must also comply with applicable data-protection rules, including the GDPR.
Startup examples: sentiment-analysis tools in call centres or user-research platforms
An exception applies to systems authorised by law for detecting, preventing or investigating criminal offences, subject to appropriate safeguards.
- Deepfakes and certain AI-generated public-interest content
Who’s responsible: the deployer
What it requires: companies must disclose when image, audio or video content contains a deepfake. They must also label AI-generated or manipulated text published to inform the public about matters of public interest — unless it has undergone genuine human review or editorial control.
Startup examples: a company publishing an AI-generated article on public-interest matters such as elections, public health or climate policy without human editorial review
For deepfakes, there is no general editorial‑review exemption.
In all four cases, the disclosure must be clear and distinguishable. It must be provided no later than the person’s first interaction or exposure to the AI system or content.
A startup may act as both a provider and a deployer. A company that develops an AI system and offers it under its own trademark may qualify as a provider, even when the system relies on another company’s foundation model. When that company uses an AI system in its own operations, it may instead act as a deployer.
The distinction matters because each role carries different obligations., Startups should therefore assess their role separately for every AI product, feature, and internal use case.
How to label AI-generated content?
Article 50 distinguishes between two forms of transparency: machine-readable markings for software and visible labels for people.
Machine-readable markings
This means the AI-generated content must contain a technical marker that not only people but also software can detect. This could include:
- embedded metadata identifying the content as AI-generated;
- a digital watermark;
- provenance information, such as Content Credentials;
- another technical signal that a detection tool can recognize.
For example, an AI-generated image may look completely normal to a viewer, but its file could contain data allowing platforms or verification tools to identify it as artificially generated.
Visible labels
Deployers must provide a clear, perceivable disclosure when publishing deepfakes or covered public-interest text. Article 50 doesn’t prescribe one mandatory phrase of visual design, but the label must be easy to notice and displayed no later than a person’s first exposure to the content.
The EU has developed three optional icons:

- Partially AI-modified: for existing human-created content that has been altered using AI.
- Fully AI-generated: for content created entirely by AI, apart from the human prompt, without human-created elements or editorial control.
- Basic AI icon: indicates that AI was involved in creating or modifying the content. It can be accompanied by a more specific explanation, such as “voice generated with AI”.
The icons are available for downloading — here.
When text accompanies the icon, the European Commission recommends using plain language, such as “AI-generated”, “Partially modified with AI”. Labels should also be accessible to assistive technologies — for example, through alt text or ARIA labels.
The key dates that should be on the founder's compliance calendar
- 2 August 2026: most Article 50 transparency obligations became enforceable across the EU, including disclosures for chatbots, deepfakes, emotion-recognition systems and certain AI-generated public-interest texts
- 2 December 2026: the transition period ends for the machine-readable marking for generative AI systems placed on the market before 2 August 2026. This extension applies solely to technical watermarking obligations.
- 2 February 2027: providers that have signed the voluntary Code of Practice and use watermarking must implement an interoperability solution for watermark detection.
An important point adopted by the European Commission is that the rules are generally not retroactive. AI-generated content and deepfakes created before 2 August do not need to be labelled retrospectively.
For public-interest text, however, the publication date matters: content published on or after 2 August may require a label even if it was generated earlier. An AI-generated editorial drafted in July but published in August may therefore require disclosure unless it underwent genuine human review and qualifies for the editorial exemption.
What penalties could startups face?
The headline penalty for breaching Article 50 can result in a fine of up to €15 million or 3% of the company’s worldwide annual turnover for the previous financial year, whichever is higher.
For startups and other SMEs, however, the AI Act applies a different rule. Under Article 99(6), the maximum fine is the lower of those two amounts. As an example, for a startup generating €2 million in annual worldwide turnover, the maximum fine would be €60,000 — not €15 million.
These figures are maximum penalties, not automatic fees. Authorities must consider factors such as the severity or duration of the infringement, whether it was intentional, and the company’s cooperation. Nevertheless, non-compliance can still create significant financial and reputational risks.
What should founders do now?
For startups that haven't yet mapped their exposure, the practical starting point looks like this:
- Map AI use cases: review customer-facing chatbots, content and image generation tools, translation software, and any emotion-recognition or biometric systems.
- Identify your role: determine whether the company is acting as a provider, deployer, or both, including when using white-labelled or third-party AI systems.
- Review chatbot disclosures: inform users at the start of their first interaction with an AI system. The “obviousness” exception should be interpreted narrowly.
- Clarify vendor responsibilities: confirm whether third-party providers add the required machine-readable markings and define each party’s responsibilities contractually.
- Establish a real editorial review process: establish procedures for identifying deepfakes and covered public-interest text. If relying on the editorial-review exemption, document substantive human review and assign clear editorial responsibility.
- Monitor the voluntary Code of Practice: decide whether to sign the voluntary Code or use it as a compliance benchmark. The Commission and AI Board have recognised it as an adequate framework for demonstrating compliance with certain Article 50 obligations.
For a more detailed compliance checklist, see this KPMG Law guide.








