Skip to content

AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001 · EU AI Act deep dive · lesson 6 of 17 · 16 min

Transparency duties: chatbots, synthetic content and deepfakes

The rules that touch almost every marketer

Article 50 is the part of the AI Act most likely to affect creators, agencies and marketing teams directly. It applies from 2 August 2026. It has four main duties, split between providers (who build the systems) and deployers (who use them).

The four duties

| Paragraph | Who | Duty | Example | |---|---|---|---| | 50(1) | Providers of AI systems intended to interact directly with people | Design the system so people are informed they are interacting with AI, unless obvious to a reasonably well-informed person | Website chatbot, voice agent, AI companion | | 50(2) | Providers of AI systems generating synthetic audio, image, video or text | Mark outputs in a machine-readable format so they are detectable as artificially generated or manipulated, as far as technically feasible | Image generators, voice generators, video tools | | 50(3) | Deployers of emotion recognition or biometric categorization systems | Inform the people exposed | Retail analytics that estimate age or mood (where lawful) | | 50(4) | Deployers generating or manipulating image, audio or video that constitute a deepfake | Disclose that the content is artificially generated or manipulated | A realistic AI video of a person saying things they never said | | 50(4) | Deployers generating or manipulating text published to inform the public on matters of public interest | Disclose, unless the text has undergone human review or editorial control and someone holds editorial responsibility | An AI-written news-style article about an election |

Information must be given clearly and distinguishably, at the latest at the time of first interaction or exposure, and meet accessibility requirements.

Deepfake means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

Artistic, creative, satirical or fictional works: where the content is evidently part of such a work, the deepfake disclosure is limited to disclosing the existence of generated or manipulated content in an appropriate manner that does not hamper display or enjoyment of the work.

The grace period and the Code of Practice

  • The 2026 Omnibus gave providers whose generative systems were placed on the market before 2 August 2026 a grace period until 2 December 2026 for the 50(2) machine-readable marking duty. Other Article 50 duties, including chatbot disclosure and deepfake labeling, apply from 2 August 2026.
  • The Commission facilitated a Code of Practice on marking and labelling AI-generated content, finalized in June 2026. It is voluntary but is expected to be a key reference for showing compliance. It covers technical marking (such as watermarks, metadata and fingerprinting, often layered) for providers, and practical labeling for deployers, including a common EU icon and alternatives such as audio disclaimers for audio-only content. Check the final text for exact recommendations.

What this means in practice for marketers

Chatbots and voice agents. Say it up front: "Hi, I'm Aria, the virtual assistant for Nova Dental." Do not design personas that deny being AI when asked.

Synthetic ad creative. Most AI-assisted marketing imagery (a stylized background, an illustrated product scene) is not a deepfake because it would not falsely appear authentic. But realistic images or video of real people, real places or real events do trigger 50(4). A realistic AI video of a real CEO endorsing a product, or of a named city after a flood, needs disclosure.

Voice clones. A cloned voice of a real person saying new words is audio that resembles an existing person. Treat it as a deepfake for disclosure purposes, in addition to needing the person's consent (Module 6 and the voice course cover consent).

Blog and news-style content. Marketing copy is generally not "public interest" text. But AI-written articles on politics, health policy or public events published to inform the public need disclosure unless a human editor reviewed them and holds editorial responsibility. Keep evidence of editorial review.

Layering: machine-readable plus human-visible

Providers mark content in machine-readable form (for example C2PA Content Credentials metadata and invisible watermarks). Deployers add human-visible labels where Article 50(4) applies. Platforms add their own labels. These layers complement each other. Do not strip metadata from generated assets in your export pipeline without a reason.

Worked example: a Lahore agency's campaign for an EU fashion client

| Asset | Deepfake? | Action | |---|---|---| | AI-generated abstract backgrounds | No | No AI Act label needed; keep Content Credentials metadata | | Realistic AI model wearing the dress (not a real person) | Possibly: realistic person who does not exist; not resembling an existing person, but assess whether it would appear authentic in context | Agency policy: label "AI-generated model"; also consider consumer law on misleading product depiction | | Voice-over cloned from the brand founder, with written consent | Yes (resembles an existing person) | Disclose AI voice in the ad or description; keep consent record | | Website chatbot for the campaign | Transparency 50(1) | Opening message states it is an AI assistant |

Hands-on: disclosure snippets

Chatbot opening line:
"Hi! I'm Nova's AI assistant. I can help with orders and sizing. You can ask for a human at any time."

Video lower-third or end card (deepfake/voice clone):
"This video contains AI-generated voice and imagery."

Audio-only ad (spoken at start or end):
"This ad uses an AI-generated voice."

Social caption:
"Made with AI: product scenes and voice-over are AI-generated. #AIgenerated"

Image alt-text/metadata note:
"AI-generated image. Content Credentials attached."

Measuring compliance

  • 100% of chatbots and voice agents open with an AI disclosure (test monthly).
  • Asset register records, for each synthetic asset: tool, whether it is a deepfake under the definition, label applied, consent record if a real person is involved.
  • Export pipeline preserves provenance metadata (spot-check files).

Pitfalls

  • Believing "we're only the deployer" removes all duties. 50(3) and 50(4) are deployer duties.
  • Hiding disclosures in terms and conditions. They must be clear and at the latest at first exposure.
  • Relying solely on platform labels. They may not satisfy your own obligations.

Video lecture: Transparency duties: chatbots, synthetic content and deepfakes

Lecture coming soon · 13 chapters · about 9 minutes. Read the full transcript below.

  1. Article 50 transparency
  2. Why it matters
  3. Four duties
  4. Analogy: food labels
  5. What is a deepfake?
  6. Public-interest text
  7. Timing and the labeling code
  8. Worked example: Lahore agency, EU client
  9. Disclosure that works
  10. Example 2: online bakery
  11. Common mistakes
  12. Watch me do it: synthetic asset register
  13. Recap and next step

Lecture transcript

Article 50 transparency

If you run a chatbot, publish AI-generated images or video, or use a cloned voice, this lesson is about you. Article fifty of the EU AI Act sets transparency duties that apply from the second of August twenty twenty-six, and they reach deep into everyday marketing. By the end, you'll know the four duties, who carries each one, what counts as a deepfake, and exactly how to label content without ruining your creative.

Why it matters

Why does this matter for everyday marketing? Because Article fifty is the part of the Act most teams will touch weekly. Every chatbot on a website, every AI voice on a phone line, every realistic synthetic image of a real person or place, and every AI-written article on public issues is in scope. It's also the most visible: customers, journalists and competitors can see your disclosures, or notice their absence. Getting it right is cheap and builds trust. Getting it wrong is public.

Four duties

There are four duties. First, providers of systems that interact with people, like chatbots and voice agents, must design them so people know they're talking to AI, unless it's obvious. Second, providers of systems that generate synthetic audio, images, video or text must mark outputs in a machine-readable way, so they're detectable as AI-generated. Third, deployers of emotion recognition or biometric categorization must tell the people exposed. And fourth, deployers who publish deepfakes, or AI-generated text meant to inform the public on matters of public interest, must disclose it.

Analogy: food labels

An analogy: think of Article fifty like labels on food packaging. The manufacturer prints a barcode and batch number that machines can read. That's machine-readable marking by the provider. The shop puts clear signs on anything that might confuse customers, like 'contains nuts'. That's your visible disclosure as a deployer. And the purpose isn't to stop anyone selling food. It's to make sure people aren't misled about what they're consuming. Labels only work if they're visible at the point of decision, not hidden in the small print.

What is a deepfake?

What counts as a deepfake? AI-generated or manipulated image, audio or video that resembles existing persons, objects, places, entities or events, and would falsely appear authentic. So a stylized AI background isn't a deepfake. A realistic video of a real CEO endorsing a product is. So is a realistic image of a named city after a flood that never happened. And a cloned voice of a real person saying new words resembles an existing person, so treat it as a deepfake. For clearly artistic, satirical or fictional works, the disclosure can be lighter, done in a way that doesn't spoil the work.

Public-interest text

And what about text? AI-generated text published to inform the public on matters of public interest must be disclosed, unless it went through human review or editorial control and someone holds editorial responsibility. Ordinary marketing copy is generally not public-interest text. But an AI-written article about elections, public health, or a public event is. The practical move: if you publish that kind of content, have a named editor review it, and keep evidence that they did.

Timing and the labeling code

Two timing details. The twenty twenty-six Omnibus gave providers whose generative systems were already on the market before August twenty twenty-six a grace period until the second of December twenty twenty-six for machine-readable marking. Everything else, including chatbot disclosure and deepfake labeling, applies from August twenty twenty-six. And the Commission facilitated a Code of Practice on marking and labelling AI-generated content, finalized in June twenty twenty-six. It covers technical marking like watermarks and metadata, and practical labels, including a common EU icon and audio disclaimers for audio-only content.

Worked example: Lahore agency, EU client

Here's a campaign from a Lahore agency for an EU fashion client. Abstract AI backgrounds: not deepfakes, no label required, but keep the Content Credentials metadata. A realistic AI model wearing the dress, who isn't a real person: a judgment call, and the agency labels it anyway to be safe and to avoid misleading shoppers. A voice-over cloned from the brand's founder, with written consent: that's a deepfake, so disclose it and keep the consent record. And the campaign chatbot: it opens by saying it's an AI assistant.

Disclosure that works

Let's get practical with wording. For a chatbot, open with something like: Hi, I'm Nova's AI assistant, I can help with orders and sizing, and you can ask for a human at any time. For video with a cloned voice or synthetic people: this video contains AI-generated voice and imagery. For audio-only ads, say it out loud at the start or end. And keep provenance metadata in your exports. Machine-readable marks from the provider, visible labels from you, and platform labels are layers that work together. You'll find copy-paste snippets in the lesson text.

Example 2: online bakery

A simple example. A bakery in Manchester sells online across the EU and adds an AI chat assistant to its website. What does it need? A first message that says it's an AI assistant, an easy way to reach a human, and nothing more exotic. The product photos are real, so there's nothing to label there. And when the bakery later uses an AI tool to create a playful cartoon of its founder as a baker superhero, that's evidently creative and not a realistic deepfake. A light touch mention that it's AI-generated is still good practice.

Common mistakes

Common mistakes. Believing that because you're only the deployer, you have no duties, when deepfake and public-interest text disclosures are deployer duties. Hiding disclosures in terms and conditions, when they must be clear and given at first exposure. And relying only on platform labels. A social network's AI label may not satisfy your own obligations, and it won't appear on your website, emails or radio ads.

Watch me do it: synthetic asset register

Watch me do it. I open a new tab called Synthetic asset register. Columns: Asset, Channel, Tool, Real person or place, Deepfake, Label used, Consent record, Metadata kept. Asset one: a sunset background for an Instagram post. Real person or place? No. Deepfake? No. Label: platform AI setting only, metadata kept: yes. Asset two: a realistic video where our founder's cloned voice explains a new product. Real person? Yes. Deepfake? Yes, audio resembles an existing person. Label: an on-screen line saying this video uses an AI-generated voice, plus a spoken tag at the end. Consent record: link to the signed consent form. Asset three: a news-style article about new public health guidance, drafted with AI. That's public-interest text, so I check: did a named editor review it and take responsibility? Yes, and I link the review log, so no AI label is legally required, though our policy adds a small note anyway. Last, I open our website chatbot and check the first message. It says hi, how can I help. I change it to: hi, I'm Nova's AI assistant.

Recap and next step

Recap. Four duties: chatbot disclosure and machine-readable marking for providers, emotion and biometric notices and deepfake and public-interest text disclosure for deployers. Deepfakes are realistic content resembling real people, places or events, and voice clones count. Disclose clearly, at first exposure, not in small print. Your next step: build an asset register for synthetic content. For each asset, record the tool, whether it's a deepfake, the label you applied, and any consent record. Then test that every chatbot you run discloses itself in its first message.

Key takeaways

  • Article 50 applies from 2 August 2026: chatbot disclosure and machine-readable marking (providers); emotion/biometric notices, deepfake and public-interest text disclosure (deployers).
  • A deepfake is realistic content resembling existing people, places, objects or events that would falsely appear authentic; voice clones of real people count.
  • Existing generative systems got a grace period to 2 December 2026 for machine-readable marking only.
  • Disclose clearly at first exposure, keep provenance metadata, and keep a synthetic asset register with consent records.

Try it

Create a synthetic asset register for your last campaign. Classify each asset (deepfake or not), record the label applied, and add consent evidence for any real person's likeness or voice.