Most coverage of the EU AI Act is written about high-risk systems, which is not where creative teams live. The part of the regulation that reaches a studio, an agency, or a production company using generative tools is Article 50, titled “Transparency obligations for providers and deployers of certain AI systems.” It is short, it is specific, and it is frequently misquoted. Everything quoted below is taken verbatim from the official text of Regulation (EU) 2024/1689 as published on EUR-Lex, so you can check each claim against the source at the bottom of this page.
Who Article 50 binds: providers and deployers
The article splits its duties between two roles. A provider is the party that develops and supplies the AI system: the company behind your image, video, or text generation tool. A deployer is the party using the system under its own authority: that is you, the creative team, when you run a generation for a client project. Most of what creative teams need to do under Article 50 comes from the deployer duties, but the provider duties matter to you too, because your compliance partly rides on the marking behaviour of the tools you choose.
What providers must do: machine-readable marking
Article 50(2) requires that providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content “shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.” The same paragraph contains an exception worth knowing precisely: the obligation “shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof.” In practical terms, a denoise pass or a routine cleanup tool is not what this paragraph is aimed at; a system that generates or substantially transforms content is.
For a creative team the consequence is a procurement question: which of your tools mark their outputs, in what format, and does that marking survive your pipeline. If your compositing or encoding steps strip the marking that the provider applied, you should know that, and your own disclosure duties do not disappear because a mark was lost in the render.
What deployers must do: the deep fake disclosure
Article 50(4) is the paragraph that reaches finished creative work. Its first sentence: “Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.” The regulation defines the term in Article 3(60): a deep fake “means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.” That definition is wider than the colloquial use of the word. A generated street scene that a viewer would take for a real photograph can fall inside it; the provision is not limited to face swaps of celebrities.
The artistic-work carve-out is lighter, not an exemption
The same paragraph contains the sentence creative teams care about most: “Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.”
Read it carefully: the obligation is limited, not removed. For an evidently artistic work you still disclose that generated or manipulated content exists; you are only freed from doing it in a way that damages the work, so a credit line or an accompanying notice can be enough where a burned-in label would not be required. Two practical points follow. First, someone on your team is making a classification decision, asset by asset, about whether the work is “evidently artistic” and what an appropriate manner of disclosure is. Second, if that classification is ever questioned, you will want a record of what was decided, by whom, and on what basis, because the decision itself is your defence.
A separate subparagraph covers text: deployers of a system that generates or manipulates text “which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated,” with an exception where the content “has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.” Marketing and entertainment copy is usually outside this subparagraph, but teams producing branded journalism or public-information campaigns should read it as applying to them.
How and when the disclosure must happen
Article 50(5) sets the manner and the moment: the information “shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure,” and it “shall conform to the applicable accessibility requirements.” Disclosure buried in a page nobody sees before viewing the content does not meet a first-exposure standard. Where and how the disclosure appeared is therefore itself a fact worth recording per publication.
The real timeline
The regulation was published in the Official Journal of the European Union on 12 July 2024 and, per Article 113, entered into force on the twentieth day following publication. The same article states the date that matters for Article 50: “It shall apply from 2 August 2026.” Some chapters started earlier, including the general provisions and prohibited practices from 2 February 2025 and the general-purpose AI rules from 2 August 2025, but the transparency obligations for content sit on the general application date. As of the date of this guide, that deadline has arrived: the obligation is current law in application, not a future plan.
The real penalty ceiling
Penalties for Article 50 sit in Article 99(4), which covers, at point (g), “transparency obligations for providers and deployers pursuant to Article 50.” Breaches in this tier “shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.” That is the ceiling for Article 50. Larger figures that circulate in coverage of the AI Act belong to other provisions of the regulation, not to the transparency duties discussed here, and quoting them against Article 50 overstates the exposure.
Two mitigating details are in the text itself. Article 99(6) states that “in the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.” And Article 99(7) directs authorities to weigh the nature, gravity and duration of the infringement when setting any fine. A ceiling is not a rate card, but it is also not a number a creative business can responsibly ignore.
What a creative team should record to be ready
Every duty above is answerable from a small set of facts, provided those facts were recorded when the work happened. Per asset, that means:
- whether the content is AI-generated or AI-manipulated at all, and which parts;
- whether it meets the Article 3(60) deep fake definition: does it resemble existing persons, objects, places, entities or events in a way a person could take for authentic;
- which system produced it, including tool, model, and version, and whether that provider marks outputs in a machine-readable format;
- where and how the disclosure was applied for each publication context, so first-exposure timing can be shown;
- if the artistic carve-out was relied on, the classification, who decided it, and when;
- the dates and the sign-off chain for all of the above.
A note on honesty, because it matters for compliance claims: a record like this proves what was captured, that it has not changed since, and when it existed. It does not prove which reference or input causally produced a given output, and no tooling currently can. Keep your compliance statements inside what your records actually demonstrate. For the delivery-side view of the same record, including the per-shot checklist clients ask for, see the companion guide How to document AI-generated work for client delivery.