Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

EU AI Act Article 50 Is 23 Days Away: The Chatbot Disclosure, Deepfake Labeling, and AI Content Transparency Checklist for Financial Services

EU AI Act Article 50 transparency obligations take effect August 2, 2026. Customer-facing chatbots must disclose AI status at first interaction. Deepfakes must be labeled. AI-generated public interest content must be flagged. Here's what financial services firms must do — and why the July 22 Code of Practice deadline still matters.

By Rebecca Leung · July 9, 2026 ·
Table of Contents

August 2, 2026 is 23 days away. If your firm deploys a customer-facing chatbot, uses generative AI to produce content EU users see, or creates any form of synthetic media — deepfakes, AI-synthesized voice, AI-manipulated images — you have three weeks to be in compliance with EU AI Act Article 50.

Most financial services firms know the August 2 headline. Far fewer have mapped what Article 50 actually requires of them, which provisions have grace periods and which don’t, or what the July 22 Code of Practice deadline means for their legal exposure — a deadline that is now just 12 days away.

TL;DR

  • EU AI Act Article 50 transparency obligations take effect August 2, 2026 — 23 days from today
  • Four specific obligations: chatbot disclosure (providers), machine-readable content marking (providers), deepfake labeling (deployers), AI-generated public interest text disclosure (deployers)
  • The AI Omnibus grants only one grace period — for machine-readable marking on existing systems until December 2, 2026. The other three requirements have no grace period
  • The July 22 Code of Practice signing deadline is 12 days away — signing gives you a presumption of conformity with Article 50(2) and Article 50(4), shifting the enforcement burden to regulators
  • Penalties: up to €15M or 3% of global annual turnover — enforced separately by national market surveillance authorities in each EU member state

What Article 50 Actually Is

Article 50 sits in the “limited risk” category of the EU AI Act — not a prohibited system, not a high-risk system, but a category with explicit transparency obligations that apply to a wide range of AI deployments. The official title is “Transparency obligations for providers and deployers of certain AI systems.”

The text creates four distinct obligations, applying to two different categories of actors (providers and deployers), covering four different types of AI interaction. They are not the same obligation stated four times. Getting one right does not satisfy the others.

The Four Obligations

Article 50(1): Chatbot and AI Interaction Disclosure

Who must comply: Providers of AI systems designed to interact with natural persons.

What it requires: The system must be designed to inform users that they are interacting with an AI — at the latest at the time of the first interaction.

The disclosure cannot be buried. The EU AI Office’s guidance is explicit: a statement buried in terms and conditions, a metadata watermark alone, or a vague reference to an “assistant” does not satisfy this requirement. The disclosure must be perceivable in the interaction itself.

Financial services applications:

  • Customer service chatbots for account inquiries, loan status, fraud alerts, and complaints
  • Robo-advisors and AI-driven investment recommendation interfaces
  • KYC and onboarding AI assistants
  • AI-powered mortgage or insurance pre-qualification systems

Exception: When the AI nature of the system is sufficiently obvious in context that a “normally informed user” would not reasonably need to be told. The Commission’s guidance suggests this is a narrow exception — “AI Assistant” branding may satisfy it in some contexts, but the test is unmistakable clarity, not brand familiarity.

No grace period. This applies from August 2, 2026.

Article 50(2): Machine-Readable Marking of AI-Generated Content

Who must comply: Providers of AI systems that generate audio, image, or video content.

What it requires: AI-generated or AI-manipulated audio, image, and video outputs must be marked in a machine-readable format that identifies them as artificially generated or manipulated. The marking must be effective, interoperable, robust, and reliable — standards currently being operationalized through the Code of Practice.

The AI Omnibus grace period: Generative AI systems already on the market before August 2, 2026 have until December 2, 2026 to implement compliant machine-readable marking. New GenAI systems deployed after August 2 have no grace period.

Financial services applications:

  • AI-generated images used in marketing or investor communications
  • Synthetic voice used in IVR systems or customer outreach
  • AI-generated video in client education, onboarding, or presentations
  • AI-manipulated imagery in ESG or annual reports

Article 50(3): Deepfake Disclosure

Who must comply: Deployers of AI systems that generate or manipulate image, audio, or video constituting a deepfake.

What it requires: The deployer must disclose that the content has been artificially generated or manipulated. This is a direct obligation on the deployer — the financial institution using the AI tool — not only the AI provider.

No grace period. This applies from August 2, 2026.

Financial services applications:

  • AI-synthesized spokesperson or digital human video in marketing
  • AI-manipulated voice in any customer-facing context
  • Digital employee or synthetic human representations in client interaction interfaces

Article 50(4): AI-Generated Text on Matters of Public Interest

Who must comply: Deployers of AI systems that generate or manipulate text published to inform the public on matters of public interest.

What it requires: Disclosure that the text has been artificially generated or manipulated.

Key exception: The obligation does not apply when the content has undergone substantive human review and a natural or legal person holds editorial responsibility for the publication. The human review must be substantive — not limited to superficial review or cursory approval. A compliance officer clicking “approve” on AI-generated text without actually reviewing its content does not satisfy this exception.

No grace period. This applies from August 2, 2026.

Financial services applications:

  • AI-generated market commentary or economic analysis distributed to retail or institutional clients
  • AI-generated press releases, earnings summaries, or investor communications
  • ESG or sustainability reports with substantial AI-generated content distributed publicly
  • AI-generated regulatory disclosure documents or consumer-facing policy communications

Provider vs. Deployer: Most Financial Services Firms Are Both

Understanding who has which obligation starts with knowing where you sit in the AI supply chain.

Provider means an entity that develops an AI system for placing on the market or putting into service. If your firm has fine-tuned a foundation model, built its own AI system, or is publishing an AI product for others to use, you are a provider.

Deployer means an entity that puts an AI system into use under its authority for purposes other than personal, non-professional activity. If you are using a third-party AI model to build a customer chatbot, you are a deployer.

Most financial services firms are deployers under Article 50(1) and (3) and (4) — they use third-party AI systems (OpenAI, Anthropic, Google, vendor-built) to power customer interactions and content generation. They may also be providers if they build or fine-tune AI systems for internal or external use.

One critical consequence: if you’re a deployer building on a third-party model, the chatbot disclosure obligation is on you, not just the model provider. Your vendor may or may not configure the model to include that disclosure by default. You need to verify the disclosure actually appears in the user experience — test it, document it.

The July 22 Code of Practice Deadline: 12 Days Away

The European AI Office published a Code of Practice on Transparency of AI-Generated Content in December 2025. It translates Article 50(2) and Article 50(4) obligations into specific technical and organizational measures for providers and deployers of GenAI systems.

Organizations that sign by July 22, 2026 receive a presumption of conformity with Article 50(2) and Article 50(4) obligations. This is the enforcement benefit that makes signing meaningful: rather than demonstrating to a national market surveillance authority that your practices comply, the authority bears the burden of demonstrating they do not.

The Code is technically voluntary. But given that Article 50(2) machine-readable marking involves technical implementation that is still being standardized, signing the Code provides both the legal protection and practical guidance for what “compliant” actually looks like.

How to sign: The signature form is submitted by email to the EU AI Office at [email protected] before July 22. This is a 12-day window. If your firm generates AI content for EU users and hasn’t signed, evaluate it now.

For a broader view of how Article 50 fits into the full EU AI Act compliance landscape for your deployed models, see the EU AI Act August 2 compliance checklist published earlier this month.

What the AI Omnibus Does and Doesn’t Change

The AI Omnibus — the provisional agreement reached by EU co-legislators in May 2026 — revised several timelines in the original AI Act. For Article 50 specifically, it created one grace period.

What the Omnibus changed: Existing generative AI systems already on the market before August 2, 2026 have until December 2, 2026 to implement the machine-readable marking requirement under Article 50(2).

What the Omnibus did not change:

  • Article 50(1) chatbot disclosure: August 2, 2026, no grace period
  • Article 50(3) deepfake disclosure: August 2, 2026, no grace period
  • Article 50(4) public interest text disclosure: August 2, 2026, no grace period

The Omnibus grace period applies narrowly to the technical machine-readable marking implementation for existing systems. It does not extend any of the disclosure and labeling requirements.

So What? The Three Actions Before August 2

1. Audit your EU-facing AI touchpoints. List every chatbot, AI-powered interface, GenAI content tool, and synthetic media system that touches EU users. For each, determine whether you’re the provider, the deployer, or both. Map which Article 50 obligations apply and what your current disclosure or labeling status is.

2. Fix the chatbot disclosure first. Article 50(1) is the highest-volume obligation for most financial services firms. If your chatbot doesn’t clearly state at the start of each conversation that the user is interacting with an AI system, update it before August 2. This is a change to the user interface — not a technical certification process. It is implementable in days.

3. Make the Code of Practice decision by July 22. If your firm generates AI audio, image, video, or text content for EU distribution, evaluate whether to sign the Code of Practice before July 22. The presumption of conformity benefit is real, and the Code provides practical implementation guidance for machine-readable marking that you’ll need eventually regardless.

For firms building or deploying AI in financial services, the Agentic AI Governance Framework post and SR 26-2 model risk management analysis cover the governance layer that sits behind these disclosure requirements.

If you’re looking for a structured way to inventory your AI use cases, tier them by regulatory applicability, and map which EU and US obligations apply to each model, the AI Risk Assessment Template & Guide covers exactly that — with worked examples for the deployment types most common in financial services.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does EU AI Act Article 50 require and when does it take effect?
Article 50 creates four transparency obligations effective August 2, 2026: (1) providers of chatbots and AI interaction systems must inform users they're interacting with AI at the start of each interaction; (2) providers of generative AI systems must mark AI-generated audio, image, and video content in machine-readable format; (3) deployers must label deepfake content as artificially generated; (4) deployers must label AI-generated text published to inform the public on matters of public interest. The AI Omnibus grants a grace period until December 2, 2026 for machine-readable marking on existing systems only — the other three obligations apply from August 2 with no grace period.
Does EU AI Act Article 50 apply to US financial services firms?
Yes, if your firm serves EU customers or deploys AI systems whose outputs reach EU residents. The EU AI Act has extraterritorial reach similar to GDPR: it applies to providers and deployers of AI systems that put outputs to use in the EU, regardless of where the provider or deployer is established. A US fintech with EU customers operating a chatbot or publishing AI-generated content for EU users is in scope for Article 50.
What specifically does chatbot disclosure require under Article 50(1)?
Providers must ensure users are informed they are interacting with an AI system at the latest at the time of the first interaction. The disclosure must appear in the interaction itself — not buried in a terms page, a metadata watermark, or a vague reference to an 'assistant.' For a chatbot, this means a clear, visible statement at the start of the conversation. One exception applies: when the AI nature of the system is so obvious that an ordinarily informed user would not reasonably need to be told.
What is the July 22 Code of Practice deadline and why does it matter?
The European AI Office's Code of Practice on Transparency of AI-Generated Content provides a voluntary implementation framework for Article 50(2) and Article 50(4). Organizations that sign by July 22, 2026 receive a 'presumption of conformity' with those specific obligations — shifting the burden of proof to regulators rather than requiring firms to prove their own compliance. Financial services firms with GenAI deployments serving EU users should evaluate signing before the deadline.
What penalties apply for violating EU AI Act Article 50?
Non-compliance with Article 50 can result in fines up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. These fines are enforced by national market surveillance authorities in each EU member state — enforcement can happen simultaneously across multiple jurisdictions. Each member state may enforce independently, and there is no single regulator to negotiate with.
Does the AI Omnibus change the August 2 Article 50 deadline?
Only for one obligation. The AI Omnibus provisional agreement of May 2026 grants existing generative AI systems already on the market before August 2, 2026 until December 2, 2026 to implement machine-readable marking (Article 50(2)). The other three obligations — chatbot disclosure (50(1)), deepfake labeling (50(3)), and public interest text disclosure (50(4)) — still apply from August 2, 2026 with no grace period for existing systems. Do not assume the Omnibus gives you a full extension.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.