You are a deployer: the AI Act transparency rules for your own content

EU flags fly outside the European Commission headquarters in Brussels, source of the AI Act's transparency guidelines
Most organisations read the AI Act’s transparency rules as somebody else’s problem. Marking AI-generated content sounds like an obligation for the companies that build the models, and there is a comfortable logic to that: they generate it, they mark it.Article 50 does not work that way. Of its four substantive paragraphs, two impose duties directly on deployers, meaning any organisation using an AI system in the course of its own activity, and a fifth paragraph binds providers and deployers alike. Those duties have applied since 2 August 2026. If your communications team published a synthetic avatar of an executive, or your corporate affairs function used a model to draft something published on a matter of public interest, you are the regulated party. Where an agency produced the content on your behalf, who holds deployer status is a question the Guidelines leave to be settled in the contract, which is its own reason to look now. Worse, the classification step the obligation depends on is one that no part of the supply chain is required to give you.

 

Where the deployer obligations actually sit

Article 50 splits along a clean line. Article 50(1) and 50(2) bind providers: disclose that a system is AI, and mark generative outputs machine-readably. Article 50(3) and both subparagraphs of Article 50(4) bind deployers.

Article 50(3) covers emotion recognition and biometric categorisation: tell the people exposed to it. Article 50(4) is the one that reaches ordinary corporate content. Its first subparagraph requires deployers to disclose deep fakes. Its second requires disclosure of AI-generated or AI-manipulated text published to inform the public on matters of public interest, unless a narrow editorial exception applies.

Article 50(5) sits across all of it: the information must be clear and distinguishable, provided at the latest at the time of first interaction or exposure, and must meet applicable accessibility requirements.

 

Intent is not a defence, and neither is your footer

Three arguments put to the Commission during consultation, most prominently in an industry paper from the Computer and Communications Industry Association, are addressed in the Guidelines whose content the Commission approved on 20 July 2026. Each comes out the way deployers will not want.

Intent to deceive is irrelevant. The deep fake assessment is objective and does not require any intention on the deployer’s part to mislead. A cheerful internal-culture video does not escape because nobody meant harm by it.

Disclosure cannot live in your terms of service. The Guidelines name terms of use, manuals and content buried behind menu layers as failure modes rather than compliance. A page footer is not on that list, but it fails the same test for the same reason: if a reasonable person encountering the content would not see the disclosure at first exposure, it does not count.

The audience test is not the average user. The relevant audience is the reasonably foreseeable one, expressly including children, older people and those with lower AI literacy. That framing sits awkwardly with the argument, made during consultation, that rising public AI literacy should shrink the obligation over time. Designing your disclosure for the least AI-literate part of your foreseeable audience is the safer reading.

One more that catches marketing functions specifically: commercial advertising will rarely benefit from the artistic and creative regime. That regime is an attenuated obligation rather than an exemption in any case, and where informative and artistic characters combine, the informative character prevails.

 

What counts as a deep fake is broader than it sounds

The term suggests political disinformation and celebrity face-swaps. The Guidelines set out cumulative criteria that reach a great deal of routine corporate output: resemblance to existing persons, objects, places, entities or events, and content that would falsely appear authentic or truthful.

Note the subject list. No real person needs to be involved. Objects, places, entities and events count, so an AI-generated image of a plausible-looking facility, product or event is in scope on the same basis as a synthetic person.

The Guidelines’ own worked examples are the most useful compliance artefact available, because they are drawn from ordinary commercial practice rather than from disinformation research. Among them: a synthetic avatar of a chief executive congratulating employees, voice-cloned presenters on a podcast, celebrity influencer advertising, and AI-generated product imagery in packaging where it could mislead about the actual product. The Guidelines pair that last one with a counter-example, a real product placed on an AI-generated background, which is treated differently. If you recognise your own content calendar in that list, the obligation is yours.

Two limits are worth knowing, because they are genuine. Internal corporate communications and private professional correspondence are not “published”, so they fall outside the second subparagraph of Article 50(4). And content is outside the deep fake definition where it both defies the laws of nature and has no potential to mislead. Note that the test is conjunctive: obviously synthetic content can still be caught if it could mislead about something real.

 

The editorial exception is narrower than your publishing process

Article 50(4)’s second subparagraph exempts AI-generated public-interest text where a human has reviewed it and someone holds editorial responsibility. Most organisations assume their existing sign-off process qualifies. Read against the Guidelines, most sign-off processes do not.

Fact-checking is treated as a minimum requirement. Cursory approval does not qualify, and neither does the mere existence of an editorial policy. Any substantive AI intervention after editorial sign-off voids the exception entirely, which matters if your workflow runs a model over approved copy for length, tone or translation. And the person or function holding editorial responsibility should be identifiable, with their identity and contact details publicly findable.

Note also how wide “matters of public interest” runs. The Guidelines give the example of AI-manipulated corporate reports containing investor information, published on a listed company’s website. Legal commentators read sustainability reporting the same way, though that extension is their reading rather than the Commission’s example. Either way, this is not a rule about newsrooms.

 

The gap nobody in your supply chain fills

Here is the structural problem, and it is the reason this obligation is harder than it reads.

To label a deep fake, you first have to know that a given asset is one. The signal designed to carry exactly that fact is the provider’s machine-readable mark under Article 50(2). Yet deployers cannot discharge an Article 50(4) labelling duty by pointing at that mark: the two subsections are separate obligations, and the deployer’s is a perceptible disclosure to a human being.

Meanwhile, the one Code of Practice measure that would connect provider marking to deployer labelling is optional. Your classification step therefore has no supplier. You are required to know something about every published asset that nothing in the chain is obliged to tell you, and the unit of inventory is not the system but the individual output.

Practically, that means the work is a content inventory rather than a systems inventory. Which of your published assets were generated or materially altered by AI, through which pipeline, reviewed by whom, and how would you prove any of that in eighteen months? Article 50 mandates no retention period, because the automatic logging in Article 12 and the documentation retention in Article 18 belong to the high-risk regime. Every organisation is currently designing its own evidentiary standard for an obligation that will be judged retrospectively.

 

Where to start

Take the Guidelines’ example list and hold it against one quarter of your own published output. Where in-scope content turns up, it is usually in marketing or corporate communications rather than anywhere near the engineering estate, which is precisely why an AI governance programme scoped around the engineering function will miss it.

Then decide who owns the classification step, because it will not be the team that generates the content and it will not be your model vendor. That ownership question is an operating model question, and it is where AI governance work either becomes real or stays on a slide.

Zartis works on both halves: advising where Article 50 lands across your content estate, then building the classification, disclosure and evidence layers that make the answer defensible. Talk to us about an Article 50 readiness assessment.

Newsletter

Zartis AI Review

Your monthly source for AI and software related news.