Does every text prepared with ChatGPT need an AI label from 2 August 2026? No. The AI Act uses different rules for conversations with AI, realistic synthetic media and text about matters of public interest.
This guide turns Article 50 into practical decisions for e-commerce, marketing, editorial, sales and customer-service teams. It is based on Regulation (EU) 2024/1689 and the final European Commission Guidelines published on 20 July 2026.
Legal position and sources checked on 20 July 2026. Article 50 applies from 2 August 2026. The Commission published its final Guidelines on the date this guide was updated. Poland’s national implementation act had completed the parliamentary stage, but we found no official confirmation of signature and promulgation by the research cut-off.
AI Act and AI content: the essential answers
Start with four questions. Each one points to the most likely answer.
- Is a person talking directly to an AI system? If so, the system should say it is AI no later than the start of the conversation, unless that is obvious to a typical user. This includes chatbots and agents that conduct correspondence by themselves.
- Could an AI-generated or altered image, recording or video be mistaken for authentic material? If it realistically depicts a person, object, place or event, its artificial origin will usually need a visible or audible disclosure.
- Is a business publishing AI-generated or substantially AI-altered text to inform people about politics, law, health, safety, the environment or another matter of public interest? If so, the text will usually need an AI disclosure.
- Did a competent person genuinely check the facts, sources and meaning, have power to change or stop the text, and did a person or organisation accept responsibility for publication? This substantive fact-and-source check by a competent person, together with editorial responsibility, is what this guide means by human review. If both are present, a visible AI disclosure may not be required. This exception is for public-interest text, not realistic images, audio or video.
The Commission’s final Q&A supports these distinctions.
Quick decision table
| Situation | Most likely result | What decides it |
|---|---|---|
| An AI-generated article on EU policy is published automatically | Disclose the text | It concerns a matter of public interest and received no substantive review |
| The same article is checked by a competent editor and the publisher accepts responsibility | Disclosure may not be required | Substantive review and editorial responsibility are both present |
| A routine product description gives colour and dimensions | Usually do not disclose | A product page is not a matter of public interest merely because it is online |
| A supplement description says it cures disease or a product is safe | Assess it carefully | Public health and consumer safety may be matters of public interest |
| AI virtually furnishes a real photograph of an existing flat | Usually disclose the image | It may look like the authentic condition of a real property |
| A customer-support bot talks to a customer | The system should say it is AI | The person is interacting directly with the system |
| An employee checks and sends an AI-assisted email | Usually no Article 50(1) disclosure | A person, not the AI, is communicating with the recipient |
| An AI agent independently sends and continues personalised emails | The system should say it is AI | The AI is conducting a direct, contextual exchange |
Use the table as a route to the relevant section, not as a substitute for assessing the actual material. You also need to know whether your organisation created or offers the system under its own name, or simply uses it.
Who the new obligations apply to
Put simply, a provider creates an AI system, or has it created, and offers or launches it under its own name. A deployer uses an AI system under its authority in a business or organisation.
Imagine an online shop using an external product-copy generator. The company that built and sells the generator is usually its provider, while the shop is its deployer. The same shop could also be the provider of a different system if it commissioned its own chatbot and made it available to customers under the shop’s name.
That distinction comes from Article 3(3). A job title, contract label or company size does not decide the role by itself.
What the provider does
For the situations covered in this guide, the provider mainly:
- designs a conversational system so that people learn they are interacting with AI;
- adds machine-readable marking to generated content where Article 50(2) applies; and
- makes that marking detectable and interoperable as far as technically feasible.
Changing the logo, colours or name of somebody else’s tool does not automatically make a business its provider. Check who is responsible for developing the particular system and under whose name it is offered or put into service.
Special case: a high-risk AI system
A high-risk AI system is one that meets Article 6 and falls within a category the AI Act specifically treats as high-risk. Examples can include certain systems used for recruitment, education, access to essential services or as a safety component of a product. The possibility of serious harm does not by itself make an ordinary content generator or chatbot a high-risk system.
Article 25 can transfer provider obligations for a high-risk system, for example after a substantial modification or change of intended purpose. Do not apply that rule automatically to every customised generator or chatbot.
What the deployer does
In a company, the deployer is usually the legal entity rather than each employee using a tool. The Commission explains that the company keeps this role when a contractor or freelancer acts on its behalf and under its responsibility.
The deployer is particularly responsible for visible or audible disclosure of a deepfake, meaning a realistic AI-generated or AI-altered image, audio recording or video that can be mistaken for authentic material, and of covered public-interest text. It must separately assess duties for emotion-recognition or biometric-categorisation systems.
Personal, non-professional activity
The AI Act excludes a natural person using AI only for personal, non-professional activity. Look at what the person actually does, including regular payment and links to employment, business or freelance work. A hobby post may be personal; a similar post on a brand account or by a paid creator is professional.
AI literacy is already required
Labels are not the only obligation. Article 4 has required providers and deployers to ensure an appropriate level of AI literacy since 2 February 2025. People who publish content should be able to recognise realistic manipulation, public-interest topics, error risks and situations that need an expert.
Articles, blogs, and SEO content
Do not label every article simply because AI helped to write it. Disclose AI-generated or substantially AI-altered text when you publish it to inform people about a matter of public interest and it has not received substantive review combined with responsibility for publication.
The Commission’s examples of matters of public interest include politics, democratic processes, public administration, justice, fundamental rights, public security, public health, environmental protection and consumer safety. Economic, financial, scientific or cultural developments can also qualify when they matter to public debate.
Case 1: AI prepares a draft and a qualified editor thoroughly reviews it
Short answer: Disclosure is not required if substantive review and editorial responsibility are both present.
What to do: Assign an editor who understands the subject. Keep the checked sources, approved version, decision-maker and approval date.
Why: A competent editor checked the facts, sources, context and meaning, could change or reject the material, and a person or organisation accepts responsibility for publication. Correcting only style or spelling is not enough.
Case 2: articles on EU policy are published automatically
Short answer: Disclosure required.
What to do: Put a clear disclosure below the headline or somewhere else readers see immediately. Do not treat the label as a substitute for quality control, especially for law, health, finance or safety.
Why: The text informs people about policy, a matter of public interest, and no competent person checked it before automatic publication. This is a core Article 50(4) case.
Case 3: SEO content on a neutral, practical subject
Short answer: Usually no disclosure, but the answer depends on the topic and purpose.
What to do: Mark the brief as routine or expert-sensitive. Send public-interest text for substantive fact-and-source review by a competent person, or disclose the use of AI.
Why: A curtain-size guide may not concern a matter of public interest. A guide to depression treatment, tax or child-seat safety may concern health, the economy or consumer safety. How the page attracts traffic does not decide the duty.
What does “manipulated by AI” mean?
Minor technical assistance does not always bring text within the rule. Article 50(2) excludes standard assistive editing that does not substantially change the input or its meaning. Fixing a typo is different from rewriting a conclusion, adding facts or producing whole paragraphs.
Product descriptions, advertising, and e-commerce
Do not automatically label an ordinary product description or text advertisement. Assess health, safety and environmental claims separately, as well as realistic images or recordings, because different Article 50 rules may apply.
A public product page is not necessarily about a matter of public interest. The subject and purpose of the text matter, not merely the fact that anybody can read it online.
Case 4: routine product description
Short answer: Disclosure not required in the typical case.
What to do: Compare the details with manufacturer data, assign someone to approve the product page and keep the source information and review result.
Why: Colour, dimensions, material and instructions for an ordinary product mainly support a sale. AI authorship alone does not create a visible Article 50(4) duty.
Case 5: health, safety or environmental claims
Short answer: The result depends on the claim. Without substantive review, disclosure may be required.
What to do: Have the product owner or a suitable expert check the evidence, permitted claims and technical documents. Record the decision. If covered text is published without that control, disclose its AI origin.
Why: A claim that a product cures disease, is safe for children or cuts emissions may inform people about health, consumer safety or the environment. Sector rules can prohibit the claim itself regardless of any AI label.
Safer practice: Block automatic publication of health, green and safety claims. “Generated by AI” does not legalise a false green claim or an unauthorised health claim.
Case 6: an AI-generated advertisement
Short answer: An advertisement does not automatically need a label, but assess its text and media separately.
What to do: Review the text, image, audio and video as separate elements. Before launch, assign a person to approve the decision for each one.
Why: Advertising an ordinary product may fall outside the public-interest text rule. A realistic alteration of a person, product, place or event may still be a deepfake, while health or safety claims need their own assessment.
Social media posts
Do not decide based on the platform name. Ask whether the post is professional, what it covers, who receives it and whether it includes realistic material created or altered by AI.
The same rule can apply to a company LinkedIn post, an Instagram reel or a post on X. Purely personal, non-commercial use may fall outside the AI Act.
Case 7: a company LinkedIn post about a change in law
Short answer: Disclosure is required without substantive review by a competent person.
What to do: Assign an editor and source list before publication. Record who checked the text and who accepts responsibility for publishing it. If either element is missing, disclose AI use with the post.
Why: A company post about the AI Act, tax, employment law or economic policy informs people about a matter of public interest. Disclosure may not be needed when a competent person checked the facts, sources and meaning, could stop publication, and the company accepts responsibility.
Case 8: an automated public-safety notice
Short answer: Disclosure is required if AI creates or alters the notice and the full review-and-responsibility exception does not apply.
What to do: Require approval by an authorised person, control the source and make errors easy to withdraw quickly. If the notice is still published automatically, show the AI disclosure immediately with the material.
Why: A warning about danger, health, safety or emergency services concerns a matter of public interest. Automatic publication without substantive review does not qualify for the review-and-responsibility exception.
Safer practice: Treat crisis content as requiring a person before publication even where the system can technically publish by itself.
Case 9: private, non-commercial social post
Short answer: Disclosure not required under the AI Act if the use is genuinely purely personal and non-professional.
What to do: Check the purpose, payment, regularity and connection to a brand or business. Remember that copyright, image rights and other laws may still apply.
Why: The Regulation excludes this kind of use by a natural person. A private profile setting is not enough if the activity is regularly paid, professional or linked to a brand.
Case 10: a post in a small closed professional group
Short answer: The result depends on whether the group is a public audience and whether the post is professional.
What to do: Record who can join, the purpose of the channel and whether material can be shared freely. If uncertain, use substantive editorial review or a visible AI disclosure.
Why: A small closed team may resemble internal communication, while a broad industry group may inform the public. Member count alone does not decide the issue. Deepfakes and direct AI interaction have separate rules.
Images, audio, and video
Disclose a deepfake when an image, audio recording or video meets the legal definition below. Do not automatically label every fantasy illustration or routine technical correction, but always assess the result and its context.
Under Article 3(60), the material must resemble an existing person, object, place, entity or event and falsely appear authentic or truthful. The Commission also includes a reference that could plausibly exist. A fantasy dragon usually does not look like a record of a real event; a realistic clip of a named politician saying words they never said is a typical deepfake.
Case 11: a realistically altered product or property photograph
Short answer: Disclosure required if the material meets the definition of a deepfake.
What to do: Put a clear message such as “Partially modified with AI” next to the image. Show it immediately, not only in metadata or terms and conditions.
Why: Virtually furnishing a real flat, removing product damage or adding a feature can look like the authentic condition of an existing object. The EU icons page uses a virtually furnished photograph of an empty apartment as an example of partial AI modification.
Safer practice: Explain the scope, for example: “AI visualisation. Furniture is not included in the offer.” This is more useful to a customer than a generic logo.
Case 12: an evidently artistic or fictional simulation
Short answer: Disclosure required if it is a deepfake, but it may use a less intrusive form appropriate to the work.
What to do: Put the information in the credits, work description, cover or interface. A typical audience must have a real chance to notice it.
Why: An artistic, creative, satirical or fictional deepfake still requires disclosure. The form may be adapted so it does not hamper display or enjoyment of the work. Material that cannot look authentic in context may fall outside the definition entirely.
Human approval does not exempt a deepfake
The substantive-review exception was written for public-interest text. It does not cover images, audio or video. A deepfake still needs disclosure even if several editors approved it.
Standard effects, colour correction and technical post-production do not always create a deepfake. The deciding question is whether the audience could take the result for an authentic record of a person, object, place or event.
Chatbots and AI assistants
Tell people they are talking to AI no later than the start of their first conversation. The provider designs this mechanism. A business using an external chatbot should check that it works in the actual deployment.
Article 50(1) covers a system designed for direct interaction with a person. The information may be omitted only when the artificial nature of the interaction is obvious to a reasonably well-informed, observant and circumspect person in that context.
Case 13: customer-service chatbot
Short answer: The system should say it is AI unless that is genuinely obvious. The binding design duty rests on the provider.
What to do: At the start of the conversation, show a message such as “You are talking to company X’s AI assistant.” If your business uses somebody else’s system, test the message after every change to its appearance or settings and assess your role.
Why: The bot conducts a direct, two-way conversation with a customer. A name such as “Assistant” or a small robot icon may not be enough if the interface, name and language suggest a person.
Safer practice: Offer an easy route to a person, explain the bot’s limitations and do not let it impersonate a real employee. These controls may arise from other duties or good practice, but not every one is literal Article 50 wording.
Case 14: an obvious professional AI coding assistant
Short answer: An extra disclosure may not be needed if a typical user immediately understands that the tool is AI.
What to do: Record how the name, onboarding, interface and way the tool is used reveal its artificial nature. Test this with the real user group. If reasonable doubt remains, show a short disclosure.
Why: A developer deliberately opening a product clearly described as an AI coding assistant may have no doubt what it is. Assess this from the viewpoint of actual users, not the team that built the product.
Provider versus the business deploying a chatbot
The binding Article 50(1) design duty belongs to the provider. A company using an external chatbot should still test the disclosure after renaming the bot, replacing its welcome screen or changing its presentation. A contract does not replace an assessment of the role or a test of the finished deployment.
Email and messages
Do not label every email merely because AI prepared a draft. Provide an AI disclosure when the system itself conducts contextual correspondence with a person, without a human intermediary.
Ask who is actually communicating with the recipient. Separately check whether the message is private correspondence or a publication addressed to the public.
Case 15: an AI agent independently sends a personalised prospecting email
Short answer: The system should disclose AI if it conducts a direct, contextual exchange with a person. The binding design duty rests on the provider.
What to do: Put a clear sentence in the first email, such as “This message was sent by company X’s AI assistant.” Test that it displays correctly, do not sign with the name of an employee who did not take part, and separately assess direct-marketing and data-protection law.
Why: The AI selects content for the recipient and communicates without a human intermediary, especially when it processes replies and continues the exchange. Using email does not remove Article 50(1).
Safer practice: Provide a simple route to a person and an option to stop automated correspondence. Keep a record of decisions and content sent by the agent.
Case 16: AI drafts, then a person reads and sends the email
Short answer: Disclosure not required under the direct-interaction rule.
What to do: Before sending, check the facts, tone, personal data, confidential information and attachments. The sender must be able to change or reject the draft.
Why: The recipient is communicating with a person and AI is only a drafting tool. A private business email is also not normally text published to inform the public.
Case 17: a fixed out-of-office reply
Short answer: Disclosure not required where it is a fixed rule rather than an AI system conducting an exchange.
What to do: Check the technology rather than relying on its marketing name. Reassess it if the mechanism starts generating contextual replies and continuing a conversation.
Why: Automation is not the same as AI. A fixed message triggered by a date or recipient may not be an AI system and does not conduct a genuine, contextual exchange.
Case 18: private professional correspondence and internal messages
Short answer: The published-text rule usually does not require disclosure when the material is not published for the public.
What to do: Separate the publication procedure from the procedure for direct AI interaction. Regardless of labels, control confidentiality, personal data, access rights and the system’s authority.
Why: The Commission’s Guidelines treat private professional correspondence and internal documents as normally outside the text published to inform the public. A direct AI agent still needs a separate Article 50(1) provider assessment, and the business still has AI-literacy duties.
Human review: when it really matters
This exception applies only to published text that AI generated or substantially altered to inform people about a matter of public interest. It does not apply to every text and does not exempt a deepfake from disclosure.
First, a competent person must substantively review the facts, sources and meaning of the text. Then a person or organisation must accept editorial responsibility for publication. Both conditions must be present.
What counts as substantive review
The Commission’s final Q&A formally describes the review as a deliberate examination of the substance by a natural person using relevant knowledge and professional judgement. Editorial control means genuine power to approve, change or reject the material for substantive reasons.
Match the review to the risk. It will usually cover:
- alignment of the principal claims with primary sources;
- currency of information and the research cut-off;
- sufficient context and absence of misleading simplification;
- numbers, names, quotations, legal bases and links;
- risks to health, safety, rights and economic decisions;
- a clear account of uncertainty or disagreement; and
- a real decision to approve, correct or reject the text.
Not every subject needs a lawyer. An experienced engineer can review a technical guide, while a product-data owner can review routine product facts. The reviewer’s competence must match the claims made.
What is not enough
The following are not enough:
- clicking approve without reading the complete text;
- changing a few words only for tone or style;
- asking another AI model to review the text without competent human judgement;
- an automated fact-check with no human decision;
- review by somebody who lacks subject knowledge and source access; or
- an approval process in which the employee cannot really alter or stop publication.
A second model may flag a risk, but it cannot replace a competent person using their own knowledge and professional judgement.
Editorial responsibility
Editorial responsibility is more than putting a person’s byline below an article. A natural or legal person must hold final responsibility for publication and use a real approval process.
A practical audit record can include:
| Field | Example |
|---|---|
| Material | URL or version identifier |
| AI involvement | Research assistance, draft, language editing |
| Public-interest subject | Yes, EU law |
| Reviewer | Name, role and relevant competence |
| Sources checked | EUR-Lex, Commission and official national sources |
| Decision | Approved after corrections |
| Editorial responsibility | Publisher or authorised person’s name |
| Date | Approval date and time |
Article 50 does not prescribe this form. It is a WebsiteInit recommendation that helps show the review actually took place.
How to label content correctly
Start with a plain statement of what AI did. Put it where people can see or hear it when they first encounter the material or begin the conversation.
Examples include:
- chatbot: “You are talking to company X’s AI assistant”;
- email sent independently by an agent: “This message was prepared and sent by company X’s AI assistant”;
- public-interest text: “This text was generated by an AI system and has not undergone substantive review by a competent person”;
- altered image: “Partially modified with AI”; and
- video: “This material contains AI-generated or AI-modified images and voices. The statements are not an authentic recording of this person”.
Match the words to the facts. Do not say that AI merely assisted if it created the whole item and nobody reviewed its substance. These examples are WebsiteInit recommendations, not official templates.
Where and how to show the information
Under Article 50(5), the information must be clear, distinguishable from the other content and accessible to people with disabilities. Put it below the headline of an article, next to an image, or on the opening screen and in the first message of a chatbot. A general sentence hidden in terms and conditions or a footer will usually not be enough.
For video, use a readable notice before playback, a caption in the material or a suitable audio message. An artistic work can use a less intrusive form, but the audience still needs a real opportunity to notice it.
Technical detail: marking added by the provider
Article 50(2) requires the provider of a system that generates audio, images, video or text to mark the output technically. The mark must make the artificial origin machine-detectable and be effective, interoperable, robust and reliable as far as technically feasible. It may use provenance metadata, content credentials or another suitable technique.
Technical marking does not replace information for people. A business publishing material covered by Article 50(4) cannot rely only on data hidden in the file.
EU icons are optional
The Commission provides EU icons for AI-generated content in base, fully generated and partially modified versions. The icons are voluntary, but an Article 50 disclosure remains binding when the rule applies. An icon alone is not enough if it is hard to see, unclear or lost when the material is shared.
The Commission page recommends plain text beside the icon, alternative text for screen readers, adequate contrast and enough display time for video or audio. These are practical recommendations from the voluntary Code and icon page, not the only lawful method.
Sharing the content again
Design the disclosure so that it survives normal sharing, embedding or downloading. On an external platform, add the information to the media or caption as well as any platform label that could disappear.
Nobody can guarantee that a label will survive unlawful copying. A business should still take reasonable steps across the publication process it controls and test that they work.
Narrow law-enforcement exceptions
Article 50 contains exceptions when use is authorised by law to detect, prevent, investigate or prosecute criminal offences. For direct interaction, safeguards for third-party rights and freedoms are required, and the exception does not cover public systems for reporting offences. This is not a general exemption for private security, internal fraud teams, private investigations or content about crime.
What a business should implement step by step
Complete these actions before 2 August 2026. Each step should produce a document, setting or test result.
Step 1: create an AI-use register
Record text, image, voice and video generators, chatbots, email agents, automatic publishers and tools used by contractors. Result: one register with the system, owner, provider, channel, audience and launch date.
Step 2: assign the legal role
Record whether the organisation is provider, deployer or both. Apply Article 3(3) first and check Article 25 additionally only for a high-risk AI system. Result: a “business role” field with a short reason and approver.
Step 3: classify content scenarios
Separate direct AI interaction, deepfakes, public-interest text, internal material and routine technical editing. Do not give one verdict to an entire tool: the same model can write a mug description and an automated election analysis. Result: a list of uses mapped to the relevant Article 50 rule.
Step 4: design decision gates
Put the four questions from the start of this guide into the publishing form. Make the result name the required disclosure, reviewer or escalation rather than return only “OK”. Result: an approved checklist with a visible decision.
Step 5: build genuine human review
Assign competent people for law, health, safety, product data and other relevant subjects. Give them sources and authority to change or stop publication. Result: a reviewer list and record of the text version, sources, decision, date and editorial responsibility.
Step 6: implement disclosures across channels
Approve wording for chatbots, email agents, articles, images, audio and video. Test desktop and mobile views, contrast, screen readers, captions and visibility after sharing. Result: a label library and screenshots of the tests.
Step 7: assess vendors and contracts
Ask providers how technical marking works, whether metadata survives export and when their systems will meet Article 50. Test chatbot disclosure in the version customers actually use. Result: provider responses, test records and a dated list of gaps.
Step 8: train, test and monitor
Train marketing, e-commerce, support, sales and contractors. Each quarter, sample materials, check labels and review records, and document corrections. Result: attendance records, an audit report and a named owner for follow-up.
Simple responsibility matrix
| Task | Owner | Consulted |
|---|---|---|
| Register tools and integrations | IT or AI owner | Procurement, security |
| Classify content | Channel owner | Legal or compliance |
| Perform substantive review | Subject expert or editor | Author, product-data owner |
| Hold editorial responsibility | Publisher or authorised person | Legal |
| Implement disclosures | Product, web, marketing operations | Accessibility, UX |
| Audit samples | Compliance or internal control | Channel owners |
Deadlines, penalties, and the position in Poland
The main date for the duties in this guide is 2 August 2026. The possible 2 December date is narrow and conditional. It does not postpone disclosure for chatbots, deepfakes or covered public-interest text.
Timeline for the obligations in this guide
| Date | Event or applicable obligation |
|---|---|
| 1 August 2024 | The AI Act entered into force |
| 2 February 2025 | Article 4 AI literacy and prohibited-practice rules, among others, started to apply |
| 10 June 2026 | The final Code of Practice on marking and labelling AI-generated content was published |
| 20 July 2026 | The Commission published its final Article 50 Guidelines and final Q&A |
| 2 August 2026 | Article 50 starts to apply, including interactive-system design, technical marking, deepfake and public-interest text rules |
| 2 December 2026 | The Commission Q&A describes an envisaged limited end date for transition relating to Article 50(2) and earlier systems |
Article 113 sets 2 August 2026 as the general date of application. The Commission’s final Q&A of 20 July says a transition until 2 December 2026 is envisaged only for machine-readable marking and detection under Article 50(2), for systems placed on the market before 2 August.
It is not a general four-month delay. The Q&A explains the Commission’s position but is not itself an amendment to the Regulation published in the Official Journal. Before relying on 2 December, a provider should verify in EUR-Lex whether the relevant AI Omnibus amendment has been finally adopted and published and check the exact transitional wording.
Even under the Commission’s current position, this would not create a transition for:
- information about direct AI interaction under Article 50(1);
- a deployer’s disclosure of deepfakes;
- a deployer’s disclosure of covered public-interest text; or
- all new systems placed on the market after the date of application.
The Commission also says that Article 50 does not require retroactive labels for content generated before 2 August 2026. It encourages voluntary labels where feasible.
Code and Guidelines: what is binding?
The Code of Practice on transparency of AI-generated content is a final, voluntary compliance aid. It is not law and does not replace Article 50. The Commission and AI Board found it adequate as a way for signatories to demonstrate compliance, but not signing it is not itself an infringement.
The final Commission Guidelines and Q&A explain the rule, but they do not change the Regulation or replace a court’s decision. This guide separates:
- a legal obligation in Article 50;
- a Commission interpretation in the final Guidelines and Q&A;
- a voluntary commitment of a Code signatory; and
- a WebsiteInit recommendation intended to reduce operational risk.
Penalties for infringement of Article 50
A missing label does not automatically produce a EUR 15 million fine. Article 99(4) sets a maximum administrative fine of EUR 15 million or, for an undertaking, 3 per cent of its total worldwide annual turnover for the preceding financial year. The higher ceiling generally applies to an undertaking.
For SMEs, including start-ups, Article 99(6) caps the maximum at the lower of the fixed amount and turnover percentage. Authorities must impose an effective, proportionate and dissuasive penalty. They consider factors such as seriousness, duration, harm, company size, cooperation, safeguards, intent and corrective action.
One mistake quickly corrected within a functioning process is different from deliberate, repeated and large-scale avoidance. The maximum is a ceiling, not an automatic bill for every missing label.
Poland: national position as at 20 July 2026
Polish status checked on 20 July 2026. Parliament had completed work on the act organising national supervision, but we found no official confirmation that the President had signed it or that it had been published in the Journal of Laws. At the research cut-off, the act was not officially verified as signed, promulgated or in force.
Article 50 applies directly as part of an EU Regulation. Poland does not need a national act to create the duty. National legislation is needed to organise authorities, market surveillance, procedures and enforcement in Poland.
According to the official Sejm process for print 2443, Parliament completed its work and sent the act to the President on 3 July 2026. The final parliamentary text would establish a Commission for the Development and Security of Artificial Intelligence as the central market-surveillance body, with sector authorities also involved.
On 20 July, the act did not appear on the official list of acts signed that month or in the 2026 Journal of Laws. We therefore do not describe the proposed Commission as already operating. Check both official sources again before publication or a later update.
Frequently asked questions
Must every text written with ChatGPT be labelled?
No. The visible text duty concerns publication intended to inform the public on a matter of public interest. Even then, genuine human review or editorial control combined with editorial responsibility creates an exception.
Is putting a human author’s name below an article enough?
No. A byline does not prove substantive review. A competent natural person must genuinely examine the content and be able to change or reject it, and a natural or legal person must hold editorial responsibility.
Does any human correction remove the labelling duty?
It depends on scope. Fixing spelling and style is not enough. Review should cover facts, sources, meaning and credibility. The exception applies to covered public-interest text, not deepfakes.
Can a second AI model perform the human review?
No. It can support the process, but the Commission refers to a natural person applying knowledge and professional judgement. Automated verification cannot replace that person.
Must an online shop label AI-generated product descriptions?
Usually not merely because AI created them. Assess health, safety, environmental and other public-interest claims. Independently of Article 50, copy must be accurate and comply with consumer and sector law.
Must every AI-generated image be labelled?
Not under the deployer rule. Article 50(4) concerns image, audio or video content that qualifies as a deepfake. The assessment turns on whether it resembles an existing or plausible reference and falsely appears authentic. A company can voluntarily adopt a broader policy.
Is retaining generator metadata enough?
No, not where a visible disclosure duty applies. Metadata and other machine-readable marking serve Article 50(2) on the provider side. A deployer publishing a deepfake or covered text must inform people clearly when they first see or hear it.
Must I use an official EU icon?
No. Icons are optional. Clear text or another adequate disclosure can be used. An icon is not automatically compliant if it is invisible, unexplained or lost during sharing.
Can a chatbot omit disclosure because it is called “AI Assistant”?
The obviousness exception can apply, but narrowly. The provider owns the binding design decision. The deploying business should assess the complete context, interface, onboarding, language and audience and verify that its configuration does not obscure the system’s artificial nature.
Does an AI-assisted email need a footer?
Not when AI only drafts and a person reviews and personally communicates with the recipient. When an AI agent independently conducts contextual correspondence, the provider must design an AI disclosure and the deployer should verify it and assess its role. A public newsletter on a matter of public interest also needs the separate published-text assessment.
Are small businesses and freelancers covered?
Yes when they act professionally as providers or deployers. Size does not remove the duty. SMEs do benefit from the lower of the amount-based and turnover-based maximum fine ceilings.
Must content from before 2 August 2026 be labelled retrospectively?
Not under the Commission’s final Article 50 position. Voluntary labelling is encouraged where feasible. If old material is substantially changed or republished later, perform a new assessment.
Can a provider rely unconditionally on 2 December 2026?
No. The Commission describes an envisaged, limited transition only for the Article 50(2) provider duty on machine-readable marking and detection for systems placed on the market before 2 August. It does not postpone chatbot, deepfake or public-text duties. Verify final AI Omnibus adoption and publication in the Official Journal before relying on it.
Does the absence of a completed Polish act postpone Article 50?
No. The EU Regulation applies directly. Poland’s national act organises authorities, proceedings and enforcement. At the 20 July 2026 cut-off, signature and promulgation had not been officially verified.
Is voluntarily labelling everything the safest answer?
It can simplify policy and improve trust, but it does not replace quality control, legalise false claims or always explain AI’s real role. A business can adopt a broader standard than the law, but should identify it as its own policy.
Primary sources and legal note
The principal primary and official sources used for this analysis are:
- Regulation (EU) 2024/1689 in EUR-Lex, particularly Articles 2, 3, 4, 25, 50, 99 and 113.
- Article 50 in the official AI Act Service Desk, with the complete duties and exceptions.
- Article 99 on penalties, including the EUR 15 million or 3 per cent ceiling and the SME rule.
- Final Commission Guidelines on Article 50, published 20 July 2026.
- Final Commission Q&A on Article 50 transparency obligations, covering roles, interaction, public-interest text, review, transition and enforcement.
- Code of Practice on transparency of AI-generated content, final and voluntary.
- Commission Q&A on the Code of Practice.
- EU icons and official presentation guidance.
- European Commission AI Act implementation timeline.
- Official Polish legislative process, Sejm print 2443 and the final parliamentary text of 3 July 2026.
- The President of Poland’s list of acts signed in July 2026 and Poland’s 2026 Journal of Laws, checked for national status.
Research cut-off: 20 July 2026. The Commission published the final Guidelines on the day this guide was updated. The Polish legislative position and enforcement practice can change quickly, so official sources should be checked again before implementation or republication.
Editorial note before publication: AI assisted with research and preparation of the working draft. Publication still requires Sebastian Tekieli’s personal substantive verification of the sources, his final editorial approval and his acceptance of editorial responsibility. Until those steps are complete, this material remains a draft.
This article provides general information based on the legal position stated above. It is not individual legal advice. For high-risk uses, disputed interpretations or regulated industries, have a lawyer assess the specific process.
