The first requirement of the AI regulation is not technical. #ARTICLE 50 AI ACT

EU AI Act  · Article 50 · Transparency Requirements · Effective as of August 2025
The first requirement
of the AI regulations.
And it's not a technical one.
On August 2, 2025, Article 50 of Regulation (EU) 2024/1689 on Artificial Intelligence entered into force. It does not require systems to be certified. It does not require model audits.
It requires something more inconvenient: stating when there is a machine on the other end.
Effective August 2, 2025
50
Article:
AI Act
Active Obligations · Art. 50, sections 1–4
What exactly does Article 50 require?
01
Interaction with AI systems
Operators of AI systems designed to interact directly with individuals must ensure that those individuals are informed that they are interacting with an AI, unless this is evident from the context and the use of the system.
Art. 50.1 · Chatbots · Virtual Assistants
02
AI-generated summary
Operators of systems that generate synthetic images, audio, video, or text must mark the output in a detectable manner, using metadata, watermarks, or interoperable technical solutions such as C2PA.
Art. 50.2 · Deepfakes · Synthetic Content
03
Emotion Recognition and Biometrics
Any system that infers emotions or processes biometric data to identify or categorize individuals must inform the individuals involved. This applies to HR, security, and customer service systems.
Art. 50.3 · Biometrics · Emotional Analysis
04
Deepfakes and Imitations of Real People
Operators that deploy systems that generate or manipulate images, audio, or video of real individuals must clearly disclose that the content has been artificially generated. This applies to advertising, entertainment, and media.
Art. 50.4 · Natural Persons · Disclosure
05
Scope, Liability, and Penalties
Article 50 applies to both the provider of the AI system and the operator that deploys it. It makes no distinction based on company size or sector. Fines: up to €15 million or 3% of annual global revenue, whichever is greater. In Spain, the AESIA (Spanish AI Supervisory Agency) will be the competent supervisory authority starting in August 2025.
Art. 50.5 · Provider + Operator · AESIA · 15M€ / 3% of total revenue
Legal Framework · Regulation (EU) 2024/1689
Regulatory Context and Related Articles
Implementation Schedule · 2024–2028
Roadmap for the EU AI Act
August 1, 2024
Effective Date
Regulation (EU) 2024/1689 enters into force. The transition period begins.
February 2, 2025
Prohibited AI Practices
Prohibition of Unacceptable Systems: Social Scoring, Mass Surveillance, Subliminal Manipulation.
August 2, 2025 · Now live
Article 50 · Transparency
Transparency Requirements for Interaction with AI, Synthetic Content, Deepfakes, and Biometrics.
December 2, 2027
High-Risk Systems (Annex I)
Compliance, audit, and human oversight requirements for critical systems.
August 2, 2028
Full implementation
All fully applicable articles, including high-risk systems in the public sector (Annex III).
Exposure economic
€15 million

's maximum fine for noncompliance with Art. 50
or whichever amount is greater
3%

's annual global revenue for the previous fiscal year
the "greater of" criterion is applied
Who is liable: both the AI system provider and the operator who integrates it into their product. If a company uses a generative AI API and does not label the output, the operator—not just the API provider—is liable for the violation.
Enforcement in Spain: The AESIA (Spanish Agency for the Supervision of Artificial Intelligence) will have the authority to impose sanctions starting in August 2025. It may initiate investigations on its own initiative or in response to a complaint.
◈ How V-PROOF Responds to Article 50
Labeling alone is not enough. Evidence is needed to show that the labeling was applied.
Article 50 requires reporting. But reporting without evidence is simply making a claim. During an inspection, the question won’t be “Do you have a labeling policy?”—it will be “Can you prove that this content was properly labeled at the time it was created?” That is the difference between declarative compliance and verifiable compliance.
◈
V-SEAL at the source
Each asset is assigned a " V-SEAL " at the time of creation; this is not applied retroactively, nor is it determined at a later date.
⬡
Hash SHA-256 on-chain
Timestamp + Human/AI ratio recorded on the Ethereum L2 Base. Verifiable by any auditor without credentials.
◯
verification without Exposure
The content never leaves the organization. Only the hash is logged. Compliant with the GDPR and data sovereignty.
◈ The Question That Matters
How many of your organization's interfaces are designed
so that users don't realize there's an AI on the other end?
Article 50 is now enforceable. The first requirement under the General Data Protection Regulation ( EU AI Act ) is not technical; it concerns expectations and transparency. Request a strategic assessment and find out at how many touchpoints your organization is currently at risk.
Request a Strategic Assessment
Do you have questions about Article 50 and your industry? Write to us directly
Previous
Previous

AI Governance: 30 Key Questions, 8 Regulatory Frameworks, 1 Layer of Evidence

Next
Next

The train carrying the foundational models has already left. Europe has another one.