On 2 August 2026, another key stage in the application of the European AI Act will begin. From that date, the transparency obligations under Article 50 of Regulation (EU) 2024/1689 will apply in particular. They concern interactive AI systems, AI-generated or manipulated content, emotion recognition and biometric categorisation, as well as deepfakes and certain AI-generated publications.
Table of Contents
Less than two weeks before the relevant provisions become applicable, the European Commission published its final guidelines on Article 50 of the AI Act on 20 July 2026. The guidelines are intended to enable authorities, providers and deployers to implement the requirements consistently, effectively and proportionately. They are not legally binding – the power to provide a binding interpretation remains with the Court of Justice of the European Union. Nevertheless, they are likely to be highly significant for supervisory practice.
For banks, payment and electronic money institutions, investment firms, insurers and fintechs, the new obligations are not merely a matter of communication or marketing. They may apply, among other things, to customer chatbots, digital assistants, automated complaint and fraud-reporting systems, AI agents, advisory applications, AI-generated customer information, annual reports, social media content and synthetic audio or video formats.
1. Four different transparency obligations
Article 50 of the AI Act does not impose a uniform labelling requirement on every use of AI. Instead, the provision distinguishes between four obligations, each with its own scope and different addressees:
- Interactive AI systems: Providers must ensure that natural persons are informed when they are interacting directly with an AI system, Article 50(1) AI Act.
- AI-generated or manipulated content: Providers of generative AI systems must mark certain audio, image, video and text content in a machine-readable format and make it detectable as artificially generated or manipulated, Article 50(2) AI Act.
- Emotion recognition and biometric categorisation: Deployers must inform affected persons that such systems are being used, Article 50(3) AI Act.
- Deepfakes and certain texts on matters of public interest: Deployers must disclose that the relevant content has been artificially generated or manipulated, Article 50(4) AI Act.
The obligations may apply cumulatively. An AI system that interacts with a customer while generating images or text may fall within both Article 50(1) and Article 50(2) AI Act. If the company deploying the system also uses it to publish a deepfake or a text concerning a matter of public interest, Article 50(4) AI Act may apply in addition. Pursuant to Article 50(5) AI Act, the information must be provided clearly and distinguishably and, as a rule, no later than the time of the first interaction or exposure. The applicable accessibility requirements must also be observed.
2. Provider or deployer – what is the financial undertaking’s role?
The distinction between providers and deployers is central to the allocation of obligations.
A provider is, in particular, a person who develops an AI system, or has an AI system developed, and places it on the market or puts it into service under its own name or trade mark. This may also include a company that develops an interactive AI system itself and uses it within its own organisation under its own responsibility. A substantial modification of an existing system, followed by its use under the company’s own name, may also result in the company being classified as a provider.
A deployer, by contrast, is a person who uses an AI system under its own authority and determines the purpose and manner of its actual use. Technical control over the system is not necessarily required. A financial undertaking that selects and configures a standard AI system supplied by an external provider and uses it for specific business processes will therefore generally be a deployer.
In practice, this means:
- If a bank uses an externally procured generative AI tool solely for internal purposes, it will generally be a deployer.
- If it has a customer chatbot developed specifically for it and makes the chatbot available under its own brand, it may also be a provider.
- If an institution substantially modifies an existing system, for example through its own training or extensive modifications, it may acquire the status of a new provider.
- Individual employees are generally not regarded as separate deployers where they use the system in the course of their duties and under the responsibility of the company.
These roles should not be assessed in the abstract at company level. They should be examined and documented separately for each individual AI system and each specific use case.
3. Customer chatbots and AI assistants: transparency from the first interaction
Article 50(1) AI Act requires an appropriate notification and applies to AI systems intended to interact directly with natural persons. This includes, in particular, chatbots, voice assistants, conversational agents and AI agents.
The Commission interprets the term “interaction” broadly. There must be a reciprocal exchange with a genuinely dialogic or responsive character. The interaction may take place in writing, orally, visually or physically and may consist of a single exchange or an extended conversation. Purely passive data collection or back-end systems without direct communication with human beings, by contrast, do not fall within Article 50(1) AI Act.
In the financial sector, the following systems may be affected in particular:
- customer chatbots on websites or in banking apps;
- AI-supported telephone assistants;
- digital assistants for product and service enquiries;
- automated complaints portals;
- AI-supported systems for receiving fraud or suspicious activity reports;
- AI agents that book appointments, conduct correspondence or prepare transactions on behalf of customers;
- interactive applications providing financial or insurance advice.
The Commission expressly identifies AI-supported fraud-reporting hotlines and digital reporting portals operated by financial institutions as use cases in which users must be informed that they are interacting with AI. This applies even where human investigators or case handlers subsequently review the information.
What form must the notification take?
The notification must be embedded in the system’s design and use. In particular, it is not sufficient to include the notification solely in general terms and conditions or as a hidden reference in a privacy notice. A mere URL linking to further information, describing the system as an “assistant” without disclosing its artificial nature, or making a general statement that “AI is also used” on the website is likewise insufficient.
Suitable notifications may include:
“You are communicating with an AI-supported assistant.”
or:
“This chat is conducted by an AI system. You may contact our customer service team if required.”
For voice-based systems, the notification should be given audibly at the beginning of the interaction. In longer, sensitive or potentially misleading interactions, repeated notifications may be necessary. In its guidelines, the Commission identifies financial advice, insurance advice, legal advice and complaint handling, among others, as particularly sensitive contexts.
Exception where the AI interaction is obvious
No information is required where the artificial nature of the interaction is obvious from the perspective of a reasonably well-informed, observant and circumspect person. The guidelines interpret this exception restrictively. General awareness that chatbots exist is not sufficient. The following factors must be considered in particular:
- the specific user group;
- the system’s design;
- the use of human names, voices or avatars;
- users’ digital and AI-related literacy;
- the inclusion of elderly, disabled or otherwise vulnerable persons;
- the specific context in which the system is used.
Financial undertakings should therefore generally not rely on this exception in relation to publicly accessible customer chatbots.
The position may be different for internal AI assistants used by demonstrably trained employees. The Commission gives the example of an internal assistant used by AI-literate employees in areas such as legal, compliance, procurement or IT, where the AI nature of the interaction may be obvious.
4. AI agents must also disclose whom they represent
The Commission’s guidance on AI agents is of particular importance. Article 50(1) AI Act applies where an AI agent interacts either with the person instructing it or, in carrying out its task, with other natural persons. According to the Commission, the agent should not only disclose that it is an AI system. It should also make clear on whose behalf it is acting. This is particularly relevant for agents that:
- conduct correspondence;
- arrange appointments;
- support contract negotiations;
- initiate purchases or orders;
- make declarations to third parties;
- operate in payment services or customer service.
For financial undertakings, this has considerable practical implications. An agent communicating with customers, merchants or other service providers on behalf of a financial institution should therefore, for example, state:
“I am an AI agent acting on behalf of X Bank.”
Where agents have more extensive powers, issues relating to authorisation, oversight, logging and liability must also be addressed. The transparency obligation does not replace these governance requirements.
5. Machine-readable labelling: primarily an obligation for system providers
Article 50(2) AI Act applies to providers of systems that generate or manipulate synthetic audio, image, video or text content. They must ensure that the outputs are:
- labelled in a machine-readable format; an
- identifiable as artificially generated or manipulated.
The technical solution must be effective, interoperable, robust and reliable, insofar as this is technically feasible. Possible solutions include digital watermarks, metadata, cryptographic provenance information, fingerprints or comparable technical markers. A marker alone is not sufficient; appropriate means of detection must also be available.
For most financial undertakings, this obligation will initially rest with the external AI provider. Nevertheless, institutions should verify:
- whether the provider offers the required labelling functionality;
- whether this functionality remains intact when the system is integrated;
- whether metadata is removed during export, format conversion or publication;
- whether contractual arrangements clearly allocate responsibility for technical labelling; and
- whether in-house development, substantial modification or deployment under the institution’s own brand results in the institution becoming a provider itself.
Not every AI output requires technical marking
The guidelines limit the scope of application. The following are, for example, not covered:
- pure data extraction and structuring without summarisation;
- machine-generated outputs not intended for human consumption;
- source code and certain machine-readable configurations;
- individual words, short labels or purely technical information;
- the mere reproduction or arrangement of existing content.
Exceptions also apply to purely supportive standard editing and to modifications that do not materially alter the input data or its meaning. Examples provided by the Commission include spelling and grammar correction, minor stylistic improvements and—of particular practical relevance—AI-generated translations, provided that they do not alter the meaning of the source text.
By contrast, AI-generated summaries, substantial rewording and texts whose content or structure has been materially changed are generally regarded as outputs requiring machine-readable labelling on the provider side.
6. Deepfakes in advertising and corporate communications
Article 50(4), first subparagraph, AI Act requires deployers to disclose where they use AI systems to generate or manipulate image, audio or video content that qualifies as a deepfake.
Under Article 3(60) AI Act, a deepfake is AI-generated or AI-manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful to a person.
The guidelines emphasise that no intention to deceive is required. The decisive factor is whether, viewed objectively and taking into account the context and the foreseeable target audience, the content is capable of creating a false impression of authenticity or truthfulness.
For financial undertakings, the following scenarios may be particularly relevant:
- realistic AI avatars of board members or employees;
- synthetic voices used in advertising or informational videos;
- AI-generated customer testimonials;
- manipulated product or usage scenarios;
- realistic videos depicting alleged corporate events;
- AI-generated portrayals of customers, branches or advisory situations.
The Commission expressly cites a realistic synthetic video of a company’s chief executive as an example of a deepfake. Likewise, an AI-generated product image used in advertising may qualify as a deepfake where it misleadingly alters the actual appearance, characteristics or use of the product.
The disclosure must be immediately perceptible to human users. An invisible technical watermark alone is not sufficient to satisfy the deployer’s obligation. Appropriate notices may include:
“This video was created using artificial intelligence.”
However, such labelling does not automatically render the content lawful. Data protection law, personality rights, copyright law, trade mark law and unfair competition law continue to apply without restriction.
7. AI-generated texts on matters of public interest
Article 50(4), second subparagraph, AI Act applies to texts that have been generated or manipulated by AI and are published with the purpose of informing the public about matters of public interest.
The Commission interprets the term “matters of public interest” broadly. It may also include economic and financial developments where these are capable of becoming the subject of public discussion or scrutiny. As an example, the Commission expressly refers to AI-manipulated corporate reports of listed companies containing investor information.
In the financial sector, this may include in particular:
- market and economic reports;
- publicly available regulatory assessments;
- investor and capital markets information;
- public reports on financial stability or cyber risks;
- press releases concerning significant corporate developments;
- publicly available analyses relating to fraud, money laundering or sanctions; and
- publications concerning political or regulatory developments in the financial markets.
By contrast, the following will generally not constitute publication within the meaning of the provision:
- individual customer correspondence;
- internal corporate communications;
- texts shared within small, closed groups; and
- individual advisory documents prepared for specific clients or customers.
Exception where there is human review and editorial responsibility
No disclosure is required where the AI-generated or AI-manipulated text:
- has been subject to human review or editorial control; and
- a natural or legal person assumes editorial responsibility for its publication.
This exception is likely to be particularly relevant for professionally prepared newsletters, expert articles, press releases and regulatory publications. However, it requires more than a purely formal approval process. A robust editorial procedure must exist under which the content is genuinely reviewed and responsibility for it is assumed. Financial undertakings should therefore document: who reviewed the text; what substantive review was carried out; whether sources, figures and legal statements were verified; who assumed editorial responsibility; and where appropriate, the final published version of the document.
8. Emotion recognition and biometric categorisation
Where a financial undertaking uses an AI system for emotion recognition or biometric categorisation, Article 50(3) AI Act requires it to inform all affected persons that the system is in operation. Possible use cases include:
- analysing voice, facial expressions or behaviour during customer interactions;
- purported detection of nervousness or deceptive behaviour;
- biometric categorisation based on age or gender; and
- analysis of emotional reactions during digital advisory processes.
The information obligation under Article 50(3) AI Act does not legitimise the use of such systems. Financial undertakings must also assess, in particular: the prohibitions under Article 5 AI Act; the requirements applicable to high-risk AI systems; and the applicable data protection legislation. The Commission expressly states in its guidelines that all emotion recognition systems may either be prohibited or generally classified as high-risk AI systems.
Financial undertakings should therefore not enable such functionality without careful assessment, even where it is offered merely as an additional feature within a broader communications, video or fraud detection solution.
9. Relationship with data protection, consumer protection and DORA
The transparency obligations under Article 50 AI Act apply in addition to other statutory information and governance requirements.
- Data protection
Article 50 AI Act does not replace the information obligations under Articles 13 and 14 GDPR. Where personal data are processed, organisations must continue to disclose, among other things: the legal basis for processing; the purposes of processing; the recipients of the data; the retention period; the rights of data subjects; and where applicable, the existence of automated decision-making.
Likewise, merely labelling content as AI-generated does not legitimise the processing of customer, employee or biometric data.
- Consumer protection
Where AI-supported products or services are offered, additional pre-contractual information obligations may apply.
Misleading statements or the omission of material information remain prohibited under consumer protection and unfair commercial practices law. This applies irrespective of whether an AI interaction might appear to be obvious within the meaning of Article 50(1) AI Act.
- DORA
Supervised financial undertakings must also assess whether the AI system constitutes an ICT service within the meaning of the Digital Operational Resilience Act (DORA) and, if so, whether it supports critical or important functions.
10. Code of Practice as a voluntary compliance pathway
On 10 June 2026, the European Commission published the final Code of Practice on Transparency of AI-Generated Content. The Code primarily addresses the labelling and detection of AI-generated content under Article 50(2) AI Act, as well as the obligations imposed on deployers under Article 50(4) and (5) AI Act. Adherence to the Code is voluntary; the statutory obligations laid down in Article 50 AI Act remain mandatory.
On 9 July 2026, the Commission concluded that the Code adequately reflects the obligations arising under Article 50(2), (4) and (5) AI Act. The AI Board subsequently reached the same conclusion. Signatories may therefore rely on the measures provided for in the Code as evidence of compliance with the transparency obligations. Organisations choosing alternative measures must demonstrate, on a case-by-case basis, that those measures provide an equivalent level of compliance.
For financial undertakings, signing the Code should be considered particularly where they act as providers of generative AI systems or regularly use deepfakes or AI-generated publications falling within the scope of Article 50 AI Act. Where financial undertakings merely use standard AI applications supplied by third parties, the more important question will generally be whether the relevant provider has signed the Code and implemented its technical requirements accordingly.
11. Transitional arrangements for existing AI systems
The transparency obligations will generally apply from 2 August 2026.
For certain AI systems that were placed on the market before that date, the Commission refers to a transitional period lasting until 2 December 2026.
However, financial undertakings should not rely on this transitional period without further assessment. Instead, they should verify:
- when the specific AI system was placed on the market or put into service;
- whether any substantial modifications have been made after the relevant date;
- which obligations apply to the provider and which apply to the deploying institution; and
- whether existing contractual arrangements and technical functionalities enable timely compliance.
Conclusion
The new guidelines demonstrate that Article 50 AI Act extends far beyond a simple statement such as “This content was created using AI.” The provision differentiates according to the type of AI system, the nature of the content, the role of the organisation, the intended audience and the publication context.
For the financial sector, three areas are particularly relevant:
- customer interaction through chatbots and AI agents;
- public communications and AI-generated content; and
- governance when procuring and integrating third-party AI systems.
Financial undertakings should not rely exclusively on their AI providers. While the technical labelling obligations under Article 50(2) AI Act will often rest with the system provider, responsibility for disclosing deepfakes, reviewing certain publications and designing compliant internal deployment processes remains with the deploying organisation.
Article 50 AI Act is therefore more than a transparency provision. It requires a combination of technical implementation, legal classification, clear allocation of responsibilities and robust editorial and operational governance. The guidelines published on 20 July 2026 provide valuable guidance in this respect, but they do not relieve financial undertakings of the obligation to assess their specific AI applications individually.
