Does your self-hosted app need AI-Act labels? Article 50, quoted in full
Article 50 of the EU AI Act sets transparency obligations — some on the provider, some on the deployer. Here is the Article quoted from the 27 July 2026 consolidated text, read 6 September 2026, with the two definitions it turns on, the dates that govern it, and the questions to put to your adviser.
If you have added an AI feature to software you host yourself — a chat box, a drafting assistant, a summariser, anything that produces text or images for the people who use your system — you have probably been told that the EU AI Act requires you to label it. You may have been told the opposite. This page does neither. It sets out what Article 50 actually says, names the two definitions the whole question turns on, and hands you the questions that decide it.
We are not your adviser and this is not advice. We sell self-hosted software; we do not sell an AI-Act product, and we are not going to tell you what your obligations are. What follows is the text, its provenance, and the questions.
Where these words come from
Every quotation below is from the consolidated text of Regulation (EU) 2024/1689, CELEX 02024R1689-20260727, whose header reads "02024R1689 — EN — 27.07.2026 — 001.001". It was read on 6 September 2026 from the Publications Office CELLAR — the datastore behind EUR-Lex — because the EUR-Lex front end was returning errors that morning. CELLAR serves the same act, not a summary of it.
The consolidation folds in one amending act: Regulation (EU) 2026/1744, the Digital Omnibus on AI, OJ L 2026/1744 of 24.7.2026. Paragraph 7 of Article 50 carries the amendment mark in the source; paragraphs 1 to 6 do not.
The consolidated text carries the Union's own standard caveat, and so does this page: "This text is meant purely as a documentation tool and has no legal effect… The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex."
The Article, in full
Article 50 sits in Chapter IV, headed "TRANSPARENCY OBLIGATIONS FOR PROVIDERS AND DEPLOYERS OF CERTAIN AI SYSTEMS". The Article's own title is "Transparency obligations for providers and deployers of certain AI systems". Note that the heading names two different roles. Which one you are is the question that decides most of what follows.
Paragraph 1 — systems that interact with people.
Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence.
Two things in that sentence are doing a great deal of work, and neither is a detail. The obligation is on providers, and it is disapplied where the fact is "obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect". The Regulation does not define what is obvious. It gives a standard and leaves the application to the facts.
Paragraph 2 — systems that generate synthetic content.
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.
That paragraph is again addressed to providers, and it carries a carve-out for systems performing "an assistive function for standard editing" or not substantially altering the deployer's input data or its semantics.
Paragraphs 3 and 4 — obligations on the deployer.
3. Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. […]
4. Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
Paragraph 4 has a second subparagraph that catches published text rather than images:
Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.
Paragraphs 5 and 6 — how, when, and what is unaffected.
5. The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.
6. Paragraphs 1 to 4 shall not affect the requirements and obligations set out in Chapter III, and shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems.
Paragraph 7 — the amended one.
The Commission shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligations laid down in paragraphs 2 and 4 of this Article, in accordance with the procedure laid down in Article 56(6). If it deems the code of practice to be inadequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).
The two definitions the question turns on
Article 50 assigns different obligations to providers and to deployers, so the first question is which of the two you are for the feature in front of you. Article 3 defines both:
(3) 'provider' means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;
(4) 'deployer' means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;
Read those two side by side and note what separates them: the provider definition turns on developing, and on placing on the market or putting into service under its own name or trademark. The deployer definition turns on using under its own authority. Neither is decided by where the software runs, and neither is decided by who wrote the code. A self-hosted install does not, on the face of these definitions, settle the question either way.
It is also worth noticing that the definitions are not mutually exclusive on their face. Nothing in the wording stops one organisation from being a provider of one system and a deployer of another — or of the same one, in different respects. Whether that is your situation is a question about your facts, not about the text.
The dates, and the one that is easy to miss
Article 113 is headed "Entry into force and application". Its general rule:
It shall apply from 2 August 2026.
It then lists exceptions at points (a) to (d): Chapters I and II from 2 February 2025 (with named provisions from 2 December 2026); Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 from 2 August 2025; Chapter III Sections 1, 2 and 3 from "2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III" and "2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I"; and Articles 102 to 110 from 27 July 2026.
Article 50 is in Chapter IV, and Chapter IV appears in none of those four exceptions. That is an observation about the structure of Article 113, and we make it as an observation rather than a conclusion: the general date is the one the Article gives, and the exception list is the one the Article gives. Whether anything else bears on your position is for your adviser.
The date that gets missed sits in a different Article altogether. Article 111(4), which carries the amendment mark:
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.
A transitional provision in Article 111 that governs an obligation in Article 50 is exactly the sort of thing a reader looking only at Chapter IV will not find.
Questions for your adviser
These are the questions we would want answered if it were our system. They are questions, not checkpoints, and a good answer to several of them is it depends, and here is on what.
- For this specific feature, are we the one who developed it and put it into service under our own name, or the one using it under our authority — or, for different parts of the same screen, both?
- Is the system "intended to interact directly with natural persons" in the sense paragraph 1 uses, and if we say the AI nature is obvious, obvious to whom — would it survive the "reasonably well-informed, observant and circumspect" standard the paragraph names?
- Does the feature generate synthetic audio, image, video or text at all, or does it only assist with standard editing without substantially altering the input or its semantics?
- If content is generated, where would a disclosure have to appear so that it lands "at the latest at the time of the first interaction or exposure", and would that placement meet the accessibility requirement paragraph 5 attaches?
- Is any text we publish "published with the purpose of informing the public on matters of public interest", and does the human review and editorial responsibility carve-out in paragraph 4 describe our actual process or only our intention?
- Was any system we operate placed on the market before 2 August 2026 — and if so, has anyone put the Article 111(4) date in the calendar?
- What did we decide not to label, and can we produce the note we wrote on the day we decided it?
That last question is the one we would ask first. A decision you can evidence is a different thing from a decision you can remember.
What we sell, and what we do not
We should be straight about this, because the page would be less useful if we were not: we do not sell an AI-Act tool. Our compliance software addresses other regimes entirely — Confida is a whistleblowing portal for Directive (EU) 2019/1937, and Cyresora tracks incident-reporting clocks under NIS2 and the CRA. Neither answers the question this page is about, and neither should be bought in the belief that it does. If you want to see what we actually make in this area, the compliance suite is the honest list.
Consolidated text read 6 September 2026 from the Publications Office CELLAR (CELEX 02024R1689-20260727). The consolidated text has no legal effect; the authentic version is the one in the Official Journal. Read the Article yourself before you plan around anything on this page.