Quick Answer
Article 50 of the EU AI Act applies from 2 August 2026. For marketing teams, the most relevant deployer duties are clear disclosure of deepfake content and of AI-generated public-interest text that has not had substantive human review or editorial control. The technical duty to make synthetic outputs machine-readable and detectable falls on providers of the generative tool, a duty that sits upstream of the marketing team. For customer-facing AI assistants, the provider must ensure the AI notice appears, and the marketing team deploying the assistant verifies that users see it from the first interaction. Fines reach EUR 15 million or 3% of worldwide annual turnover, and the rules apply wherever your content reaches people in the EU.
The gap most teams hit is not legal, it is operational: knowing where AI entered the pipeline and whether it had substantive human review. Darwin helps turn these rules into a workable operating model through its AI Readiness & Enablement work.
TL;DR
- Article 50 is live. It became enforceable on 2 August 2026 and reaches any AI system used in a few specific situations, including AI-generated marketing content, whatever the system's own risk level.
- Marketing teams are deployers. Your deployer duties are the visible ones: deepfake labels and disclosure on AI-generated public-interest text. For chatbots, the provider must ensure the AI notice appears, and you verify that users see it.
- Marking is the provider’s job. Machine-readable marking of synthetic content under Article 50(2) sits with the provider of the generative tool. Your contracts are where you hold vendors to it.
- The fix is operational. Build disclosure into CMS fields, approval routing, and an AI content inventory so compliance produces an audit trail as a by-product.
- Penalties and reach are wide. Fines hit EUR 15 million or 3% of worldwide turnover, and the rules apply extraterritorially to any content reaching people in the EU.
Since 2 August 2026, Article 50 transparency obligations have been in effect, and they reach more marketing teams than almost any other part of the EU AI Act.
The reason is scope. These transparency rules are not limited to "high-risk" systems. Some AI-assisted marketing workflows fall within Article 50, including deepfake creatives and public-interest text published without substantive human review or editorial control.
For a marketing team, the practical weight lands in one place. You are almost always a deployer, so the visible disclosure and the record behind it belong to you. A US-based team running AI-generated campaigns that reach European audiences is in scope, because the obligation follows the content and the audience wherever the head office sits. Treating this as a question of AI governance and audit readiness keeps the response proportionate.
What Article 50 Means for Marketing Teams
Article 50 sits in the limited-risk tier of the EU AI Act, the transparency-only category. The catch is that these obligations attach to specific uses of AI, whatever the system's own risk classification. The Article 50 transparency obligations break down into four separate duties bundled together.
First, direct AI interaction. When an AI system talks to people through a chatbot, a virtual assistant, or an automated phone line, users have to know they are dealing with a machine. The one relief valve: disclosure is unnecessary when it is already obvious to a reasonably informed person.
Second, machine-readable marking of synthetic content. Providers of generative AI systems that produce synthetic audio, image, video, or text must mark those outputs in a machine-readable format so downstream tools can detect them as AI-generated. This duty sits with the provider, the company that supplies the generative tool. Marketing teams do not carry this technical marking duty; the practical lever on your side is a vendor contract that requires it. Your own responsibility is the visible-disclosure side. It is worth building the same audit third-party AI vendors discipline you would apply elsewhere, and treating security and compliance foundations for your AI stack as part of the same effort.

Third, deepfake disclosure. Deployers who publish AI-generated or manipulated image, audio, or video content that constitutes a deepfake must disclose it. A deepfake, defined in Article 3(60), is content that resembles real persons, objects, places, or events and would falsely appear authentic. Photorealistic AI imagery of a product in a real-looking setting can fall in scope; an obvious fantasy scene does not.
“Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.”, – EU AI Act, Article 50(4)
Fourth, AI-generated public-interest text. When AI-generated text is published to inform the public on a matter of public interest, deployers disclose that it is AI-generated. The exemption turns on how to review AI-generated content before publication: a human with relevant competence reviews the text and a natural or legal person holds editorial responsibility for it.
Two practical points close this section. Penalties for getting it wrong reach EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. And on 20 July 2026 the European Commission adopted the final version of its Guidelines on Article 50, a 51-page reference that national authorities are expected to follow.
On timing, the official FAQ gives a clean rule: content generated before 2 August 2026 does not require retroactive labelling. From that date forward, new AI-generated assets fall under the disclosure duties described above.
What Marketing Teams Need to Disclose
The fastest way to cut through the anxiety is to sort your assets into three buckets: mandatory disclosure, clear exemption, and gray area that needs a judgment call.
Chatbots and interactive systems. The provider must ensure a chatbot or interactive AI system informs users they are dealing with AI. A marketing team deploying the assistant verifies that users see the notice from the first interaction. A short banner does the job: "You're chatting with an AI assistant." The notice belongs in the first message, and stays out of a buried footer.
Generative content marking. Two separate bases trigger disclosure, and they should not be blurred. AI-generated public-interest text requires disclosure when it is published without substantive human review and editorial responsibility. AI-generated or manipulated image, audio, and video require disclosure only where the asset qualifies as a deepfake. An AI-drafted blog post on cybersecurity regulation with no human review needs a label; a product description drafted by AI and then reviewed and edited by your team does not. Start by listing the AI tools in your marketing stack, then review vendor responsibilities and ownership in your stack.
Deepfakes. Synthetic media depicting a real person in a situation that did not happen requires disclosure at first exposure: synthetic testimonials, AI-generated images of real executives, deepfake product demos featuring actual individuals. The label is plain: "This video contains synthetic media."
Public-interest text. Text on politics, health, finance, legal matters, public safety, or consumer protection triggers disclosure when AI produced it without human editorial oversight. This spans blog posts on regulatory topics, whitepapers on market risk, and educational content on data security. Human review and clear editorial responsibility are what either unlock the exemption or confirm the disclosure is accurate.
Exemptions and gray areas. Internal sales enablement decks, AI-assisted copy that a human substantively edits and stands behind, most AI-generated product graphics that show no real people, and routine spell-check or grammar tools stay outside the requirement. The genuine gray areas are fully synthetic landing-page text on public-interest topics, AI-generated nurture sequences shipped without review, and social posts touching safety or consumer protection. When the call is close, disclosure is the safer choice.
Real B2B SaaS Marketing Cases
Most people open an article like this with one question: what about my blog, my chatbot, my landing page? Here is how the rules land on everyday B2B SaaS work.
AI-generated blog post with human review. Your team drafts a data-security guide with an AI tool, then edits, fact-checks, and adds original analysis prior to publication. Substantive human review carried the content, so no Article 50 disclosure applies. Ship that same AI draft with light copy-editing and no fact-check on a regulatory-compliance topic, and disclosure becomes necessary. This is where editorial quality in AI content creation earns its keep.
Landing page with AI-generated images. A campaign page uses AI-generated product mockups that read as realistic. If the images could make a visitor believe they are seeing real product photos, they may meet the deepfake threshold and a line such as "Product images are AI-generated for illustration" is the safe call. Clearly stylized graphics used as design elements generally fall outside the requirement. The deciding factor is whether the image could deceive.
Nurture email sequence. Your automation tool generates full email bodies for a six-email sequence with little human editing. Most marketing emails are private outreach, so they usually fall outside the public-interest text rule and need no Article 50 label. Where AI also profiles contacts or drives automated decisions, GDPR obligations can apply separately, which is a distinct question from Article 50 disclosure. Teams running these at scale often lean on marketing automation workflows.
Product demo video. A screen-recorded walkthrough with a human voiceover is standard video marketing, no disclosure required. Swap in an AI-generated narrator face or a synthetic presentation of a customer testimonial, even a consented one, and the AI-generated elements need disclosure in the description or on screen.
Sales enablement deck. Your RevOps team builds internal battlecards with AI-assisted competitive analysis. The content is internal and never reaches the public, so Article 50 does not apply.
Website chatbot. The provider must ensure the chatbot gives visitors a clear notice from the first interaction: "You're chatting with an AI assistant." A marketing team deploying the tool verifies that the notice appears in the opening message, and stays out of a buried footer. The same discipline applies to AI agents in marketing operations.
LinkedIn campaign images. Abstract or clearly stylized AI graphics for LinkedIn ads are not deepfakes, so Article 50 does not compel a label. A voluntary "Image created with AI" note is a transparency choice a brand can make, separate from any legal requirement.
If you want a structured read on your own exposure, it helps to see what an AI Readiness Sprint assesses against these cases.

CMS and Approval Workflow Changes
Article 50 does not prescribe specific CMS fields or an inventory format. What follows are operational controls, a best-practice way to meet the disclosure duties reliably and to produce an audit trail as a by-product. The teams that stay clean build these habits into the systems they already use every day.
CMS fields at the point of creation. Update your content management system to flag AI involvement the moment content is made. In HubSpot, Marketo, or a custom platform, add a field, call it "AI Content Type," with clear options: AI-generated text with no human review, AI-generated text with human review, AI-generated image or video, deepfake or synthetic media, and human-created. When a marketer creates or uploads an asset, they pick one. That single choice drives everything downstream: approval routing, disclosure language, and asset tagging.
Two-tier approval. Set up two review stages. The first is standard editorial: grammar, brand voice, accuracy. The second is an AI-specific compliance check for anything flagged for disclosure. Route public-interest AI content through Marketing Operations or legal before it goes live, confirming that the disclosure language is accurate and visible, that the human-review threshold was genuinely met, and that any synthetic media is correctly identified. Teams that automate approval and publishing workflows keep this consistent, and it is worth planning how to integrate the controls into your publishing workflow.
AI content inventory and audit trail. Before you can govern anything, you need to see it. Build a central inventory of AI-generated assets: asset name and type, the AI tool used, publication date, disclosure status, owner, and last-reviewed date. Keep it current. The inventory is the artifact that demonstrates good-faith effort if a question ever arises, and it turns "we think we're compliant" into something you can show. The same instinct drives AI inventory and audit trails for privacy.
Governance and ownership. Assign one accountable owner. Marketing Operations or the CMO holds overall governance, and a designated AI content steward, usually a senior MarOps person, trains the team, reviews flagged content, maintains the inventory, and runs periodic checks. A single point of accountability keeps the rules consistent for in-house staff, agencies, and freelancers alike, and it helps to document governance and ownership once and reuse it.
How to Operationalize Article 50 Compliance
Compliance is achievable when you treat it as a workflow upgrade that lives inside your daily systems. A working sequence looks like this.
Audit your live content first: blog posts, landing pages, emails, videos, chatbots, and social campaigns, flagging what AI created or heavily modified (the same instinct as when you map your AI use cases before automating). Map every AI tool in your stack, from generative writing to design to chatbot builders, so you know which sources feed disclosure decisions. Set your disclosure standards next, deciding how AI content gets marked: CMS metadata, visible badges, chatbot disclaimers, email-footer language, applied the same way each time. Wire those standards into your CMS with a flag or an approval step, and document who reviews what, which criteria trigger disclosure, and who signs off. Train the team in a short workshop covering the requirements, your standards, and the common cases. Run a dry test on a handful of upcoming assets to confirm tags render, approvals route, and published content displays as intended. Then set a recurring review so live content keeps its labels as production scales.
Article 50 Is a Test of Your Operating Layer
Article 50 does not create a one-off labelling task. It exposes whether the operating layer behind your AI content is reliable. In Darwin Flux terms, teams capture the right signals at the point of creation (Surface), connect them to CMS and approval workflows (Connections), create shared rules for review and disclosure (Clarity), and only then automate publishing at scale (Momentum). The operational layer AI depends on is the same one covered in Marketing Data Readiness for AI Agents. Every gap in that chain is a place where an AI asset ships without the disclosure, the review, or the record it needed.
How Darwin Helps
Most organizations that struggle with Article 50 will not fail because someone forgot a single label.
They struggle because they cannot say where AI entered the content lifecycle, who reviewed the output, and who owns the decision to disclose.
Compliance starts long before publication. It starts the moment AI becomes part of the content workflow. That is the gap Darwin closes.
Darwin builds that operating layer. At Tech.co, Darwin implemented an AI-powered content operation spanning research, editorial planning, creation, distribution, and results tracking.
The program cut manual work by 50%, lifted content output 4X, and drove an 8X increase in overall output, freeing more than 20 hours a month.
A workflow moving at that speed is exactly the kind that now needs a governance layer on top: identify the output type, assign substantive human review, record the approval, and assess whether an Article 50 disclosure applies at the point of publishing.
Darwin delivers the operational side of that governance through its AI Readiness Sprint, which maps AI tools, approvals, ownership, and publishing flows and returns a readiness scorecard with a prioritized list of blockers. The legal reading of any specific asset is something a team confirms with its own counsel.
For teams past the pilot stage, the next question is how to measure AI workflow ROI and how to move from AI content scale to a governed operating model.
FAQs
Q1. When did Article 50 become enforceable, and what are the penalties?
Article 50 of the EU AI Act became enforceable on 2 August 2026. Organizations that fail to comply face administrative fines up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.
Q2. Do I need to disclose AI content if a human reviewed it first?
If a human with relevant competence reviewed the AI-generated text and a natural or legal person holds editorial responsibility for it, including authority to approve or reject it, disclosure is not required for that public-interest text. Both conditions must be met.
Q3. What is the difference between providers and deployers?
Providers develop AI systems and place them on the market, and they handle technical duties like machine-readable marking. Deployers use AI systems in a professional capacity, and they handle visible disclosures such as labeling deepfakes and disclosing AI-generated public-interest text. For chatbots the provider must ensure the AI notice appears, and the deployer verifies users see it. Most marketing teams are deployers.
Q4. Do I need to label AI-edited product photos?
It depends on whether the image qualifies as a deepfake, for example one that deceptively resembles a real person, object, place, or event. Minor edits such as lighting adjustments or background cleanup generally do not trigger Article 50 disclosure. For other AI-generated product imagery, a label can be a voluntary transparency choice, separate from any legal requirement.
Q5. Does Article 50 apply if my company is outside the EU?
Yes. The regulation applies extraterritorially. If your AI-generated marketing content reaches people in the EU, you comply with Article 50 wherever your organization is based.