Updated on 15 July 2026
AI Act Provider Deployer Obligations: Who Has to Label What Under Art. 50?
As of: July 21, 2026
The AI Act provider deployer obligations are the most commonly misunderstood part of AI labeling. The reason: Article 50 of the AI Act distributes the transparency obligations across two completely different roles. If you only use OpenAI, Midjourney, or another AI system, you have different obligations than the company that develops and provides the system. If you confuse the roles, you'll either label too much, too little, or incorrectly. This article sorts you cleanly into place: provider or deployer, paragraph 2 or paragraph 4, machine-readable or visible. The obligations under Art. 50 apply from August 2, 2026, high time to clarify your own role.
Key Takeaways
- Two roles, two obligations: The provider marks AI output machine-readably (Art. 50(2)); the deployer discloses it visibly (Art. 50(4)).
- If you only use ChatGPT, Midjourney, or Gemini, you're a deployer, not a provider. That means paragraph 4 applies to you, not paragraph 2.
- D2C, e-commerce, agencies, and marketing are almost always deployers and owe visible labeling of deepfakes and certain texts.
- The deadline is August 2, 2026. Only the machine-readable marking (para. 2) for systems placed on the market before this date is provisionally postponed to December 2, 2026 via the Digital Omnibus. The visible deployer obligation (para. 4) is not postponed.
- Fines: up to 15 million euros or 3% of global annual turnover.
- The official EU icons are optional, the labeling obligation itself is not.
Table of Contents
- Two roles, two obligations (Art. 50 explained simply)
- Provider obligation: machine-readable marking (para. 2)
- Deployer obligation: visible disclosure (para. 4)
- Comparison table: provider or deployer
- Am I a deployer if I use ChatGPT?
- Role check in 4 steps
- Gray areas you should know
- Practical scenarios from marketing and e-commerce
- The official EU icon set
- Your next step
- FAQ
AI Act provider deployer obligations: two roles, two obligations (Art. 50 AI Act explained simply)
The official title of Article 50 is "Transparency Obligations for Providers and Deployers of Certain AI Systems." Even the title separates the addressees:
- A provider is anyone who develops an AI system and places it on the market or puts it into service under their own name. Examples: OpenAI (ChatGPT, DALL-E), Midjourney, Google (Gemini, Imagen), Black Forest Labs (Flux), Anthropic, Runway.
- A deployer is anyone who uses such an AI system in the course of a professional activity. Examples: the online shop that generates product images with Midjourney; the agency that writes ad copy with ChatGPT; the real estate agent who virtually furnishes properties.
The crucial consequence: different obligations can attach to the same piece of content. The provider ensures the output is technically marked as AI-generated. The deployer ensures users can actually see the AI nature. Both obligations exist side by side; neither replaces the other.
So an image from an AI generator may already carry an invisible, machine-readable marking (the provider's obligation) and still require an additional visible notice from you (your obligation as a deployer) as soon as it qualifies as a deepfake. Whoever fulfills only one of the two levels is, in case of doubt, not compliant.
Our overview of the AI labeling obligation under the EU AI Act shows how this separation of roles fits into the overall picture of obligations.
Provider obligation: machine-readable marking (Art. 50(2))
Paragraph 2 addresses providers of generative AI systems. They must ensure that outputs, synthetically generated images, audio, video, and text, are marked in a machine-readable format as artificially created or manipulated, and are identifiable as such.
The regulation requires solutions that are "effective, interoperable, robust, and reliable, as far as this is technically feasible." In practice, this covers three families of technology:
- IPTC metadata (DigitalSourceType) and XMP, standardized fields in the file that declare the AI origin.
- C2PA / content credentials, cryptographically signed provenance data that tamper-evidently document how content was created.
- Watermarks, embedded visibly or invisibly in the pixels or the audio signal (e.g., SynthID).
This marking is invisible to the human eye but readable by machines, platforms, and verification tools. It "travels" with the file. We explain the technical background and differences of these methods in C2PA, IPTC, and watermarks.
Important for deployers: this obligation rests with the AI system's provider, not with you. You only need to preserve the machine-readable labeling, not create it yourself. In practice, though, it often gets lost: screenshots, re-exports, and compression by social networks or image editing tools strip metadata. That's why it's worth adding the machine-readable data yourself, even though it's not a legal obligation, for example with our tool.
Note the transition rule: The Digital Omnibus (as of May 2026, preliminary) has postponed the machine-readable marking under para. 2 until December 2, 2026 for systems placed on the market before August 2, 2026. The core deadline of August 2, 2026 remains fixed. Visible deployer labeling (para. 4) and chatbot disclosure (para. 1) are not postponed. The final version of the Omnibus is authoritative.
Deployer obligation: visible disclosure (Art. 50(4))
Paragraph 4 is the paragraph that affects most businesses. It addresses deployers and requires a humanly visible disclosure in two cases:
- Deepfakes, AI-generated or AI-manipulated image, audio, or video content that resembles real people, objects, places, or events and could falsely appear genuine. These must be disclosed as artificially created.
- AI texts on matters of public interest: if a text is published to inform the public about matters of public interest, the AI origin must be disclosed. An exception applies, among other things, if the content is subject to human editorial control and a natural or legal person holds editorial responsibility.
A relaxed standard applies to art, satire, fiction, and similar works: disclosure may be done in a way that doesn't impair the enjoyment of the work, for example in the credits instead of in the middle of the image.
What this visible disclosure looks like in practice depends on the medium: for images, a label on or below the visual; for videos, an on-screen notice; for texts, a written note. You'll find detailed implementations in Labeling AI images, Labeling AI videos, and Labeling ChatGPT texts. For the tricky question of when an image even qualifies as a deepfake, see Deepfake labeling.
For D2C, e-commerce, and marketing in practice, this means: you're generally a deployer and owe visible labeling. For the specific implementation in a shop, read AI labeling in e-commerce and marketing.
Comparison table: provider or deployer under the EU AI Act
| Criterion | Provider | Deployer |
|---|---|---|
| Who | Develops/places the AI system on the market | Uses the AI system professionally |
| Legal basis | Art. 50(2) | Art. 50(4) |
| Obligation | Mark output machine-readably | Disclose AI nature visibly |
| Visibility | Invisible (metadata/watermark) | Visible to the user |
| Applies to | Image, audio, video, text | Deepfakes; texts on matters of public interest |
| Technique | IPTC/XMP, C2PA, watermark | Label, on-screen notice, text notice, EU icon |
| Examples | OpenAI, Midjourney, Google, Flux | Online shop, agency, real estate agent, editorial team |
| Deadline | August 2, 2026 (legacy systems: December 2, 2026) | August 2, 2026 (not postponed) |
| Exceptions | "as far as technically feasible" | Art/satire: relaxed; editorial control |
Am I a deployer if I use ChatGPT?
The short answer: you're a deployer. If you only operate ChatGPT, Midjourney, or Gemini, you don't develop an AI system and don't place it on the market, you use it. That means paragraph 4 applies, not paragraph 2. In this case, the machine-readable marking is owed by OpenAI, Midjourney, or Google respectively.
There's an important exception: anyone who substantially modifies an AI system, renames it, or offers it as a product under their own name (for example, their own SaaS built on someone else's model, or a function embedded via API into a customer product that you market under your own brand) can themselves become a provider, with the corresponding para. 2 obligations. This shift in roles is a typical gray area (see below).
Role check in 4 steps
A quick self-assessment following the regulation:
- Do you develop or integrate your own AI model and bring it to market under your own name? If yes, you're (also) a provider and owe machine-readable marking under para. 2. If no, move on to step 2.
- Do you use third-party AI tools professionally to create content? If yes, you're a deployer. Move on to step 3.
- Does your content produce deepfakes (realistic-looking people/places/events) or texts on matters of public interest? If yes, the visible disclosure obligation under para. 4 applies to this content.
- Do you also operate a chatbot? Then the separate disclosure under para. 1 applies, the notice at the start of the interaction.
If you're unsure, the self-check walks you through the same questions and names the applicable obligations. The AI labeling checklist provides a complete task list.
Gray areas you should know
1. Retouching vs. generative creation. Small corrections (brightness, cropping, removing a speck of dust) don't turn a photo into AI content. Only once AI generates or manipulates substantial content does labeling apply. The transitions are fluid; label if in doubt and for photorealistic results.
2. Platform label ≠ legal obligation. The automatic "Made with AI" from Instagram, TikTok, or Meta satisfies the platform's terms of use, but not automatically Art. 50. It often only appears if metadata has been preserved, and it's not within your control. Don't rely on it. Details in AI advertising on Meta, Instagram & Ads.
3. Is every AI image a deepfake? No. An obviously artificial fantasy motif or a stylized illustration is not a deepfake within the meaning of the regulation. Deepfake refers to content that could look real. We cover this distinction in Deepfake labeling.
4. Dual role. A provider can simultaneously be a deployer for its own published content, in which case both paragraphs apply. Conversely, a deployer who only uses a standard model remains solely addressed by para. 4.
5. Chatbots. If you operate a chatbot, a separate transparency obligation under Art. 50(1) applies: users must learn at the start of the interaction that they're communicating with an AI, unless this is obvious.
6. Marketplaces. If you sell via Amazon or eBay, deployer obligations apply to you despite the platform's own rules. What exactly to do there is shown in Labeling AI product images on Amazon & eBay.
Practical scenarios from marketing and e-commerce
Three typical cases and their clean classification:
Scenario A, AI product image in a shop. An online shop uses Midjourney to generate a photorealistic image showing a real product in a scene that never took place. Role: deployer. Midjourney owes the machine-readable marking; the shop owes the visible labeling because the image counts as realistic (close to a deepfake). Recommendation: visible label plus your own IPTC metadata as proof.
Scenario B, AI ad copy for a product. An agency uses ChatGPT to write ad copy that is edited and approved by a human. Role: deployer. Since this involves product advertising rather than information on matters of public interest, and editorial control exists, visible labeling of the text is generally not mandatory, though good practice may still suggest it.
Scenario C, own AI tool with a white label model. A SaaS embeds a third-party model but markets the image generation under its own brand. Role: here the SaaS can itself become a provider and then owes machine-readable marking under para. 2, in addition to any deployer obligations for its own publications.
Optional: the official EU icon set
For visible labeling, the European Commission provides an official, optional icon set (variants "basic," "fully AI-generated," and "partially AI-modified," each in several versions, as SVG and PNG). Use of these icons is voluntary; the labeling obligation itself exists regardless. But they give your visible notice a uniform, recognizable format. How to use the icons correctly is explained in EU icons for AI content; you'll find the original files at the European Commission.
What to do? Your next step
If you publish AI content and aren't a model developer, you're very likely a deployer and owe visible labeling, ideally supplemented with machine-readable metadata so your proof is complete. What happens in case of violations and how cease and desist procedures unfold is covered in AI labeling: fines and cease and desist letters. The AI labeling glossary clarifies unclear terms.
Our free tool at ki-kennzeichnen.de handles exactly this practical implementation: a visible EU label applied to images and video via drag and drop, plus machine-readable IPTC/XMP metadata (optionally C2PA and an invisible watermark), batch processing of up to 50 files as a ZIP, a REST API for integration, and a labeling register with SHA-256 checksum and timestamp as proof, including CSV export. Unsure which role applies to you? Take the self-check.
Frequently asked questions (FAQ)
Who has to label AI content, the provider or the deployer? Both, but differently. Providers mark the output machine-readably (Art. 50(2)); deployers visibly disclose deepfakes and certain texts (para. 4). For businesses that only use AI, visible labeling under para. 4 is the decisive rule.
Am I a provider or a deployer if I use ChatGPT or Midjourney? You're a deployer. You use the system but don't develop it. You only become a provider once you substantially modify, rename, or offer an AI system as a product under your own name.
What does Art. 50 of the AI Act require, explained simply? Transparency. Providers ensure a technical, machine-readable marking of AI-generated outputs. Deployers ensure that people can recognize the AI nature, for deepfakes and for texts on matters of public interest.
From when do the obligations under Art. 50 apply? From August 2, 2026. Only the machine-readable marking under para. 2 for systems placed on the market before this date is provisionally postponed via the Digital Omnibus until December 2, 2026. The visible deployer obligation under para. 4 is not postponed.
From when does a chatbot have to indicate it's AI? From August 2, 2026. The notice must be given at the start of the interaction, unless it's already obvious that you're talking to an AI (Art. 50(1)).
Do I as a deployer have to set the machine-readable metadata myself? Legally, no, this obligation falls on the provider. In practice, however, metadata is often lost. It's good practice and strengthens your proof to add IPTC/XMP data yourself.
Is the automatic AI label from Instagram or TikTok sufficient? No. Platform labels satisfy their terms of use, not necessarily the legal obligation under Art. 50. Label your content on your own responsibility.
Do I have to visibly label AI-generated ad copy? Generally not: product advertising isn't a "matter of public interest" within the meaning of para. 4, and an exception applies where human editorial responsibility exists. Images and videos, however, can require labeling as deepfakes.
What happens in case of violations? Violations of Art. 50 can incur fines of up to 15 million euros or 3% of global annual turnover. Details in AI Act deadlines and fines.
Our pillar article AI labeling obligation under the EU AI Act gives a complete overview of the deadline, roles, and sanctions.
Sources
- Art. 50 EU AI Act, artificialintelligenceact.eu
- EU guidelines on transparency obligations (providers & deployers)
- EU timeline for implementing the AI Act
- EU icons for labeling AI-generated content
- Sidley, EU AI Act Transparency Obligations (2 August 2026)
- Gibson Dunn, EU AI Act Omnibus Agreement
This article reflects the status as of July 21, 2026, and does not constitute legal advice. The Digital Omnibus is preliminary as of publication; the final version is authoritative. For your specific case, please consult legal counsel.