AI Act Article 50: the disclosures your shop needs since 2 August
The AI Act's transparency rules became applicable on 2 August 2026. The Digital Omnibus delayed the high-risk regime but left Article 50 untouched. Here is what merchants must disclose and where the duty sits with the vendor instead.
Article 50 has been in force since 2 August
Article 50 of the EU AI Act became applicable on 2 August 2026. It requires that people can tell when they are dealing with an AI system. For shop operators that touches the storefront directly: support chatbots, AI-driven search, automated replies to customer enquiries.
The Digital Omnibus pushed several AI Act deadlines back over the summer. Article 50 was not among them. Annex III high-risk obligations moved to 2 December 2027, the transparency rules stayed on the original date.
The work involved is small. Most shops need a handful of sentences in the right places, plus an inventory of which AI is actually running in the storefront. The inventory is usually the part nobody has.
Provider or deployer decides who owes what
Article 50 splits its duties across two roles. Paragraph 1 (disclosure on direct interaction) and paragraph 2 (machine-readable marking of generated output) address the provider. Paragraph 3 (emotion recognition, biometric categorisation) and paragraph 4 (deepfakes) address the deployer.
Where merchants change roles
Most merchants are deployers. They license a chatbot and embed it. Two situations change that:
- The bot runs white-label, under the shop's own name and branding.
- The system is substantially modified or used for a purpose the vendor did not intend.
Article 25 then applies and the shop becomes the provider, inheriting the paragraph 1 and 2 duties. If your assistant has a first name and the vendor logo is gone, that is worth a look.
Deployers still have one job in the contract: confirm that the vendor actually delivers machine-readable marking. Without that commitment you are running a tool that cannot meet its own obligation.
Definitions
Five terms that decide the outcome
The regulation works with narrow definitions. Knowing them saves a long argument with legal.
- Provider
- Develops an AI system or places it on the market under its own name. A shop presenting a white-label bot as its own assistant can qualify.
- Deployer
- Uses an AI system under its own authority in a professional context. This covers most merchants.
- Synthetic content
- AI-generated text, image, audio or video. The provider must mark it in machine-readable form, for example through watermarks or metadata.
- Deepfake
- Generated image, audio or video resembling real people, places or events and appearing authentic. In commerce this shows up as AI-generated model photography.
- AI literacy
- The Article 4 duty, applicable since 2 February 2025. Whoever uses AI must make sure their staff can handle it competently.
The binding definitions sit in Article 3 of the AI Act.
Implementation
What belongs in the shop this week
Five checks that take hours, not weeks.
-
Inventory · Write down every AI running in the storefront: chat, search, recommendations, review summaries, translations. Without the list, everything after it is guesswork.
-
Chat disclosure · The notice must appear before the first message, not buried in the widget's terms. One sentence in the greeting is enough.
-
Service email · Replies generated entirely by an AI system and sent without human sign-off need the same disclosure as the chat.
-
Image library · Review AI-generated model shots and product scenes. Anything that reads as a real photograph of a real person goes on the review list.
-
Contracts · For every AI vendor, check whether machine-readable marking is contractually promised and which role the vendor claims for itself.
This is not legal advice, but it covers the cases that come up in real storefronts.
FAQ
The four questions that come up every time
As of late August 2026.
Do AI-written product descriptions need a label?
Not under paragraph 4. The text duty covers matters of public interest such as politics, health or security. Product copy is not that. Paragraph 2 marking sits with the provider of the generator.
What about AI-generated model photography?
The grey area. If the image reads as a photograph of a real person, paragraph 4 deepfake labelling is the safer reading. A visibly illustrative rendering is less likely to qualify.
Is there a transition period?
Only for paragraph 2 marking, and only for generative systems already on the market before 2 August 2026. Those have until 2 December 2026. Anything later complies immediately.
Who enforces this in Germany?
The Bundesnetzagentur, as central market surveillance authority. The German implementing act passed the Bundestag on 11 June 2026. Fines reach EUR 15 million or 3 percent of worldwide annual turnover, with the lower figure applying to SMEs.
Where this leaves you
Article 50 asks nothing technically demanding of a shop. It asks that someone knows which AI is running and who answers for it. That list is missing in most projects, because the systems arrived over months from different directions: chat from the marketing agency, search from the plugin vendor, translation from the backend.
The next date is already set. On 2 December 2026 the transition period ends for machine-readable marking in generative systems that were on the market before August. That obligation sits with providers rather than merchants, but it changes the contractual picture. By then you should know which vendor delivers marking and which does not.
An hour spent on the inventory covers most of the work. The remainder is copy in three or four places in the storefront.