Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
News

EU AI Disclosures Are Live—The Deployer Cannot Pass the Duty to a Vendor

|Author: QUASA Editorial Team|6 min read
EU AI Disclosures Are Live—The Deployer Cannot Pass the Duty to a Vendor

The EU AI Act’s Article 50 transparency obligations began applying on August 2, 2026. The European Commission’s July announcement set out the start date and the separate duties imposed on providers and deployers of covered AI systems.

The immediate consequence is a division of responsibility, not a transfer of every disclosure to the technology vendor. Providers must build specified notices and machine-readable markings into their systems, while deployers remain responsible when Article 50 attaches a disclosure to their operation of an AI system or publication of its output.

The provider-versus-deployer decision tree

The official text of Article 50 assigns each obligation according to the regulated activity. Buying a third-party system does not, by itself, determine which party carries every transparency duty.

  • Does the system interact directly with a person? The provider must design and develop it so the person is informed that the interaction is with AI, unless that is obvious in the circumstances.
  • Does the system generate synthetic text, audio, images or video? The provider must make covered output machine-readable and detectable as artificially generated or manipulated, subject to the provision’s limits and exceptions.
  • Is emotion recognition or biometric categorisation being used? The deployer must inform the natural persons exposed to the system.
  • Is qualifying image, audio or video a deepfake? The deployer must disclose that it was artificially generated or manipulated.
  • Is AI-generated or manipulated text being published to inform the public about a matter of public interest? The deployer must disclose its artificial origin unless the statutory human-review and editorial-responsibility exception applies.

The chatbot branch is narrower than a general rule that every customer deploying AI must display its own notice. Article 50(1) assigns the system-design obligation to the provider. A customer’s separate deployer obligations arise when its use falls within the emotion-recognition, biometric-categorisation, deepfake or public-interest-text branches.

The legal role follows the real arrangement. A provider develops an AI system, or has it developed, and places it on the EU market or puts it into service under its own name or trademark; a deployer uses a system under its authority for a professional activity. The rules can also reach providers outside the EU when their system’s output is used in the Union.

A vendor cannot absorb the deployer’s disclosure

A legal entity remains the deployer when contractors or freelancers operate the system on its behalf and under its responsibility and control. The Commission’s Article 50 FAQ also specifies that a deployer disclosing a deepfake cannot rely only on the provider’s embedded machine-readable marking: the audience-facing notice must be clear and perceivable without special technical tools, no later than first exposure.

This is the practical boundary behind the headline. A vendor may supply labels, provenance features or workflow controls, but those services do not relocate a statutory duty attached to the deployer’s operation or publication decision. Contract terms can allocate implementation work and commercial risk between the parties, but they do not rewrite which regulated actor Article 50 addresses.

The boundary works in both directions. A deployer is not automatically responsible for every control in the supply chain merely because it bought and uses the system. Providers remain accountable for the interaction-design and machine-readable-marking duties assigned to them.

What providers must put into covered systems

For systems intended to interact directly with people, providers must ensure that users are informed they are dealing with AI unless that fact would be obvious to a reasonably well-informed, observant and circumspect person in the relevant context. The information must be clear and distinguishable and appear by the first interaction at the latest.

For systems generating synthetic audio, images, video or text, providers must mark covered output in a machine-readable format and make it detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust and reliable as far as technically feasible, taking account of the content type, implementation costs and the state of the art.

The marking obligation has limits. It does not apply to the extent that a system performs an assistive function for standard editing or does not substantially alter the deployer’s input or its meaning. The duty concerns the technical detectability of covered output; it is distinct from a visible or audible disclosure delivered to an audience.

What deployers must tell people

Deployers of emotion-recognition or biometric-categorisation systems must inform the natural persons exposed to their operation. That branch turns on exposure to the system, rather than on whether the deployer publishes generated content.

For deepfakes, the disclosure duty covers AI-generated or manipulated image, audio or video content that resembles an existing person, object, place, entity or event and would falsely appear authentic or truthful. Evidently artistic, creative, satirical, fictional or analogous works receive a narrower presentation rule: the disclosure must be appropriate without hampering display or enjoyment of the work.

The public-interest-text branch is not a blanket label for every AI-assisted document. It applies to generated or manipulated text published for the purpose of informing the public on a matter of public interest. No Article 50 label is required where the content has undergone substantive human review or editorial control and a natural or legal person holds editorial responsibility; spelling or grammar correction alone does not amount to that review.

The December transition does not suspend deployer duties

The four-month transition is confined to one provider obligation. Under Regulation (EU) 2026/1744, providers of synthetic-content-generating systems placed on the market before August 2, 2026 have until December 2, 2026 to comply with Article 50(2)’s machine-readable marking and detection requirement.

That extension does not postpone the provider’s direct-interaction rule or the deployer duties for emotion recognition, biometric categorisation, deepfakes and qualifying public-interest text. Content generated before August 2 is not subject to mandatory retroactive labelling.

Broader AI Act delays concern different provisions. ITPro’s August 3 coverage reported Article 50 transparency requirements as operative while placing requirements for stand-alone high-risk systems on December 2, 2027 and those for high-risk systems embedded in regulated products on August 2, 2028. The related high-risk timetable changes therefore did not pause Article 50.

The position as of August 9 is limited but clear: Article 50 is applying, responsibility follows the role and activity identified in each paragraph, and only qualifying providers of older systems received the December extension. That transition covers machine-readable marking—not a deployer’s live audience-facing disclosure.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0