AI Content Disclosure Audit: EU AI Act Article 50 Checklist for Client Work
When does client work trigger an AI disclosure duty under Article 50?
EU AI Act Article 50 transparency obligations became enforceable EU-wide on 2 August 2026 (Regulation (EU) 2024/1689, Article 113). The trigger is role-based and use-case-based, not tool-based: an agency does not have to label every commercial made with Midjourney or every script drafted with ChatGPT. A disclosure duty fires only when specific client work meets one of four triggers — an AI chatbot or brand assistant at first contact, synthetic image/audio/video that passes the deepfake test, AI-drafted text informing the public on matters of public interest, or a custom AI tool built on a model that shifts the agency into provider territory. Run the audit items below before client work ships to EU markets, and keep the evidence in the client file.
On 31 August 2026, VIA Nederland — the Dutch advertising trade body — published guidance mapping exactly when creative agencies owe AI transparency duties (AI-transparantie voor creatieve bureaus, Dutch original), and PPC Land's September 5, 2026 coverage walked agencies through the same four triggers. The law behind the guidance is not speculative: Article 50 has been live since 2 August 2026, with Commission implementing guidelines (C(2026) 5054 final) adopted 20 July 2026. This page turns the framework into a disclosure audit you can run on client work — whether you produce the work at an agency or buy it from one.
Start the audit with the role check, then test each of the four triggers as a yes/no item. When a trigger fires, the item tells you who labels, how, and what evidence to keep.
EU AI Act Article 50 disclosure triggers
Work through the seven audit items below. Each item has a concrete verification step. If an item fails, the fix is a disclosure, a documented review, or an engineering change — not a renegotiation of the whole engagement.
-
Role check: are you a deployer or a provider for this piece of client work? A provider develops an AI system — or has it developed — and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority for professional purposes. Most creative agencies are deployers: they do not build models, they use existing systems such as ChatGPT, Midjourney or Adobe Firefly. The role decides which duty applies. Providers must ensure synthetic output is marked in a machine-readable format and detectable as artificially generated (Article 50(2)). Deployers owe the visible, human-perceivable labels for deepfakes and public-interest text (Article 50(4)). A deployer cannot satisfy a visible label by pointing at the provider's machine-readable marking. Yes/no test: for this engagement, do you only use existing AI systems (deployer), or did you build or commission an AI system placed under your own name (provider)? Keep the role determination in the client file.
-
Trigger 1 — AI chatbot or brand assistant: is AI disclosed at first contact? When an AI system communicates directly with people — a brand chatbot answering questions, an AI brand assistant giving product advice, an AI persona — users must be informed they are interacting with AI (Article 50(1)), unless it is obvious from the point of view of a reasonably well-informed, observant and circumspect person given the context. A consumer-facing chatbot styled to resemble a human employee rarely gets the "obvious" pass. Yes/no test: does the client work deploy an interactive AI that talks to people? If yes, is there a clear AI notice at first contact — a short text notice for chat, a spoken notice for a voice assistant? A mention buried in terms and conditions, or anywhere a user must search, does not satisfy the duty. Evidence to collect: the first-contact script and proof of where the notice appears.
-
Trigger 2 — Synthetic image, audio or video: does it pass the deepfake test? A deepfake is AI-generated or manipulated image, audio or video content "that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful" (Article 3(60)). The practical test: could a viewer be deceived about the authenticity of the content? Two details matter. First, the AI person does not have to match a known real individual — what counts is whether the created person could be taken for a real one. Second, clearly fictional scenes, minor technical post-production, and the mere fact AI was in the pipeline do not by themselves make a deepfake. Yes/no test: for each AI-generated or manipulated image, audio or video deliverable, could the audience be deceived about authenticity — including a photoreal AI talent in a realistic setting, a synthetic voice resembling a known presenter, or content implying an event that did not happen? If yes, the deployer must disclose at first exposure in a clear, distinguishable, human-perceivable way. Metadata alone or an invisible technical watermark is not enough, and the artistic-content carve-out does not rescue content where the commercial message dominates. Evidence to collect: the visible label asset, its placement, and the creative-review note. If no, keep the rationale: the Commission's own example treats AI video of cartoon mice arguing over cheese in an ad as clearly fictional, not a deepfake.
-
Trigger 3 — AI-drafted text: is it public-interest text that must be disclosed? Deployers owe a text disclosure only when AI generates or manipulates text "published with the purpose of informing the public on matters of public interest" — politics, public health, public safety, fundamental rights, or other developments relevant to public debate (Article 50(4), second sub-paragraph). For agencies this usually means societal and public-awareness campaigns, not routine commercial copy, blogs or social posts. Yes/no test: is the AI-drafted or AI-assisted text informing the public on a matter of public interest? If yes, disclose that the text is artificially generated — unless it "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication." The human review must be substantive and documented: a spellcheck or rewriting a few sentences is not enough. Evidence to collect: the label on the published text, or the editorial sign-off naming the person who reviewed it and when.
-
Trigger 4 — Custom AI tool built on a model: are you in provider territory? An agency that develops its own AI system, or an application layered on an existing model, may qualify as a provider for that specific tool — the least common but most consequential scenario. VIA's rule: each application must be assessed individually; there is no bright-line test. Yes/no test: did your agency build a custom AI tool or application on top of an existing model — for example a branded "campaign copy generator" or a client-facing assistant wrapper? If yes, assess whether the agency is a provider for that tool. If it is, synthetic output from the tool must be "marked in a machine-readable format and detectable as artificially generated or manipulated" (Article 50(2)), typically with digitally signed, time-stamped metadata plus an imperceptible watermark per the Code of Practice — not merely a visible label. Marking is not required where AI only performs an assistive function for standard editing or does not substantially alter the input. Evidence to collect: the per-application role assessment and the technical marking specification. Note: using the same API model directly to draft one client's copy does not flip the role for that engagement.
-
Responsibility-chain analysis: who in the agency-client workflow must label, and how? Article 50 duties do not follow the tool — they follow the role each organization plays in the chain. Map the workflow: which party develops or places the AI system (provider duties: machine-readable marking), and which party uses it under its own authority for professional purposes (deployer duties: visible labels)? When the agency builds the interactive tool for a client, the provider-side duties sit with the builder; when the client uses an existing off-the-shelf assistant, determine which party in the chain owes the first-contact disclosure — VIA flags this as a separate analysis with no bright-line answer. When the agency merely uses signatory tools (Google, Meta, Anthropic and roughly 190 others adhere to the Code of Practice), the agency inherits the machine-readable marking those providers add — no build work needed. Verification step: for each AI-touching deliverable, write down who must label (provider, deployer, or both), what the label must be (machine-readable marking, visible label, or both), and where in the deliverable it appears. Keep that map in the client file so a regulator, client or insurer can see the decision.
-
Evidence field: assemble the disclosure audit file. An Article 50 audit is only as good as its evidence. For each client engagement that touches AI, collect: (1) the first-contact script and placement proof for any chatbot or brand assistant; (2) the visual or audio label assets and placement proof for any synthetic image, audio or video that passed the deepfake test; (3) the machine-readable marking specification (metadata and watermark approach) for any custom AI tool your agency built on a model; (4) the editorial sign-off record naming the human who substantively reviewed public-interest text and holds editorial responsibility; and (5) the role-assessment memo documenting the deployer/provider determination per application. Store the evidence with the client file, not in a folder only the account team knows about. Verification step: open the file for a completed AI-touching engagement — can a new person reconstruct who labeled what, how, and on what date?
Legal consequence note — the stakes are real. Article 50 has been enforceable since 2 August 2026 EU-wide under Regulation (EU) 2024/1689. Breaches of the Article 50 transparency obligations can draw fines of up to EUR 15,000,000 or, for an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)(g)). These are maximums set by the Regulation and applied by EU member state authorities under national penalty regimes — the correct framing is "up to 3% of turnover," not a flat 3% fine. There is no retroactive labelling for content created before 2 August 2026, with one exception: AI text on public-interest matters generated before 2 August but first published on or after that date does need a label. The 2 December 2026 grandfathering date applies only to providers' machine-readable marking of AI systems placed on the market before 2 August 2026 — deployer-side duties have been live since 2 August with no grace period.
What not to overstate. Not every AI-assisted deliverable carries a duty. Ordinary commercial copy, blogs and social posts are generally outside the deployer text-label obligation; clearly fictional imagery and minor post-production are not deepfakes; and the artistic carve-out does not rescue creative advertising where the commercial message dominates. This page is informational, not legal advice — confirm any specific exposure with counsel qualified in the relevant EU member state.
How this audit fits your other AI checks
The Article 50 disclosure audit covers the transparency side of client-facing AI work: who must tell the public that content or an interaction is AI. It complements the operational audits on this site — the AI agent risk checklist for agent security and permissions, and the Claude watermark and C2PA audit guide for what provenance marks do and do not prove when you verify AI content from vendors. For the agency-side explainer of the same four triggers — with the checklist table, agency examples, and the deployer/provider role split — see the EU AI Act Article 50 guide for AI agencies on Find AI Agency. If you buy AI services rather than produce them, run the same four triggers against your agency's deliverables: the duty in the chain is exactly what a vendor should be able to document.
Bottom line
EU AI Act Article 50 is enforceable law since 2 August 2026, and the Dutch trade body VIA Nederland has given agencies a concrete four-trigger framework for when client work must be disclosed as AI. The audit is runnable in an afternoon: confirm your role as deployer or provider, test the chatbot, deepfake, public-interest-text and custom-tool triggers as yes/no items, map who in the chain must label and how, and keep the first-contact scripts, label assets, marking specs and editorial sign-offs in the client file. The agencies that treat transparency as part of delivery — not a pre-launch scramble — are the ones that will be ready when a client, an insurer, or a regulator asks to see the audit trail.
Frequently asked questions
Do we have to label every AI-assisted ad or ChatGPT draft for EU clients?
No. Article 50 duties are role-based and use-case-based, not tool-based. Most agencies are deployers, and most client work made with ChatGPT, Midjourney or Adobe Firefly does not automatically need a label. A duty arises only when a specific trigger is met: an AI chatbot or brand assistant at first contact, synthetic image/audio/video that passes the deepfake test, AI-drafted text informing the public on matters of public interest, or a custom AI tool built on a model that makes you a provider for that tool.
When did the EU AI Act Article 50 transparency rules become enforceable?
Article 50 became legally applicable across the EU on 2 August 2026 under Regulation (EU) 2024/1689 (Article 113). The Commission's implementing guidelines, C(2026) 5054 final, were adopted on 20 July 2026. Deployer-side duties had no grace period; a 2 December 2026 grandfathering date covers only providers' machine-readable marking obligation for AI systems placed on the market before 2 August 2026.
What are the penalties for missing an Article 50 AI disclosure?
Breaches of the Article 50 transparency obligations can draw fines of up to EUR 15,000,000 or, for an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)(g) of Regulation (EU) 2024/1689). These are maximums applied by EU member state authorities under national penalty regimes, not flat fines.
Who is responsible for labeling AI content: the agency or the AI tool provider?
It depends on role. Providers of generative AI systems carry machine-readable marking duties; deployers who use those systems for professional purposes carry the visible labelling duties for deepfakes and public-interest text. Most agencies are deployers when they use ChatGPT, Midjourney or Adobe Firefly. When an agency builds a custom application on a model, each application must be assessed individually — the agency may qualify as a provider for that tool. There is no single answer for who labels in a chain; the audit maps it per engagement.
Does an invisible watermark or metadata satisfy the deepfake label requirement?
No. For synthetic or manipulated image, audio or video that passes the deepfake test, the deployer must disclose at first exposure in a clear, distinguishable, human-perceivable way. Metadata alone or an invisible technical watermark is not sufficient, and a deployer cannot rely on the machine-readable marking the model provider embeds under Article 50(2).
What counts as AI-drafted text that must be disclosed?
Only AI-generated or manipulated text published with the purpose of informing the public on matters of public interest — politics, public health, public safety, fundamental rights, or other developments relevant to public debate. That text must be disclosed as artificially generated unless it has undergone substantive human review or editorial control with a named person or organization holding editorial responsibility. Ordinary commercial copy, blogs and social posts generally sit outside this deployer duty.
Sources:
- [1] VIA Nederland — "AI-transparantie voor creatieve bureaus: wanneer moet je AI-gebruik vermelden" (guidance dated August 31, 2026, Dutch original; English renderings on this page are working translations): vianederland.nl — AI transparency for creative agencies
- [2] PPC Land — "Dutch trade body maps 4 AI disclosure triggers for ad agencies" (September 5, 2026): ppc.land — 4 AI disclosure triggers for ad agencies
- [3] European Commission — Guidelines on transparency obligations for providers and deployers of AI systems (library page, publication July 20, 2026): digital-strategy.ec.europa.eu — Article 50 guidelines
- [4] European Commission — Code of Practice on Transparency of AI-generated Content (final code text June 10, 2026; adequacy confirmed July 20, 2026): digital-strategy.ec.europa.eu — Code of Practice
- [5] European Commission — Guidelines on the implementation of the transparency obligations under Article 50, C(2026) 5054 final (July 20, 2026): Commission guidelines C(2026) 5054 final (PDF)
- [6] EUR-Lex — Regulation (EU) 2024/1689 (EU AI Act), Articles 3(60), 50, 99(4)(g), 113: eur-lex.europa.eu — Regulation (EU) 2024/1689
Accuracy note: Verified 2026-09-05 against the research brief for this update (grounded-citations verify passed, 6/6 sources evidence-backed). Article 50 became applicable EU-wide on 2 August 2026 (Article 113, Regulation (EU) 2024/1689); guidelines C(2026) 5054 final are dated 20 July 2026; final Code of Practice text is dated 10 June 2026 with adequacy confirmed 20 July 2026. Fines are described as maximums ("up to EUR 15M or 3% of total worldwide annual turnover, whichever is higher"), applied by member state authorities. VIA quotations and framework descriptions are working translations from the Dutch original (31 August 2026); the PPC Land coverage is dated September 5, 2026. Informational only — not legal advice.