There's a new EU rule about being upfront when AI is involved, and it starts on 2 August 2026. If that sentence made you sigh — relax. It's mostly common sense, it won't make you rebuild anything, and if you're on the Mitigate platform, most of it is already done for you.
Here's the plain-English version, a 5-minute checklist you can actually run this week, and exactly what we've handled on your behalf.
The short version
- Tell people when they're talking to AI.
- Put an invisible "made by AI" stamp on AI-generated files — think of it as a nutrition label software can read.
- If you make deepfakes or publish AI-written news, say so — most businesses never touch this.
That's Article 50 of the EU AI Act. It applies whenever your AI output reaches people — through a chatbot, synthetic media, or public-interest text — no matter how "risky" the system is. (Purely internal AI, with none of those outputs, may trigger nothing at all.)
What the rule actually asks for
- Tell people they're talking to AI — right in the conversation, by the first message, unless it's already obvious they're dealing with AI. (This one's on the provider — 50(1).)
- Mark AI-generated content so software can spot it. (Also the provider — 50(2).)
- Label deepfakes and AI-written public-interest articles — unless a human reviewed the content and someone holds editorial responsibility for it. (This one's on you as the deployer — 50(4) — but most businesses never make deepfakes or publish AI news.)
No badge on every sentence. No product rebuild. Just be honest about where AI shows up.
Who's actually responsible
- The provider builds and ships the AI system. That's us (Mitigate) for the platform, and the model labs (Anthropic, OpenAI) for the engine underneath. Telling users it's AI, and marking the output — that's our job.
- The deployer is you, using the chatbot in your business. Your one extra duty only kicks in if you use AI to make deepfakes or publish articles on public-interest topics — then you label them. For everyday business use, it doesn't come up.
- The person chatting is the one being protected. They carry no obligations.
A quick myth-buster: "the model is Anthropic's, so it's their problem" doesn't hold — as a deployer, you still have your part. (And if you white-label or heavily rework a system under your own brand, you may step into the provider's shoes.)
Your 5-minute checklist
- Make a quick list of the AI that faces people — your website chatbot, AI-drafted emails, AI-generated reports or offers. For each, check two things: does it tell people it's AI, and is its output marked as AI-made? Every "no" is something to fix.
- Make sure the AI notice is real — visible in the chat, not buried in the fine print. A vague "assistant" or a hidden tag doesn't count.
- Check it's accessible — can a screen-reader user hear it? (The rule requires it.)
- Ask your vendors — in writing — do they mark AI-generated content? Keep the reply on file.
- Flag AI-written public-interest text, if you publish any.
- Don't over-label — internal, obviously-AI tools don't need a badge on everything.
- Watch the clock — systems already live get until 2 December 2026 to add the machine-readable marking, but the AI notice (50(1)) and deepfake/public-interest labeling (50(4)) apply from 2 August, no delay.
We ran this on ourselves — and on the big guys
Before publishing, we did our own audit. Two things stood out:
- Our chatbot already showed the "AI" notice. It had been sitting under the chat the whole time — we just needed to make it editable and translatable. Lesson: check what you already have before building anything.
- We asked ChatGPT and Claude to generate a Word file, then opened its properties. Both were blank — no "made by AI" marker anywhere. The most popular AI tools don't mark generated documents at all. So the moment you do even a little, you're ahead of the pack.
What Mitigate already does
- We tell users it's AI. A clear notice under the chat, from the first message, on by default — and editable per language so you can localise it (keep it visible; switching it off is a deliberate, logged choice): "AI assistant can make mistakes. Check important info."
- We nudge people to double-check — the same line, the way Claude and ChatGPT do it.
- We stamp generated files. Documents we generate carry a machine-readable "Generated with AI (Mitigate AI Platform) — EU AI Act Art. 50(2)" mark in their properties, plus a visible footer for official-use files. For PDFs we use C2PA Content Credentials — the industry standard, which covers PDFs and documents, not just images.
- We don't make images or audio, so that kind of watermarking isn't ours to worry about. If it ever becomes relevant, we'll add C2PA there too.
The honest part
We'd rather tell you the limits than oversell.
- File metadata is best-effort — it can be stripped, and heavy manual editing may wipe it, which is why we add a visible footer as backup. For context: as of mid-2026, files from ChatGPT and Claude carry no marking at all — so we're already at or above the industry line.
- Invisible text watermarking isn't ready yet (today it's basically Google's SynthID on Gemini; OpenAI and Anthropic don't watermark text). The law only asks for what's "technically feasible," so we're watching the standards and will add it the moment something actually holds.
Our rule of thumb
Do what the law asks — and nothing performative. Clear AI disclosure, machine-readable marking where it counts, and no badge-spam that clutters the experience. You stay compliant; your users stay happy.
Sources and further reading
- Regulation (EU) 2024/1689 (AI Act) — Article 50, EUR-Lex
- European Commission — Guidelines on transparency obligations (Article 50)
- European Commission — Code of Practice on marking AI-generated content
- C2PA — Content Credentials (content provenance standard)
A practical summary, last fact-checked 4 August 2026.

