Your application has a chatbot that talks to users. Or maybe it analyses images, generates descriptions, or helps create content. For the past two years, no one asked whether the user should know that they are using artificial intelligence. Now these questions are coming back more and more often. Has the AI Act been postponed? Are the new obligations already in force? Can you be fined €35 million for failing to label the use of AI in a product? If your application was written with the help of AI, do you have to tell users about it?
In this article, we explain what the AI Act is and which of its obligations apply to mobile applications and web applications. We will show when you need to inform the user that AI is being used, when generated content needs to be labelled, and when you do not need to do anything.
What is the AI Act?
The AI Act is an EU regulation governing how artificial intelligence systems are made available and used. The rules divide AI systems according to the level of risk they may pose.
The biggest requirements apply to systems that can influence important decisions about people, such as recruitment, education, or creditworthiness. The deadlines for applying these rules were postponed by the July 2026 amendment, which means that most of them will only start applying on 2 December 2027.
This does not mean, however, that all other applications have been covered by the postponement. A separate category consists of the transparency obligations set out in Article 50 of the AI Act. They mainly concern whether the user knows that they:
- are talking to an AI system,
- are viewing or listening to content generated by AI,
- are dealing with emotion recognition or biometric data analysis,
- are viewing realistic material that was actually generated or modified by AI.
These obligations started applying on 2 August 2026.
Planning an app with AI?
Discuss Your ProjectDoes application code written with AI assistance have to be labelled?
No. The AI Act regulates the product (what the user sees and uses, not the process used to create it). The mere fact that a developer uses tools such as GitHub Copilot, Cursor, or other AI-assisted coding tools does not mean that there is an obligation to add special information to the repository or label the code as AI-generated.
The obligations under Article 50 concern specific ways of using AI systems, in particular interaction with the user and the generation or substantial modification of content, not the way the code itself was created.
Does Article 50 apply to your application?
The obligations under Article 50 of the AI Act do not automatically apply to the entire application. The specific functions and the role of the company using them are assessed.
Therefore, for each AI function, it is worth answering two questions:
- Is this function an AI system?
- Are we the provider of this system, or are we only a deployer using it in our business?
Is this function an AI system?
In simple terms, an AI system can be understood as a system that analyses data and, based on that data, generates an output that is not directly determined by one predefined rule.
Example of an AI system:
- The user enters a question into an AI-powered chatbot. The model analyses the input and generates a response based on what it has learned previously.
- No one wrote this specific answer beforehand. Two people asking similar questions may receive different results.
- The same applies to models that analyse images, generate graphics, create audio, or prepare text.
Example of ordinary automation in an application that is not an AI system
- The user selects the “complaint” option in a form, and the application displays information about the processing time.
- The message was prepared in advance by a developer and saved in the code. Each time, the application displays the same content.
Provider or deployer?
Article 50 of the AI Act imposes obligations depending on the company’s role.
A provider is a company that makes its own AI system available to users. If, for example, you create an application with a chatbot, you must inform the user that they are talking to AI and ensure that content generated by the system is properly labelled.
A deployer is a company that uses an existing AI system in its business. If, for example, you use a tool that estimates customers’ age based on a facial image, you must inform the people who are subject to such analysis. In the case of deepfakes and certain content concerning matters of public interest, there may also be obligations to label the content.
The difference is therefore simple: the provider makes an AI system available to others, while the deployer uses it for its own purposes.
Four situations where the use of AI must be labelled
1. Chatbot, voice assistant, or avatar
If a user interacts with an AI system, they should know that they are being answered by a programme, not a person. This applies not only to chatbots. A similar obligation may arise in the case of:
- a voice assistant,
- an avatar,
- a virtual consultant,
- a character having a conversation with the user.
In practice, a clear message in the interface is usually enough, for example:
You are talking to an AI assistant.
The information should appear no later than the first exchange. It may take the form of:
- an opening message,
- a permanent label next to the message input field,
- a voice message at the beginning of the session.
The icon or name “assistant” alone may not be enough. The user should understand without much doubt that they are dealing with AI.
For applications intended for children, older people, as well as tools providing health or financial advice, the message may need to be repeated while using the function.
2. Generating or substantially modifying content
The second obligation applies to providers of systems that generate or substantially modify:
- text,
- images,
- audio,
- video.
Such content should be labelled in a way that can be read by software. The label should be stored in the file itself or linked to it in a way that makes it possible to determine that the material was created with the involvement of AI.
Simply adding the word “AI” to the corner of an image does not replace such a label. It may disappear after cropping, conversion, or further editing of the file.
The obligation applies both to content generated from scratch and to materials that have been substantially modified.
Substantial or non-substantial change?
Not every content edit means that Article 50 applies. Standard editing that does not change the meaning of the material remains outside its scope.
| Text | Image | Audio |
|---|---|---|
| – spelling and grammar correction – translation – text formatting | – cropping – colour correction – brightening and sharpening – removing red-eye | – noise reduction – transcription of a conversation |
If a tool can both generate an image and crop an existing photo, the obligation may apply only to image generation. Cropping itself does not necessarily trigger the obligation.
What does labelling look like in practice?
The technical label can be stored in the file’s metadata or embedded in its content, for example through an invisible watermark.
Metadata is easier to read, but it can be removed during file conversion. A watermark may be more resistant to some changes, but it also requires proper implementation.
Adding a label is not enough, however. The provider should also make a tool available that allows users to check whether a given piece of content was generated or modified by AI.
It is worth checking whether the provider of the model being used already adds such labels. This may reduce the amount of work required from the team, but it does not release the company from the responsibility of checking whether the solution is compliant.
You should also make sure that the way files are stored, transferred, and converted in the application does not remove the labels.
3. Emotion recognition and biometric data analysis
The third obligation applies to deployers using systems that:
- infer emotions based on a person’s face or voice,
- assign people to categories based on biometric data.
In practice, this may involve recognising whether someone is happy, nervous, or bored. The provision may also cover estimating age or gender based on a facial image.
For example, simply visualising a product on a user’s photo does not necessarily require an additional message. However, if the system also analyses the user’s age or gender to select a size or make recommendations, there may be an obligation to inform the user that such a function is being used.
In this case, the message does not have to explain in detail how the system works. It is enough to inform the user about its use.
4. Deepfakes and realistic marketing materials
The final obligation concerns content that looks real even though it was generated or modified by AI.
In applications, this may occur when the system creates:
- a realistic image of a person,
- a picture of a product that does not actually exist in the form shown,
- video or audio material imitating a real event.
Such material should be appropriately labelled in a visible or audible way.
The obligation may also apply to a company’s marketing, even if the application itself does not contain an AI function. If a realistic image of a person or product is generated for an advertising campaign, it must be assessed whether it requires labelling.
Not every piece of advertising content is subject to this obligation, however. A standard product description or marketing text does not have to be labelled simply because it was prepared with the help of AI.
Thinking about AI for your app?
Book a CallWhat about ambiguous functions?
Not every function can be assessed using one simple checklist.
A beauty filter is one example:
- a minor colour correction will usually remain outside the scope,
- changing body shape may require labelling,
- skin smoothing may depend on the specific effect.
The same applies to a chatbot whose artificial nature may be obvious to one group of users but not to another.
In such cases, it is worth:
- describing how the function works,
- determining whether it changes the meaning or perception of the content,
- determining who is the provider or deployer,
- documenting the reasoning behind the decision.
The point is not to give every function a detailed legal analysis. However, short documentation of the decision can help explain why a given function was considered subject to the obligation or excluded from its scope.

What does the AI Act mean for product and development teams?
In practice, the obligations under Article 50 can be divided into two groups.
UX/UI changes
For chatbots, assistants, and avatars, it may be necessary to add:
- a message on first contact,
- a permanent label next to the AI function,
- a voice message,
- additional messages in special cases.
These are elements that are best considered already at the interface design stage.
Changes to code and file handling
More work may be required to label generated content.
The team should check:
- what files the application generates,
- whether it uses models that add labels,
- whether labels are preserved during saving and transfer,
- whether format conversion removes them,
- whether the user or an external tool can verify the origin of the file.
It is worth including these tasks in the backlog, especially if the application generates images, audio, or video.
Deadlines and penalties
The most important dates indicated in the source material are:
| Date | What starts applying |
|---|---|
| 2 August 2026 | Transparency obligations under Article 50 |
| 2 December 2026 | End of the transition period for selected generative systems already on the market |
| 2 December 2027 | Requirements for high-risk systems |
| 2 August 2028 | Requirements for AI embedded in medical devices and other regulated products |
High financial penalties are provided for violations of the obligations under Article 50. Their maximum amount does not, however, mean an automatic fine for every violation. When determining the penalty, factors include:
- the seriousness of the violation,
- its duration,
- whether the action was intentional,
- the circumstances of the specific case.
The €35 million figure often appearing in headlines refers to a different category of violations – prohibited practices defined in Article 5 of the AI Act. It is not an automatic penalty for failing to provide information about a chatbot or failing to label a single file.
Checklist: where to start?
If you are developing an application that uses AI, start with a short review of its functions.
- List all functions that use AI — including less obvious ones, such as moderation, search, or image analysis.
- For each function, determine whether you are the provider or the deployer.
- Check whether the function interacts with the user.
- Determine whether it generates or substantially modifies text, images, audio, or video.
- Check whether it analyses emotions or biometric data.
- Assess whether the generated materials may look real.
- Verify what labels the model provider provides.
- Check whether the application preserves labels when saving and transferring files.
- Add the required messages to the UX/UI.
- Plan technical content labelling in the backlog.
Summary
The AI Act does not require every application to be rebuilt. The obligations depend on the AI functions being used and the role of the company. In practice, they may include informing users that they are interacting with a chatbot, labelling content generated or substantially modified by AI, communicating the use of functions that analyse emotions and biometric data, and labelling realistic materials generated by AI.
Simply using AI to create code does not require the code to be labelled. It is best to analyse each function separately and determine whether it is subject to the obligations under Article 50.
Wondering how to implement AI?
Schedule a ConsultationSources
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
Official Journal of the European Union L, 2024/1689, 12.7.2024
http://data.europa.eu/eli/reg/2024/1689/oj
In the article, we used Articles 3(1), 3(3), 3(4), 3(39), 3(40), and 3(60), Article 5, Article 6, Article 50, and Article 99.
Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Official Journal of the European Union, 24.7.2026, applicable from 27.7.2026
Changes the deadlines for applying the rules on high-risk systems and introduces a transition period for labelling generated content.
European Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689
C(2026) 5054 final, Brussels, 20.7.2026
Code of Practice on Transparency of AI-Generated Content
Developed through a process led by the AI Office and assessed by the Commission as adequate within the meaning of Article 50(7) of the AI Act.
This material is for informational purposes only and does not constitute legal advice. The legal status is as of the date of publication. In specific cases, the assessment may be different, and only the Court of Justice of the European Union provides binding interpretations of EU law.







