Mobitouch

AI Act and Your App: What You Need to Label and What You Don’t?

Napisz do nas
AI Act and your app – what you need to label

Your application has a chatbot that talks to users. Or maybe it analyses images, generates descriptions, or helps create content. For the past two years, no one asked whether the user should know that they are using artificial intelligence. Now these questions are coming back more and more often. Has the AI Act been postponed? Are the new obligations already in force? Can you be fined €35 million for failing to label the use of AI in a product? If your application was written with the help of AI, do you have to tell users about it?

In this article, we explain what the AI Act is and which of its obligations apply to mobile applications and web applications. We will show when you need to inform the user that AI is being used, when generated content needs to be labelled, and when you do not need to do anything.

What is the AI Act?

The AI Act is an EU regulation governing how artificial intelligence systems are made available and used. The rules divide AI systems according to the level of risk they may pose.

The biggest requirements apply to systems that can influence important decisions about people, such as recruitment, education, or creditworthiness. The deadlines for applying these rules were postponed by the July 2026 amendment, which means that most of them will only start applying on 2 December 2027.

This does not mean, however, that all other applications have been covered by the postponement. A separate category consists of the transparency obligations set out in Article 50 of the AI Act. They mainly concern whether the user knows that they:

  • are talking to an AI system,
  • are viewing or listening to content generated by AI,
  • are dealing with emotion recognition or biometric data analysis,
  • are viewing realistic material that was actually generated or modified by AI.

These obligations started applying on 2 August 2026.

Planning an app with AI?

Discuss Your Project

Does application code written with AI assistance have to be labelled?

No. The AI Act regulates the product (what the user sees and uses, not the process used to create it). The mere fact that a developer uses tools such as GitHub Copilot, Cursor, or other AI-assisted coding tools does not mean that there is an obligation to add special information to the repository or label the code as AI-generated.

The obligations under Article 50 concern specific ways of using AI systems, in particular interaction with the user and the generation or substantial modification of content, not the way the code itself was created.

Does Article 50 apply to your application?

The obligations under Article 50 of the AI Act do not automatically apply to the entire application. The specific functions and the role of the company using them are assessed.

Therefore, for each AI function, it is worth answering two questions:

  1. Is this function an AI system?
  2. Are we the provider of this system, or are we only a deployer using it in our business?

Is this function an AI system?

In simple terms, an AI system can be understood as a system that analyses data and, based on that data, generates an output that is not directly determined by one predefined rule.

Example of an AI system:

  • The user enters a question into an AI-powered chatbot. The model analyses the input and generates a response based on what it has learned previously.
  • No one wrote this specific answer beforehand. Two people asking similar questions may receive different results.
  • The same applies to models that analyse images, generate graphics, create audio, or prepare text.

Example of ordinary automation in an application that is not an AI system

  • The user selects the “complaint” option in a form, and the application displays information about the processing time.
  • The message was prepared in advance by a developer and saved in the code. Each time, the application displays the same content.

Provider or deployer?

Article 50 of the AI Act imposes obligations depending on the company’s role.

A provider is a company that makes its own AI system available to users. If, for example, you create an application with a chatbot, you must inform the user that they are talking to AI and ensure that content generated by the system is properly labelled.

A deployer is a company that uses an existing AI system in its business. If, for example, you use a tool that estimates customers’ age based on a facial image, you must inform the people who are subject to such analysis. In the case of deepfakes and certain content concerning matters of public interest, there may also be obligations to label the content.

The difference is therefore simple: the provider makes an AI system available to others, while the deployer uses it for its own purposes.

Four situations where the use of AI must be labelled

1. Chatbot, voice assistant, or avatar

If a user interacts with an AI system, they should know that they are being answered by a programme, not a person. This applies not only to chatbots. A similar obligation may arise in the case of:

  • a voice assistant,
  • an avatar,
  • a virtual consultant,
  • a character having a conversation with the user.

In practice, a clear message in the interface is usually enough, for example:

You are talking to an AI assistant.

The information should appear no later than the first exchange. It may take the form of:

  • an opening message,
  • a permanent label next to the message input field,
  • a voice message at the beginning of the session.

The icon or name “assistant” alone may not be enough. The user should understand without much doubt that they are dealing with AI.

For applications intended for children, older people, as well as tools providing health or financial advice, the message may need to be repeated while using the function.

2. Generating or substantially modifying content

The second obligation applies to providers of systems that generate or substantially modify:

  • text,
  • images,
  • audio,
  • video.

Such content should be labelled in a way that can be read by software. The label should be stored in the file itself or linked to it in a way that makes it possible to determine that the material was created with the involvement of AI.

Simply adding the word “AI” to the corner of an image does not replace such a label. It may disappear after cropping, conversion, or further editing of the file.

The obligation applies both to content generated from scratch and to materials that have been substantially modified.

Substantial or non-substantial change?

Not every content edit means that Article 50 applies. Standard editing that does not change the meaning of the material remains outside its scope.

TextImageAudio
– spelling and grammar correction
– translation
– text formatting
– cropping
– colour correction
– brightening and sharpening
– removing red-eye
– noise reduction
– transcription of a conversation

If a tool can both generate an image and crop an existing photo, the obligation may apply only to image generation. Cropping itself does not necessarily trigger the obligation.

What does labelling look like in practice?

The technical label can be stored in the file’s metadata or embedded in its content, for example through an invisible watermark.

Metadata is easier to read, but it can be removed during file conversion. A watermark may be more resistant to some changes, but it also requires proper implementation.

Adding a label is not enough, however. The provider should also make a tool available that allows users to check whether a given piece of content was generated or modified by AI.

It is worth checking whether the provider of the model being used already adds such labels. This may reduce the amount of work required from the team, but it does not release the company from the responsibility of checking whether the solution is compliant.

You should also make sure that the way files are stored, transferred, and converted in the application does not remove the labels.

3. Emotion recognition and biometric data analysis

The third obligation applies to deployers using systems that:

  • infer emotions based on a person’s face or voice,
  • assign people to categories based on biometric data.

In practice, this may involve recognising whether someone is happy, nervous, or bored. The provision may also cover estimating age or gender based on a facial image.

For example, simply visualising a product on a user’s photo does not necessarily require an additional message. However, if the system also analyses the user’s age or gender to select a size or make recommendations, there may be an obligation to inform the user that such a function is being used.

In this case, the message does not have to explain in detail how the system works. It is enough to inform the user about its use.

4. Deepfakes and realistic marketing materials

The final obligation concerns content that looks real even though it was generated or modified by AI.

In applications, this may occur when the system creates:

  • a realistic image of a person,
  • a picture of a product that does not actually exist in the form shown,
  • video or audio material imitating a real event.

Such material should be appropriately labelled in a visible or audible way.

The obligation may also apply to a company’s marketing, even if the application itself does not contain an AI function. If a realistic image of a person or product is generated for an advertising campaign, it must be assessed whether it requires labelling.

Not every piece of advertising content is subject to this obligation, however. A standard product description or marketing text does not have to be labelled simply because it was prepared with the help of AI.

Thinking about AI for your app?

Book a Call

What about ambiguous functions?

Not every function can be assessed using one simple checklist.

A beauty filter is one example:

  • a minor colour correction will usually remain outside the scope,
  • changing body shape may require labelling,
  • skin smoothing may depend on the specific effect.

The same applies to a chatbot whose artificial nature may be obvious to one group of users but not to another.

In such cases, it is worth:

  1. describing how the function works,
  2. determining whether it changes the meaning or perception of the content,
  3. determining who is the provider or deployer,
  4. documenting the reasoning behind the decision.

The point is not to give every function a detailed legal analysis. However, short documentation of the decision can help explain why a given function was considered subject to the obligation or excluded from its scope.

AI Act

What does the AI Act mean for product and development teams?

In practice, the obligations under Article 50 can be divided into two groups.

UX/UI changes

For chatbots, assistants, and avatars, it may be necessary to add:

  • a message on first contact,
  • a permanent label next to the AI function,
  • a voice message,
  • additional messages in special cases.

These are elements that are best considered already at the interface design stage.

Changes to code and file handling

More work may be required to label generated content.

The team should check:

  • what files the application generates,
  • whether it uses models that add labels,
  • whether labels are preserved during saving and transfer,
  • whether format conversion removes them,
  • whether the user or an external tool can verify the origin of the file.

It is worth including these tasks in the backlog, especially if the application generates images, audio, or video.

Deadlines and penalties

The most important dates indicated in the source material are:

DateWhat starts applying
2 August 2026Transparency obligations under Article 50
2 December 2026End of the transition period for selected generative systems already on the market
2 December 2027Requirements for high-risk systems
2 August 2028Requirements for AI embedded in medical devices and other regulated products

High financial penalties are provided for violations of the obligations under Article 50. Their maximum amount does not, however, mean an automatic fine for every violation. When determining the penalty, factors include:

  • the seriousness of the violation,
  • its duration,
  • whether the action was intentional,
  • the circumstances of the specific case.

The €35 million figure often appearing in headlines refers to a different category of violations – prohibited practices defined in Article 5 of the AI Act. It is not an automatic penalty for failing to provide information about a chatbot or failing to label a single file.

Checklist: where to start?

If you are developing an application that uses AI, start with a short review of its functions.

  1. List all functions that use AI — including less obvious ones, such as moderation, search, or image analysis.
  2. For each function, determine whether you are the provider or the deployer.
  3. Check whether the function interacts with the user.
  4. Determine whether it generates or substantially modifies text, images, audio, or video.
  5. Check whether it analyses emotions or biometric data.
  6. Assess whether the generated materials may look real.
  7. Verify what labels the model provider provides.
  8. Check whether the application preserves labels when saving and transferring files.
  9. Add the required messages to the UX/UI.
  10. Plan technical content labelling in the backlog.

Summary

The AI Act does not require every application to be rebuilt. The obligations depend on the AI functions being used and the role of the company. In practice, they may include informing users that they are interacting with a chatbot, labelling content generated or substantially modified by AI, communicating the use of functions that analyse emotions and biometric data, and labelling realistic materials generated by AI.

Simply using AI to create code does not require the code to be labelled. It is best to analyse each function separately and determine whether it is subject to the obligations under Article 50.

Wondering how to implement AI?

Schedule a Consultation
Sources

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

Official Journal of the European Union L, 2024/1689, 12.7.2024

http://data.europa.eu/eli/reg/2024/1689/oj

In the article, we used Articles 3(1), 3(3), 3(4), 3(39), 3(40), and 3(60), Article 5, Article 6, Article 50, and Article 99.

Regulation (EU) 2026/1744 (Digital Omnibus on AI)

Official Journal of the European Union, 24.7.2026, applicable from 27.7.2026

Changes the deadlines for applying the rules on high-risk systems and introduces a transition period for labelling generated content.

European Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689

C(2026) 5054 final, Brussels, 20.7.2026

Code of Practice on Transparency of AI-Generated Content

Developed through a process led by the AI Office and assessed by the Commission as adequate within the meaning of Article 50(7) of the AI Act.

This material is for informational purposes only and does not constitute legal advice. The legal status is as of the date of publication. In specific cases, the assessment may be different, and only the Court of Justice of the European Union provides binding interpretations of EU law.

Najczęściej zadawane pytania

Does content generated before the rules came into force have to be labelled?

According to the source material, content generated before 2 August 2026 does not require retrospective labelling. The exception applies to texts that were created earlier but are published after that date.



The model we use labels the content itself. Is that enough?

Not always. Labels added by the model provider may reduce the amount of work required from the company, but you need to check:

  • what exactly is being labelled,
  • in which formats,
  • whether the provider makes a verification tool available,
  • whether the application removes labels when saving or converting files.
The chatbot is available only to logged-in business customers. Do we still need to say that it is AI?

This depends on the specific group of users and on whether the artificial nature of the conversation is obvious to them. The fact that the tool is available only to business customers does not automatically mean that the obligation does not apply.

Does a recommendation engine have to be labelled?

A recommendation engine that only sorts and ranks existing materials does not require labelling under Article 50. It does not interact with the user or create new content. The situation changes if it also generates descriptions or summaries, because the obligation to label content may then apply.



When can a chatbot become a high-risk system?

The mere fact that a chatbot conducts a conversation does not mean that it is high-risk. Such a classification may arise when the system starts affecting someone’s economic or social situation, for example by automatically evaluating job candidates or creditworthiness.

Głodny wiedzy? Sprawdź nasze pozostałe artykuły!

Zobacz wszystkie
A humanoid robot listening to a young woman entrepreneur, who is talking about ai chatbots for business
09/05/2025

Chatboty AI dla biznesu: praktyczny przewodnik

Asystent AI do obsługi klienta nie jest już futurystyczną koncepcją — to coraz bardziej dostępne i praktyczne rozwiązanie dla małych i średnich przedsiębiorstw (MŚP). Wraz ze wzrostem oczekiwań klientów dotyczących szybszej, dostępnej non-stop i bardziej spersonalizowanej obsługi, rośnie presja na MŚP, by dotrzymać kroku większym konkurentom. Wiele mniejszych firm zmaga się z ograniczoną liczbą pracowników, […]

Dawit Netere
Business Development Specialist
AI robot standing in a server room that illustrates an article about self-hosted ai
11/07/2025

Wszystko, co musisz wiedzieć o self-hosted AI (na prawdziwym przykładzie)

Sztuczna inteligencja jest dziś wszędzie — pomaga pisać maile, odpowiadać na pytania, a nawet wykrywać oszustwa. Ale coraz częściej pojawia się ważne pytanie: czy firmy powinny powierzać swoje wrażliwe dane zewnętrznym usługom AI, czy raczej uruchamiać sztuczną inteligencję samodzielnie, na własnej infrastrukturze? Obawy o prywatność, rosnące koszty i nieprzewidywalne „halucynacje” AI sprawiają, że coraz więcej […]

Dawit Netere
Business Development Specialist
Funkcje AI w aplikacji – koszty, najlepsze praktyki i przykłady
20/03/2026

Funkcje AI w aplikacjach – koszty, najlepsze praktyki i przykłady

Sztuczna inteligencja coraz częściej pojawia się w aplikacjach mobilnych i webowych. Jeszcze kilka lat temu jej wdrożenie wymagało budowania własnych modeli, trenowania ich na ogromnych zbiorach danych i utrzymywania skomplikowanej infrastruktury. Dziś wygląda to zupełnie inaczej. W większości przypadków funkcje AI w aplikacji powstają poprzez integrację z gotowymi modelami dostępnymi przez API. Dzięki temu aplikacja […]

Oliwia Czaban marketing specialist mobitouch
Oliwia Czaban
Marketing Specialist

Z chęcią doradzimy rozwiązanie, które sprawdzi się w Twojej firmie.