Chapter 9: Limited-Risk AI — The Transparency Obligations You Cannot Skip
What you will learn: By the end of this chapter, you will understand which AI systems fall into the limited-risk category, what transparency obligations Article 50 imposes, who bears each obligation (provider vs deployer), and how to implement compliance in practice.
Why Transparency Matters
Article 50 exists because AI systems that interact with people, generate content, or process biometric data can mislead, manipulate, or harm individuals without their knowledge. The AI Act’s response is proportionate: rather than imposing the full compliance burden of high-risk obligations, it requires transparency. People affected by these systems must know they are interacting with AI, that their emotions or biometric characteristics are being processed, or that the content they are consuming was generated by AI.
The four transparency obligations in Article 50 are independent of each other. A single AI system may trigger one, two, or all four. They apply in addition to any high-risk obligations that may separately apply to the same system, and in addition to GDPR transparency requirements. They are not a lighter alternative to high-risk compliance — they are a parallel obligation.
Fines for non-compliance with Article 50 can reach €15 million or 3% of global annual turnover — identical to the fines for failing to meet high-risk deployer obligations. Limited-risk does not mean lower stakes.
What Counts as Limited-Risk
Type 1 — AI Systems That Interact with People (Article 50(1))
What the law requires: Any AI system designed to interact directly with natural persons must inform those persons that they are interacting with an AI system, before or at the start of the interaction. The obligation applies to chatbots, virtual assistants, AI-driven phone agents, automated customer service systems, and any other technology that engages with people in a conversational or interactive mode.
The “obvious from context” exception: Article 50(1) does not apply where it is obvious from context that the user is interacting with an AI. This exception is narrow. A clearly labelled widget that reads “Chat with our AI assistant” meets the threshold. A voice agent that answers calls with a human-sounding name and voice does not — regardless of what the company’s website says. The test is not whether an informed observer would recognise the technology: it is whether a reasonable user in that specific interaction, without prior knowledge, would know they are interacting with AI without being told.
Provider vs deployer split: Article 50(1) places this obligation on providers: they must design and develop the system so that the person is informed they are interacting with an AI system. It is not, in its own terms, a deployer obligation — Article 50’s deployer-facing duties are paragraphs (3) and (4). In practice a provider’s default configuration may omit or genericise the disclosure in ways that are insufficient for a specific deployer’s audience, and Article 50(6) preserves other transparency obligations under Union or national law, so deployers should still verify what their users actually experience — but as good practice and under those other rules, not under Article 50(1).
Type 2 — Emotion Recognition and Biometric Categorisation (Article 50(3))
What the law requires: Systems that detect, infer, or predict emotional states — happiness, stress, anger, fatigue, engagement — or that categorise individuals by biometric characteristics such as age, apparent gender, ethnicity, or other inferred attributes must inform individuals before processing begins. This obligation applies to any natural person who is exposed to such a system.
What the disclosure must cover: Article 50(3) requires deployers to inform the exposed persons of the operation of the system — what is being detected or inferred (emotional states, biometric categories) — and to process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680. The further detail (what data is collected, how long it is retained, and the purpose for which it is used) is required by GDPR Articles 13 and 14 rather than by Article 50(3), but it belongs in the same notice. Generic privacy-notice language does not satisfy Article 50(3) — the notice must specifically address the emotion-recognition or biometric-categorisation functionality of the system in question.
Classification context matters: The same underlying technology may be prohibited in workplaces and educational institutions (Article 5), high-risk in law enforcement, border control, or other Annex III contexts, or limited-risk in other commercial deployments such as retail analytics, audience measurement, or entertainment. Article 50(3) applies only in limited-risk contexts. If your deployment falls into a prohibited or high-risk category, the rules for that category govern instead.
Type 3 — Synthetic Media (Article 50(4))
What the law requires: Article 50(4) requires deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake to disclose that the content has been artificially generated or manipulated. Separately, Article 50(2) requires providers of AI systems generating synthetic audio, image, video or text to mark the outputs in a machine-readable format, detectable as artificially generated or manipulated, as far as this is technically feasible. Together the two paragraphs produce the practical result most organisations plan for: a visible disclosure to the user (deployer, Article 50(2) aside) plus machine-readable metadata or watermarks embedded in the content (provider). Be clear about which of the two you are: the marking duty is not yours as a deployer.
Visible disclosure must be clear and conspicuous. It must be presented before the user consumes the content, not buried in credits or a footer. Machine-readable marking — embedded metadata, watermarks, or provenance signals — is required wherever the technology makes it possible. In practice, most professionally produced AI-generated content should include machine-readable marking given the capabilities of current generation tools.
The artistic and creative exception: This is a limitation on the disclosure, not an exemption from it. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, Article 50(4) reduces the obligation to disclosing the existence of the generated or manipulated content “in an appropriate manner that does not hamper the display or enjoyment of the work”. An animated short film, an obviously stylised AI illustration, or a comedic deepfake in a clearly satirical context may qualify for that lighter treatment — but some disclosure is still required. AI-generated photorealistic images used in advertising, corporate communications, product marketing, or social media content does not qualify — even if the content involves creative choices. If a reasonable viewer could plausibly mistake the content for authentic, the labelling obligation applies.
Type 4 — AI-Generated Text on Matters of Public Interest (Article 50(4), second subparagraph)
What the law requires: AI systems used to produce text published on matters of public interest — news reporting, political analysis, public policy commentary, civic information — must disclose that the text was AI-generated. This obligation falls primarily on the deployer: the entity that decides to publish AI-generated text bears responsibility for disclosing it.
The editorial exception: The obligation does not apply where a human editor has substantially edited the AI-generated output and takes editorial responsibility for the published content. Two conditions must both be met. First, the editing must be substantial — reviewing facts, restructuring arguments, rewriting passages, exercising genuine editorial judgment about content and framing. Correcting typos, reformatting for layout, or approving a draft without meaningful engagement does not qualify. Second, the person who edited the text must take editorial responsibility — they must be accountable for its accuracy and content as the identified author or editor, not merely as a proofreader. A practical test: if the editor would not be comfortable being identified as the author of the published text, the exception is not met.
Practical Implementation
Implementing Type 1 (chatbot and virtual assistant disclosure)
What to do: Implement a standard opening message that identifies the system as AI before any conversation content is exchanged. For voice agents, the first words spoken must identify the system. For text-based systems, the opening message must be displayed before the user reads or responds to any substantive content.
Wording: Use plain language suited to the audience. “You are speaking with an AI assistant” is sufficient. “This conversation may be handled by an automated system” hedges in a way that may not satisfy the obligation. Review wording with your legal team, as national implementations may prescribe particular language.
Evidence to retain: The disclosure text or script in use, the date it was implemented, and documentation of any changes to the wording over time.
Implementing Type 2 (emotion recognition and biometric categorisation)
What to do: Design the disclosure as a pre-processing notice — not a dismissible pop-up or a buried terms clause. The notice must be presented before any processing begins. In digital interfaces, this means before the system accesses camera or microphone input. In physical spaces, it requires clear, visible signage at the point of entry, before the person enters the space where the system operates.
What the notice must state: That an AI system is in use that processes emotional or biometric data, what categories of data are collected, the purpose, and the retention period. Generic references to “digital technologies” do not satisfy the obligation.
Evidence to retain: The notice text, the locations and channels where it is displayed, the data collected and retention periods, and the date it was implemented.
Implementing Type 3 (synthetic media labelling)
What to do: Implement a consistent labelling workflow for all AI-generated content before publication or distribution. For images and video, embed machine-readable metadata using tools provided by the generation platform or post-processing software. Apply visible labelling using clear, standardised language — “AI-generated,” “Created with AI,” or equivalent — placed where it will be seen before the content is consumed.
Exception documentation: Establish an internal policy that defines the artistic exception and applies it conservatively. Document the basis for any decision to claim the exception.
Evidence to retain: The labelling policy, records of content produced and the labels applied, documentation of machine-readable marking implementation, and the basis for any exception claims.
Implementing Type 4 (AI-generated text)
What to do: Implement an editorial policy that defines what “substantial editing” means in your organisation and establishes a review process that meets that standard. For content where the exception does not apply, attach a clear disclosure to the published text — either inline (“This article was generated with AI assistance”) or in standardised metadata.
Practical test: After editing, would the human editor be comfortable being identified as the author of the published text? If yes, the editorial responsibility requirement is likely met. If no, the disclosure obligation applies.
Evidence to retain: The editorial policy, records of which content involved AI generation, documentation of the editing process and editor responsible, and records of the disclosure decision for each piece of published content.
Overlap with High-Risk
A system can simultaneously be high-risk under Article 6 and subject to transparency obligations under Article 50. An AI-powered recruitment tool that ranks candidates based on video interviews is high-risk under Annex III (employment domain). If that tool also analyses facial expressions to infer engagement or stress, it may trigger the Type 2 transparency obligation under Article 50(3) as well. Both sets of obligations apply independently.
The most significant area of overlap is between Type 2 and high-risk systems. Biometric identification systems in Annex III are high-risk. If those systems also perform emotion inference or biometric categorisation, the Article 50(3) notice obligation applies in addition to the high-risk obligations. Conduct a system-by-system audit: a face-scanning tool used for access control may be high-risk under Annex III and subject to Article 50(3) simultaneously.
The inverse does not hold: satisfying Article 50 transparency obligations does not reduce or discharge any high-risk obligation. They are parallel tracks.
Overlap with GDPR
Article 50 transparency obligations coexist with GDPR transparency requirements under Articles 13 and 14, but they are separate obligations requiring separate compliance.
GDPR Articles 13 and 14 require information about data processing — legal basis, categories of data, retention periods, data subject rights, and transfers to third countries. Article 50 requires information about AI-specific characteristics — that a system is AI, that it processes emotions or biometric data, or that content was AI-generated. Neither satisfies the other. A privacy notice that does not mention the AI nature of the chatbot fails Article 50. An Article 50 disclosure that does not address legal basis and data subject rights fails GDPR.
Design your disclosures so that the information required for both obligations is presented together, clearly, and in the context where it is relevant. The timing requirements also differ: GDPR requires layered notices with full information accessible at or before data collection; Article 50 requires disclosure at the start of the interaction or before processing begins. Design your disclosure architecture to satisfy both requirements simultaneously.
Common Mistakes
Mistake 1: Relying on the “obvious from context” exception too broadly. Many organisations assume that because their product is publicly known to use AI, the Article 50(1) disclosure obligation does not apply. The test is not whether the organisation’s branding mentions AI. It is whether a reasonable user in the specific interaction context — someone who may not have visited the website, read the terms, or heard of the product — would know they are talking to AI. An AI phone agent that answers calls with a human-sounding name and does not identify itself as AI does not meet this threshold, regardless of what is written on the company’s homepage.
Mistake 2: Treating Article 50 disclosures as additions to GDPR privacy notices. Article 50 obligations must be satisfied in context — at the moment of interaction, processing, or content consumption — not in a general privacy policy. A chatbot that includes an AI disclosure on page 12 of a privacy policy does not satisfy Article 50(1). Disclosures must be contextual, timely, and clearly connected to the specific system the user is interacting with at that moment.
Mistake 3: Applying the artistic exception to commercial AI-generated content. The exception for clearly fictional or satirical content is narrow. AI-generated photorealistic images of real or plausible people, places, or events used in advertising, corporate communications, product marketing, or social media content are subject to the labelling obligation. The question is whether a reasonable viewer could mistake the content for authentic — not whether the organisation considers the content to be creative or artistic. Err on the side of disclosure.
Mistake 4: Applying the editorial exception to minimally reviewed AI text. Publishing AI-generated text with light editing — correcting grammar, checking facts, reformatting — and then claiming the editorial exception is incorrect. The exception requires both substantial editing and assumption of editorial responsibility. A rigorous test: would the editor be comfortable identifying themselves as the author? If the answer is not a clear yes, the disclosure obligation applies.
Mistake 5: Auditing for one obligation type and assuming the others do not apply. A system that generates photorealistic video narrated by an AI voice agent with emotion-recognition functionality may trigger Type 1, Type 2, and Type 3 obligations simultaneously. Each obligation must be satisfied independently. Identifying and addressing one does not discharge the others. Audit each AI system in your organisation against all four Article 50 types.
Self-Check: Article 50 Transparency Obligations
For each AI system you operate, verify your compliance status:
| # | Question | Status |
|---|---|---|
| 1 | Have you identified all AI systems in your organisation that interact directly with natural persons? | |
| 2 | For each such system, is there a clear, contextual disclosure that the user is interacting with AI, made before or at the start of each interaction? | |
| 3 | Have you identified all systems that perform emotion recognition or biometric categorisation? | |
| 4 | For each such system, is there a pre-processing notice informing individuals of what is detected, what data is collected, the purpose, and the retention period? | |
| 5 | Do you produce or distribute AI-generated or AI-manipulated images, audio, or video? | |
| 6 | For each piece of synthetic media that could be mistaken for authentic, is there a visible label and, where technically feasible, machine-readable metadata or watermarks? | |
| 7 | Do you publish AI-generated text on matters of public interest? | |
| 8 | For each piece of AI-generated text published, either a human editor has taken substantial editorial responsibility (documented), or the content is clearly labelled as AI-generated. |
Any item marked incomplete is a gap that must be resolved. Article 50 sits in Chapter IV, which is not among the provisions Article 113(b) brings forward to 2 August 2025, so all four transparency obligations apply from 2 August 2026. Do not wait for that date to audit your limited-risk obligations — disclosure architecture takes longer to change than the deadline suggests.
Summary
Article 50 imposes four transparency obligations on providers and deployers of AI systems that interact directly with people, process emotional or biometric data, produce synthetic media, or generate text on matters of public interest. These obligations are legally independent of each other, of high-risk obligations, and of GDPR requirements — but they coexist with and overlap all three. Non-compliance carries fines of up to €15 million or 3% of global annual turnover. The four types are: chatbot and virtual assistant disclosure (Article 50(1)), emotion recognition and biometric categorisation notice (Article 50(3)), synthetic media labelling (Article 50(4)), and AI-generated text disclosure (Article 50(4), second subparagraph). Each requires a distinct implementation: a contextual opening disclosure, a pre-processing notice, a visible label with machine-readable marking, and an editorial policy with clear disclosure rules. The five most common mistakes are: over-relying on the obvious-from-context exception, treating Article 50 as a GDPR supplement, misapplying the artistic exception to commercial content, misapplying the editorial exception to minimally reviewed text, and failing to audit for all four obligation types simultaneously. Chapter 10 covers general-purpose AI models (GPAI) and the specific obligations that apply to providers of foundation models under Articles 51 to 56.
← Back to Blog Summary Chapter 10 →