Chapter 6. Transparency: Art. 50, chatbots, deepfakes, content labeling | Grigoriy Dobryakov

Grigoriy Dobryakov

Course · AI Compliance

Chapter 6AI Compliance course

Chapter 6. Transparency: Art. 50, chatbots, deepfakes, content labeling

A separate, standalone layer of obligations — on top of (and independent from) the risk class.

The situation at Kompas

Besides scoring, Kompas has two functions that were almost forgotten during the high-risk analysis: a chatbot that answers the candidate about application status and asks clarifying questions, and a text generator — rejection letters, follow-ups, invitations. The candidate often doesn't realize they're chatting with a machine, and the generated letters look like they were written by the recruiter.

This is a separate layer of obligations. Transparency requirements hang not on the risk class but on the very fact of AI interacting with a human and on generated content — and they apply regardless of whether the system is high-risk or not. What's more, by date they arrive earlier than the main high-risk obligations: Art. 50 is already in force, whereas high-risk is shifted to 2027–2028.

What the rule says

Art. 50 — transparency obligations, in force from 02.08.2026 (and, unlike high-risk, the Digital Omnibus did not shift them):

Machine-readability and provenance. The requirement for machine-readable labeling technically connects to content-provenance standards — first of all C2PA / Content Credentials (cryptographically signed metadata about origin). It is a way to meet the requirement, not the law itself.

Relation to high-risk. Transparency is an additional layer, not a replacement for the obligations of chapters 3–4. A system can be high-risk (scoring) and carry transparency duties (chatbot) at once — these are two independent sets.

How it lands on the product

Kompas's chatbot gets an explicit notice, "you're chatting with an AI assistant," at the start of the dialogue. Generated letters and texts are labeled machine-readably as AI content, and where appropriate — with a human-readable disclosure.

The chapter's artifact is a transparency map: a map of all the points where Kompas's AI touches a human (chatbot, letters, scoring notices) and the disclosure method at each. This map, by the way, partly overlaps with the duty to inform affected persons from ch. 5 — it's useful to keep them together.

Where it breaks

"If not obvious" — a subjective boundary. The law exempts you from the notice when it's already clear you're facing a bot. But "obvious" for the developer and for an anxious candidate are different things. Safer to disclose than to argue about obviousness.

Text labeling is technically fragile. For images, audio and video there are mature methods (watermarks, C2PA). For plain text, machine-readable labeling resilient to copying is an immature area: metadata is lost on copy-paste. The requirement exists; a reliable technology for text does not yet.

C2PA doesn't grant automatic conformity. The standard is voluntary and not harmonized under the AI Act — it reduces risk and closes the technical side, but by itself is not legal proof of conformity with Art. 50.

What to do as engineer/product

Compile a map of AI↔human contact points and disclose each one explicitly — don't rely on "it's clear anyway." For Kompas that's at least the chatbot and outgoing letters.

For media content, adopt C2PA / Content Credentials; for text, fix the disclosure at the UX level (a note in the letter, a banner in the chat), since a reliable machine-readable labeling of text doesn't yet exist. Account for the Art. 50(2) grace period, but don't put it off until its end.

Provocation

Transparency is the cheapest obligation of the AI Act and the most often forgotten: teams analyze high-risk for months and miss the line about the chatbot, which arrives earlier. And the fact — hidden from the candidate — that a machine is sorting them and answering them costs the company trust more than any penalty. And now the law makes that disclosure not a gesture of goodwill but a duty.

Read next

Shipping an AI product under regulatory risk?

A read of your product against the EU AI Act: risk class, role in the value chain, obligations and dossier — as a design constraint on the way in, not a lawyer's check at the end.

Email me

The transition engine

Next Move Engine — the system that takes a team to an autonomous delivery loop.

Next Move Engine →