AI Act UX Compliance: A CTO's Guide to Article 50

AI Act UX Compliance: A CTO's Guide to Article 50

A practical AI Act UX compliance guide for CTOs of AI and SaaS companies selling into the EU, covering scope, engineering work, ownership and cost.

AI Act UX Compliance: A CTO's Guide to Article 50

AI Act UX Compliance: A CTO's Guide to Article 50

A practical AI Act UX compliance guide for CTOs of AI and SaaS companies selling into the EU, covering scope, engineering work, ownership and cost.

Article 50 of the EU AI Act now applies to any AI product with EU users. Most teams respond with a label. This guide covers what your product and engineering teams actually need to ship, and who should own it.

What Article 50 means for your product, your engineers and your budget.

Isometric illustration of a person presenting a product interface, with a desktop dashboard, a 4.7 rating card, a bar chart, a settings panel and mobile screens around it.

TL;DR

  • Article 50 of the EU AI Act has applied since 2 August 2026. Fines reach €15 million or 3% of global turnover.

  • US companies are in scope if their AI reaches EU users.

  • Compliance needs product work (clear disclosures) and engineering work (machine-readable marking, logging, admin controls).

  • A bare AI label can lower trust. Pair every disclosure with a source, a human check or an override.

If your product has a chatbot, generates text, images or audio, or serves EU customers, AI Act UX compliance is now a live requirement. Article 50 of the EU AI Act took effect on 2 August 2026, and it wasn't postponed with the rest of the Act.

For most CTOs, the request arrives from legal as a single ticket: "add an AI label before the deadline." Your team ships a badge in a sprint, and everyone moves on.

That leaves three problems. First, the law also requires machine-readable marking of generated content, which is an engineering task, not a UI one. Second, if you sell B2B, your customers carry obligations too, and they will expect your product to support them. Third, research shows a bare AI label can reduce trust, which shows up later in activation and renewal numbers.

This guide is for CTOs and product leaders at AI and SaaS companies with EU users. It covers what Article 50 requires, the engineering work behind it, who should own each piece, and what it costs by stage. It's a product and engineering reading of the rules, not legal advice, so confirm your interpretation with counsel.

What AI Act UX Compliance Requires From Your Product in 2026

Scales diagram comparing AI Act UX compliance roles, with content marking and interaction disclosure weighted to the AI system provider, and deepfake and public-interest labels plus emotion and biometric notices weighted to the AI system deployer.

AI Act UX compliance under Article 50 means four things for most AI products: tell people when they're interacting with an AI system, mark AI-generated content in a machine-readable way, inform people exposed to emotion recognition or biometric categorization, and visibly label deepfakes and AI-written text on matters of public interest.

According to the European Commission's Article 50 FAQ, the duties split between the company that builds the AI system (the provider) and the company that uses it with its own audience (the deployer):

  • Interaction disclosure (provider). Anyone in a two-way exchange with an AI system must be told from the first interaction, unless it's obvious.

  • Content marking (provider). Generated audio, images, video and text must carry a machine-readable mark.

  • Emotion and biometric notices (deployer). People exposed to these systems must be informed.

  • Deepfake and public-interest text labels (deployer). These need a visible label, with exceptions for satire, fiction and text that went through genuine editorial review.

The timeline is fixed. The AI Omnibus entered into force on 27 July 2026 and moved high-risk obligations to December 2027, but it left Article 50 in place. The only relief is a grace period to 2 December 2026 for the marking duty on systems already on the market before August.

US headquarters don't change the answer. Under Article 2 of the AI Act, providers outside the EU are covered when they place systems on the EU market or when their system's output is used there.

Action check:

  • Which of your AI features reach users in the EU, directly or through your customers?

  • Which of them generate content, and which only assist?

  • Who on your team has been assigned Article 50 today?

The AI onboarding playbook top teams use to boost activation.

Reduce first-session confusion, speed up time-to-value, and build user trust, built from real onboarding audits of AI products.

No Spam. Free Lifetime

The AI onboarding playbook top teams use to boost activation.

Reduce first-session confusion, speed up time-to-value, and build user trust, built from real onboarding audits of AI products.

No Spam. Free Lifetime

Why a Disclosure Badge Alone Is a Business Risk

Legal risk is the obvious reason to act. The less obvious one is commercial: how you disclose AI affects whether people trust and adopt it.

A 2025 study by Schilke and Reimann in *Organizational Behavior and Human Decision Processes* ran 13 experiments and found that disclosing AI use reduced trust in whoever disclosed it. The effect held even when the disclosure was mandatory. A required label doesn't get a pass.

At the same time, buyers want rules. The 2025 KPMG and University of Melbourne global study of 48,000+ people found only 46% are willing to trust AI systems, while 70% say AI regulation is needed.

So your customers expect disclosure, then discount whatever carries it. The fix is not to hide the label but to attach accountability to it: a source the user can check, a note that a human reviewed the output, or a clear way to override it. That turns a compliance cost into something that supports adoption, and it's the approach we take in our UX design work for AI products.

The Engineering Work Behind AI Act UX Compliance

AI Act UX compliance is roughly half engineering. Your team needs machine-readable marking on generated content, a record of which disclosures were shown and when, configuration that lets customers control disclosures, and export paths that keep labels attached. None of this is visible in a mockup, which is why it's often missed.

The Commission published its Code of Practice on marking and labelling AI-generated content on 10 June 2026. It's voluntary, but signing it or following it is the clearest way to show compliance. Summaries of the final code describe a layered approach: signed provenance metadata in the style of C2PA content credentials, plus watermarks that survive re-encoding and screenshots, plus free public detection.

Obligation

Product surface

Engineering work

Likely owner

Interaction disclosure

Chat, voice, agent entry points

Disclosure component in the design system; event logged when shown

Product + design

Content marking

Every generated asset

Provenance metadata and watermarking in the generation pipeline; detection endpoint

Engineering

Customer (deployer) labeling

Admin settings, export, publish

Per-tenant disclosure settings; labels preserved on export and API output

Product + engineering

Accessibility

All of the above

Screen-reader text, audio cues, contrast

Design + QA

Audit evidence

Internal

Logs and configuration history retained

Engineering + legal

Products that generate media at scale feel this most.

Camb.ai, whose AI dubbing dashboard and editor we redesigned, produces speech in more than 140 languages. For a product like that, a label in the editor covers only part of the obligation. The exported audio has to carry the marking too.

What "Clear and Distinguishable" Means for Your Interface

This is the part of Article 50 your design team will ask about first.

"Clear and distinguishable" means a person notices the AI disclosure without looking for it. The Commission's draft guidelines reject disclosures buried in terms, footers or documentation, and they don't accept metadata alone for people, because people never see it. A combination of plain-language notices and persistent visual or audio indicators is the expected standard.

That reading comes from Greenberg Traurig's review of the Commission's draft Article 50 guidelines, published in May 2026. In practice:

Surface

Works

Doesn't work

Chat or assistant

AI named in the first message, identity shown in the header

"Powered by AI" in the footer

Voice

Spoken disclosure before the first answer

Disclosure only in app settings

Images and video

Visible label plus embedded marking

Embedded marking only

Generated text

Inline "AI draft" marker until a human edits and approves

A line in the terms of service

Two details are worth flagging to your product lead. The "obvious" exception is narrow: it only applies if a reasonably well-informed member of your audience would recognize the AI unaided, and the bar rises for children and vulnerable users. And disclosures must meet accessibility requirements, so a label a screen reader can't announce doesn't count.

Provider or Deployer: Who Owns Article 50 in a B2B SaaS Company

Diagram showing who owns Article 50 responsibilities in a B2B SaaS company: legal interprets scope and signs off on disclosure wording, product owns disclosure placement and customer-facing controls, engineering owns marking, logging and export behavior, and design owns disclosure components and accessibility.

Most B2B SaaS companies are both provider and deployer. You're the provider of the AI features you build, and your customers become deployers when they publish your AI's output to their own audiences. That means your product has to give customers the controls they need to meet their own obligations, not just meet yours.

The practical requirement is admin-level control: switch AI features on or off per workspace, choose how disclosures appear, and see which content was generated. When we redesigned LearnSphere's AI-powered learning platform, which serves four roles from Super Admin to Student, we included per-school admin toggles to turn AI features on or off. That kind of control is what enterprise buyers now ask about in security and procurement reviews.

Internally, assign ownership before you assign tickets:

1. Legal interprets scope and signs off on disclosure wording.

2. Product owns where disclosures appear and the customer-facing controls.

3. Engineering owns marking, logging and export behavior.

4. Design owns the disclosure components and their accessibility.

Action check: if an EU customer's procurement team asked tomorrow how your product supports their Article 50 duties, who would answer, and what would they show?

What AI Act UX Compliance Costs by Stage

AI Act UX compliance costs scale with the number of AI surfaces and user roles. A Seed-stage product with one assistant typically needs one to two weeks of design and engineering work. A Series B+ platform with generated media, agents and enterprise admins can need two to three months across teams.

Stage

Typical AI surface

Scope

Directional effort

Seed

One chatbot or copilot

Interaction disclosure, accessibility, basic logging

1–2 weeks

Series A

Assistant plus generated content

Content marking, inline labels, export handling

3–6 weeks

Series B+

Agents, media generation, enterprise admins

Per-tenant controls, detection endpoint, audit evidence, design system components

6–12 weeks

These are directional 2026 estimates for combined design and engineering effort. The biggest cost driver is discovery: finding every place your product generates or shows AI output. Teams that inventory surfaces first usually finish faster than teams that start by designing a badge.

Conclusion: What to Decide This Quarter

  • Decide scope. List every AI feature that reaches EU users and classify it as interaction, generation or both.

  • Assign owners. Legal for interpretation, product for surfaces and controls, engineering for marking and logs, design for components.

  • Budget realistically. Plan for one to twelve weeks depending on stage, with marking and admin controls as the long poles.

If you want a second opinion before committing the roadmap, book a 30-minute call with our team. We'll review your AI surfaces with your product and engineering leads and flag where disclosure design and engineering work are likely to collide.

Article 50 of the EU AI Act now applies to any AI product with EU users. Most teams respond with a label. This guide covers what your product and engineering teams actually need to ship, and who should own it.

What Article 50 means for your product, your engineers and your budget.

Isometric illustration of a person presenting a product interface, with a desktop dashboard, a 4.7 rating card, a bar chart, a settings panel and mobile screens around it.

TL;DR

  • Article 50 of the EU AI Act has applied since 2 August 2026. Fines reach €15 million or 3% of global turnover.

  • US companies are in scope if their AI reaches EU users.

  • Compliance needs product work (clear disclosures) and engineering work (machine-readable marking, logging, admin controls).

  • A bare AI label can lower trust. Pair every disclosure with a source, a human check or an override.

If your product has a chatbot, generates text, images or audio, or serves EU customers, AI Act UX compliance is now a live requirement. Article 50 of the EU AI Act took effect on 2 August 2026, and it wasn't postponed with the rest of the Act.

For most CTOs, the request arrives from legal as a single ticket: "add an AI label before the deadline." Your team ships a badge in a sprint, and everyone moves on.

That leaves three problems. First, the law also requires machine-readable marking of generated content, which is an engineering task, not a UI one. Second, if you sell B2B, your customers carry obligations too, and they will expect your product to support them. Third, research shows a bare AI label can reduce trust, which shows up later in activation and renewal numbers.

This guide is for CTOs and product leaders at AI and SaaS companies with EU users. It covers what Article 50 requires, the engineering work behind it, who should own each piece, and what it costs by stage. It's a product and engineering reading of the rules, not legal advice, so confirm your interpretation with counsel.

What AI Act UX Compliance Requires From Your Product in 2026

Scales diagram comparing AI Act UX compliance roles, with content marking and interaction disclosure weighted to the AI system provider, and deepfake and public-interest labels plus emotion and biometric notices weighted to the AI system deployer.

AI Act UX compliance under Article 50 means four things for most AI products: tell people when they're interacting with an AI system, mark AI-generated content in a machine-readable way, inform people exposed to emotion recognition or biometric categorization, and visibly label deepfakes and AI-written text on matters of public interest.

According to the European Commission's Article 50 FAQ, the duties split between the company that builds the AI system (the provider) and the company that uses it with its own audience (the deployer):

  • Interaction disclosure (provider). Anyone in a two-way exchange with an AI system must be told from the first interaction, unless it's obvious.

  • Content marking (provider). Generated audio, images, video and text must carry a machine-readable mark.

  • Emotion and biometric notices (deployer). People exposed to these systems must be informed.

  • Deepfake and public-interest text labels (deployer). These need a visible label, with exceptions for satire, fiction and text that went through genuine editorial review.

The timeline is fixed. The AI Omnibus entered into force on 27 July 2026 and moved high-risk obligations to December 2027, but it left Article 50 in place. The only relief is a grace period to 2 December 2026 for the marking duty on systems already on the market before August.

US headquarters don't change the answer. Under Article 2 of the AI Act, providers outside the EU are covered when they place systems on the EU market or when their system's output is used there.

Action check:

  • Which of your AI features reach users in the EU, directly or through your customers?

  • Which of them generate content, and which only assist?

  • Who on your team has been assigned Article 50 today?

The AI onboarding playbook top teams use to boost activation.

Reduce first-session confusion, speed up time-to-value, and build user trust, built from real onboarding audits of AI products.

No Spam. Free Lifetime

Why a Disclosure Badge Alone Is a Business Risk

Legal risk is the obvious reason to act. The less obvious one is commercial: how you disclose AI affects whether people trust and adopt it.

A 2025 study by Schilke and Reimann in *Organizational Behavior and Human Decision Processes* ran 13 experiments and found that disclosing AI use reduced trust in whoever disclosed it. The effect held even when the disclosure was mandatory. A required label doesn't get a pass.

At the same time, buyers want rules. The 2025 KPMG and University of Melbourne global study of 48,000+ people found only 46% are willing to trust AI systems, while 70% say AI regulation is needed.

So your customers expect disclosure, then discount whatever carries it. The fix is not to hide the label but to attach accountability to it: a source the user can check, a note that a human reviewed the output, or a clear way to override it. That turns a compliance cost into something that supports adoption, and it's the approach we take in our UX design work for AI products.

The Engineering Work Behind AI Act UX Compliance

AI Act UX compliance is roughly half engineering. Your team needs machine-readable marking on generated content, a record of which disclosures were shown and when, configuration that lets customers control disclosures, and export paths that keep labels attached. None of this is visible in a mockup, which is why it's often missed.

The Commission published its Code of Practice on marking and labelling AI-generated content on 10 June 2026. It's voluntary, but signing it or following it is the clearest way to show compliance. Summaries of the final code describe a layered approach: signed provenance metadata in the style of C2PA content credentials, plus watermarks that survive re-encoding and screenshots, plus free public detection.

Obligation

Product surface

Engineering work

Likely owner

Interaction disclosure

Chat, voice, agent entry points

Disclosure component in the design system; event logged when shown

Product + design

Content marking

Every generated asset

Provenance metadata and watermarking in the generation pipeline; detection endpoint

Engineering

Customer (deployer) labeling

Admin settings, export, publish

Per-tenant disclosure settings; labels preserved on export and API output

Product + engineering

Accessibility

All of the above

Screen-reader text, audio cues, contrast

Design + QA

Audit evidence

Internal

Logs and configuration history retained

Engineering + legal

Products that generate media at scale feel this most.

Camb.ai, whose AI dubbing dashboard and editor we redesigned, produces speech in more than 140 languages. For a product like that, a label in the editor covers only part of the obligation. The exported audio has to carry the marking too.

What "Clear and Distinguishable" Means for Your Interface

This is the part of Article 50 your design team will ask about first.

"Clear and distinguishable" means a person notices the AI disclosure without looking for it. The Commission's draft guidelines reject disclosures buried in terms, footers or documentation, and they don't accept metadata alone for people, because people never see it. A combination of plain-language notices and persistent visual or audio indicators is the expected standard.

That reading comes from Greenberg Traurig's review of the Commission's draft Article 50 guidelines, published in May 2026. In practice:

Surface

Works

Doesn't work

Chat or assistant

AI named in the first message, identity shown in the header

"Powered by AI" in the footer

Voice

Spoken disclosure before the first answer

Disclosure only in app settings

Images and video

Visible label plus embedded marking

Embedded marking only

Generated text

Inline "AI draft" marker until a human edits and approves

A line in the terms of service

Two details are worth flagging to your product lead. The "obvious" exception is narrow: it only applies if a reasonably well-informed member of your audience would recognize the AI unaided, and the bar rises for children and vulnerable users. And disclosures must meet accessibility requirements, so a label a screen reader can't announce doesn't count.

Provider or Deployer: Who Owns Article 50 in a B2B SaaS Company

Diagram showing who owns Article 50 responsibilities in a B2B SaaS company: legal interprets scope and signs off on disclosure wording, product owns disclosure placement and customer-facing controls, engineering owns marking, logging and export behavior, and design owns disclosure components and accessibility.

Most B2B SaaS companies are both provider and deployer. You're the provider of the AI features you build, and your customers become deployers when they publish your AI's output to their own audiences. That means your product has to give customers the controls they need to meet their own obligations, not just meet yours.

The practical requirement is admin-level control: switch AI features on or off per workspace, choose how disclosures appear, and see which content was generated. When we redesigned LearnSphere's AI-powered learning platform, which serves four roles from Super Admin to Student, we included per-school admin toggles to turn AI features on or off. That kind of control is what enterprise buyers now ask about in security and procurement reviews.

Internally, assign ownership before you assign tickets:

1. Legal interprets scope and signs off on disclosure wording.

2. Product owns where disclosures appear and the customer-facing controls.

3. Engineering owns marking, logging and export behavior.

4. Design owns the disclosure components and their accessibility.

Action check: if an EU customer's procurement team asked tomorrow how your product supports their Article 50 duties, who would answer, and what would they show?

What AI Act UX Compliance Costs by Stage

AI Act UX compliance costs scale with the number of AI surfaces and user roles. A Seed-stage product with one assistant typically needs one to two weeks of design and engineering work. A Series B+ platform with generated media, agents and enterprise admins can need two to three months across teams.

Stage

Typical AI surface

Scope

Directional effort

Seed

One chatbot or copilot

Interaction disclosure, accessibility, basic logging

1–2 weeks

Series A

Assistant plus generated content

Content marking, inline labels, export handling

3–6 weeks

Series B+

Agents, media generation, enterprise admins

Per-tenant controls, detection endpoint, audit evidence, design system components

6–12 weeks

These are directional 2026 estimates for combined design and engineering effort. The biggest cost driver is discovery: finding every place your product generates or shows AI output. Teams that inventory surfaces first usually finish faster than teams that start by designing a badge.

Conclusion: What to Decide This Quarter

  • Decide scope. List every AI feature that reaches EU users and classify it as interaction, generation or both.

  • Assign owners. Legal for interpretation, product for surfaces and controls, engineering for marking and logs, design for components.

  • Budget realistically. Plan for one to twelve weeks depending on stage, with marking and admin controls as the long poles.

If you want a second opinion before committing the roadmap, book a 30-minute call with our team. We'll review your AI surfaces with your product and engineering leads and flag where disclosure design and engineering work are likely to collide.

Have a project in mind?

Let’s talk through your idea and see what makes sense.

Harpreet Singh

Founder at Groto

Have a project in mind?

Let’s talk through your idea and see what makes sense.

Harpreet Singh

Founder at Groto

FAQ

Everything you were going to ask (and a few things you didn’t know to)

Does Article 50 apply to AI features in internal tools used by our EU employees?

Generally yes for interaction disclosure, because employees are people interacting with an AI system. The "obvious" exception may apply for trained staff using a clearly labeled internal tool, but that is a judgment call to document. Confirm the position with counsel before relying on it.

Do we need to mark AI-assisted text, like email drafts our users edit and send?

Not always. The Commission's FAQ exempts assistive editing functions that don't substantially alter the user's input, such as grammar or tone suggestions. Features that generate most of the text are more likely to be in scope for machine-readable marking.

Is the EU common icon for AI-generated content mandatory?

No. The icons come with the voluntary Code of Practice. Using them is still worth considering, because a recognized standard makes it easier to show a regulator or enterprise buyer that your labels are clear and distinguishable.

What evidence should we keep in case a regulator or customer asks?

Keep a record of where each disclosure appears, logs showing disclosures were displayed, your marking and watermarking configuration, and the history of changes to those settings. Design specs and accessibility test results help too. Evidence is far cheaper to collect as you build than to reconstruct later.

If we use a third-party model that already watermarks outputs, are we covered?

Not automatically. If you build and ship the AI system, you may count as its provider, so you need to confirm the marking survives your own processing, storage and export. Ask your model vendor for documentation and test it end to end.

How does Article 50 relate to the high-risk rules coming in December 2027?

They're separate. Article 50 applies now to most AI products with EU users. If your product is also used for high-risk purposes listed in Annex III, such as hiring or credit decisions, additional obligations will apply from 2 December 2027, including human oversight requirements.

Does Article 50 apply to AI features in internal tools used by our EU employees?

Generally yes for interaction disclosure, because employees are people interacting with an AI system. The "obvious" exception may apply for trained staff using a clearly labeled internal tool, but that is a judgment call to document. Confirm the position with counsel before relying on it.

Do we need to mark AI-assisted text, like email drafts our users edit and send?

Not always. The Commission's FAQ exempts assistive editing functions that don't substantially alter the user's input, such as grammar or tone suggestions. Features that generate most of the text are more likely to be in scope for machine-readable marking.

Is the EU common icon for AI-generated content mandatory?

No. The icons come with the voluntary Code of Practice. Using them is still worth considering, because a recognized standard makes it easier to show a regulator or enterprise buyer that your labels are clear and distinguishable.

What evidence should we keep in case a regulator or customer asks?

Keep a record of where each disclosure appears, logs showing disclosures were displayed, your marking and watermarking configuration, and the history of changes to those settings. Design specs and accessibility test results help too. Evidence is far cheaper to collect as you build than to reconstruct later.

If we use a third-party model that already watermarks outputs, are we covered?

Not automatically. If you build and ship the AI system, you may count as its provider, so you need to confirm the marking survives your own processing, storage and export. Ask your model vendor for documentation and test it end to end.

How does Article 50 relate to the high-risk rules coming in December 2027?

They're separate. Article 50 applies now to most AI products with EU users. If your product is also used for high-risk purposes listed in Annex III, such as hiring or credit decisions, additional obligations will apply from 2 December 2027, including human oversight requirements.

More Articles

Extreme close-up black and white photograph of a human eye

Let’s bring your vision to life

Tell us what's on your mind? We'll hit you back in 24 hours. No fluff, no delays - just a solid vision to bring your idea to life.

Profile portrait of a man in a white shirt against a light background

Harpreet Singh

Founder and Creative Director

Get in Touch

Extreme close-up black and white photograph of a human eye

Let’s bring your vision to life

Tell us what's on your mind? We'll hit you back in 24 hours. No fluff, no delays - just a solid vision to bring your idea to life.

Profile portrait of a man in a white shirt against a light background

Harpreet Singh

Founder and Creative Director

Get in Touch

Extreme close-up black and white photograph of a human eye

Let’s bring your vision to life

Tell us what's on your mind? We'll hit you back in 24 hours. No fluff, no delays - just a solid vision to bring your idea to life.

Profile portrait of a man in a white shirt against a light background

Harpreet Singh

Founder and Creative Director

Get in Touch