Your customer service chatbot clearly states that it is powered by AI. But what happens when content produced by the same AI solution is copied into a customer email, stored in a content management system, published on a website, or modified by another application?
From 2 August 2026, the transparency obligations under Article 50 of the EU AI Act began to apply to providers and deployers of certain AI systems. The rules address situations in which people interact directly with AI or encounter specific types of AI-generated or manipulated content. Their purpose is to help people recognise the use of AI, make informed decisions, and protect themselves from deception, impersonation, and misinformation. The immediate reaction may be to add a label, an icon, or a notice to a chatbot interface. In our view, that is only the visible part of the challenge.
AI transparency is not primarily a labeling exercise. It is an AI inventory, metadata, ownership, architecture, and lifecycle-management challenge.
What changed on 2 August 2026?
Article 50 does not apply the same way to every AI system. It covers four situations – AI that interacts directly with people, AI-generated or manipulated content, emotion recognition and biometric categorisation, and deepfakes or unedited AI-generated public-interest content – and which obligations apply depends on what the system does and whether the organization is acting as a provider or a deployer in that particular case. The European Commission’s guidelines walk through each situation in detail.
Model providers are building technical signals – Content provenance
Anthropic provides a timely example of how model providers respond to the new requirements. The company has described the use of machine-readable signals in Claude-generated content, including imperceptible marking for text and signed provenance metadata for supported files. From an AI governance perspective, this is notable because Anthropic effectively chose Google's watermarking research as the foundation for its compliance strategy, rather than inventing a completely different text provenance mechanism.
Other technology companies, including Microsoft, Adobe, OpenAI, and Meta, are developing different combinations of watermarks, provenance metadata, Content Credentials, visible disclosures, and verification mechanisms. Microsoft is focusing on Coalition for Content Provenance and Authenticity (C2PA)-based provenance plus watermarking technologies of its own ecosystem.
This is positive progress. Technical provenance signals can make it easier to determine whether AI was involved in creating or modifying content. However, there is not yet a single universal label or technical mechanism that covers every model, content type, application, and publishing channel.
More importantly, the model provider's technical signal is only the starting point of the enterprise content lifecycle. AI-generated content often moves through multiple systems and processes before reaching its final audience. During that journey, provenance information may be weakened or lost as content is copied between applications, re-uploaded to different platforms, edited by humans or other AI systems, converted into new file formats, processed by content management systems, optimized for publication, or redistributed through third-party channels.
Anthropic's approach is therefore an important provider-level control, but it does not automatically resolve the deploying organization's responsibilities. Enterprises must still determine what Article 50 means for their own products, services, users, publishing processes, and governance practices.
What does this mean for your organization?
Knowing whether you use AI isn't enough. What matters is where AI is being used, what it produces, who encounters the output, where that output travels and who is accountable for it.
1. Know where AI is used
An organization cannot apply transparency requirements consistently without first understanding where AI is already being used. This inventory should extend beyond centrally governed development projects and include AI capabilities embedded in SaaS applications, productivity tools, customer-facing services, and business processes.
In practice, organizations often discover AI in more places than expected. Common examples include customer service chatbots, internal copilots, document and proposal generation, intelligent search solutions, automated customer communications, and AI features embedded in business applications. At Zure, we have worked with customers on AI-powered assistants, conversational interfaces, document automation, knowledge discovery solutions, and agent-based workflows built on platforms such as Microsoft Copilot, Microsoft Foundry, and Microsoft Fabric.
The inventory should not be a one-time spreadsheet exercise. Instead, it should become a living source of information that helps the organization understand and govern its AI landscape as it evolves.
2. Determine your role for each use case
The EU AI Act distinguishes between providers and deployers, and many organizations will play both roles at the same time. A company may act as a deployer when using a standard third-party AI service internally, while taking on provider responsibilities when integrating foundation models into customer-facing solutions delivered under its own brand.
For this reason, responsibilities should be assessed separately for each AI use case. The assessment should consider who developed the solution, who defines its intended purpose, whether it has been substantially modified, and under whose name it is offered. Understanding these distinctions is essential because the applicable obligations depend on the role the organization plays in each scenario.
3. Classify the interaction and the output
Once AI systems have been identified, organizations need to understand how people interact with them and what types of outputs they produce. Some systems directly engage with users through conversations, while others generate documents, images, audio, video, or recommendations that later become part of a business process.
This classification helps determine when transparency obligations may apply. It also supports consistent decision-making by distinguishing between content that reaches employees, customers, or the public and content that remains within automated machine-to-machine processes. A structured view of interactions and outputs reduces the risk of both under-labeling and unnecessary labeling.
4. Assign clear accountability
Transparency cannot be owned by a single function. Business teams, architects, developers, data owners, compliance specialists, and user experience designers all contribute to how AI systems are implemented and used.
Each AI use case should therefore have clearly defined ownership across business, technical, data, and compliance domains. The responsible stakeholders should be able to explain how the system works, which models and data sources are involved, how outputs are delivered to users, and what transparency controls have been implemented. Without clear accountability, labeling decisions are often made late in the development process and without a complete understanding of the content lifecycle.
5. Preserve transparency throughout the lifecycle
Transparency does not end when content is generated. Organizations also need to ensure that disclosure information, provenance metadata, and other transparency mechanisms survive the full lifecycle of the content.
In practice, this means validating that metadata remains intact as content moves through content management systems, document conversions, publication workflows, downloads, uploads, and downstream applications. AI-generated content should remain traceable to its source system and responsible owner, and organizations should be able to demonstrate the effectiveness of their controls during audits. This is where AI transparency becomes an enterprise architecture and information management challenge rather than simply a user interface requirement.
Our view: labeling is the last mile, not the starting point
Organizations should not begin by asking which icon, watermark, or disclaimer to display to users. They should begin by identifying their AI systems, assigning ownership, classifying interactions and outputs, and understanding how AI-generated content moves across the organization.
A label is merely the visible outcome of a much broader governance capability. Effective transparency depends on AI inventories, ownership models, metadata management, architecture documentation, content lineage, governance decisions, and operational controls. These foundations will look familiar to anyone with experience in data governance.
In many ways, the EU AI Act reinforces practices that mature organizations have already established around ownership, classification, cataloging, traceability, auditability, and lifecycle management. The difference is that the governance scope now extends beyond data to include AI models, agents, prompts, generated content, and their interactions. Strong data governance will not automatically make an organization compliant with the EU AI Act, but it provides many of the capabilities needed to implement and demonstrate AI transparency effectively.
AI transparency requires more than an AI policy
The Article 50 transparency requirements do not make every AI solution subject to the same label. They do, however, make one organizational capability increasingly important.
Organizations must know:
- where AI is used
- what it produces
- which data and models are involved
- who is responsible
- how outputs reach people
- which controls remain in place throughout the lifecycle
Model providers can supply watermarks and provenance metadata. Technology teams can implement notices and labels. Neither will work consistently without inventory, ownership, metadata, architecture, and lifecycle controls.
Our view is that AI transparency should not be treated as an isolated compliance project. It should be built into enterprise architecture, data governance, software development, and content-management practices.
The organizations best prepared for Article 50 will not necessarily be those with the longest AI policies. They will be those that can trace AI from the model and data source to the final interaction or piece of content.
Zure helps organizations discover and classify their AI estate, establish ownership and governance, map AI-related data and content flows, and implement practical transparency controls in Microsoft Azure, Foundry and Fabric, and modern enterprise application environments.