What’s new: Openlayer named in the 2026 Gartner Market Guide® for AI Evaluation and Observability Platforms. Learn More

EU AI Act limited risk AI systems: compliance requirements in May 2026

Published June 3, 20268 min read

You deployed your chatbot before Article 50 transparency requirements were finalized. Now it's a limited risk AI system, and it needs to disclose that it's not human before users engage. The compliance window shortened from six months to three, so if you haven't started building transparency workflows into your AI deployments, you're already behind schedule for the December 2, 2026 deadline.

TLDR:

  • Limited risk AI systems include chatbots and synthetic content generators that must disclose AI involvement to users by May 2026
  • Article 50 requires providers to label AI-generated content and deployers to inform users before interaction
  • Non-compliance penalties reach €7.5 million or 1.5% of global turnover per violation
  • Openlayer automatically maps AI projects to EU AI Act frameworks and generates audit-ready compliance documentation through 100+ automated tests

What limited risk AI systems are under the EU AI Act

EU AI Act limited risk AI systems occupy a middle tier in the Act's three-level classification structure. They face fewer obligations than high-risk AI systems, but they are not exempt. The category covers two main system types:

  • AI systems that interact directly with people, such as chatbots and conversational agents, where users might reasonably believe they are speaking with a human.
  • AI systems that generate synthetic content, including deepfakes, AI-generated images, and manipulated audio or video, where audiences may not recognize the content as machine-generated.

The defining characteristic is the potential for user deception or misunderstanding, not the sophistication of the underlying model.

Article 50 transparency obligations for providers

Under Article 50, providers of limited risk AI systems face specific disclosure duties tied to how users interact with their systems. Any AI system that engages users through synthetic text, images, audio, or video must make clear that the content is AI-generated, meeting transparency obligations under the EU AI Act. Chatbots must inform users they are interacting with an AI, not a human. Deepfake or manipulated media requires explicit labeling.

These obligations apply at the point of interaction, before users engage with outputs that could mislead or manipulate. The European Commission's draft implementation guidelines for Article 50 (published May 8, 2026, open for consultation until June 3) clarify the scope of disclosure obligations, specify timing requirements for when notices must appear, and detail watermarking standards for AI-generated content, covering aspects not handled by the separate Code of Practice on marking and labeling.

Providers have specific obligations under Article 50:

  • Inform users when they are interacting with an AI system, unless this is already obvious from context.
  • Label AI-generated or AI-manipulated content so users can make informed decisions about what they consume.
  • Build disclosure mechanisms directly into the user experience, not buried in terms of service or fine print.

Article 50 transparency obligations for deployers

Deployers carry their own distinct obligations under Article 50, separate from what the provider built into the system.

Running an emotion recognition system that analyzes customer sentiment in call center interactions? You must inform people they are being analyzed. Deploying content generation tools that produce public interest material, including news or political advertising, requires explicit AI labeling. Deepfakes in any customer-facing product must be disclosed to the audience before they engage with it. Practically, this covers:

  • Marketing chatbots disclosing AI involvement before users engage with the conversation.
  • Customer service voice synthesis flagging that the voice is AI-generated.
  • Content tools generating political or news material carrying explicit AI labels.

The line between provider and deployer blurs quickly in enterprise settings. If you are building on top of a third-party model, you are acting as a deployer. Article 50 still applies, regardless of who wrote the underlying code.

Provider and deployer obligations under Article 50

The table below provides a high-level overview of the system type and the obligations both providers and deployers have, when they must disclose, and the penalty range for non-compliance.

System TypeProvider ObligationsDeployer ObligationsDisclosure TimingPenalty Range
Chatbots and conversational AIBuild disclosure mechanisms into the system interface that inform users they are interacting with AI before engagement beginsInform users they are communicating with an AI system before the conversation starts, regardless of provider-built disclosuresBefore first user interactionUp to €7.5M or 1.5% global turnover
Synthetic content generation (text, images, video)Label all AI-generated or AI-manipulated content with machine-readable watermarks and visible user-facing markersFlag AI-generated content with explicit labels when deployed in public interest contexts (news, political advertising)At point of content displayUp to €7.5M or 1.5% global turnover
Deepfakes and manipulated mediaImplement detectable markers that downstream tools can identify, meeting technical watermarking standardsDisclose deepfake content to audiences before they engage with it in any customer-facing productBefore content consumptionUp to €7.5M or 1.5% global turnover
Emotion recognition systemsDocument system capabilities and provide technical specifications for disclosure implementationInform individuals they are being analyzed for emotional state during interactions (call centers, customer service)Before analysis beginsUp to €7.5M or 1.5% global turnover
Voice synthesis in customer serviceBuild audio disclosure mechanisms or text notifications into the voice interface designFlag that the voice users hear is AI-generated, not human, before customer engagementAt call initiationUp to €7.5M or 1.5% global turnover

The August 2026 compliance deadline and recent amendments

Article 50 obligations formally apply from August 2, 2026. Under the original timeline, organizations had a six-month grace period to finalize technical transparency solutions, pushing the hard implementation deadline to February 2, 2027. Then came the Digital Omnibus agreement, which cut that grace period from six months to three months. The new hard deadline for full Article 50 compliance is December 2, 2026.

For many enterprises, that delta matters more than the headline date. Six months is enough time to design, build, and evaluate disclosure mechanisms at scale. Three months is not. If your organization has not started planning transparency workflows into your AI deployments, you are already behind.

Treat August 2026 as your internal target, not December.

Common limited risk AI systems in enterprise environments

Most enterprises already run several limited risk systems without realizing they carry Article 50 obligations. Identifying them is step one. The systems most likely to trigger transparency requirements include:

  • Customer service chatbots handling billing inquiries, support tickets, or account management
  • Virtual assistants embedded in consumer-facing products or mobile apps
  • Marketing content tools generating emails, ad copy, or social media posts at scale
  • HR chatbots managing onboarding, benefits questions, or internal helpdesk requests
  • Recommendation engines surfacing personalized content, products, or job listings to end users

Many of these were deployed before Article 50 obligations were finalized. Retrofitting disclosure into a live production system is meaningfully harder than designing it in from day one. If your team cannot currently answer which deployed systems interact directly with users or generate synthetic content, that gap is your starting point.

Implementing machine-readable watermarking and content detection

A clean, modern technical illustration showing digital watermarking and content authentication. Abstract visualization of invisible digital signatures being embedded into synthetic media layers - images, audio waveforms, and text patterns. Show subtle geometric patterns representing machine-readable markers being woven into digital content streams. Use a professional color palette with blues and purples against a light background. Technical but accessible style, showing the concept of detectable AI-content markers without any text labels.

Machine-readable watermarking is one of the more technical obligations tied to EU AI Act limited risk AI systems that generate synthetic content. Systems producing AI-generated text, images, audio, or video must embed detectable markers so that downstream tools and users can identify the content's origin.

The regulation does not prescribe a specific watermarking standard, which leaves implementation decisions to developers. In practice, the method depends on the content modality:

  • Images: Invisible pixel-level encoding embeds imperceptible signals into image data that survive typical compression and resizing. Approaches like steganographic bit-plane encoding or frequency-domain watermarks (DCT/DWT) are common. The Coalition for Content Provenance and Authenticity (C2PA) standard provides an open technical specification for attaching cryptographically signed provenance metadata directly to image and video files, and is gaining traction as a de facto baseline for compliance.
  • Audio: Spectral watermarking encodes identifiers into frequency bands inaudible to humans but detectable by classifiers. The signal must be robust enough to survive format conversion, playback, and re-recording scenarios common in customer service voice synthesis deployments.
  • Text: Statistical token distribution shifts alter the probability weights of a language model's output during generation, creating a detectable pattern in the resulting token sequences. Unlike image or audio watermarks, text watermarks degrade under paraphrasing or translation, which is an open implementation challenge with no fully solved approach yet.

Content detection also falls on deployers. Systems must flag AI-generated media before it reaches end users, requiring integration with detection APIs or in-house classifiers trained to recognize synthetic signatures. In practice, deployers must build a detection layer at the point of content display or delivery, beyond the generation step alone. Classifiers must be retrained as generative models evolve, since detection accuracy degrades when the underlying model architecture changes. Deployers operating across multiple content types need separate detection pipelines per modality, or a unified provider that covers image, audio, and text under a single API contract.

Penalties and enforcement mechanisms for Article 50 violations

A professional abstract illustration showing regulatory enforcement and compliance penalties. Visualize a layered structure with escalating levels representing different penalty tiers - subtle geometric shapes in blues and purples showing increasing scales of enforcement. Include abstract representations of European member states as interconnected nodes with monitoring symbols. Show data flows and surveillance patterns across a network grid. Modern, clean technical style with a light background, emphasizing oversight, accountability, and multi-jurisdictional regulatory framework without any text or numbers.

Non-compliance with Article 50 transparency obligations can result in fines up to €7.5 million or 1.5% of global annual turnover, whichever is higher. That sits at the lower end of the EU AI Act's penalty structure. High-risk system violations reach €30 million or 6% of global turnover. Prohibited AI violations go higher still. Limited risk penalties look modest by comparison, until you factor in the reputational cost of a public enforcement action. National market surveillance authorities in each EU member state hold enforcement power. They can investigate, audit, and impose fines independently, so a company operating across multiple EU markets faces overlapping regulatory scrutiny rather than a single centralized review.

How to build continuous Article 50 compliance

Article 50 sets transparency obligations, but the EU AI Act treats compliance as an ongoing requirement, not a one-time checkbox. Regulators expect documented evidence that your systems consistently meet disclosure standards across every user interaction. Continuous compliance rests on three core pillars:

  • Logging and audit trails: Every interaction where an AI system generates content or communicates with users should be logged with timestamps, system version identifiers, and disclosure delivery confirmation. These records become your evidence layer during regulatory review.
  • Monitoring disclosure delivery: Transparency notices can break silently due to UI changes, API updates, or localization errors. Automated monitoring catches failures before they accumulate into a compliance gap.
  • Periodic system re-evaluation: As your AI system evolves, its risk classification may shift. Re-evaluate whether your disclosure obligations have changed whenever the underlying model or deployment context changes.

Openlayer's automated compliance for limited risk AI systems

openlayer.png

Openlayer maps every AI project directly to EU AI Act frameworks, including Article 50 transparency obligations, automatically through its AI governance and compliance platform. No manual configuration required. For limited risk systems, Openlayer covers the full Article 50 surface area:

  • Chatbots, generative content tools, and synthetic media pipelines are inventoried across the enterprise and continuously evaluated against disclosure requirements.
  • 100+ automated tests validate that systems properly identify themselves as AI, flag synthetic content, and surface compliance failures before they reach users.
  • Real-time guardrails prevent non-compliant outputs from going live.
  • Audit-ready documentation is generated continuously, mapping test results directly to Article 50 requirements.
  • Compliance reports are exportable and structured for regulatory submission from day one.

What regulators want is evidence, not assurances. When a national market surveillance authority asks how your chatbot disclosures work across 40 million monthly interactions, the answer exists in your compliance dashboard, not in someone's email thread.

Final thoughts on transparency compliance for limited risk systems

Managing EU AI Act limited risk AI systems means proving that your chatbots, content tools, and synthetic media pipelines consistently meet transparency standards across every user interaction. You need logging, monitoring, and audit-ready documentation built into your workflows before regulators ask for it. Contact us if you want to see how automated compliance validation maps directly to Article 50 obligations.

FAQ

Can I build EU AI Act compliance for limited risk systems without hiring consultants?

Yes. Platforms like Openlayer automatically map your AI systems to Article 50 transparency obligations, generate audit-ready evidence continuously, and validate disclosure mechanisms through automated tests, eliminating the need for manual compliance workflows or external consultants.

Limited risk AI systems vs high-risk systems: what's the compliance difference?

Limited risk systems face transparency obligations under Article 50 (disclosure of AI interaction, synthetic content labeling), while high-risk systems require conformity assessments, risk management systems, and CE marking. The penalty structure differs too: €7.5M or 1.5% of global turnover for Article 50 violations versus €30M or 6% for high-risk breaches.

What qualifies as a limited risk AI system under the EU AI Act?

Any AI system that interacts directly with users (chatbots, virtual assistants) where users might believe they're speaking with a human, or systems generating synthetic content (deepfakes, AI-generated images, manipulated media) where audiences may not recognize machine-generated origins. The category is defined by potential for user deception, not model sophistication.

How long does Article 50 compliance implementation take?

The Digital Omnibus amendment cut the technical implementation window from 6 months to 3 months, with full compliance required by December 2, 2026. Organizations treating August 2026 as an internal target rather than December have enough runway to design, build, and validate disclosure mechanisms at scale without rushing.

What happens if my chatbot doesn't disclose AI involvement to users?

National market surveillance authorities can impose fines up to €7.5 million or 1.5% of global annual turnover for Article 50 violations. Beyond financial penalties, a public enforcement action creates reputational damage and triggers overlapping regulatory scrutiny across EU member states where you operate.

Work on the future.

2026 Openlayer. All rights reserved.