Introduction
On 2 August 2026, the transparency and disclosure requirements under Article 50 of the European Union’s Artificial Intelligence Act (the “EU AI Act“) officially entered into force.[1] The EU AI Act imposes comprehensive rules on businesses with a presence in the EU, as well as those seeking to establish one.[2] Even businesses without an EU presence may face scrutiny if they serve European clients or publish AI-generated content for European audiences.[3] Consequently, relying solely on domestic legal frameworks is no longer sufficient to mitigate cross-border regulatory risk.
While much of the international legal discourse has focused on obligations for AI system developers (“providers”), many firms within Taiwan’s business ecosystem operate as AI deployers.[4] Importantly, Article 50 imposes direct disclosure requirements on deployers, and deployers cannot simply assume that the AI provider’s compliance shields them from legal liability. Furthermore, although much of the EU AI Act regulates high-risk systems through risk classification, the transparency requirements under Article 50 apply to all systems—regardless of risk level.[5]
In this article, we examine the role of deployers within the AI value chain, review deployer obligations under the EU AI Act, and outline practical steps businesses can take to ensure compliance.
Context
As AI-generated content becomes increasingly indistinguishable from authentic human output, the primary purpose of Article 50’s transparency requirements is to inform individuals when they interact with AI systems or are exposed to AI-generated content. The goal is to prevent misinformation, fraud, and deception while safeguarding the integrity of the information ecosystem.[6] For disclosures to be effective, they must be presented clearly and distinguishably—before or at the moment of first exposure to the AI system or content.[7]
Understanding Your Role in the AI Value Chain
Before taking steps toward compliance, businesses must first determine whether they operate as a provider or deployer, as each role carries distinct legal obligations under Article 50. A provider is an entity that develops an AI system and either places it on the market or puts it into service.[8] A deployer,[9] on the other hand, is any entity using AI systems under its authority within its professional activities.[10] Importantly, a deployer can unwittingly become a provider—triggering heavier and more complex compliance burdens. For limited-risk systems, a deployer may become a provider by outsourcing development or modifying an existing system with new training data before placing it into service under its own name.[11] The threshold is lower for high-risk or systemic-risk systems: simply making a substantial modification or rebranding—even without introducing new training data—could turn a deployer into a provider.[12]
Core Obligations for AI Deployers under Article 50(4)
For deployers, the EU AI Act imposes two separate obligations:
- Deployers must disclose any AI-generated or manipulated image, audio, or video content constituting a deepfake as artificial content. “Deepfakes” are defined as “AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.”[13] The subject does not need to actually exist—it only needs to be plausibly real. Furthermore, a deployer must consider whether the manipulated content would appear authentic or truthful to its intended audience, not simply whether the average person would perceive it as such. That said, minor edits and AI-generated media used solely as background sets fall outside the definition of “deepfakes” and are exempt from disclosure, provided they do not materially alter the authenticity or primary focus of the content.[14]
- Deployers must disclose any AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. “Matters of public interest” is interpreted broadly to encompass political, democratic, administrative, environmental, economic, and scientific issues that form part of public debate.[15] Article 50(4) contains a crucial exemption: AI-generated text does not require disclosure if it has undergone genuine human review and if a natural or legal person assumes explicit editorial responsibility for the publication.[16] Superficial, formal, or procedural checks (such as spelling and grammar review) are not sufficient to satisfy this exemption.[17]
It is also worth noting that Article 50’s transparency requirements do not apply retroactively to deepfakes generated before 2 August 2026, regardless of whether they are published before or after that date.[18] However, AI-generated texts must be labeled if they are published on or after 2 August 2026, even if the content was generated earlier.[19]
Practical Steps for Compliance
To navigate these new requirements, deployers with exposure to the European market should take concrete operational steps to ensure compliance.
First, we recommend that firms establish internal compliance processes and conduct audits of their production workflows to identify where AI-generated media is being published. Second, firms should establish, adopt, or maintain a human-review editorial process to ensure the exemption in Article 50(4) can be relied upon—and the identity of the natural or legal person holding editorial responsibility should be disclosed. Finally, businesses are well-advised to adhere to the European Commission’s Code of Practice and design disclosure labels in line with its guidelines.[20] Although the Code is voluntary, non-signatories will face greater scrutiny when assessed for compliance and may be required to demonstrate compliance through alternative means that demand more detailed information.[21]
Concluding Remarks
With enforcement under the EU AI Act now officially underway, noncompliance carries tangible regulatory and commercial consequences.[22] For deployers, failure to adhere to the transparency and disclosure requirements under Article 50 can lead to administrative fines of up to EUR 15 million or 3% of a company’s total worldwide annual turnover for the preceding fiscal year, whichever is higher (for small and medium-sized enterprises, whichever is lower).[23] For Taiwanese businesses, these penalties pose a significant risk that should not be ignored. As European regulation shifts to hard legal mandates, we encourage Taiwanese businesses to view proactive compliance not merely as a regulatory burden but as a competitive advantage—one that signals trustworthiness, accountability, and reliability to the European market.
Because the content of this article involves foreign regulations that are subject to rapid change, we recommend that readers independently verify original sources.
This article was written by Greg Buxton, Chi-hsien Nieh, and legal intern Truth Lee.
If you have any questions or require additional information on the global regulatory landscape for AI development and deployment, please contact Greg Buxton at gbuxton@winklerpartners.com.
[1] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) [2024] OJ L1689/1, art 50.
[2] Artificial Intelligence Act, art 2(1).
[3] Ibid.
[4]Artificial Intelligence Act, art 3(4); Hung Yi Chen, ‘The Global Ripple Effect of the EU AI Act: A Game-Theoretic Analysis of Cross-Border Corporate Compliance and Taiwan’s Strategic Response’ (Hung Yi Chen, 2025) <https://www.hungyichen.com/en/insights/eu-ai-act-global-compliance>.
[5] Artificial Intelligence Act, art 50.
[6] Di Cooke et al, ‘As Good as a Coin Toss: Human Detection of AI-Generated Content’ (2025) 68(10) Communications of the ACM 100; Artificial Intelligence Act, recital 133.
[7] Artificial Intelligence Act, art 50(5).
[8] Artificial Intelligence Act, art 3(3).
[9] Artificial Intelligence Act, art 3(3).
[10] Artificial Intelligence Act, art 3(4).
[11] Artificial Intelligence Act, art 3(3); European Commission, ‘Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (the ‘AI Act’)’ COM (2026) 5054 final, para 11. While the Commission’s Guidelines offer practical interpretation, they are non-binding; only the Court of Justice of the European Union (CJEU) can provide authoritative legal interpretation of the AI Act.
[12] Artificial Intelligence Act, art 25.
[13] Artificial Intelligence Act, art 3(60).
[14] Commission Guidelines (n 10) paras 113-116.
[15] Ibid para 131.
[16]Artificial Intelligence Act, art 50(4).
[17] Commission Guidelines (n 10) para 135.
[18] Commission Guidelines (n 10) para 154.
[19] Ibid.
[20] European Commission, ‘Code of Practice on transparency of AI-generated content’ (June 2026) <https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content> paras 33-36.
[21] Commission Guidelines (n 10) para 148.
[22] Artificial Intelligence Act, arts 64-68, 74.
[23] Artificial Intelligence Act, art 99(4).

