Article 50 transparency & deepfake labelling
Binds Providers & deployers of interactive, synthetic-content or biometric AI. Disclosure of AI interaction; marking of AI-generated content.
Stated maximum penalty — Up to 3% turnover or €15M
Topic dossier
When people have to be told they are dealing with AI, and content has to be marked as model-generated — chatbot disclosure, content labelling and training-data transparency. 38 obligations across 11 jurisdictions — 22 in force. Next dated deadline: 12 Aug 2026.
Transparency is the most common thread running through AI law. Three duties recur: telling a person when they are interacting with an AI system, marking content that an AI generated, and — increasingly — disclosing what data a model was trained on. The instruments below each carry one or more of these duties, tracked to their primary sources.
Binds Providers & deployers of interactive, synthetic-content or biometric AI. Disclosure of AI interaction; marking of AI-generated content.
Stated maximum penalty — Up to 3% turnover or €15M
Binds Operators of AI companion models serving New York users (excludes customer-service / internal-productivity-only systems). AI-identity disclosure at session start + every 3h and suicide/self-harm crisis referral (988) for AI companion operators; NY AG enforces.
Stated maximum penalty — Up to $15,000/day per violation (AG only; no private right of action)
Binds Operators of companion-chatbot platforms available in California. AI-status disclosure + self-harm protocols.
Stated maximum penalty — Private right of action
Binds Developers of generative AI systems made available to Californians. Public dataset-summary disclosure for generative AI offered to Californians.
Stated maximum penalty — Civil enforcement
Binds Persons, firms, or corporations engaged in commerce who produce or create advertisements using synthetic performers with actual knowledge of their use in New York. Requires conspicuous disclosure when AI-generated synthetic performers (digitally created human assets not recognizable as any identifiable real person) appear in advertisements in any medium — newspapers, magazines, radio, TV, streaming, billboards, and transit. Advertisers must have actual knowledge of synthetic performer use. Exempts expressive works, audio-only ads, and language-translation uses.
Stated maximum penalty — $1,000 first violation; $5,000 subsequent violations (civil penalties)
Binds Private health carriers and public employee health plans using AI in prior authorization in Washington. AI cannot be sole basis for denying health care services; human clinical review required for AI-generated denials.
Annual reporting to OIC on AI-generated prior auth statistics required.
Stated maximum penalty — OIC enforcement (civil penalties; license actions)
Binds Healthcare providers and facilities using AI transcription in Rhode Island. Healthcare providers using AI transcription for clinical visits must document and notify patients.
Signed 22 June 2026 (R.I. Gen. Laws ch. 23-106); effective upon passage.
Stated maximum penalty — RI healthcare licensing enforcement
Binds Operators of conversational AI services serving Iowa consumers. Disclosure and safeguard obligations for conversational AI operators serving Iowa users; compliance applicable 2027-07-01.
Law in force 2026-07-01; compliance obligations applicable from July 1, 2027.
Stated maximum penalty — Civil enforcement by Iowa AG (amount TBD)
Binds Health insurers and health benefit providers in Indiana. AI cannot be sole basis for claim downcoding; insurers must disclose AI use in adverse determinations.
Stated maximum penalty — Indiana DOI enforcement
Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.
Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.
Stated maximum penalty — $1,000/violation up to $1,000,000/operator
Binds Covered GenAI providers with >1M monthly users accessible in California. AI-detection tool + content provenance for >1M-user providers.
Stated maximum penalty — Civil penalties per violation/day
Binds Large online platforms and device manufacturers with >1M monthly users/visitors in California. Extends SB 942 AI-detection & watermarking duties to large platforms and device manufacturers; Phase 2 obligations (1M+ users) from Jan 1, 2027.
Phase 1 (Aug 2, 2026): AI detection tools & manifest disclosures. Phase 2 (Jan 1, 2027): additional large-platform obligations.
Stated maximum penalty — $5,000/day per violation
Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.
Signed 2026-05-22 by Governor Lee as Public Chapter 1082. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.
Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators
Binds Regulated psychotherapy professionals in Colorado using AI; any entity misrepresenting AI as professional-equivalent. AI cannot deliver psychotherapy without licensed professional's real-time involvement; disclosure and written consent required.
Stated maximum penalty — Unfair trade practice (CO Consumer Protection Act; AG enforcement)
Binds Subscription AI providers, frontier developers, AI companion operators, AEDT deployers, and social media platforms serving Connecticut users. Tiered AI obligations: subscription AI disclosures (Oct 2026), companion AI safeguards (Jan 2027), AEDT pre-decision notices (Oct 2027), social media minor restrictions (Jan 2028).
Multiple tiers: subscription AI disclosures 2026-10-01; AI companion 2027-01-01; AEDT disclosures 2027-10-01; social media minor restrictions 2028-01-01.
Stated maximum penalty — CT AG enforcement (unfair/deceptive trade practices)
Binds Health insurers using AI in coverage determinations in Alabama. AI may not be sole basis for coverage denial; health insurers must disclose AI use and file annual certification with Alabama DOI.
Annual certification to Alabama DOI required.
Stated maximum penalty — Alabama DOI disciplinary action (license revocation/suspension)
Binds Health insurers operating in Utah for prior authorization processes. Insurers must disclose AI use in prior authorization reviews; adverse determinations must reflect independent medical judgment.
Stated maximum penalty — Disclosure to Utah Insurance Department required
Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.
Disclosures every 3 hours (all users) or 1 hour (minor users).
Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)
Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.
Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees
Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.
Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01.
Stated maximum penalty — CO AG enforcement
Binds Chatbot and companion AI operators serving Rhode Island users. Chatbot/companion AI operators must include suicidal-ideation protocols and crisis referrals; annual reporting to AG from 2027-07-01.
Signed 2026-06-22 by Governor McKee; general effective date 2027-01-01. Annual reports to RI AG beginning July 1, 2027.
Stated maximum penalty — RI AG enforcement
Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.
Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.
Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified
Binds AI content creators and operators serving Washington users. Operators/creators must inform users when content is developed or modified through AI.
Signed 2026-03-24; codified as Chapter 167, Laws of 2026. Enforced exclusively by the WA Attorney General under the Consumer Protection Act (ch. 19.86 RCW).
Stated maximum penalty — Civil penalty up to $100,000 per covered provider (WA Consumer Protection Act, ch. 19.86 RCW; AG enforcement only)
Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.
Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)
Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.
Modeled on Nebraska LB 525. Signed 2026-04-01.
Stated maximum penalty — Idaho AG enforcement (amount TBD)
Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.
Signed April 14, 2026; operative July 1, 2027 (sections 12–18).
Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only
Binds UK controllers making significant automated decisions with legal or similarly significant effects on data subjects. Replaces UK GDPR Art. 22 default prohibition on significant automated decisions. Controllers may now make such decisions using any lawful basis (incl. legitimate interests), but must: notify data subjects pre-decision, allow representations, provide meaningful human review, and enable contest rights. Special category data remains more restricted.
In force February 5, 2026 per SI 2026/82 (Commencement No. 6). Replaces and substantively restructures UK GDPR Art. 22: removes default prohibition; adds mandatory pre-decision notification, representations, human review, and contest rights. Secondary legislation: UK GDPR (Amendment) Regulations 2026.
Stated maximum penalty — UK GDPR penalties (up to £17.5M or 4% global annual turnover — whichever higher); ICO enforcement
Binds AI-content service & propagation platforms, app stores, and users. Explicit (visible) and implicit (metadata/watermark) labels on AI-generated content.
Stated maximum penalty — CAC administrative penalties
Binds Developers and deployers of AI agent services in China; mandatory compliance for healthcare, transportation, media, and public safety sectors; guidance-level for others. First national policy framework for AI agents. Mandatory for 19 priority sectors (healthcare, transport, media, public safety): filing, compliance testing, product recall provisions. Establishes three-tier decision authority model. AI-generated content labeling required. Enforceable via existing CSL/DSL/PIPL frameworks.
Published and operative from May 8, 2026 (jointly issued by CAC, NDRC, MIIT). Three-tier decision authority model: decisions requiring human-only authority; decisions requiring user approval; decisions agent may handle autonomously. High-risk sector filing and testing obligations enforceable under Cybersecurity Law, Data Security Law, PIPL. No standalone penalty regime; enforcement via existing frameworks.
Stated maximum penalty — Enforcement via CSL/DSL/PIPL (no standalone penalties specified)
Binds Providers of anthropomorphic AI interactive services (virtual companions, emotional chatbots, human-like AI) publicly available in mainland China. Dedicated compliance regime for AI companion services, virtual chatbots and emotionally interactive AI; mandates AI-identity disclosure, minor protections, usage-time warnings, and prohibits inducing emotional dependence.
In force 15 Jul 2026.
Stated maximum penalty — CAC administrative penalties; service suspension
Binds AI business operators offering AI products/services in Korea (extraterritorial). Pre-notify users that a service uses AI; label generative and realistic synthetic outputs.
MSIT enforcement grace period of one year from 22 Jan 2026; fines deferred until ~22 Jan 2027.
Stated maximum penalty — Admin fine up to ₩30M
Binds All internet users (duty not to spread false election information); candidates and campaign organisations (AI labelling obligation); large-scale platform operators (X, YouTube, Meta) operating in Japan. AI-generated election content must display an 'AI作成' label; large social media platforms must implement harm-mitigation measures and publish annual reports covering election misinformation. Applies from March 2027.
Passed the House of Councillors July 13, 2026; promulgated July 17, 2026 as Law No. 58 of Reiwa 8 (令和8年法律第58号). Amends the Public Offices Election Law and the Platform Countermeasures Act (情プラ法). Enforcement March 1, 2027 ahead of April 2027 unified local elections. No new criminal penalties for platform duties (political compromise). AI-generated content that could be mistaken for authentic footage must display 'AI作成' label; clearly identifiable illustrations/animation are exempt.
Stated maximum penalty — No new criminal penalties created; existing election law criminal provisions (Art. 235-2) continue to apply to candidates
Binds Providers / deployers of generative AI and user-facing AI systems. Machine-readable labels on AI media; disclose when users interact with AI; deceptive deepfakes banned.
Stated maximum penalty — Admin fines (decree-set)
Binds Operators and providers of the 46 designated high-risk AI systems in Vietnam. Designates 46 specific AI systems as high-risk; new deployments require pre-deployment conformity assessment from Aug 15 2026.
Existing systems have transition period: March 1, 2027 (most sectors) or September 1, 2027 (healthcare, education, banking).
Stated maximum penalty — Enforcement under Vietnam AI Law 134/2025 / Decree 142
Binds Intermediaries, significant social-media intermediaries (5M+ users), GenAI tool providers. Mandatory labels on AI-generated (SGI) content; 3-hour government-ordered takedown; significant-platform traceability.
Stated maximum penalty — Loss of safe harbour; IT Act offences
Binds Organisations making automated decisions using personal information in Quebec. Right to be informed + disclosure of key factors for automated decisions using personal info (Quebec).
Stated maximum penalty — AMPs up to C$10M / 2% turnover
Binds All Australian Privacy Principle (APP) entities using automated decision-making affecting individual rights or interests. All APP entities using personal information in ADM that could significantly affect individual rights must disclose this in their privacy policies.
Stated maximum penalty — Civil penalties up to AUD $50M (OAIC enforcement)
Binds AI providers, importers, distributors, and deployers of AI systems operating in Germany under EU AI Act scope (Reg. EU 2024/1689). Designates Bundesnetzagentur (BNetzA) as Germany's lead AI authority; establishes enforcement architecture for EU AI Act in Germany, including AI regulatory sandboxes (KI-Reallabore) and domestic penalty regime.
National implementing law for EU AI Act. EU phased obligations still apply: Art.50 transparency in force Aug 2, 2026; high-risk Annex I AI → Aug 2, 2027; full high-risk Annex III → Dec 2, 2027.
Stated maximum penalty — €35M or 7% global turnover (prohibited AI practices); €15M or 3% (high-risk violations); €50K for domestic procedural violations (KI-MIG §§15–17)
Several laws now require it. The EU AI Act’s Article 50, California’s SB 243 companion-chatbot rules, South Korea’s AI Basic Act and Vietnam’s Law on AI all require users to be told that they are dealing with an AI system rather than a human.
A duty to publish a summary of the data used to train a model. California’s AB 2013 requires generative-AI developers to post a dataset summary; the EU AI Act requires GPAI providers to publish a sufficiently detailed summary of training content.
Quebec’s Law 25 gives individuals a right to be informed of, and to understand the main factors behind, an automated decision made about them using personal information; Colorado’s AI Act adds consumer notice and appeal rights for consequential automated decisions.
We currently track transparency & disclosure obligations across 11 jurisdictions: European Union, United States, United Kingdom, China, South Korea, Japan, Vietnam, India, Canada, Australia and Germany. Each is dated and linked to its primary source on this page.
Not legal advice. Each obligation links to its primary source and carries the date it was last checked; verify the legal text before relying on it.