Try

The EU AI Act, Article 50, explained for families

EU AI Act Article 50 has applied since 2 August 2026. It requires that people are told when they are speaking with an AI system, and that synthetic audio, images and video are marked as artificially generated. MemoriesBox does both, and this page shows where.

Facts on this page verified

The short answer

Article 50 is the transparency article of the EU AI Act, Regulation (EU) 2024/1689. It has applied since 2 August 2026, which is fifteen days before this page was written. It says two simple things and one technical one: you must be told when you are interacting with an AI system, content generated by AI must be marked so that machines can detect it, and anyone deploying a system that produces a synthetic voice or face of a real person must disclose that it is artificial.

It does not ban voice cloning. It regulates how honest you have to be about it.

The date is checked against Article 113 of the Regulation as it stands on eur-lex at the verification date at the top of this page. The Commission's digital omnibus proposals of late 2025 proposed grace periods for some Article 50 marking duties; whatever is finally adopted, we treat 2 August 2026 as the date we are bound from, because the disclosure was going to be right whether or not the law made it mandatory.

What Article 50 actually says

Article 50 has four substantive paragraphs, and each one binds a different party.

Paragraph Who it binds In plain words Applies to MemoriesBox
50(1) Providers of AI systems that interact directly with people The system must be built so that a person is informed they are interacting with AI, unless that is obvious to a reasonably well-informed, observant and circumspect person Yes
50(2) Providers of systems generating synthetic audio, image, video or text The output must be marked in a machine-readable format and detectable as artificially generated or manipulated, as far as technically feasible Yes
50(3) Deployers of emotion recognition or biometric categorisation systems People exposed to the system must be informed No. We operate neither
50(4) Deployers of systems producing a deep fake Disclose that the content has been artificially generated or manipulated Yes

Two definitions do a lot of work here. A deep fake, under Article 3(60), is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places or events and would falsely appear to be authentic. A synthesised voice of a real person sits squarely inside that definition, whether it was made with love or with bad intent. The law does not distinguish by motive, and it is right not to.

Article 50(5) sets the timing. The information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", and it must meet applicable accessibility requirements. Not in the terms of service. Not on page four of a settings screen. At the start, in a form the person can actually perceive.

The dates that matter

Date What began
1 August 2024 The AI Act entered into force
2 February 2025 Prohibited practices (Article 5) and the AI literacy duty (Article 4)
2 August 2025 General-purpose AI rules, governance, and the penalty regime
2 August 2026 General application, including the Article 50 transparency obligations
2 August 2027 High-risk classification under Article 6(1) and the obligations attached to it

The staging is set out in Article 113 of the Regulation.

Which hat MemoriesBox wears

The Act divides duties between providers, who put a system on the market, and deployers, who use one. A small company that builds a family-facing product on top of somebody else's speech model can plausibly be both.

We have not tried to argue our way into the lighter category. We treat ourselves as bound by Article 50(1), 50(2) and 50(4), and we disclose accordingly. If the classification is ever tested and lands differently, the behaviour on the page will not change.

What this means when your family opens MemoriesBox

  • The conversation identifies itself as AI at the first interaction, every session. Not once at signup.
  • Synthetic audio produced by the avatar is marked so that a machine can detect it as artificially generated. Recital 133 of the Regulation names the sorts of techniques used for this: watermarks, metadata identifications, cryptographic methods for proving provenance, and logging.
  • The original recordings your relative made are not synthetic. They are a person speaking into a microphone, and nothing about Article 50 requires them to be marked. This distinction matters more than any other on this page.

What that looks like in the product, specifically:

Duty Where it is met
50(1), tell the person it is AI A line under the conversation heading on the digital-self page, every session, in all five languages: "This is a digital imitation built only from your own recordings. It is not a person, and it will not know anything you did not tell it." The model itself is told never to claim to be an AI in character, which is exactly why the label lives in the interface and not in the reply
50(2), machine-readable marking Every generated audio file is stored with metadata identification — the technique Recital 133 names first — reading ai-generated: true and naming the generator, in the object store and in the media library's tags. A machine reading the file can tell it from a recording of the person, which is the point
50(4), disclose the deep fake The same line, plus this page, plus the fact that a recording of the person and a generated reply are stored and labelled differently

What is not yet done: an audible or in-band watermark inside the audio itself. Metadata travels with the file in our storage and is stripped the moment somebody re-records it through a speaker, which is the limit the Regulation itself acknowledges. We will add an in-band mark when a standard the AI Office's codes of practice endorse exists to add; until then, the metadata is the marking, and this paragraph is the disclosure that it is metadata.

What Article 50 does not do

  • It does not ban voice cloning. Nothing in Article 50 prohibits building a synthetic voice of a consenting person.
  • It does not replace the GDPR. Article 50(6) is explicit that these obligations are without prejudice to other Union and national law. Consent, lawful basis and data subject rights are separate questions, covered on /trust/is-voice-cloning-legal-in-europe.
  • It does not protect the dead. The Article 50 obligations run to natural persons who interact with, or are exposed to, a system. A person who has died is not a natural person exposed to anything. What protects them is national personality law and whatever they arranged while alive. See /trust/who-owns-a-voice-clone.
  • It does not decide whether this is a good idea. That is on /trust/consent, where the criticism of the category is set out rather than answered with a slogan.
  • It does not apply outside the EU. A US or Australian service reaching European families may be in scope depending on how it operates, but a family in Ohio using an American product has no Article 50 to lean on.

What happens when a company ignores it

Non-compliance with Article 50 sits in Article 99(4)(g) of the Regulation: administrative fines of up to EUR 15,000,000 or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For small and medium-sized enterprises, including start-ups, Article 99(6) reverses the test, so the cap is whichever of the two is lower. That is the provision a company our size would be judged under.

Enforcement runs through national market surveillance authorities designated under Article 70. Under Article 85, any natural or legal person with grounds to consider that the Regulation has been infringed may submit a complaint to the relevant market surveillance authority. You do not need a lawyer to do that, and you do not need to be a customer.

The EU is not alone in reaching this conclusion. Draft rules published by the Cyberspace Administration of China in April 2026 require digital-human content to be marked as AI-generated, prohibit clones made without proper consent, and set fines from ¥10,000 to ¥200,000. In the United States, the proposed NO FAKES Act and a growing set of state digital-replica laws point the same way.

What we can't promise

  • We cannot promise a marking survives everything. Machine-readable marking is required "as far as technically feasible", and audio that is re-recorded, compressed, or played through a phone speaker into another microphone can lose it. The Regulation acknowledges the state of the art as a limit. Anyone claiming an unbreakable audio watermark is overstating it.
  • We cannot promise the standards are settled. Article 50(7) tasks the AI Office with facilitating codes of practice on detection and labelling, and that work is not finished. What is state of the art today may be inadequate in two years.
  • We cannot promise this page is legal advice. It is a plain-language reading by the people who have to comply with it. For a decision that matters, read the Regulation or ask a lawyer in your member state.
  • We cannot promise compliance protects you from the thing you are actually worried about. A perfectly labelled synthetic voice can still be upsetting to hear. Disclosure is a floor, not a comfort.

What the law says, in the original

Questions people ask

When did the EU AI Act Article 50 come into force?

The AI Act entered into force on 1 August 2024, and the Article 50 transparency obligations have applied since 2 August 2026. The staged dates are set out in Article 113 of the Regulation.

Does the EU AI Act ban AI voice clones of dead people?

No. Article 50 is a transparency rule, not a prohibition. It requires disclosure that you are dealing with AI and machine-readable marking of synthetic audio. Whether a particular clone is lawful depends on consent and on national law, not on Article 50.

Do I have to be told when I am talking to an AI?

Yes. Article 50(1) requires that you are informed, and Article 50(5) requires it to be clear, distinguishable, accessible, and given at the latest at the time of the first interaction.

What is the fine for breaking Article 50?

Up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher, under Article 99(4)(g). For small and medium-sized enterprises the cap is whichever is lower, under Article 99(6).

Does Article 50 apply to the recordings of my grandmother's real voice?

No. Article 50 covers AI-generated and AI-manipulated content. A recording of a person speaking is not synthetic content, and it does not need to be marked. Only the synthesised voice does.


Related: Is voice cloning legal in Europe · Who owns a cloned voice · How the voice clone is built · Where your data lives · Every other way to keep a voice · The full comparison table

MemoriesBox is $139 a year, hosted in the EU, first 14 days free. Start here if this answered the question you came with.