Article 13 vs Article 50: the AI Act’s dual transparency channel

Ferrer-Bonsoms · AI Act series for businesses (no. 7) · 6 October 2026

The conversation we have been having with companies that have deployed artificial intelligence tends to open the same way: “ours isn’t high-risk, so AI Act transparency doesn’t reach us yet.”

The first half of that sentence is usually true. The second is false, and the error is expensive, because a deadline is running right now.

The AI Act does not have one transparency regime but two, with different addressees, different content and different dates. Only one of them was deferred.

Two channels, two addressees

Article 13 governs what the provider owes the deployer. It is a documentary, technical, business-to-business channel. It operates only for high-risk systems.

Article 50 governs what is owed to the natural person on the other side of the screen. It is a perceptual, immediate, public-facing channel. And it does not ask what risk category the system falls into.

That last sentence is the heart of the matter. A chatbot on a shop’s website is not high-risk. It is fully subject to Article 50.

Article 13: what your provider owes you

Article 13 requires the provider of a high-risk system to design it so that its operation is sufficiently transparent for the deployer to interpret its output and use it appropriately, and to supply instructions for use with prescribed content: the provider’s identity and contact details; intended purpose; levels of accuracy, robustness and cybersecurity; known or foreseeable circumstances that may give rise to risks to health, safety or fundamental rights; specifications for input data; the human oversight measures of Article 14; the computational resources required, expected lifetime and maintenance; and the logging mechanisms of Article 12.

It is a document that ends up in a drawer, and that is where the misunderstanding lies. Those instructions are the deployer’s evidence: they are what establishes what the system was represented to do, within what limits and under what conditions. When something goes wrong, the difference between having demanded them and not having demanded them is the difference between a defensible file and an indefensible one.

Article 13 is not yet enforceable. But the contract with your provider is signed today, and it is not renegotiated afterwards. Asking now, in writing, for a commitment to supply the instructions for use costs nothing; asking in 2028, when the contract has been running for two years, costs a great deal.

Article 50: what you owe the person in front of you

Four obligations, and it matters not to confuse who bears each one.

On the provider. That systems intended to interact directly with natural persons are designed so that those persons are informed they are dealing with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person taking into account the circumstances and context of use. And that systems generating synthetic content — audio, image, video or text — mark their outputs in a machine-readable format and detectable as artificially generated or manipulated, with exceptions for assistive functions for standard editing or where the input data or its semantics are not substantially altered.

On the deployer. To inform exposed persons where emotion recognition or biometric categorisation systems are used. And to disclose that content is artificial where it constitutes a deep fake, with a softened exception for evidently artistic, creative, satirical or analogous works, where disclosure need only be made in a manner that does not hamper enjoyment of the work. Likewise where AI-generated text is published to inform the public on matters of public interest, unless there is human review and someone assumes editorial responsibility.

In every case the information must be given clearly and distinguishably at the latest at the time of the first interaction or exposure, and in line with applicable accessibility requirements.

For the typical Spanish company, which is a deployer and not a provider, the practical consequence runs two ways. Its direct obligations are the last two. But it must verify that the provider has complied with the first two, because if the notice does not appear or the content is unmarked, it is you facing the customer and your brand on the screen. And if you white-label the system or alter its intended purpose, you may find yourself standing in the provider’s shoes.

The dates, which is where the problem sits

Article 50 has applied since 2 August 2026. The Digital Omnibus deferred the requirements for high-risk systems — and with them Article 13 — but left the Article 50 date untouched.

For systems already on the market before that date there is a grace period for machine-readable marking which ends on 2 December 2026. Content generated before 2 August need not be labelled retroactively.

That leaves under two months.

Breach of Article 50 sits among the infringements in Article 99: up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.

Article 13, by contrast, follows the high-risk calendar: 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for those embedded in Annex I products.

And Spanish law gives you no breathing room

The second common misreading: “the Spanish law hasn’t been passed yet.”

True. The Organic Law Bill on the good use and governance of artificial intelligence was approved by the Council of Ministers on 26 May 2026 and is before Parliament. It has not been published in the Official State Gazette and is not in force.

And it is irrelevant to whether you must comply. The obligations arise from Regulation (EU) 2024/1689, which is directly applicable without any domestic implementing measure. What the Spanish law adds is who supervises — AESIA as market surveillance authority, with the data protection authority for biometric systems — and the national scale of infringements.

Put plainly: the duty already exists. What is being assembled is the machinery for punishing its breach.

A prior warning on emotion recognition

Before asking whether you must inform, ask whether you may do it at all.

Article 5 prohibits AI systems used to infer the emotions of a natural person in the areas of the workplace and education institutions, save for medical or safety reasons. That prohibition has applied since 2 February 2025 and its breach falls within the highest tier of penalties.

If someone has offered you emotional analytics for recruitment, performance review or student monitoring, your problem is not one of transparency.

What to review this week

First, whatever talks to people. Chatbots, voice assistants, automated calls. Check that the notice that this is an AI exists and appears at first interaction, not buried in the terms of use.

Second, whatever generates content. If you publish generated images, video, audio or text, ask your provider in writing whether the tool emits machine-readable marking and under what standard. If the answer is vague, you have until 2 December.

Third, deep fakes and public-interest text. Advertising with synthetic faces or voices, press releases drafted by AI. Disclose, or evidence human review with an identified editorial responsible.

Fourth, the instructions for use. Ask your providers for them now even though they are not yet enforceable, and write them in as a contractual obligation in everything you sign from today.

Fifth, your data protection information layer. The Article 50 notice is not the information required by Articles 13 and 14 GDPR. They are triggered by different things and they coexist: there can be a duty to inform under the AI Act with no personal data processed at all.

At Ferrer-Bonsoms we help companies organise this work: system inventory, risk classification, review of notices and of clauses with providers. If you have deployed AI and are unsure where you stand, get in touch and we will review it.

Download our free Artificial Intelligence Compliance Calendar 2026-2028: every AI Act application date after the Digital Omnibus, on a single page.

This article is part of our AI Act series for businesses. Next in the series: the prohibited practices of Article 5, which have applied since February 2025.

Scroll to Top