Provider or deployer: who labels under Article 50
Providers mark output in machine-readable form; deployers label deepfakes visibly on first exposure. Here is which role you occupy on a hosted generator.
Article 50 of the EU AI Act does not impose one labelling duty. It imposes two, on two different parties, satisfied by two different artefacts. One is a machine-readable marker in the output, aimed at a detector. The other is a perceivable label, aimed at a person. Confusing them produces the two most common failure states: a producer building watermarking infrastructure they were never asked for, or a producer assuming a tool's embedded marking discharges a duty that was always theirs.
The sorting question is short. Did you place the generative system on the market, or did you use someone else's to make something you then published?
The two duties, side by side
| Provider duty (50(2)) | Deployer duty (50(4)) | |
|---|---|---|
| Who carries it | Whoever places the generative AI system on the market or puts it into service under their own name or trademark | Whoever uses that system under their authority to produce a deepfake they then put in front of an audience |
| What it produces | Machine-readable marking so synthetic audio, image, video and text is detectable as generated or manipulated | A disclosure a person can perceive that the content was artificially generated or manipulated |
| Who reads it | Detection tooling, platforms, downstream verifiers | The viewer |
| Where it lives | In the output: metadata, watermark, or another embedded signal | On or around the content, by first exposure |
| Satisfied by metadata alone? | Metadata is one method, not the whole duty. The output must be machine-readable and detectable | No |
| Timing | At generation | At the latest at first exposure (Article 50(5)) |
The row that decides most arguments is the last-but-one. A deployer duty is not satisfied by embedded metadata, because metadata is not something a scrolling viewer perceives. A visible caption does not satisfy the provider duty, because a caption is not machine-readable in the sense the obligation means. Neither absorbs the other.
Article 50(4) is not a duty to label every synthetic pixel. It applies to deployers of a system that generates or manipulates image, audio or video constituting a deepfake, and, in a second paragraph, to certain AI-generated text published to inform the public on matters of public interest. Colour grading and background cleanup that do not produce a deepfake are a different question.
Which role a hosted generator puts you in
If you sign in to a generation platform, prompt it, download the output and publish it, you are a deployer of that system. You did not place it on the market. You are not the addressee of 50(2), and you cannot retrofit machine-readable marking if the export does not carry it. That engineering sits upstream.
This is the accurate description for agencies, brands, in-house marketing teams, solo creators and production studios. You do not need a watermarking pipeline, a detection API, or C2PA signing infrastructure to meet 50(2), because 50(2) is not addressed to you.
What you do carry is the 50(4) label, and it does not wait on anyone.
The edge that is worth checking
There is a version of "I only use hosted tools" that stops being a deployer story, and it is worth recognising before a client asks.
If you are embedding a generative system into your own product and presenting it to customers under your own name, you are no longer only using a system. You may be placing one on the market. That covers a white-labelled generator inside your SaaS, a branded creative tool for clients, or an API you resell as your own. Whether that flips you into the provider column depends on the arrangement, and it belongs in front of counsel. The signal: whose name and trademark does the end user see on the generation surface?
The same caution applies if you materially alter a system's behaviour and distribute the result. Fine-tuning for your own internal output is one thing; publishing the tuned model or offering it as a service is another.
The middle ground — you use hosted models, you are the only person prompting them, the output goes out as your creative work — is deployer territory.
What "first exposure" actually asks for
Article 50(5) requires the information in paragraphs 1 to 4 to be provided "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure." There is not a pile of decided cases on what that means for a mobile feed. The working production reading is: the viewer can perceive the disclosure when they first encounter the content, without extra taps and without waiting out the clip.
Treat these as failure modes of that reading, not as holdings:
- Behind a tap. A disclosure that requires expanding a caption is easy to miss on a mobile feed. Do not rely on post copy as the only label.
- At the end. A credit that appears in the last second of a short clip is technically present and easy to miss.
- A flash frame. Present for a few frames satisfies a screenshot, not a viewer.
- In the file only. Provenance metadata is a provider-layer artefact. It is useful and it is not your 50(4) label.
- Wrong asset. Disclose on the asset that reaches the audience. If a 9:16 cut-down goes out separately from the master, the cut-down needs its own label.
The workable pattern is a fixed, consistent, readable disclosure placed where the eye already is, repeated identically across a channel. A label that looks the same every time reads as part of your format rather than as a warning.
One narrowing worth knowing: where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, 50(4) limits the duty to disclosing the existence of the generated or manipulated content in a way that does not hamper display or enjoyment of the work. The load-bearing word is "evidently." Work engineered to look like an ordinary recording of a real person, place or event is a poor fit for it. The artistic carve-out in Article 50 walks the boundary.
Doing the deployer half in a real pipeline
The deployer label is a production step, not a settings toggle, which is why it belongs in the edit rather than in a compliance folder.
- Flag the assets that need it at brief stage. Realistic avatars, cloned voices and any generated footage that could pass as an ordinary recording of a real person, place or event, headed for an audience that includes EU viewers. Anything built as a photoreal talking-head or a voice clone starts flagged by default.
- Burn the label into the cut, not the upload form. In Versely that is a text overlay on the timeline. A request like "add the text 'Made with AI' as a small overlay in the bottom-left corner for the full clip" runs the text overlay step with your wording and position, so the label travels with the file to every destination rather than living in one platform's metadata field.
- Check it against a preview before you spend on the export. The editor runs off a single re-renderable EDL, so a free 480p preview pass — subject to a short per-user cooldown — shows you exactly where the label lands at real playback size. The final export is charged once, whatever the clip count.
- Set the platform toggle as well. The AI content label on YouTube, Meta or TikTok is contractual policy, not statute, and it stacks on top of the legal duty rather than replacing it. One disclosure, five destinations is the per-platform version of this step.
- Do not wait for the provider's marking to appear. Whether a given tool's export carries an embedded marker tells you about that provider's engineering timeline, not about your duty. The December deadline nobody diarised covers why some tools are still switching marking on.
Where the file layer still matters to you
Embedded provenance is not your 50(2) duty, but it is increasingly a commercial one: buyers ask and platforms read it. A manifest is a hard binding to a file, and any re-encode, screenshot or non-aware edit invalidates it. Social platforms re-encode on upload as a matter of course. Treat it as a compliance aid, not proof — sign, strip, survive walks the chain.
If the question you actually have is which section of the voluntary Code of Practice your organisation would sign, that maps onto the same split in where a creator actually sits in the transparency code.
FAQ
I use a hosted generator. Am I a provider of anything?
Almost certainly not, if you are prompting someone else's system and publishing the result as your own creative work. You are a deployer. The marking obligation in 50(2) belongs to whoever operates the system.
Does my tool's watermark cover my disclosure duty?
No. Machine-readable marking answers a detector. The deployer duty answers a viewer, at first exposure. A file can carry perfect provenance metadata and still leave the labelling duty unmet.
What if I white-label a generator inside my own product?
That is the case where the line genuinely blurs, because your customers see a generative system presented under your name. Get advice on the specific arrangement rather than assuming the deployer answer carries over.
Do I need to label everything I make with AI?
The deployer labelling duty in 50(4) is aimed at deepfakes — realistic synthetic image, audio or video that could be taken for authentic — and at certain public-interest text. Colour grading, background cleanup and obviously non-realistic work are treated differently, and separate platform rules may still ask for a toggle regardless.