Published:
August 3, 2026
Updated:
August 5, 2026

The EU AI Act, Article 50: What Businesses Need to Know Right Now

A practical guide to the EU AI Act's Article 50 transparency obligations, now enforceable from 2 August 2026, covering what marketing teams need to know about AI disclosure for chatbots, synthetic content labelling, deepfake rules, and GDPR intersections.

20
Mins Read
Play / Stop Audio

Contents

Share this news

The EU AI Act, Article 50: What Businesses  Need to Know Right Now

A joint perspective from Homes for Students and VerbaFlo

If your marketing team uses AI, and in 2026 most marketing teams do, then the EU AI Act's transparency obligations are now part of your legal landscape. Article 50 of the Act is enforceable from 2 August 2026. It is not a distant compliance horizon; it is live.

This article breaks down what Article 50 actually requires, where it intersects with the tools marketing teams use every day, from AI-generated imagery to chatbots and voice assistants, and what practical steps teams should be taking now. We have written it jointly because Homes for Students operates at scale in PBSA and build-to-rent marketing, and VerbaFlo builds the AI communications infrastructure that sits inside those operations. Between us, we deal with both sides of the provider-deployer relationship that Article 50 creates.

Two documents shape the practical reading of Article 50 alongside the Regulation itself, and we reference both throughout. The Code of Practice on Transparency of AI-generated Content was published on 10 June 2026, and the Commission's Guidelines on the Article 50 transparency obligations were adopted on 20 July 2026. The Guidelines are expected to be the primary reference for national authorities applying Article 50, and a good deal of the operative detail now lives there rather than in the Act itself.

What the EU AI Act Actually Is

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 and applies in phases. The regulation classifies AI systems by risk level: unacceptable risk (banned outright), high risk (heavily regulated), limited risk (transparency obligations), and minimal risk (largely unregulated).

Most marketing AI tools, chatbots, content generators, image generators, voice assistants, and data-processing tools, fall into the limited-risk category. They are not banned or heavily restricted, but they do carry specific transparency obligations under Article 50. As we set out later, one part of a typical operator's stack often sits in the high-risk category as well, and it is usually not the part marketing teams are looking at.

The critical dates are as follows:

  • 2 February 2025: Prohibited AI practices (Article 5) and the AI literacy obligation (Article 4) took effect.
  • 2 August 2025: General-purpose AI model rules took effect.
  • 2 August 2026: Article 50 transparency obligations and most remaining provisions become enforceable.
  • 2 December 2026: Extended deadline for the machine-readable marking duty under Article 50(2) only, and only for generative AI systems already on the market before 2 August 2026. Systems launched from 2 August onwards must comply from day one.
  • 2 December 2027: Application date for Annex III standalone high-risk systems, moved from 2 August 2026 by the 2026 Digital Omnibus on AI.
  • 2 August 2028: Application date for Annex I embedded high-risk systems, moved from 2 August 2027 by the same instrument.

One clarification is worth making, given recent headlines. The Digital Omnibus on AI was signed on 8 July 2026 and extended the two high-risk application dates just listed, but it left the Article 50 transparency obligations, the Article 5 prohibitions, and the Article 4 literacy obligation completely untouched. If you have read that the AI Act has been postponed and quietly stood down your preparations, the deadline that affects marketing teams is 2 August 2026, and it has arrived.

Article 50: The Transparency Obligations

Article 50 creates several distinct transparency obligations. Each applies to different AI use cases, and each carries different responsibilities depending on whether you are the provider (the company that built or supplies the AI system) or the deployer (the company that uses it). Marketing teams are almost always deployers. AI vendors like VerbaFlo are providers; companies like Homes for Students are deployers.

Before we walk through the paragraphs, one general point about timing and language sits in Article 50(5) and applies across paragraphs 1 to 4. The information required must be provided "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", and must conform to applicable accessibility requirements. In practice, this means the disclosure must happen at the start of a chatbot conversation, on first exposure to a synthetic image, on first playback of AI-generated audio, and so on. Timing is not a detail; it is part of the obligation.

Obligation 1: Disclose when people are talking to AI (Article 50(1))

Article 50(1) requires that any AI system designed to interact directly with natural persons must inform them that they are interacting with an AI, unless it is obvious to a reasonably well-informed, observant and circumspect person in context. Read alongside Article 50(5), the information must be clear, distinguishable, and provided at the latest at the time of the first interaction.

For marketing teams, this means:

  • Website chatbots must identify themselves as AI at the start of the conversation, not buried in terms and conditions, not in small print, but clearly and immediately.
  • AI voice assistants handling inbound or outbound calls must disclose that they are AI, not human agents.
  • AI-powered email or messaging responses must be identifiable as AI-generated where the recipient could reasonably believe they are communicating with a person.

This is not a best-practice recommendation. It is law, enforceable from 2nd August 2026 onwards.

Where the obligation lands. If you build your own chatbot or voice solution, the disclosure obligation falls on you to implement. If you use a provider like VerbaFlo, the provider carries the primary responsibility for designing the system to meet Article 50(1), but you still need to ensure you have not overridden or obscured those disclosures in your implementation.

Three points that cut against the obvious reading. The Commission's Guidelines make some things clearer than the plain text of the Article suggests.

  • The obviousness exception is narrow. A friendly persona name attached to a human-sounding voice makes an AI interaction less obvious rather than more, so an assistant called "Sarah" with a natural British voice actually raises the disclosure bar rather than lowering it. Teams tend to treat a persona as a neutral branding decision, and it is not one.
  • Disclosure must be in the language of the interaction. A multilingual assistant that answers a Spanish enquiry in Spanish, but discloses only in English, fails in substance while appearing to comply. If you can answer in a language, you can disclose in it.
  • Not everything is in scope. The obligation applies where a system is designed for a genuine two-way exchange, and where the AI communicates directly with the person rather than through a human intermediary. Agent-assist tools, where AI drafts and a human reviews before sending, arguably fall outside it. One-way broadcast notifications arguably do too. This matters when you are working out which of your tools are actually caught by Article 50(1), rather than assuming all of them are.

Outbound calling is the harder case. Most commentary on Article 50(1) focuses on inbound chatbots, where the visitor initiated the conversation and has some context for it. Outbound automated calling, for payment reminders, lost-lead re-engagement, or deposit chasing, is a harder case, because the recipient did not initiate the conversation and has no context for it at all. A late or ambiguous disclosure on an outbound arrears call is probably the most exposed thing in a typical operator's stack. It is also worth flagging in passing that automated outbound calling engages PECR in the UK and national ePrivacy rules in the EU, on top of Article 50. That is a separate regime and we will not pull it into scope here, but a reader ought to know it is there.

Obligation 2: Mark AI-generated content in a machine-readable format (Article 50(2))

Article 50(2) requires providers of AI systems that generate synthetic audio, image, video, or text content to ensure those outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. The technical solutions must be effective, interoperable, robust, and reliable to the extent technically feasible.

Note the word, providers. This obligation sits with the company that built the AI system, not with the marketing team using it. If you use an AI image generator to create marketing visuals, it is the provider of that tool who must embed machine-readable markers, using techniques such as C2PA metadata or watermarking, identifying the content as AI-generated.

The Article itself carves out two situations where 50(2) does not apply: where the AI performs an assistive function for standard editing, and where it does not substantially alter the input data or its semantics. In practical terms, tidy-up use of AI on copy a person has written, or minor colour correction on a real photograph, will usually fall inside that carve-out. Generating a scene from a text prompt does not.

Timing for voice deserves its own note. For generative systems already on the market before 2 August 2026, the marking duty applies from 2 December 2026. That is four months from 2nd August 2026. The Code of Practice's expectations for synthetic audio are the most demanding in this area: multi-layered marking using at least two techniques, with signed metadata alongside a watermark robust to compression and format conversion. For any operator running AI voice, this is a live deadline rather than a footnote, and it is worth putting to your voice vendors now.

Deployers are not entirely off the hook. If you strip, alter, or fail to preserve those markers when publishing AI-generated content, you undermine the transparency the regulation is designed to protect, and you expose your organisation to risk. In practice, this means checking that your publishing workflows, image compression, CMS uploads, and social media pipelines, do not silently discard the metadata your provider embedded. This is the unglamorous part of compliance, and the part most likely to fail silently.

A relief worth knowing about. Content generated before 2 August 2026 does not require retroactive labelling, although the Commission encourages it. If you have an archive of AI-generated imagery from 2024 or 2025, you do not need to go back through it, though it is a defensible thing to do where the archive is small and the images are still in active use.

Obligation 3: Disclose deepfakes and AI-generated text on matters of public interest (Article 50(4))

Article 50(4) contains two separate duties, both on deployers, and it is worth reading closely because most commentary conflates them or misplaces them elsewhere in the Article.

The first duty applies to deployers of AI systems that generate or manipulate image, audio, or video content constituting a deep fake. They must disclose that the content has been artificially generated or manipulated. A deep fake is content that "appreciably resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful". For content that is evidently artistic, creative, satirical, fictional, or analogous, the disclosure is limited to what is appropriate without hampering enjoyment of the work.

The second duty applies to deployers of AI systems that generate or manipulate text published with the purpose of informing the public on matters of public interest. They must disclose that the text has been artificially generated or manipulated, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication.

The deployer deepfake duty is the point most likely to surprise a marketing team. The Commission's Guidelines are explicit that deployers cannot rely on the provider's machine-readable marking to satisfy their own disclosure obligation under Article 50(4). Deployer disclosure has to be understandable and perceivable by people, which means a visible or audible label, without anyone needing a technical tool to find it.

For PBSA and BTR marketing, that changes the instruction materially. AI-rendered interiors of rooms that do not yet exist, presented as photography on a listing page, meet the deepfake criteria fairly clearly: resemblance to something that exists or could plausibly exist, and a false appearance of being authentic. On that reading, they need a human-visible label on the page, not just preserved metadata. Telling a marketing director to check that their CMS is not stripping C2PA data is useful. Telling them their AI-staged room shots need a visible label is the thing that changes their workflow, and it is the point on which a careful reading of the draft guidance can lead you to think you are compliant when you are not.

Honest virtual staging, clearly labelled as such, is exactly what the Act anticipates and is not problematic. AI-generated images presented as real photography, without a label, are.

On AI-generated text, the picture is narrower than commonly reported. The provider-side marking duty under Article 50(2) applies to text, and the deployer disclosure duty under Article 50(4) applies to text published to inform the public on matters of public interest. Most marketing output, listing descriptions, email campaigns, promotional social posts, exists to let rooms rather than to inform public debate, and sits outside the second duty.

The Commission's Guidelines, however, read "matters of public interest" more broadly than the phrase suggests on first reading. They include consumer safety, and economic, financial, political, scientific, or cultural developments that may be a relevant subject of public debate. Rent and affordability commentary, cost-of-living guidance, supply and demand market reports, and joint thought leadership on regulation sit closer to that line than a strict "we're just marketing" reading allows. Both of our organisations publish that kind of content, and this article is arguably an example of it.

The human review carve-out is also a higher bar than casual reading suggests. Human review means deliberate examination of the substance by someone with relevant knowledge and professional judgement; superficial or purely formal checks such as spell-checking do not qualify. Editorial responsibility means a named person holds ultimate legal responsibility for publication. Most professional marketing teams already work this way, but already doing it and being able to demonstrate it are different claims, and only the second one helps under scrutiny. A named editorial responsibility line at the foot of a published piece, of the kind we have added to this one, costs nothing and demonstrates the practice rather than only describing it.

A separate obligation people mistake for a marketing rule: Article 50(3)

Article 50(3) is not a marketing content obligation at all, but it is worth understanding because it sits inside the same Article and because the underlying technology sometimes turns up in marketing and sales stacks by accident.

Article 50(3) requires deployers of emotion recognition systems and biometric categorisation systems to inform the people exposed to them, and to process personal data in accordance with GDPR and related instruments. Where a system infers emotions or intentions from biometric data, meaning voice characteristics, prosody, or the audio signal itself as distinct from transcript text, it is an emotion recognition system, and the disclosure obligation applies. Text-only sentiment scoring on chat transcripts is likely outside the definition, since the definition turns on biometric data.

The higher-severity point in this area is not a transparency one, however. Emotion recognition in workplaces and education institutions is prohibited outright under Article 5(1)(f), and has been since 2 February 2025. An operator using call sentiment analysis to assess its own leasing agents would be in prohibited territory, at the 7 per cent or EUR 35 million level, rather than facing a disclosure failure. This sort of capability tends to get bought without anyone asking the question, and it is worth asking.

The Provider-Deployer Distinction: Who Is Responsible for What?

One of the most important things for marketing teams to understand is the provider-deployer relationship under the AI Act. This is not a simple "the vendor handles it" situation.

Providers (companies like VerbaFlo that build and supply AI systems) are responsible for:

  • Designing systems that inform users they are interacting with AI (Article 50(1)).
  • Ensuring AI-generated outputs carry machine-readable markers (Article 50(2)).
  • Building technical solutions that are effective, interoperable, robust, and reliable.

Deployers (companies like Homes for Students that use AI systems in their operations) are responsible for:

  • Ensuring the AI system is used in accordance with its intended purpose.
  • Not overriding or obscuring transparency features that the provider has built in.
  • Applying human-perceivable labels where they generate or manipulate content constituting a deep fake (Article 50(4), first subparagraph).
  • Disclosing AI-generated text published to inform the public on matters of public interest, unless the human review and editorial responsibility carve-out applies (Article 50(4), second subparagraph).
  • Informing exposed persons where they deploy emotion recognition or biometric categorisation systems (Article 50(3)), on top of GDPR obligations.
  • Ensuring disclosures are timely, clear, distinguishable, in the language of the interaction, and accessible (Article 50(5)).
  • Maintaining their own compliance documentation.

In practice, this means marketing teams cannot simply point to their AI vendor and say "they handle compliance." You need to understand what your tools do, how they implement transparency, and whether your specific use case introduces additional obligations.

For PBSA and BTR operators specifically, the deployer obligations are significant. You are the ones publishing AI-generated property images on your website and social channels. You are the ones deploying chatbots on your leasing pages. You are the ones sending AI-assisted email campaigns to prospective residents. The compliance responsibility flows through your organisation, even when the underlying AI is provided by a third party.

The Part of the Stack That May Not Be "Limited Risk" at All

If you take one thing from this article beyond Article 50 itself, take this. The part of an operator's stack most likely to be regulated is not the leasing chatbot. It is the screening and referencing layer sitting behind it.

Annex III, point 5(b) covers AI systems used to evaluate the creditworthiness of natural persons or establish credit scores, whether or not the system makes the final decision. Financial fraud detection is carved out; general affordability and creditworthiness scoring is not. These are high-risk systems, and Article 27 requires deployers of Annex III point 5(b) and 5(c) systems to complete a Fundamental Rights Impact Assessment before use.

Whether BTR affordability checking and PBSA guarantor referencing fall inside Annex III point 5(b) is arguable rather than settled, and models differ enough that a single answer would be wrong for every operator. What we would say with confidence is this: where any part of the referencing chain runs through a third party that uses AI to score, rank, or evaluate applicants, the classification question is live. The application date for Annex III standalone systems has moved to 2 December 2027, so there is some breathing space, but the classification question is one to answer in 2026, not in late 2027.

Marketing teams do not usually own referencing. They often do own the vendor relationships that sit alongside it, and they are frequently the internal function that first notices when a supplier's product description includes phrases like "AI-powered affordability scoring". That is the moment to route it into whoever handles high-risk AI classification for the organisation.

Case Study: What Compliance Looks Like in Practice

This example is illustrative, drawn from typical operator configurations. It is not a description of any specific deployment.

Consider a PBSA operator running AI across its marketing and leasing funnel: a conversational AI platform handling enquiries across web chat, WhatsApp, email, and voice, alongside AI-assisted content production for listings and campaigns. Here is how each Article 50 obligation lands in practice.

  • Chatbot disclosure, Article 50(1) with 50(5). Every conversation opens with a clear statement, in the language of the interaction, that the prospective student is speaking with an AI assistant, before the substantive exchange begins. The disclosure appears on every channel, and where a conversation is handed to a human agent, that transition is signalled too. Building the disclosure into the platform, rather than adding it operator-by-operator, makes it much harder to lose during a website refresh or forget when a new channel is added, though good implementation still requires the deployer to check nothing has been overridden in configuration.
    • This is compliance engineered into the workflow, rather than compliance by memo, and it matters because the obligation applies per interaction, not per policy document.
  • Content generation, Article 50(2) and Article 50(4). Property descriptions and campaign copy are drafted with AI, then reviewed, edited, and approved by a named marketing owner before anything is published. Machine-readable marking of generated output is the provider's responsibility under Article 50(2). Genuine editorial control by a named individual keeps the operator inside the human-review carve-out to the Article 50(4) public-interest text duty, and the approval step is logged so the operator can demonstrate editorial responsibility rather than merely assert it.
  • AI-rendered visuals and deep fake labelling. Where the operator uses AI to render interiors of rooms not yet built, or to visualise concepts that a viewer might mistake for a photograph, a human-visible label is applied on the page ("AI-generated visualisation", or similar), in addition to the machine-readable markers embedded by the provider. Real photography lightly enhanced by AI (colour correction, spot repair) falls within the standard-editing carve-out and is not treated as a deep fake.
  • Preserving markers. The publishing workflow is checked so that image compression, CMS uploads, and social scheduling tools do not strip the machine-readable markers embedded in AI-generated visuals.
  • Records. Conversation logs, disclosure timestamps, and content approval trails are retained. If a regulator, or an investor's due diligence team, asks how the operator complies with Article 50, the answer is a report rather than a scramble.
  • On the cost of disclosure. Disclosure adds a line to every opening message, and it would be dishonest to pretend that costs nothing at all. What we can say is that the cost is small, measurable, and worth stating openly, and that operators are much better served by knowing the number than by being told there is no trade-off at all. Enquiries are still answered at two in the morning in the applicant's own language; the difference is that transparency is engineered into the workflow rather than bolted on afterwards.

The GDPR Intersection: Data Processing Meets AI Transparency

Article 50 does not operate in isolation. For marketing teams, the most important intersection is with the General Data Protection Regulation (GDPR), which has been in force since 2018 and applies to all personal data processing.

AI systems that process personal data, which includes chatbots capturing lead information, voice AI recording conversations, and data analytics tools profiling prospective residents, must comply with both the AI Act and GDPR simultaneously. These are complementary, not competing, regulatory frameworks.

Key GDPR intersections for marketing AI:

  • Lawful basis. You need a lawful basis (typically legitimate interest or consent) for processing personal data through AI systems. A chatbot that captures a prospect's name, email, phone number, and accommodation preferences is processing personal data.
  • Special category data (Article 9). A leasing chatbot does more than collect names and email addresses. Accessible-room requests, wellbeing check-ins, and financial hardship conversations all generate health and vulnerability data, at volume, in the middle of a leasing season. Article 9 requires more than legitimate interest, and a chatbot capturing an accessibility requirement is processing special category data whether or not anyone designed it to. Route it through the same lawful-basis and safeguards analysis you would for any special category processing.
  • Minors. First-year student applicants routinely include 17 year olds, and parent guarantors bring a second data subject into the same conversation. The ICO's Age Appropriate Design Code applies to services likely to be accessed by children, and Article 5(1)(b) of the AI Act prohibits exploiting age-based vulnerability. For PBSA operators this is a core case rather than an edge one.
  • Data subject rights. Individuals have the right to know how their data is processed, including whether AI is involved in decision-making. This aligns with the AI Act's transparency obligations.
  • Automated decision-making. Article 22 of GDPR restricts solely automated decision-making that produces legal or similarly significant effects. If your AI system makes or influences leasing decisions, for example automated pre-qualification, additional safeguards apply, and any such system is also a candidate for the high-risk classification discussed earlier.
  • Data Protection Impact Assessments (DPIAs). AI systems that process personal data at scale, particularly when combined with profiling, may require a DPIA under GDPR.
  • International data transfers. If your AI provider processes data outside the EEA (cloud servers in the US, for example), GDPR's transfer rules apply alongside the AI Act.

For PBSA and BTR operators, the data processing volume is substantial. A single property might handle thousands of enquiries per leasing season, each generating personal data that flows through AI systems. The combination of Article 50 transparency obligations and GDPR data processing requirements means compliance cannot be an afterthought.

Enforcement: There Is No One-Stop-Shop

This is the structural point most likely to catch out an operator whose mental model has been shaped by GDPR.

Article 50 is enforced primarily by national market surveillance authorities, one per Member State, with the AI Office at EU level playing a coordinating role and a directly competent role only in narrow cases (broadly, where the same entity provides both the model and the system, or where the system sits inside a designated very large online platform or search engine). There is no lead-authority mechanism of the kind GDPR provides through the one-stop-shop.

For a portfolio spanning UK and European cities, that means answering to national regulators, plural, with no single point of contact and no consistency mechanism. Documentation matters more in this environment, not less, because it is the thing that scales across multiple regulators asking similar questions in different languages.

Beyond Real Estate

Article 50 applies across every sector that uses AI in marketing and customer engagement. The principle is consistent: if your organisation deploys AI systems that interact with people or generate content, Article 50 applies to you regardless of sector. Adjacent regimes (MHRA and CQC for health, FCA for financial services, consumer protection law for retail, the ICO's Age Appropriate Design Code for services likely to be accessed by children) sit on top of, rather than instead of, the AI Act.

What About the UK?

This article focuses on the EU AI Act, but most of the companies reading it will be UK-based. So the obvious question is: does any of this apply to UK-based companies?

The short answer is: not directly, if you operate exclusively in the UK. The EU AI Act is EU law. Post-Brexit, the UK is a third country, and the regulation does not automatically apply to UK organisations serving only UK customers.

The longer answer is more nuanced.

Extraterritorial reach

Like GDPR before it, the EU AI Act has extraterritorial provisions. It applies to any provider that places an AI system on the EU market, regardless of where that provider is based. It applies to any deployer whose AI system outputs are used by persons located in the EU. If a UK PBSA operator markets to EU students, or a UK PropTech company serves EU clients, the relevant AI activity falls within scope. This is the same mechanism that made UK companies comply with GDPR even after Brexit: if you touch EU residents, you play by EU rules.

UK domestic regulation

For purely UK operations, the regulatory landscape is different but not absent. The UK GDPR and the Data Protection Act 2018 remain in force and apply to all personal data processing, including AI-driven processing. The ICO has published specific guidance on AI and data protection, and has enforcement powers over automated decision-making under Article 22 of UK GDPR. A private member's AI Regulation Bill has been introduced in Parliament, and the government's stated approach is a principles-based framework overseen by existing sectoral regulators (Ofcom, FCA, CMA, ICO) rather than a single horizontal AI law. The approach is deliberately lighter-touch than the EU's, but it is not a regulatory vacuum.

Practical convergence

In practice, many UK organisations will adopt EU AI Act standards as a compliance baseline, even where not strictly required. This is pragmatic: if you operate across borders, it is simpler to meet one standard than to maintain separate UK and EU compliance tracks. It is also strategic: the EU AI Act is becoming the global reference point for AI regulation, much as GDPR became the global reference point for data protection. Organisations that build to EU standards now are building for where regulation is heading, not just where it currently sits.

For UK marketing teams specifically, the practical advice in this article applies regardless of jurisdiction. Disclosing when customers are interacting with AI, applying human-visible labels to AI-rendered visuals that could pass for photography, preserving metadata markers on AI-generated content, maintaining human review processes for AI-assisted copy, and documenting your AI tooling are good practices everywhere. They build trust with your audience. They reduce your regulatory risk as UK regulation catches up. And they ensure you are ready if your organisation expands into EU markets.

The EU AI Act may not be your law today. But its principles are becoming the language of responsible AI use globally, and the organisations that understand that first will be the ones best positioned when the regulatory landscape inevitably shifts closer to the EU model.

Penalties for Non-Compliance

The EU AI Act carries significant financial penalties, enforced primarily by national market surveillance authorities with a coordinating role for the AI Office at EU level. The structure escalates with the seriousness of the violation (Article 99):

  • Prohibited AI practices (Article 5): up to EUR 35 million or 7% of global annual turnover, whichever is higher.
  • High-risk system violations: up to EUR 15 million or 3% of global annual turnover.
  • Article 50 transparency violations: up to EUR 15 million or 3% of global annual turnover.

Article 5 sits at the top of the scale for a reason. Emotion recognition in workplaces and education institutions, the case flagged earlier, is a category-one exposure, not a transparency question.

The phased implementation timeline means there is no "we're still getting ready" defence available for provisions that are already in force.

What Marketing Teams Should Do Now

This is not a compliance checklist for lawyers. It is a practical action list for marketing teams that need to understand their exposure and take reasonable steps.

  1. Audit your AI tools. List every AI tool your marketing team uses: chatbots, voice assistants, content generators, image generators, data analytics platforms, personalisation engines. For each one, determine whether it falls under Article 50(1) (human interaction), 50(2) (content generation), 50(3) (emotion recognition or biometric categorisation), or 50(4) (deep fakes or public-interest text), and note whether adjacent Annex III classifications may apply.
  2. Check your providers. For each AI tool, ask the provider how they implement Article 50 transparency. Do they build in AI disclosure for chatbot interactions, in the language of the interaction? Do they embed machine-readable markers in generated content? For voice, are they meeting the multi-layered marking expectation, and are they ready for 2 December 2026? If they cannot answer these questions clearly, that is a red flag.
  3. Ask about the Code of Practice. Is the vendor a signatory to the Commission's Code of Practice on Transparency of AI-generated Content, and if not, how do they demonstrate compliance? Signatories can rely on the Code regardless of where they are established or which supervisory authority is competent, which gives them a degree of legal certainty. Vendors who have declined have to demonstrate compliance by other means and can expect more requests for information from national regulators.
  4. Review your published content. Look at your website, social channels, email campaigns, and printed materials. Identify content that is AI-generated or AI-assisted. For text content, determine whether the human review carve-out to Article 50(4) applies, and be prepared to demonstrate it. For images and video, verify that machine-readable markers are present and preserved, and that AI-rendered content that could pass for photography carries a human-visible label.
  5. Implement disclosure where needed. If your chatbots do not currently identify as AI on first interaction, in the interaction language, fix that now. If your AI-generated images do not carry metadata markers, work with your provider to implement them. If AI-rendered visuals on your listings do not carry a visible label, add one. If you publish AI-generated text on matters that could be read as public interest, ensure genuine human review with a named editorial owner.
  6. Look past the chatbot to the referencing layer. Where any part of your affordability checking, credit scoring, or guarantor referencing chain uses AI, route the Annex III point 5(b) classification question through whoever handles high-risk AI in your organisation. Article 27 Fundamental Rights Impact Assessments apply if it lands inside Annex III.
  7. Document your compliance approach. Regulators expect organisations to demonstrate compliance, not just claim it. Document which AI tools you use, how you implement transparency, what human review processes exist for text content, and how you handle data processing under GDPR. In a multi-market operation, remember there is no lead authority, so documentation needs to work for national regulators, plural.
  8. Train your team. AI literacy is a binding requirement under Article 4 of the AI Act, in force since 2 February 2025 and applying to both providers and deployers. Your marketing team should understand the transparency obligations, not just the capabilities of the AI tools they use.
  9. Build compliance into procurement. When evaluating new AI tools, make Article 50 compliance a procurement requirement, not an afterthought. Ask vendors for their AI Act compliance documentation, and specifically their Code of Practice position, as part of the evaluation process.

The Bigger Picture

The EU AI Act is not a reason to stop using AI in marketing. It is a reason to use it thoughtfully. The transparency obligations in Article 50 are designed to build trust, not create barriers. When a prospective student knows they are talking to a chatbot, they can adjust their expectations accordingly. When an AI-rendered room shot is labelled as such, the applicant can evaluate it with that context. When AI-generated imagery carries proper metadata and public-interest text carries proper attribution, the industry maintains its credibility.

The organisations that treat compliance as a competitive advantage, rather than a regulatory burden, will be the ones that earn and retain trust in an AI-mediated world. That is true in PBSA, it is true in build-to-rent, and it is true in every other sector where AI is reshaping how organisations communicate with the people they serve.

The EU AI Act is here. Article 50 is enforceable from 2nd August 2026 onwards.

The question for marketing teams is not whether to comply, but how quickly they can get there.

Written by David Chadderton & Sayantan Biswas.

Editorial responsibility for the publication of this article is held by David Chadderton, Chief Marketing Officer, Homes for Students.

David Chadderton is the Chief Marketing Officer at Homes for Students, VervLife, and Orla, overseeing marketing for over 60,000 PBSA, BTR, and Co-living beds and apartments across 60 UK and European cities.

Sayantan Biswas is the Founder and Chief Executive Officer at VerbaFlo, the AI communications platform for real estate operators, powering voice, chat, and multi-channel automation for PBSA, build-to-rent, and multifamily portfolios.

This article is for informational purposes only and does not constitute legal advice. Organisations should seek independent legal counsel for specific compliance requirements under the EU AI Act, GDPR, and applicable legislation in England and Wales, Scotland, and Northern Ireland.

Ready to hear it for yourself?

Get a personalized demo to learn how VerbaFlo can help you drive measurable business value.

Ready to hear it for yourself?

Get a personalized demo to learn how VerbaFlo can help you drive measurable business value.