Communication

AI Act Article 50: what changed for internal video

Article 50 of the EU AI Act applies from 2 August 2026. Why internal AI video is in scope, why a watermark is not enough, and what comms teams should do now.

Kirsten Brown
Kirsten Brown
17.8.2026
Reading time:
11 min read

What changed on 2 August 2026 for AI generated video?

Article 50 of the EU AI Act became applicable on 2 August 2026 (European Commission, 2026). From that date, any organisation deploying AI video that constitutes a deepfake has to disclose it to the people watching. Internal audiences are included. If your town hall features a synthetic version of your CEO, your employees have to be told.

That last sentence is the part most compliance summaries miss, and it is worth being precise about why.

Does Article 50 apply to video that only employees see?

Yes, where the video is a deepfake. The obligation does not depend on publication.

Read Article 50(4) closely and it has two separate limbs with two very different scopes (AI Act Article 50). The text limb applies only where AI generated text is "published with the purpose of informing the public on matters of public interest", and it comes with an exemption where a human reviewed the content and someone holds editorial responsibility. The deepfake limb, covering image, audio and video, has none of that. No publication requirement. No public interest test.

Two qualifications belong here rather than in the small print. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the obligation is not removed, it is narrowed: disclosure still happens, but in a manner that does not hamper the display or enjoyment of the work. Separately, the duty does not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences.

What actually counts as a deepfake?

This is the gate, and it is narrower than "made with AI". The Commission sets three cumulative criteria: the content resembles a person, object, place or event; that subject exists or could plausibly be taken to exist; and the result falsely appears authentic or truthful (European Commission Article 50 FAQ, 2026).

So a fully invented presenter over abstract motion graphics may fail the first two criteria and sit outside Article 50(4) altogether. A synthetic version of your named CEO passes all three comfortably. The third criterion is also where audience context enters, because the Commission points to the reasonably foreseeable audience and their expectations. An internal audience that already knows a given channel is AI produced changes that analysis. Note which way that cuts: it is an argument for setting the expectation openly and consistently, not for staying quiet and hoping.

The practical consequence is counter intuitive. An AI drafted intranet article about the new travel policy probably sits outside Article 50, because it is not published to inform the public on a matter of public interest. An AI generated video of your CEO delivering the same travel policy update, shown only on the intranet to 8,000 employees, sits inside it. Employees are natural persons. The Act does not carve out an internal audience.

This is also where the picture has moved since we last wrote about what the EU AI Act means for comms teams using AI video in June. That guide was written before the final Guidelines existed. Three things have landed since.

What did the Commission publish in July, and why does it matter?

The Commission published its final Guidelines on transparency of AI generated content on 20 July 2026, replacing the earlier draft, and an accompanying Article 50 FAQ (European Commission, 2026). The FAQ is the more useful document for practitioners, because it closes the loophole most vendors were implicitly relying on.

The Commission states that deployers "cannot simply rely on the machine-readable marking embedded in the content by the provider under Article 50(2) of the AI Act to fulfil their disclosure obligation" (European Commission Article 50 FAQ, 2026). Disclosure has to be "understandable and perceivable by natural persons (e.g. with visible or audible labels), without need for any specific technical tools or performing dedicated actions". And it has to happen "upon first exposure at the latest".

So an invisible watermark in the file metadata does not discharge the duty. Somebody watching the video has to be able to see or hear that it is AI generated, at the start, not in a footnote on a policy page.

Alongside the Guidelines, around 190 organisations signed the Code of Practice on Transparency of AI generated Content (European Commission, 31 July 2026). 82 signed Section 1 and 152 signed Section 2, and organisations can sign both, so the two lists overlap rather than partition. The Commission and the AI Board concluded the Code was adequate on 8 and 9 July 2026 respectively (Reed Smith, 2026). Deutsche Lufthansa AG is among the signatories, which is a useful signal that this is not a pure technology vendor conversation.

Why is the deployer, not the AI vendor, on the hook?

Because Article 50 splits the duties, and the visible one belongs to you.

The provider of the generative system carries the Article 50(2) obligation to mark outputs in a machine readable format. The deployer, meaning the organisation actually using the system to produce and distribute the video, carries the Article 50(4) obligation to disclose the content to the people who see it. Your video vendor cannot absorb this for you. In a large company the deployer is, in practice, the comms team that pressed publish.

There is one timing nuance worth putting in your plan. Generative systems placed on the market before 2 August 2026 have until 2 December 2026 for the Article 50(2) marking and detection obligations, with a further watermark interoperability date of 2 February 2027 (European Commission FAQ, 2026; Reed Smith, 2026). That grace period came in through the Digital Omnibus and it covers the provider side marking. It does not extend your disclosure duty, which applies now.

Nor is a broader delay coming. The Omnibus, agreed politically on 6 May 2026 and confirmed by the Council on 13 May, postponed the high risk obligations, moving Annex III to 2 December 2027 and Annex I to 2 August 2028 (Gibson Dunn, 2026). The Article 50 transparency obligations were left largely unaffected, the December grace period above being the one adjustment on this side. Article 50 breaches sit in the middle penalty tier of the Act at up to EUR 15 million or 3% of total worldwide annual turnover (AI Act Article 99).

What is Germany adding on top?

A named regulator and a place to send complaints, as of five days before Article 50 became applicable.

The KI-Marktüberwachungs- und Innovationsförderungs-Gesetz (KI-MIG) entered into force on 29 July 2026 (BMDS, 29.07.2026). It makes the Bundesnetzagentur Germany's national coordinator for the AI Act, gives it a market surveillance role, and sets it up as the central contact point with a KI-Service Desk and a complaints body. It builds on the existing sectoral market surveillance authorities rather than replacing them, so most companies keep their familiar counterparts. For a DACH comms team, the shift is that "who would even notice" now has an answer, and an employee who feels misled by an unlabelled AI video has somewhere to go.

Bitkom president Dr. Ralf Wintergerst noted at the end of July that companies have had little preparation time because the central guidelines and interpretive aids were published only recently (Bitkom, 31 July 2026). That is a fair characterisation. It is also not a defence.

Why the trust case is stronger than the compliance case

Here is the finding that should shape your policy more than the penalty tier does.

Only 34% of Germans trust their own ability to reliably identify a deepfake, while 89% consider deepfakes dangerous (Bitkom, "Social Media, Desinformation und Deepfakes", 25 June 2026, n=1,006). Awareness has climbed fast, from 56% in 2024 to 75% today, 61% say they have already encountered a deepfake, and 87% associate the format with video. Your employees are part of that sample. They think synthetic video is dangerous and they know they cannot spot it.

Put that next to the Commission's requirement for a human perceivable label and the two arguments converge. The regulator is asking for exactly the thing that protects the credibility of your leadership channel. An unlabelled AI CEO message that employees later identify as synthetic does more damage to internal trust than the label ever would have.

Meanwhile the capability is already deployed. 85.6% of DACH internal comms professionals use AI in their daily work and 92.3% see it as an opportunity for the function, yet 42.4% of those not using it say it is prohibited for operational reasons (Staffbase / SCM Trendmonitor Interne Kommunikation 2026, 14 January 2026, n=431). Adoption has outrun governance. The obligation has now landed on a function that was already using the technology without a policy for it.

How do comms teams make labelling actually happen?

By building the disclosure into the template rather than the checklist.

Carmen, the internal comms manager most of this applies to, is brought in late with urgent requests and works in a small team. A compliance step that depends on somebody remembering it under deadline pressure will fail, and it will fail on the highest profile video, because that is the one produced fastest. The fix is structural.

Classify before you produce. Draw the line by what the video contains, not by where it is published. Employee recorded footage where a real person speaks their own words is not a deepfake. A synthetic likeness or cloned voice of a real, named executive almost always is, because it meets all three criteria at once. A wholly invented presenter is the genuinely arguable case, and that is exactly the one to write down and decide once rather than case by case. AI dubbing sits in the middle and depends on whether the result presents as the original speaker; if the voice is cloned, treat it as in scope. Our note on how AI dubbing works in practice covers the mechanics.

Put the label in the template, not the workflow. An opening frame or a persistent on screen marker that renders automatically for every AI generated output satisfies "upon first exposure at the latest" without asking anyone to remember anything. This is what Brand Templates does at cofenster. During onboarding your brand rules are implemented into the product, and from that point every output from Theo (text to video) and Ella (guided employee recording) carries them by construction. A disclosure rule is a brand rule.

Log the classification. Keep a record of which videos were classified as in scope and why. When the Bundesnetzagentur or a works council asks, the useful artefact is the decision trail, not the video.

Give the Betriebsrat the policy early. In German co determination the works council will engage with synthetic likenesses of employees and executives. Arriving with a written labelling standard is a materially different conversation from arriving with a finished video.

Teams already repurposing recordings have an advantage here, because one town hall recording can carry weeks of content and real footage of real people needs no disclosure at all. The cheapest compliance strategy is often to keep humans on camera where you can, and reserve synthetic presenters for the cases where they genuinely earn their place.

Key takeaways

Internal video is in scope when it is a deepfake. The Article 50(4) deepfake limb has no publication and no public interest gate, unlike the text limb. Employees are natural persons.

Test against the deepfake criteria, not the word "AI". Resemblance, plausible existence, and a false appearance of authenticity. A synthetic named executive meets all three; an invented presenter over abstract graphics may not.

Machine readable marking is not enough. Deployers cannot rely on the provider's embedded marking. A visible or audible label is required, at first exposure.

The duty is yours, not your vendor's. Providers mark under 50(2), deployers disclose under 50(4). The comms team is the deployer.

Design the label in, do not bolt it on. Most DACH comms teams already use AI daily, so a manual compliance step will not hold under deadline pressure. Put the disclosure in the template.

Where cofenster fits

cofenster is the AI video platform for enterprise communications. Our AI Video Agents let Comms, HR, and Marketing teams produce on brand video at scale, and Brand Templates is the layer that makes a disclosure standard enforceable rather than aspirational. We are EU AI Act compliant, ISO 27001:2022 certified, and GDPR compliant, and we work with teams at Continental, Commerzbank, Hugo Boss, and Hermès on exactly this kind of governed video production.

If you want to see how a labelling rule behaves when it is baked into the template, book a live demo.

Frequently asked questions

Does the Code of Practice on transparency make us compliant?

No, signing is voluntary and it does not replace the legal obligation. It is a way of demonstrating a good faith approach to the requirements. Around 190 organisations signed ahead of the obligations taking effect, with 82 signing Section 1 and 152 signing Section 2 (European Commission, 31 July 2026). Organisations can sign both, so those lists overlap. Deutsche Lufthansa AG is among the signatories.

Do we need to label video of real employees speaking on camera?

No. Article 50(4) covers image, audio and video content that constitutes a deepfake, meaning artificially generated or manipulated content that falsely appears authentic. Genuine footage of a real person saying their own words is neither, so no disclosure obligation arises, regardless of whether the recording was made on a phone or in a studio. Standard editing such as trimming, colour grading, or captions does not convert authentic footage into a deepfake. This is one reason employee recorded video remains the lowest friction format for internal comms.

What does a compliant label actually look like on a video?

The Act does not prescribe a specific wording or design. It requires disclosure that is clear, distinguishable, understandable and perceivable by natural persons without technical tools, made upon first exposure at the latest (European Commission Article 50 FAQ, 2026). In practice that means a visible on screen statement such as "This video was generated with AI", shown at the opening of the video or persistently in frame, or an equivalent audible statement. A note buried in a description field or a policy page does not meet the first exposure standard.

Does the works council need to be involved?

In Germany, plan for it. Synthetic likenesses of employees or executives touch co determination interests, and a works council will reasonably want to know how AI generated video is classified, labelled, and stored. Nothing in Article 50 creates that obligation, it comes from German co determination law, but the two interact. Bringing a written labelling standard to the conversation early is a materially easier path than seeking approval for a finished synthetic video after the fact.

Photo by Sam McGhee on Unsplash

See what governed AI video looks like

Brand Templates puts your disclosure rule inside the template, so every AI generated output carries it automatically.

Book a live demo
Kirsten Brown
Kirsten Brown
Revenue Operations Automation Lead

Frequently asked questions

Does AI dubbing of an internal video trigger Article 50?

It depends on the output. If the dubbing produces a cloned voice that presents as the original speaker, treat it as manipulated audio content within the Article 50(4) deepfake limb and disclose it. If the result is an obviously separate narration track or subtitles, the deepfake analysis does not bite in the same way. Because the deepfake limb has no public interest gate, the safer default for internal leadership content is to label cloned voice output at first exposure.

What happens on 2 December 2026?

That is the end of the Article 50(2) grace period for generative AI systems placed on the market before 2 August 2026 (European Commission FAQ, 2026). Those systems get until 2 December 2026 to comply with the machine readable marking and detection requirements, with a further interoperability date of 2 February 2027. It does not delay your deployer disclosure duty under Article 50(4), which has applied since 2 August 2026.

Who enforces Article 50 in Germany?

The Bundesnetzagentur. The KI-MIG entered into force on 29 July 2026 and names it Germany's national coordinator and central contact point for the AI Act, with a market surveillance role, a KI-Service Desk and a complaints body (BMDS, 29.07.2026). It builds on the existing sectoral market surveillance authorities rather than replacing them. AI Act penalties themselves sit under Article 99, where Article 50 breaches fall in the tier of up to EUR 15 million or 3% of total worldwide annual turnover.

More from cofenster

Internal communications manager desk with laptop by a window in natural light
Communication

Comms debt: the hidden cost of unexplained change

Comms debt is the backlog of change you announced but never explained. What it costs, and how to pay it down.

Read more
All categories
Two colleagues talking in a modern office hallway, illustrating the workplace grapevine
Communication

Why the workplace grapevine beats your internal comms

Why official internal comms keeps losing to the grapevine, and the 2026 data-backed case for fast, human video that reaches employees before the rumor does.

Read more
All categories
Diverse international team collaborating on laptops during a multilingual internal communications meeting
Communication

Multilingual internal communications that reach everyone

One message, produced on-brand in every language your workforce actually speaks. Why native-language video, not just translated text, closes the comprehension and engagement gap.

Read more
All categories

Make videos that do more.

Our world is more connected than ever, yet many people say they feel a lack of connection.

Schedule demo
Three young people outside smiling into the camera
By clicking “Accept all”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.