When Transparency Meets the Player Journey: How Article 50 of the EU AI Act Is Reshaping iGaming
Article 50 of the EU AI Act is the transparency layer: it asks whether people can tell they are dealing with AI, whatever the system’s risk classification. For iGaming operators, it lands right on top of how the player journey already works: chatbots, AI marketing, generated visuals, personalized offers. Applicable from 2 August 2026.
Why iGaming feels this one more
Article 50 covers four obligations: AI that interacts directly with people, AI that generates or manipulates content, emotion recognition and biometric categorization, and deepfakes and public-interest text. In iGaming, these are not an edge case in the tech stack, they ARE the customer journey.
The four areas that Article 50 impacts
- Chatbots. Support bots, onboarding assistants, win-back agents, VIP hosts: Article 50(1) generally requires a clear “I’m a machine” at first contact, in plain language rather than buried in terms and conditions. The “obviously artificial interaction” exception isn’t always a free pass and where the context is sensitive or the audience includes vulnerable users, a single notice at the start of the session may not be enough: periodic reminders may be expected. Complaints handling, financial discussions and safer-gambling conversations can all sit in that zone.
- Marketing. Banners, offers, push-notifications, promo emails: the use of AI for these purposes does not, in itself, give rise to a general disclosure or labelling obligation under the AI Act. Under Article 50(4), deployers must disclose AI-generated or manipulated images, audio or video content constituting a deepfake, and the assessment is objective: the absence of any intention to mislead is irrelevant. AI-generated text must be disclosed only where it is published for the purpose of informing the public on matters of public interest; commercial copy generally sits outside that limb, but claims relating to health, consumer safety or sustainability are carved out, placing safer-gambling messaging closer to the line than a bonus email. Separately, the machine-readable marking of generative outputs under Article 50(2) is the responsibility of the provider of the tool, not of the operator publishing the campaign. And a deployer cannot rely on that marking to satisfy Article 50(4), since it is not perceivable to the audience.
- Personalization. Using AI to decide which bonus, game or email a player receives does not trigger disclosure on its own. The obligation begins when the AI interacts directly with the player. Compliance with Article 50 says nothing about lawfulness, though, systems may still be prohibited under Article 5, which bans AI exploiting vulnerabilities arising from age, disability or socio-economic situations.
- Synthetic media. Synthetic brand ambassadors or digitally altered hosts may qualify as “deepfakes” where the output appreciably resembles someone who exists or could plausibly exist and could pass as authentic.
As a rule, deepfakes must be clearly disclosed; a lighter regime applies for evidently artistic, creative or fictional work, read strictly. Where a deepfake forms part of evidently artistic, creative, satirical, fictional or analogous work, disclosure is limited to what is appropriate and does not hamper display or enjoyment of the work. Content recognizable as commercial is excluded, and where a piece mixes creative and informative character, the informative character prevails.
Where AI-generated or manipulated text is published with the purpose of informing the public on matters of public interest, deployers must disclose that it has been artificially generated or manipulated. No label is required where two conditions are both met: human review or editorial control, and editorial responsibility as defined under the AI Act. Superficial checks such as spell-checking do not qualify, and any substantive AI intervention after editorial sign-off voids the exception.
The distinction that decides what you are fined for
Are you the provider or the deployer? Providers carry the interaction disclosure (Article 50(1)) and the machine-readable marking of generative outputs (Article 50(2)). Deployers carry the notice for emotion recognition systems (Article 50(3)) and the visible labelling of deepfakes and public-interest text (Article 50(4)). A business that integrates a third-party AI system generally remains a deployer, unless it substantially modifies the system and puts it into service under its own name.
The practical path, and the cost of getting it wrong
On 20 July 2026 the European Commission published Guidelines on transparency obligations, ahead of the obligations imposed by Article 50 becoming applicable on 2 August 2026.
These guidelines clarify these obligations, providing legal certainty about the scope and complementing the Code of Practice on transparency of AI-generated content.
Adhering to the Code of Practice is voluntary, but for signatories, enforcement authorities will focus on whether the measures in the Code have been implemented. Those who do not wish to sign it remain free to show compliance by other adequate means.
Breaching Article 50 can cost up to €15 million or 3% of global turnover, whichever is higher. Cross into Article 5’s prohibited practices and the ceiling rises to €35 million or 7%.
Three things worth sitting with
Content created before 2 August 2026 does not have to be labelled retroactively, though for text on matters of public interest, what matters is when it was published, not drafted.
Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the Article 50(2) marking obligation.
Systems placed on or after 2 August 2026 do not benefit from the afore-mentioned extension.
The bottom line
Before 2 August 2026:
Know where AI is being used: For each system, identify whether you’re a provider or deployer, which Article 50 duties apply, and when it was launched or put into service.
Roll out transparency measures now: Check every player-facing AI touchpoint and confirm disclosures are ready before 2 August 2026. This means telling users when they’re dealing with AI, and labelling deepfakes and other content covered by Article 50.
Set up governance: Update supplier contracts to spell out who owns Article 50 compliance, put internal AI policies in place, and assign clear ownership across legal, compliance, tech and business teams. Build in regular audits and reviews so your transparency measures keep working as your AI systems change.
This material is for information only and does not constitute legal advice.