Quick Summary (TL;DR)
Article 50 requires transparency when interacting with AI. Pharma teams don’t need to label everything; they need a classification process to document human review and disclosure. Use this 10-minute triage guide to classify pharma use cases, manage disclosure risks, and document human review.
Contents:
Speak to Iguazu about an AI content & agent governance review
What is Article 50 and what does it mean for pharma teams?
Article 50 is the EU AI Act’s transparency framework: it sets rules for when people must be told they are interacting with AI, how certain AI-generated or manipulated content should be marked, and when synthetic media such as deepfakes or AI-generated public-interest text may need disclosure. It places different responsibilities on providers and deployers of AI systems.
From 2 August 2026, these obligations are live.
For pharma, the practical answer is not to put an “AI-generated” label on everything. Teams need to classify each use case: who provides and who deploys the system, whether a person is interacting directly with AI, what type of content is being generated or manipulated, and what meaningful human review takes place before publication.
THE KEY POINT: For many pharma workflows, existing review processes can become part of the control framework – but only when the review is substantive, documented and carried out by people with authority to change or reject the content.
Before you label anything: two questions
1. Are you the provider or the deployer?
The distinction matters because Article 50 puts different duties on each.
- Provider: Develops/commissions AI under their own name. Has full transparency duties.
- Deployer: Uses a third-party system professionally. Focuses on disclosure and human review.
A pharma company can be a deployer when it uses a third-party AI product, but it may become a provider if it commissions or launches an AI system under its own name. Agencies and technology suppliers can also sit at different points in that chain.
2. What is the AI actually doing?
Assess by use case, not tool. The same generative AI platform can create one output that needs a visible disclosure and another that does not.
| Scenario | Trigger | Action Required |
|---|---|---|
| HCP Chatbots | Direct Interaction | Disclose AI presence at first interaction. |
| Email/CLM Copy | Public Interest Text | Document substantive human review; skip labels. |
| Synthetic Media | Realistic Media | Disclose “AI-generated” at first exposure. |
| Assistive Editing | Standard Production | Classify as “Assistive”; no label needed. |
WHAT THIS MEANS:Â Article 50 should be assessed by use case, not by tool. The same generative AI platform can create one output that needs a visible disclosure and another that does not.
Deep-dive: four pharma scenarios – and what to do
Scenario 1: AI-assisted image editing and localisation
The Challenge: Tools like Photoshop now have Generative AI built-in. It can be hard to know when a quick touch-up crosses the line into “AI-generated content” that requires disclosure under Article 50. Not all AI edits are equal.
What to do: Create a clear dividing line for your design and localisation teams based on these three levels:
1. Level 1: Assistive Edits (No AI disclosure required)
What it is: Routine touch-ups, resizing, or enhancements that do not alter the core meaning, subject, or truthfulness of the image.
Pharma Examples:
- Using AI to extend a plain background (outpainting) so an image fits a new website banner dimension.
- Removing a stray hair, a distracting logo on a background extra’s shirt, or a blemish.
- Upscaling a low-resolution image or applying AI colour correction.
PRACTICAL ACTION: Proceed as normal. Standard MLR review applies, and no special AI transparency labels or metadata are needed.
2. Level 2: Substantial Generation (Machine-readable marking required)
What it is: Using AI to create or significantly alter the primary subjects, objects, or scenes in an image.
Pharma Examples:
- Generating a completely synthetic “patient” face for a disease awareness campaign.
- Using Generative Fill to change a stock model’s clothing to meet local market compliance (e.g., adding a lab coat or changing short sleeves to long sleeves).
- Generating scientific equipment or a clinic environment that wasn’t in the original photo.
PRACTICAL ACTION: Article 50(2) mandates that this content carries machine-readable metadata marking it as AI-generated (such as C2PA credentials). Ensure your design team is using enterprise tools that automatically embed these watermarks, and check that your web publishing workflow doesn’t accidentally strip this metadata out when compressing images.
3. Level 3: Potential Deepfakes (Clear, visible disclosure required)
What it is: AI content that realistically depicts a real person doing/saying something they didn’t, or portrays a synthetic but highly realistic medical event.
Pharma Examples:
- Using an AI dubbing tool to make a real Key Opinion Leader (KOL) appear to be speaking a different language with lip-syncing.
- Creating a photorealistic but entirely synthetic video of a “patient” experiencing a medical event (like a seizure or allergic reaction) for educational purposes.
PRACTICAL ACTION: You must add a clear, visible or audible disclaimer directly on the media itself (e.g., “AI-generated avatar” or “Simulated medical event generated by AI”).
PRACTICAL RULE OF THUMB FOR AGENCIES & TEAMS:
Tell your creators: “If you use AI to clean up an image, it’s fine. If you use AI to add something new or change the subject, you must flag it for an Article 50 transparency check.”
Scenario 2: An HCP chatbot on a brand or medical website
Disclose in the opening state (not the footer).
An HCP uses a website chatbot that provides answers based on approved product or medical information. The provider must ensure that users are clearly informed they are interacting with AI, unless it’s obvious, and this information should be provided by the first interaction.
PRACTICAL ACTION: Do not hide the disclosure in a privacy page or footer. Put it in the opening state of the chatbot, and make sure the vendor or development partner can evidence how Article 50(1) has been implemented.
EXAMPLE WORDING: “You are interacting with an AI assistant.” Add any medical-information, pharmacovigilance or escalation wording required by your own compliance process separately.
How does this work at Iguazu?
For a client chatbot, we would review the interaction design, first-use disclosure, source boundaries, escalation routes and the evidence retained from the technology provider. Unsure where to start with implementing Article 50?Â
Scenario 3: AI-assisted Approved Email or CLM
Add an “AI Provenance” field to your MLR workflow. Substantive review exempts you from generic labels.
A brand team uses AI to suggest subject lines, adapt approved content for emails, or create initial drafts of CLM (Customer Lifecycle Management) copy. These drafts then go through the standard medical, legal, and regulatory review process. However, this does not automatically require an “AI-generated” label. According to Article 50(4), the label is only necessary for AI-generated or manipulated text aimed at the public. The classification of each healthcare professional (HCP) communication depends on its context. If there is substantial human review and editorial responsibility involved, the communication may be exempt from the requirement of a visible AI label.
PRACTICAL ACTION:Â Do not add AI labels to every Veeva asset by default. Instead, add a simple AI provenance field to the job: where AI was used, what approved source material it used, who substantively reviewed the output, and who owns editorial responsibility.
WHY THIS IS USEFUL: It turns an existing MLR process into evidence rather than creating a completely separate AI approval bureaucracy.
Scenario 4: A virtual KOL, synthetic patient or cloned voice
Treat as high-risk. Disclose at first exposure. Ensure machine-readable marks are preserved.
A pharma marketing team produces an AI video featuring a real KOL seemingly saying something they never recorded, using cloned voices or manipulated footage that could be mistaken for authentic content. This qualifies as a deepfake under the AI Act.
When dealing with deepfake content, the deployer must ensure clear and noticeable disclosure that the content is artificially generated or manipulated, provided at first exposure. Additionally, while a machine-readable mark from the AI provider is required, it does not fulfil the deployer’s obligation for visible disclosure on its own.
EXAMPLE WORDING: “This video contains AI-generated or AI-manipulated content.” The exact wording and placement should be agreed with legal/compliance for the use case.
PRACTICAL ACTION: Treat voice cloning, digital replicas and realistic synthetic presenters as a separate creative-risk category. Make “deepfake assessment + disclosure” part of video QA before release.
One less-common use case worth mentioning:
If a platform uses AI to infer emotion or apply biometric categorisation – for example from facial, voice or behavioural signals – Article 50 has a separate requirement to inform the people exposed to that system. Other AI Act and data-protection restrictions may also apply, so this is a use case to escalate for specialist legal review rather than treat as a normal marketing feature.
The 10-minute Article 50 triage checklist for pharma teams
1. Define Role: Provider or Deployer?
Write down the legal entity that provides the AI system and the entity using it. If the system is commissioned or branded as your own, check whether your role changes.
2. Interaction: Is it direct? Disclose if yes.
If yes, check that the system clearly informs them they are interacting with AI no later than the first interaction, unless it is genuinely obvious.
3. Output: Is it text, image, audio? Check machine-readable marks.
If yes, identify the provider’s machine-readable marking approach and whether any Article 50(2) exception is relevant.
4. Deepfake Risk: Could the media be mistaken for an authentic person, object, place or event? Disclose if realistic.
If yes, perform a deepfake assessment and, where in scope, plan a clear visible or audible disclosure at first exposure.
5. Public Interest: Is AI-generated text being published to inform the public on a matter of public interest?
If yes, determine whether a visible disclosure is required or whether substantive human review/editorial control with editorial responsibility applies.
6. Provenance: Can you prove the decision later? Record the "Why" for compliance.
Record the use case, AI role, disclosure decision, reviewer, sources, supplier evidence and final owner. A policy without evidence will be weak in practice.
THE OUTPUT YOU WANT: A one-page decision record that tells a team “yes, you can use AI here – these are the controls”. Not a 60-page policy that nobody opens.
Three things pharma teams should create now
- AI Use-Case Register: Capture system, owner, role, and disclosure decision.
- Human-Review Record: Document reviewer, sources, and editorial responsibility.
- Transparency Pattern Library: Pre-approve disclosures and AI provenance fields.
Six questions pharma companies need to ask their AI suppliers
- Are you the “provider” of the AI system for EU AI Act purposes, or could our organisation become the provider because of how the system is branded or commissioned?
- How do you implement Article 50(1) disclosure for directly interactive AI systems?
- How are synthetic text, image, audio and video outputs marked in a machine-readable way under Article 50(2)?
- What happens to those marks when content is exported, compressed, transcoded or moved into our CMS, Veeva or production workflow?
- Have you signed the EU Code of Practice on Transparency of AI-generated Content, or how do you otherwise demonstrate compliance?
- What evidence can you provide to our legal/compliance team if the implementation is challenged?
The Code of Practice is voluntary, but the Commission and AI Board have assessed it as an adequate tool to help demonstrate compliance with Article 50(2), (4) and (5). Organisations that do not use the Code still need to demonstrate compliance by other adequate means.
The deadline for AI compliance in Article 50
Article 50 applies from 2 August 2026.
The Commission also describes a limited transition to 2 December 2026 for the Article 50(2) machine-readable marking obligation for certain generative AI systems already placed on the market before 2 August 2026. That is not a general four-month grace period for all Article 50 duties.
DON’T MAKE THIS MISTAKE: Do not assume chatbot disclosures, deepfake labels or public-interest text obligations can simply wait until December.
How Iguazu can help
The useful opportunity for pharma is not another generic AI policy. It is translating Article 50 into rules that fit the way marketing, medical, digital, Veeva, content production and agency workflows actually operate.
What to expect from AI content & agent governance review
- Comprehensive AI use-case inventory
- Decision matrix for providers and deployers
- Human review and editorial checklist
- Standardised disclosure and labelling guidelines
- Supplier and technology due diligence framework
- Operational SOP or playbook
Using AI-generated content, agents or HCP-facing AI?
References and further reading on Article 50: European Commission sources
Frequently Asked Questions (FAQs)
No. Article 50 is not a blanket labelling rule. Visible disclosure depends on the type of interaction or content and, for certain public-interest text, whether substantive human review/editorial control and editorial responsibility exist.
For systems designed to interact directly with people, the provider must design the experience so users are informed they are interacting with AI unless this is already obvious. The information should be clear and provided no later than first interaction.
Potentially, where Article 50(4) public-interest text is in scope. The Commission says human review must examine the substance using relevant knowledge and professional judgement; superficial or purely procedural checks do not count. Editorial responsibility must also sit with a person or legal entity.
Article 50(2) places that duty on the provider of the generative AI system. A pharma deployer should still verify what the provider does, preserve relevant evidence and assess whether its own role could make it a provider in a particular arrangement.
Build the use-case register, classify provider/deployer roles, identify the handful of use cases that trigger Article 50, and document the control pattern for each. That gives teams something operational immediately.
Not sure where to start implementing AI compliance? Ask the AI experts at Iguazu
Further reading
If you found this article helpful, explore these related resources to further future-proof your pharmaceutical marketing strategy:

The Future of Approved Emails in an AI-Driven Omnichannel World

When Platforms Start Learning: The Future of AI-Driven eLearning

The Best First AI Agent in Pharma Is Probably Boring

Humanising Pharma Communication: How AI Avatars Scale Engagement and Compliance
Howard Cairns
Director
About Iguazu: We are a digital agency specialising in delivering tactical marketing solutions to the healthcare and pharmaceutical industry.

