A note for readers outside the EU. This article is about the European AI Act. The United Kingdom does not apply that regulation, and neither do other non-EU countries. It is written for readers who deal with counterparts, customers or subsidiaries inside the European Union, or who place systems on the EU market, since that is where the obligations described here bite.
Since 2 August 2026, the transparency obligations of the EU AI Act (Article 50) have been in application. One question has been circulating in boardrooms ever since: do you have to warn a client, a supplier or an employee that an email was drafted with the help of AI? The answer is short, but it deserves an explanation, because the confusion comes from a text that says nothing at all about your emails.
⚖️ Quick answer: the AI Act creates no general obligation to disclose that a business email was written with AI. The duty to label generated text sits in Article 50(4), it falls on the deployer, and it only covers text published for the purpose of informing the public on matters of public interest. An email sent to a client, a supplier or an employee is not in that scope.
AI transparency and generated content: what Article 50 actually requires
Article 50 is not one obligation but three distinct ones, and they do not fall on the same people: informing a person that they are interacting with an AI system (Article 50(1), on the provider), marking synthetic outputs in a machine-readable format (Article 50(2), on the provider), and labelling certain disseminated content (Article 50(4), on the deployer).
That split between provider and deployer is the whole point. The provider develops an AI system and places it on the market under its own name. The deployer uses that system under its own authority, in the course of its professional activity. A company that rolls out a drafting assistant is, in this vocabulary, a deployer. It therefore does not inherit obligations written for providers, and the reverse is equally true.
What happened on 2 August, what falls due on 2 December
The European Commission notes in its FAQ on Article 50 that the transparency obligations have applied since 2 August 2026, to providers and deployers alike. One timing nuance sits on top: generative AI systems placed on the market before that date benefit from a four-month grace period, until 2 December 2026, for the machine-readable marking obligation of Article 50(2) only.
That December date is routinely presented as a deadline for user companies. That reading is wrong: Article 50(2) is addressed to system providers. If you use a drafting assistant, the question to put to your provider is whether it considers itself in scope of that obligation and what it has implemented, not how you are going to mark your own emails.
Under Article 99 of the regulation, breaches of Article 50 are subject to administrative fines of up to 15 million euros or 3 % of total worldwide annual turnover, whichever is higher. That ceiling applies to the operator bound by the obligation at stake, under the conditions set by the text, not to an executive sending an email.
Provider or deployer: the distinction that decides everything
| Provision | Who is bound | What is required | Your emails? |
|---|---|---|---|
| Art. 50(1) | Provider | Design systems intended to interact directly with natural persons so that those persons are informed they are dealing with an AI system, unless this is obvious from the context | No |
| Art. 50(2) | Provider | Mark synthetic outputs (text, image, audio, video) in a machine-readable format. Exceptions notably where the system performs an assistive function for standard editing or does not substantially alter the input data | No |
| Art. 50(4) | Deployer | Disclose that content has been artificially generated or manipulated, for text published to inform the public on matters of public interest. Exception where the content has undergone human review or editorial control and a person holds editorial responsibility | No for a private email |
Why a business email falls outside the scope
The Article 50(4) duty on text rests on two cumulative conditions: the text must be published, and it must be published for the purpose of informing the public on matters of public interest. The Commission places in that last category subjects such as politics, public administration, justice, fundamental rights, security, health and the environment.
A quote, a payment reminder, a reply to a complaint or a summary sent to three people meets neither condition. It is not published, and it is not addressed to the public. The honest answer to the question in the title is therefore no: there is no general obligation to mention AI in a business email.
The case worth examining. If the same text leaves the inbox to be published, on a website, in a press release or in an opinion piece, and it concerns a matter of public interest, then the Article 50(4) question does arise for your company as a deployer. The trigger is not the tool you used, it is publication.
An assistant that drafts is not a chatbot
The other common confusion concerns Article 50(1), which covers systems intended to interact directly with natural persons. This is a design obligation, on the provider, and it targets the direct exchange between the system and the person.
An assistant that prepares a draft submitted to its own user does not converse with the recipient of the email. The recipient gets a message sent by a person, not a conversation with a system. As for the user, opening an AI assistant is precisely the kind of obvious context the text refers to. The definitive characterisation depends on the system concerned and on how its provider designed it, which is a question to put to that provider.
Human review, a point of convergence
One detail of the text deserves an executive's attention. The Article 50(4) duty falls away where the generated content has undergone human review or editorial control and a person holds responsibility for it. In other words, the European legislator considers that content taken up, checked and owned by a human is no longer quite the same object as a raw machine output.
That is precisely how Neston works: the assistant proposes a reply based on your style and the context of the exchange, and a human always validates before sending. No email leaves without going through you. This is not a compliance argument, and it is not offered as one: Article 50(4) does not cover your business email in the first place. It is simply a convergence of logic, between a text that gives weight to owned human responsibility and a product built on the same principle.
Who enforces this, and where
The regulation is the same text in all twenty-seven member states, but designating the national authorities that enforce it is left to each country, and several of those designations were still being finalised when this article was published. Spain's AI supervision agency, AESIA, relays the Commission's Article 50 FAQs and guidelines, while noting that enforcement rests with the competent national market surveillance authorities. In Germany, the Bundesnetzagentur describes its own role in AI market surveillance on its site, with the national implementing act still going through the legislative process. In France, a draft designation published on 9 September 2025 puts the DGCCRF in a coordinating role, and the digital part of the Ddadue bill examined in the Senate on 17 February 2026 gives a central role to the CNIL. That bill was still moving between the two chambers.
The practical consequence for a company operating across several member states: check the state of play in each country where you deploy, rather than assuming that your data protection authority is automatically the AI authority.
Neston is in early access.
The assistant plugs into Outlook, learns your writing style, and prepares a reply that you read and approve before it is sent. Early access is free, on a waiting list.
Join the waiting list →Windows 10/11 · Outlook · Optional Mistral EU
Further reading
- Email and AI: how to write with an assistant, the day-to-day method
- AI email and GDPR in 2026, the other framework to know, distinct from the AI Act
- How an AI learns your writing style, what happens before a reply is proposed
- The Neston manifesto, why human validation is a design decision
- AI text detectors and your emails, what these tools actually measure
FAQ: AI transparency and emails
🔬 Sources
- European Commission, FAQs on the transparency obligations under Article 50 of the AI Act: application date of 2 August 2026, grace period until 2 December 2026, scope of Article 50(4), human review exception
- Text of Article 50, Regulation (EU) 2024/1689: wording of paragraphs 1, 2 and 4 and their exceptions
- Text of Article 99, Regulation (EU) 2024/1689: ceiling of 15 million euros or 3 % of worldwide annual turnover
- AESIA (Spain), FAQs on the Commission guidelines on transparency of AI-generated content
- Bundesnetzagentur (Germany), Market surveillance under the AI Act
- DGCCRF (France), draft designation of national authorities, 9 September 2025
Published 30 August 2026 · Reading time: 6 minutes · approx. 1,300 words