ART. 50 EU AI ACT: THE LEGAL TEST FRAMEWORK LINKEDIN WON'T SHOW YOU – PLUS THE SUNO REALITY CHECK
2026-08-08

WHAT’S THIS ABOUT?
This is about Article 50 of the EU AI Act. Not as a LinkedIn wheel of fortune with three buzzwords, but as a real legal test framework: first scope, then timeline, then roles, then case groups, then consequences. Top to bottom. Like short-circuit evaluation, just with a fine hammer instead of a stack trace.
The core: transparency obligations are not a decorative sticker for AI content. They depend on who acts - provider or deployer -, what gets generated - text, image, audio, video, deepfake - and when the system was placed on the market. Mix that up and you produce compliance folklore. Pretty. Useless. Dangerous.
And then comes the reality check: Suno. The AI music service announces watermarks and fingerprinting. Sounds like voluntary love for artists. It’s probably a lot less campfire and a lot more Article 50(2) EU AI Act. Result: Suno must mark synthetic audio content machine-readably: robust, interoperable, at the latest once the legacy-system deadline runs out. And whoever uses Suno to rebuild the voices of real artists and publishes the result has an additional deepfake problem on the deployer side.
In short: this article does not explain “AI content must be labelled”. That would be E = mc² on a cheap hoodie. This is about how to run the analysis properly, by legal standards.
Explained by a hybrid (computer scientist & lawyer) with more than 20 years of experience in computer science and law, including major corporations like Microsoft, Daimler, EnBW, Zeiss and GÖRG, to name just a few.
WHY THIS ARTICLE - AND WHY I’M FOAMING AT THE MOUTH
I’ve had it.
I scroll through LinkedIn and see the same ritual around the EU AI Act: half-knowledge, reheated, prettily plated, then served with maximum conviction. ChatGPT style: spew out LSD hallucinations while sounding like Einstein on coke.
Right. Now you, dear AI shaman, need to clench your teeth real hard. I know, you already believe you know everything. Then just keep reading for a moment - maybe you’ll learn something after all:
For this topic you need two tools in your hands at the same time: law and computer science. Not “I once read a GDPR post” law. And not “I can read Python when it rattles past in a Claude Code window” computer science. Both, load-bearing: statutes and pipeline. Otherwise you’re not advising here, you’re cosplaying competence.
The EU AI Act is not a pretty Pinterest poster with three bullet points. It’s a legal construct with trapdoors. Whoever classifies it legally must understand technically how the stuff gets built. Whoever builds it technically must understand legally which obligations attach to which roles. If you’re holding only one card, you cannot seriously advise in this field.
And if you squeeze the second card - or both - out of ChatGPT: accelerated shit is still shit.
Less profanely:
A fool with a tool is still a fool!
When I talk about something I know nothing about, I label it upfront. Layman’s opinion. Done. I would never presume to lecture on recruiting. Or medicine.
This academic humility - actually: this perfectly ordinary humility - is gone. Not since AI exists. Since humans use AI. Subtle difference. Decisive. The tool is not the problem. The human is the problem.
There’s a name for it: Dunning-Kruger. The less substance, the more chest-drumming.
I see the same thing in MMA.
I’m active again. Competing myself? Nope. At my age that’s a dumb bet against your own remaining runtime - I recently caught a hit that knocked me out clean. Whatever. I need that fight club.
And the same mechanic shows up there: new people overestimate themselves. Not out of malice. They simply don’t know yet how much chaos a real fight is. Nothing elegant, nothing movie-grade. Just air hunger, adrenaline and wild flailing until the theory of the clean jab collapses.
But - and this is the difference: that’s not bragging. That’s not-knowing. I have compassion for that. We old hands look out for them. No issue.
The braggarts on LinkedIn?
Zero.
And the people I actually feel sorry for are the readers who see it and think: oh, lots of followers, surely they know what they’re writing.
Spoiler: reach is no substitute for competence. Otherwise the tabloids could actually raise the dead instead of merely claiming it in headlines.
I don’t have many followers. Fine by me.
Partly because I’m often bone-honest and use language that’s more Wild West than LinkedIn. Was like that in my legal traineeship already. Still: almost exclusively double-digit grades - and anyone who knows German law exams knows: that’s rare.
Meaning: I know what I’m talking about.
Even if I sometimes sound like Lucky Luke while doing it.
But you know - and now I’m talking to my actual readers: Lucky Luke has a damn big heart, and he masters his craft. Even from the hip.
E = MC² IS NOT THE THEORY OF RELATIVITY
Before we start, the warning: this legal test framework is what it is. Not “complicated because I like sounding smart”. Complicated because the EU AI Act is a legal blast furnace: lots of heat, lots of hatches, lots of spots where you pinch your fingers off.
“Simplifying” Article 50 is usually not a service but a fraud on the reader. It’s like: “E = mc² ⇒ that’s the theory of relativity.” No. That’s a result. Behind it stands the genius, not the sticker. Whoever just parrots the formula has understood nothing and still sells it as knowledge. Exactly that LinkedIn circus.
And yes: the EU AI Act is not rocket science. Still, the core truth stands: what you’re getting here is already simplified. I’ve sanded down the worst corners for you. And plenty will still think, for the first time:
Holy shit, this really is more than three bullet points and a Canva poster.
Why? Because you have to check properly:
- Which role do you carry: provider? Deployer? Double role?
- Is there even an AI system in the legal sense, or just marketing babble about “AI”?
- Does EU law even apply here (yes, sometimes the answer is: clarify first, talk later)?
And if you never learned how to build a legal test framework, you build junk: you test obligations that don’t even apply, or you miss the ones that later press the fine hammer into your face.
This article is for people who want substance. For product, project, business. For “I have to build this and defend it” - not for “I want to extract an opinion from AI slop and then wave it around loudly”.
SOURCES, METHOD, AND WHY AI ALONE WON’T SAVE YOU HERE
My sources: the legislative text in its current consolidated version (more on that in a minute - keyword: Digital Omnibus), a legal commentary (Bomhard/Pieper/Wende/Merkle on the AI Act), several treatises (including Wendt and Voigt’s handbook), and my own knowledge from twenty-plus years of computer science and law. Everything has been checked against the text of the Regulation.
Can errors still creep in? Sure. I’m not perfect. If you find one: tell me, I’ll fix it. Any uncomfortable truth beats the prettiest lie.
Side note: I’m currently writing a technical book for Rheinwerk, a major German publisher, with wonderful editors at my side whom I genuinely love working with. A book like that is a mountain of work. If you think you can knock one out quickly with AI: no. You can’t.
And there’s a reason for that which most people don’t know: legal knowledge in Germany is still paper knowledge. Much of what isn’t paper comes from secondary literature, and the truly reliable online sources have sat behind paywalls from day one. I once put it like this in another article: when the AI crawlers swept through the web in 2022 like a horde of bloodthirsty vampires, draining entire mountains of knowledge and leaving them behind as digital corpses - see Stack Overflow - the German legal knowledge mountains stood at the gate draped in garlic and armed with wooden stakes. The crawlers never got in.
The consequence: to this day, the training corpora of many frontier models contain legal garbage. Outdated statutes. Confident nonsense. And the eternal half-knowledge people have always dribbled out anyway - now machine-reheated. Which is why, especially with legal texts, you still have to work hands-on: look things up, cross-check, verify.
Dump unchecked AI-generated legal reasoning into court filings and things get grotesque: in Withers v. City of Aberdeen (N.D. Miss., June 8, 2026), both sides pelted each other with confabulated (= hallucinated) case law. Senior District Judge Sharion Aycock removed all four attorneys from the case, barred two from her court for two years and imposed a total of USD 8,000 in sanctions. The problem wasn’t using AI - it was solemnly signing off its output as attorney work product (https://www.damiencharlotin.com/hallucinations/ - a damn long list of hallucination cases; it’s become a genuine plague in the US - last visit: 2026-08-08 - 14:57)
So when you see genuine colleagues from the legal field here - real attorneys: trust them more than whatever an AI spits out. Go get their advice.
I myself am not bookable for legal advice in the attorney sense. I am still an IT guy with law as bycatch. Meaning: I show you how to implement all of this, with legal precision. I advise on how to build systems that are compliant by design - that’s where my background as a software architect earns its keep. With me, you save yourself the endless interpreting rounds between the legal department and engineering.
And yes, here comes the best possible call to action, entirely shame-free: I am currently available for projects again. If you want to book me - now’s your chance. Would love to hear from you.
As of: 2026-08-08 - 12:30
Right. Enough talk. Time to run the analysis. And at the end, we’ll push a red-hot current case through the framework: does Suno have to label its AI songs?
PART 1: THE LEGAL TEST FRAMEWORK FOR ART. 50 EU AI ACT
A word on method first, for everyone without a German state law exam: you work through a legal test framework top to bottom. If you jump in at step three because steps one and two sound boring, you produce exactly the errors I described above. The order is not a suggestion. It is the product of centuries of legal methodology - and it stops you from testing obligations that don’t even apply to your case.
Computer science has the same thing: compilers call it short-circuit evaluation. Meaning: if the first part of a condition already decides the outcome, the rest never runs. false && somethingExpensive() never calls somethingExpensive(). Because the result is already settled. A legal test framework works exactly like that: if EU law doesn’t apply at all, you don’t merrily keep testing Article 50. That branch is dead. End of show.

A. DOES EU LAW APPLY AT ALL?
Sounds trivial. It isn’t. The AI Act is public commercial law - specifically: product safety and market conduct law.
Which means classic private international law does not run the show here: Rome I (contracts) and Rome II (torts) are irrelevant for the regulatory obligations. The Regulation defines its own territorial reach, unilaterally, via Article 2 - structurally like Article 3 GDPR: the marketplace principle.
The practical consequence that routinely drowns on LinkedIn: a choice-of-law clause in a US provider’s terms (“governed by the laws of California”) changes nothing. Article 2(1) covers:
- anyone placing AI systems on the market or putting them into service in the Union - regardless of where they’re established (lit. a),
- deployers established in the Union (lit. b),
- and the third-country joker: providers and deployers in third countries, whenever the output is used in the Union (lit. c).
B. SCOPE ANALYSIS: PERSONAL, TEMPORAL, MATERIAL SCOPE & LEX SPECIALIS CHECKS
1. CARVE-OUTS: AM I OUT IMMEDIATELY?
Now the carve-outs of Article 2. You check these upfront, completely, before you even think about Article 50. Five matter here:
- military, defence and national security (para. 3)
- scientific research and development as the sole purpose (para. 6)
- research and testing before placing on the market (para. 8)
- personal use (para. 10)
- open source (para. 12)
The first three are usually ticked off quickly. The last two look like a free pass - and that’s exactly where the AI Act sets two traps that people walk into in droves:
Trap 1 - personal use (para. 10) is only half an exemption. Exempt are exclusively the deployer obligations of natural persons acting in a purely personal, non-professional capacity. Meaning: the private user is out of Article 50(3) and (4). The provider obligations under paragraphs 1 and 2 remain completely untouched. If you believe “private = safe”, you’ve read only half the provision.
Concretely: you privately build a Suno track in which a politician sings things he never said, and you send it to your buddies. As a private deployer, the deepfake disclosure duty of paragraph 4 doesn’t touch you - the exemption applies. Suno, however, must still mark the output machine-readably as AI-generated (para. 2), because your private use changes exactly nothing about the provider obligations. And the moment you blast the track onto your channel and gain reach or money with it, “purely personal” is history - then you’re fully back in.
Trap 2 - open source (para. 12) is precisely no shield. The counter-exception almost everyone misses: AI systems under free and open-source licences are exempt from the AI Act … unless they are high-risk, fall under the prohibitions of Article 5 - or under Article 50. Read that twice. FOSS is no shield against the transparency obligations. If you place an open generative model on the market as a system, you’re in anyway.
2. TEMPORAL SCOPE - AND WHAT THE DIGITAL OMNIBUS ACTUALLY CHANGED
This is where the wheat separates from the chaff right now, because as of a few days ago the legal situation is different from what 90% of LinkedIn posts claim.
Under Article 113, the AI Act applies in principle since 2 August 2026. Chapter IV - which consists of exactly one article, our Article 50 - is covered by no special rule. Result: Article 50 has been live since 2 August 2026. Fully. Directly. In every Member State. Exception: see right below, the grace period for legacy systems.
And now the part most people slept through: on 27 July 2026 the Digital Omnibus entered into force - Regulation (EU) 2026/1744, which rebuilt the AI Act in quite a few places. What did it change for Article 50?
- Postponed: nothing. While the high-risk obligations of Chapter III were pushed to 2 December 2027 (Annex III systems) and 2 August 2028 (Annex I products), Article 50 remained untouched. So if you’re currently celebrating “the AI Act got delayed!”, you caught half the truth - the wrong half.
- New: a grace period for legacy systems. The new Article 111(4) gives providers of AI systems generating synthetic content that were placed on the market before 2 August 2026 until 2 December 2026 to implement the machine-readable marking under Article 50(2). Memorize that date - it plays a lead role in the Suno part below. And careful: the grace period covers only paragraph 2. The obligations under paragraphs 1, 3 and 4 have applied to legacy systems since 2 August.
- Article 50(7) was recast - recast, not invented: codes of practice were already in the original 2024 text. There, however, the AI Office was in charge of encouraging and facilitating them, and the Commission could approve the codes by implementing act. The Omnibus rebuilt both: in the consolidated version, the Commission itself now encourages and facilitates the codes of practice, assesses - taking utmost account of the Board’s opinion - whether adherence to them suffices for the obligations under paragraphs 2 and 4, and can impose binding common rules by implementing act if a code proves inadequate. Translation: what “machine-readable” concretely means will materialize through those codes - ignore them and you’ll be negotiating with the regulator later. (And whoever still tells you “the AI Office” is in charge here is quoting the 2024 version or 2025 commentary literature - which brings us right back to outdated knowledge in AI corpora. Read the consolidated version. Always.)
- Flanking measure: from 2 December 2026, new prohibitions in Article 5(1)(ba) and (bb) apply - non-consensual intimate deepfakes and AI-generated abuse material. At that point it’s no longer a transparency question; it’s simply banned.
3. CONCURRENCE: WHAT TAKES PRIORITY, WHAT RUNS IN PARALLEL?
Within the AI Act, a staged analysis applies, and the order is not decorative:
Stage 1 - prohibitions before transparency. If the practice falls under Article 5, it is prohibited. Full stop. Transparency cures nothing. If you start your emotion-recognition-at-work analysis with Article 50(3), you’ve built the structural error of the year: the thing is already banned under Article 5(1)(f) (except for medical or safety reasons). Same for biometric categorisation by sensitive attributes (lit. g). Only once Article 5 has been checked and ruled out do you move on to Article 50.
Stage 2 - high-risk runs in parallel, not instead. Article 50(6) makes it explicit: paragraphs 1 to 4 do not affect Chapter III. A high-risk system can be subject to the transparency obligations on top - cumulation, not speciality. Spicy detail: emotion recognition and biometric categorisation, where not already prohibited, are simultaneously high-risk under Annex III No. 1(b) and (c).
Stage 3 - GPAI is its own regime. The obligations for GPAI models (Article 51 et seq.) sit alongside Article 50. And Article 50(2) explicitly covers GPAI systems itself.
Outside the AI Act: the GDPR runs in parallel (Articles 13, 14, and Article 22 for automated individual decisions) - Article 50(3) even references it expressly.
The Digital Services Act is complemented, but beware the short circuit: a violation of Article 50 does not make content illegal content within the meaning of the DSA (Recital 136).
And then there’s a piece of German law practically nobody has on their radar: the Interstate Media Treaty (Medienstaatsvertrag, MStV). Not a federal statute, but a treaty between all 16 German states, in force since November 2020 as the successor to the old Interstate Broadcasting Treaty. Its § 18(3) MStV contains a social-bot labelling duty: providers of telemedia in social networks must disclose the fact of automation for content or messages created automatically, whenever the user account, by its outward appearance, has been made available for use by natural persons. Translation: if your bot account looks like a human, you must write on it that a machine is typing. And before anyone objects that this only hits “telemedia providers”: that’s exactly what you are. A telemedia provider is any natural or legal person holding their own or third-party telemedia available. Classic German administrative prose, I know. Your social-media account is itself the telemedium; you, as the user of the bot, are the provider. The legislative rationale says it verbatim: obligated are the users of the social bots; the platforms merely have to ensure, per § 93(4) MStV, that labelling happens. And unlike the imprint duty of paragraph 1, paragraph 3 knows no exemption for purely personal purposes. Germany thus had bot labelling years before Brussels even finished the AI Act.
Except: the scope is much narrower than Article 50 - social networks only, human-looking accounts only. Article 50(1), by contrast, covers every interaction system, no matter where it runs. And because an EU regulation applies directly and takes precedence over state law, the social-bot labelling of § 18(3) MStV will, per the prevailing view in the literature, be absorbed by the directly applicable Article 50.
So in practice you test Article 50 going forward - and § 18(3) MStV is the footnote for the transition period.
4. THE THRESHOLD QUESTION EVERYONE SKIPS: IS THERE EVEN AN AI SYSTEM? (MATERIAL SCOPE)
Before anyone has to label anything, you need an AI system within the meaning of Article 3(1): a machine-based system operating with varying levels of autonomy, possibly adaptive, that infers from its inputs how to generate outputs - predictions, content, recommendations, decisions. That separates generative models from purely rule-based conventional software. Your 90s mail-merge macro is not an AI system, no matter what marketing wishes.
5. WHO AM I WITHIN THE MEANING OF THE EU AI ACT? (PERSONAL SCOPE)
Then the role question, which determines everything that follows:
- Provider (Article 3(3)): develops the system - or has it developed - and places it on the market under its own name or trademark.
- Deployer (Article 3(4)): uses the system under its own authority - except in a purely personal, non-professional capacity.
Two classics from practice: under Article 25 a deployer can become a provider - for instance by offering someone else’s system under its own brand or substantially modifying it (white-label chatbots, I’m looking at you). And the double role is possible: whoever develops their customer-service chatbot in-house and runs it themselves carries provider and deployer obligations cumulatively.
C. THE CASE GROUPS OF ARTICLE 50 - WHO OWES WHAT?

Case group 1 - interaction systems (para. 1, provider). AI systems intended to interact directly with humans: chatbots, voicebots, social bots. The duty attaches at the design level: the system must be conceived and developed so the person learns they are talking to an AI. That’s a by-design obligation, not a footnote added later. Exception: obviousness - measured against a reasonably well-informed, observant and circumspect person (hello, European consumer benchmark). Indicators: the label “chatbot”, the appearance, an unnaturally fast response time. Second exception: legally authorised law-enforcement systems.
Case group 2 - synthetic content (para. 2, provider, incl. GPAI systems). Whoever provides a system generating synthetic audio, image, video or text content must mark the outputs in a machine-readable format, detectable as artificially generated or manipulated. The addressee of this marking - here comes the part that people without a computer science background love to mix up - is the machine, not the human. The point is that detection tools, platforms and crawlers can identify the content as synthetic.
The technical solution must meet four quality requirements - as far as technically feasible, taking into account content type, implementation costs and the state of the art:

And what do you actually mark with? Recital 133 names five technique families - none is mandatory, combining them is expressly encouraged:

As a software architect I’ll tell you where the music plays: robust and interoperable. A watermark that doesn’t survive the first MP3 transcode is compliance theater. A metadata tag that every platform strips on upload, likewise. That’s why practice combines (keyword C2PA): robust signal-embedded watermarks plus metadata plus server-side fingerprinting with a matching database. And that’s why you document your trade-off analysis - content type, costs, state of the art - in writing. That’s your line of defence when the regulator comes asking.
Exceptions to paragraph 2: assistive functions for standard editing (brightness, contrast, spell-checking, noise reduction), systems that do not substantially alter the input, and law enforcement.
Case group 3 - emotion recognition and biometric categorisation (para. 3, deployer). Check Article 5 first (see above - workplace and education: prohibited!). If a lawful use case survives, the deployer must inform the exposed persons about the operation of the system - the “whether”, not necessarily every technical “how” - and process the data in compliance with the GDPR. A dual structure: transparency and data-protection compliance.
And here hides a wording detail for connoisseurs: the law-enforcement exception in paragraph 3 only names detection, prevention and investigation - “prosecution” is missing, unlike in paragraphs 1, 2 and 4. On a strict reading, the information duty therefore survives within the criminal proceedings themselves. Asymmetries like this are troubling from a legislative-drafting perspective: they don’t just raise the cognitive load of “learning” the statute, they also routinely land on the (digital) desks of judges who then have to iron out the asymmetry through interpretation.
Case group 4 - deepfakes and AI texts (para. 4, deployer). Two variants:
Variant A - deepfakes: image, audio or video content constituting a deepfake. The legal definition (Article 3(60)) requires that the content resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. Important: purely fictional content with no link to reality already fails the definition - then only the provider duty under paragraph 2 remains. The deployer must disclose that the content was artificially generated or manipulated - and this disclosure, unlike paragraph 2, addresses the human: a visible watermark, a text notice, an announcement.
For art, satire and fiction there is a relief, not an exemption (as is often claimed): disclosure must then happen in a way that does not hamper the display or enjoyment of the work.
Variant B - texts: AI-generated or -manipulated texts published to inform the public on matters of public interest. Exception: the text has undergone human review or editorial control, and a natural or legal person holds editorial responsibility. That’s the editorial privilege - the reason your newspaper doesn’t have to label every AI-assisted article, while your editor-less content bot does.
For perspective on where Article 50(4) even sits in the big picture - namely on only one of five regulatory levels:

D. THE MODALITIES: HOW AND WHEN TO INFORM? (PARA. 5)
All information under paragraphs 1 to 4 must be provided in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure. The legal commentary on the AI Act (Bomhard/Pieper/Wende/Merkle, 1st ed. 2025, Art. 50 - see sources below) puts it bluntly: an AI notice buried on page 14 of the privacy policy or in the cookie-banner fine print does not suffice. Add accessibility: the information must conform to the applicable accessibility requirements ⇒ in Germany, think of the Barrierefreiheitsstärkungsgesetz (BFSG) implementing the European Accessibility Act.
E. CONSEQUENCES: WHAT HAPPENS IF YOU SCREW IT UP?
Now the part the first German state exam skips and the second one makes the main event - and which almost nobody on LinkedIn thinks through:
Supervision: violations of Article 50 are explicitly listed as their own non-compliance category in the market-surveillance procedure (Article 79(6)(d)). The authority can order corrective measures, pull the system from the market or have it recalled. In Germany, the AI Act Implementation Act has been in force since 29 July 2026: the Bundesnetzagentur (Federal Network Agency) is the central market-surveillance authority, flanked by the KoKIVO coordination and competence centre; sectoral authorities such as BaFin and BfArM keep their turf.
Fines: Article 99(4)(g) - up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs and start-ups the lower amount applies; the Digital Omnibus extended that privilege to small mid-caps.
Individual remedies: anyone can lodge a complaint with the market-surveillance authority (Article 85). The AI Act itself contains no damages claim - and the Commission buried the planned AI Liability Directive. National law it is.
And now the actually sharp sword almost nobody has on their radar - the civil-law flank: in Germany, via § 3a UWG (unfair competition through breach of law), competitors and associations can send warning letters and demand injunctions - whether Article 50 qualifies as a market-conduct rule hasn’t been adjudicated yet, but for the consumer-protective duties of paragraphs 1 and 4 it’s well arguable; independently of that, the misleading-omission route via §§ 5, 5a UWG is open. On top: Article 110 AI Act inserted the Regulation into the annex of the EU Representative Actions Directive - qualified consumer associations can build collective actions on it. And with deepfakes, personality rights and image rights run in parallel anyway - transparency is no substitute for consent.
If you’ve been thinking “a fine will never hit my small shop”: your competitor’s cease-and-desist letter doesn’t wait for the Bundesnetzagentur.
PART 2: THE REALITY CHECK - DOES SUNO HAVE TO LABEL?
Now let’s push a current case through the framework. Suno - the AI music service that just lost against GEMA before the Munich Regional Court (my in-depth analysis: GEMA slaps Suno) - has announced it will equip generated songs with watermarks and fingerprinting. Heise reported (Suno: AI music service wants to watermark generated songs). The stated rationale: transparency and protecting artists. The context is visibly the copyright pressure after the Munich ruling.
What appears in neither the press coverage nor Suno’s own communication: the EU AI Act. So let’s run the analysis ourselves. Top to bottom, as it should be.
Step 1 - does EU law apply? Suno is a US company. Irrelevant. The service is offered in the Union, EU users generate songs with it - placing on the market in the Union (Article 2(1)(a)). And even if you wanted to quibble: the output is used in the Union (lit. c). The Californian choice-of-law clause in the terms interests - see above - exactly nobody. Carve-outs? None apply. EU law: applicable.
Step 2 - temporal scope? Article 50 has applied since 2 August 2026. Suno was placed on the market before that date - so the legacy-system grace period of Article 111(4) kicks in: the machine-readable marking under paragraph 2 must be in place by 2 December 2026. Now hold Suno’s announcement next to that - watermarks coming “in the coming weeks”. Do the math. The window matches the statutory deadline suspiciously well. Suno is selling the public a voluntary transparency commitment that, from December, is simply an enforceable legal obligation. Hats off to the marketing department.
Step 3 - AI system? A generative audio model inferring music from prompts: autonomy, inference, content output. Article 3(1) - clearly yes.
Step 4 - roles? Suno develops the system and offers it under its own brand: provider (Article 3(3)). The users generating and publishing songs: deployers (Article 3(4)) - unless they act purely privately (Article 2(10)).
Step 5 - case group 2 for Suno itself: music is synthetic audio content. Hence: machine-readable marking, duty under Article 50(2). Exceptions? A full text-to-song generator is no “assistive function for standard editing”, and nobody can seriously argue that “prompt in, finished song out” leaves the semantics of the input substantially unaltered. The duty stands. The announced combination - inaudible audio watermark plus fingerprinting - reads like it was copied straight out of Recital 133: watermarks plus fingerprints, a combination of several techniques. Exactly right. The interesting question is robustness: does the watermark survive transcoding, streaming compression, tempo shifts and the YouTube upload pipeline? That is the “robust and reliable, as far as technically feasible” standard - and that’s precisely where the codes of practice under paragraph 7 will let loose.
Step 6 - case group 1, briefly: Suno’s web interface is an obvious AI application - the obviousness exception should apply. No drama.
Step 7 - case group 4 for the user side: whoever uses Suno to generate a song that sounds like the voice of an existing artist and publishes the thing creates an audio deepfake (Article 3(60)) - and must disclose as a deployer. Relief for evidently artistic works: yes, but relief means discreet disclosure, not zero disclosure. The purely private sphere stays out. Purely fictional music with no link to real existing persons, by contrast, fails the deepfake definition - leaving only Suno’s provider duty under paragraph 2.
Step 8 - consequences of a violation: up to EUR 15 million or 3% of worldwide annual turnover (Article 99(4)(g)), market surveillance by the Bundesnetzagentur - and the unfair-competition flank: picture the joy with which music majors and collecting societies, already dismantling Suno in court, will staple an additional transparency violation into their briefs from December.
Result: yes, Suno has to label. Machine-readable, robust, by 2 December 2026 at the latest. The watermark announcement is neither a favour nor a PR gift to the music industry - it is the fulfilment of a legal obligation, five minutes before the deadline. That Suno sells it as goodwill and doesn’t mention the AI Act with a single syllable is skilled communications work. That almost the entire press coverage falls for it and doesn’t mention the AI Act either - that is exactly the competence problem this article opened with.
CONCLUSION
Article 50 has been live since 2 August 2026. The Digital Omnibus postponed high-risk - not the transparency obligations. Legacy systems get air until 2 December 2026 for the machine-readable marking, and for nothing else. The duties are precisely distributed between providers and deployers, the exceptions are narrow, and enforcement will come not only via fines but foreseeably via competitor warning letters and collective actions.
And whoever tells you all of this boils down to “AI content must be labelled” is telling you E = mc² and calling it the theory of relativity.
If you need to not merely understand all this but implement it in your systems - compliant, documented, with a marking architecture that survives a regulatory audit: that’s exactly what I’m here for. IT guy with law as bycatch, software architect with state-exam precision. No legal advice in the attorney sense - for that, go to the real lawyers; they do good work. But the bridge between statute and production - that’s the one I build.
Currently available for projects again. Get in touch.
SOURCES
- Regulation (EU) 2024/1689 (AI Act), consolidated version of 27 July 2026 including the amendments by Regulation (EU) 2026/1744 (“Digital Omnibus”), EUR-Lex
- Regulation (EU) 2026/1744 of 8 July 2026, EUR-Lex
- Bomhard/Pieper/Wende/Merkle, KI-VO, 1st ed. 2025, Art. 50
- Wendt/Wendt, Das neue Recht der Künstlichen Intelligenz; Voigt, Handbuch KI-Verordnung
- German AI Act Implementation Act, in force since 29 July 2026 (BGBl. 2026 I No. 233), BMDS
- Heise: Suno: AI music service wants to watermark generated songs
- My ruling analysis: GEMA slaps Suno - the Suno ruling of the Munich Regional Court (see: Medium or here on my website: ki-codex.ai)
This article is not legal advice for individual cases and does not replace counsel from an attorney. It is meant to help you understand the regulatory framework and ask the right questions in practice.
When it comes to actually implementing your AI application - the intersection of IT & law (compliance by design, documentation, marking and process architecture) - you can hire me for that. I come from hands-on software practice (over 10 years of C# development, a long stretch of it “classic” without AI, now of course with an AI rocket boost) and I still build prototypes in client projects when needed.
