Kilde › Guides › AI Act Art 50 › Internal AI tools: the three-condition…

Internal AI tools: the three-condition carve-out, and everything it doesn't cover

Current to 26 August 2026 · updates land in the changelog.

“It's only internal” is half an argument. The final guidelines recognise a carve-out from the marking machinery for business contexts — but it is three cumulative conditions, not a vibe: the content is not shared externally, it stays in a controlled environment, and safeguards against misuse exist. Miss one and the carve-out is gone.

Reading the three conditions honestly

Not shared externally fails the day a generated draft lands in a customer email or a public deck — and content has a way of leaving. Controlled environment points to access-managed systems, not “our staff use a public tool with personal logins”. Misuse safeguards wants something real: policy, access control, logging — evidence a regulator could inspect. The honest reading: the carve-out fits genuinely closed pipelines, and content that might ever exit deserves marking at generation, because retrofitting marks at the moment of publication never actually happens.

What the carve-out does not touch

It addresses content marking — not the other duties. Staff interacting with an internal bot: 50(1) analysis still runs (here the obviousness exemption does its most legitimate work — a labeled internal tool used by trained staff is the easy case). Emotion recognition on employees: 50(3) — and workplace emotion inference may sit in prohibited territory altogether. Machine-to-machine interim outputs in closed workflows are separately excluded via the assistive-exclusions list.

The artifact worth keeping

A per-tool scope memo: which condition is satisfied how, what egress controls exist, who reviewed it. Three paragraphs now beats an unanswerable question later — and it doubles as the enterprise-sales answer when your customers start asking about the AI Act.

Related guides

Quick answers

Are internal AI tools exempt from the EU AI Act's marking duty?
Only under a narrow carve-out with three cumulative conditions from the final guidelines: content not shared externally, a controlled environment, and safeguards against misuse. All three must hold.
Do internal chatbots need AI disclosure to staff?
Article 50(1) still applies; in a labeled internal tool used by informed staff the obviousness exemption plausibly carries it — the case for documenting that assessment rather than assuming it.
Ship the disclosures before enforcement finds the gap.

The AI Act Article 50 Kit: the disclosure copy library (English + 中文), the marking implementation guide with survival-test protocol, deepfake and text-labeling walkthroughs, obviousness and scope memos, the evidence log, the Code of Practice accession path — built from the regulation and the final guidelines, with pinpoint citations.

Get the kit — US$190 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and no clearance opinions. Sources are Regulation (EU) 2024/1689 (Articles 50 and 99), Regulation (EU) 2026/1744, the Commission's final Article 50 guidelines of 20 July 2026 (non-binding) and our audited kit research. Marking-technology status changes fast: treat vendor announcements as live only once verified. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com