Does your chatbot need an AI disclosure? What Article 50 actually requires by August 2026.

The EU AI Act does not just regulate high-risk systems. From 2 August 2026, Article 50 makes ordinary chatbots, AI writers, and synthetic media tell people they are AI. Here is which of the four duties applies to you and what the disclosure has to say.

Download the PDF guide

Most of the EU AI Act coverage is about high-risk systems: hiring, credit, biometrics. That makes it easy to assume the Act does not touch you if you only run a support chatbot or use an AI writer. It does. Article 50 is the transparency layer, and it applies to ordinary tools that talk to people or generate content.

It does not ban anything and it does not impose the heavy high-risk conformity regime. It asks one thing: that people are not misled about whether they are dealing with, or looking at the output of, an AI system. The duty splits into four clauses, and which ones bind you depends on what your system does and whether you are its provider or its deployer.

The four duties, in plain terms

  • Article 50(1), direct interaction: if a system talks to people, the provider must make sure they know it is an AI system, unless that is already obvious. This is the chatbot, voice-assistant, and AI-phone-agent clause.
  • Article 50(2), synthetic-content marking: providers of systems that generate synthetic audio, image, video, or text must mark the output, in a machine-readable form, as artificially generated or manipulated. A visible label on its own is not enough.
  • Article 50(3), emotion and biometric systems: deployers of an emotion-recognition or biometric-categorisation system must tell the people exposed to it that it is running.
  • Article 50(4), deepfakes and public-interest text: deployers must disclose deepfake image, audio, or video as artificially generated, and must disclose AI-generated text published to inform the public on matters of public interest.

Provider or deployer changes who is on the hook

The marking duty in 50(2) belongs to the provider, the party that builds or puts the generative system on the market. The disclosure duties in 50(3) and 50(4) belong to the deployer, the party that uses the system in practice. Plenty of companies are both, which is why you work from the system and what it does, not from a single label for your business. A team that fine-tunes and ships its own model is a provider; a team that runs someone else's model to publish deepfakes is a deployer; a team that does both wears both hats.

What the disclosure has to say, and when

Under Article 50(5) the information must be clear and distinguishable, and given at the latest at the first interaction or exposure. In practice that means the notice goes in front of the person before they send their first chatbot message or at the point they first see the synthetic content, not buried in a privacy policy they will never open. The wording does not have to be legalistic; it has to be honest and visible.

The "it is obvious" exception is narrower than it sounds

The 50(1) interaction duty carries one carve-out: you do not have to announce the AI where a reasonably well-informed person would already find it obvious in the circumstances. It is tempting to lean on that for a chatbot that plainly looks like a bot, and skip the notice. Do not build your compliance around it. In draft guidelines on Article 50 published in May 2026, non-binding and still to be finalised before the rules apply, the European Commission reads this exception narrowly and illustrates it with examples that keep its scope small. The safe reading is that obviousness excuses the notice only in the clearest cases, and that a visible line telling people they are talking to an AI is cheaper than arguing after the fact that it went without saying. When you are unsure, disclose.

The deadline the omnibus did not move

The transparency obligations apply from 2 August 2026. The May 2026 digital omnibus pushed several high-risk deadlines later, to December 2027 and August 2028, but it left Article 50 in place. So the transparency layer is now the nearer deadline for most companies, which is the opposite of how the timeline read a year ago. If you assumed AI Act compliance was a 2027 problem, the chatbot disclosure is the part that arrives first.

What skipping it can cost

The transparency duties come with real teeth, not just a date. A breach of Article 50 sits in the mid penalty tier of the AI Act, Article 99(4): for a company, up to 15 million euro or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. That is below the 35 million euro or 7 percent reserved for the banned practices in Article 5, but it is still the kind of figure that turns a missing one-line notice into an expensive omission.

The part worth knowing if you are small is Article 99(6): for SMEs and start-ups the fine is capped at whichever of those two figures is lower, not higher, so a small company is measured against 3 percent of its own turnover rather than the 15 million euro headline. Enforcement sits with the national market surveillance authority each member state designates, not a central EU body, and the fines it sets have to be effective, proportionate and dissuasive, weighing things like whether the breach was intentional, how long it ran, and the size of the operator. So a first, quickly fixed omission on a small support chatbot is not the maximum-fine scenario; the exposure scales with how deliberate the breach is and how big you are. Our EU AI Act fine calculator and the piece on the real maximum fine for an SME run that number against your own turnover.

There is also a voluntary Code you can sign

For the marking and labelling side of Article 50, the Commission published a Code of Practice on transparency of AI-generated content, and it opened for signature in 2026. It is voluntary, and it covers the synthetic-content duties, meaning the 50(2) machine-readable marking, the 50(4) deepfake and public-interest-text disclosure, and the 50(5) clear-and-distinguishable manner. It does not cover the 50(1) chatbot-interaction duty or the 50(3) emotion and biometric one, so a plain support chatbot is not what this Code is for.

To be on the first published list of signatories, a provider or deployer has to submit the signatory form by 22 July 2026 at 18:00 CEST, and that list is published before the rules start applying on 2 August 2026. Following a positive assessment by the Commission and the AI Board, a signatory can rely on the Code to demonstrate compliance with those obligations. Not signing changes nothing about the underlying law, because any enforcement is about Article 50 itself rather than the absence of the Code, but a non-signatory carries the burden of showing compliance another way and can expect more requests for information from the market surveillance authorities. So if you generate synthetic media, or publish deepfakes or AI-written public-interest text, the Code is worth a look; if you only run a chatbot, the free notice on this page is still the whole job.

The cheap way to be ready

You do not need a law firm to write a one-line notice. Classify each AI surface you run against the four clauses, write the disclosure for the ones that apply, place it where the person meets the system, and keep a dated record of where you put it. The generator on this page does the first three in a few minutes and gives you the copy in three languages plus a machine-readable marking note for the 50(2) case. Doing it now, calmly, is far cheaper than doing it under a complaint.

One honest caveat

This is an organisational aid, not legal advice. Whether a specific duty binds your exact system, and how it interacts with sector rules, is a question for a qualified adviser. The value of acting early is that the simple version, written without a deadline overhead, beats the expensive version written after someone asks why the notice was missing.

Frequently asked questions

Does a chatbot need to say it is AI under the EU AI Act?

Yes. Under Article 50(1) of Regulation (EU) 2024/1689, the provider of a system that interacts directly with people, such as a chatbot, voice assistant, or AI phone agent, must make sure those people are informed they are dealing with an AI system. The only exception is where that is already obvious to a reasonably well-informed person in the circumstances. The information has to be given at the latest at the first interaction, and the obligation starts applying on 2 August 2026.

When do the Article 50 transparency rules start applying?

The Article 50 transparency obligations apply from 2 August 2026. That date was not changed by the May 2026 digital omnibus, which moved several high-risk deadlines later but left the transparency layer in place. So while parts of the high-risk regime now bind in December 2027 and August 2028, the duty to disclose chatbots, synthetic content, and deepfakes is the one with the nearer deadline.

If it is obvious my chatbot is a bot, do I still need to disclose that it is AI?

Assume yes. Article 50(1) drops the duty only where a reasonably well-informed person would already find it obvious they are dealing with an AI system, and the European Commission draft guidelines on Article 50 published in May 2026, non-binding and still to be finalised before 2 August 2026, read that exception narrowly. Relying on obviousness is a judgement call a regulator can second-guess, whereas a short visible notice at the first interaction removes the question. The disclosure costs nothing to add, so treat the exception as a rare edge case rather than a default.

Who has to make the disclosure, the builder or the user of the system?

It depends on the duty. The synthetic-content marking duty in Article 50(2) sits with the provider, the party that builds or puts the generative system on the market. The disclosure duties in 50(3) for emotion recognition and biometric categorisation and in 50(4) for deepfakes and AI-generated public-interest text sit with the deployer, the party that uses the system in practice. Many companies are both at once, which is why you classify the system by what it does rather than by a single label for your business.

Is a visible "made with AI" label enough?

For interaction and deepfake disclosure aimed at people, a clear visible notice is the point. But for the synthetic-content marking duty in Article 50(2), a visible label on its own is not enough: providers must also mark output in a machine-readable format so that systems downstream can detect it was artificially generated or manipulated, using techniques such as the C2PA content-credentials standard. The disclosure to people and the machine-readable marking are two separate requirements.

Can signing the EU Code of Practice on AI-content transparency prove Article 50 compliance?

For the marking and labelling side, yes. The Commission published a voluntary Code of Practice on transparency of AI-generated content that covers Article 50(2), (4) and (5), and following a positive assessment by the Commission and the AI Board a signatory can rely on it to demonstrate compliance with those obligations. It does not cover the 50(1) chatbot-interaction duty or the 50(3) emotion and biometric one. To be on the first published list of signatories you submit the signatory form by 22 July 2026 at 18:00 CEST, ahead of the rules applying on 2 August 2026. Not signing is allowed, because enforcement is about Article 50 itself, but non-signatories must show compliance another way and can expect more requests for information.

What is the penalty for not disclosing that a chatbot is AI?

A breach of the Article 50 transparency duties falls under the mid penalty tier of the EU AI Act, Article 99(4): for a company, up to 15 million euro or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. That is below the 35 million euro or 7 percent that applies to the prohibited practices in Article 5. For SMEs and start-ups, Article 99(6) caps the fine at whichever of those two figures is lower, so a small company is judged against 3 percent of its own turnover, not the 15 million euro headline. National market surveillance authorities set the actual fine and must keep it effective, proportionate and dissuasive, so a first, quickly corrected omission on a small chatbot is not the maximum-fine case.

Run the numbers for your own case

Every figure above comes from a free tool you can use in your browser, with no signup.

Generate your Article 50 transparency notice

What to actually use

The disclosure itself costs nothing. The generator on this page writes the user-facing notice in English, Dutch, and French, plus a pasteable HTML snippet and an internal memo, and keeping a screenshot of where you placed it is enough of a record for most teams. A continuous-compliance platform only earns its fee once these disclosures are one item inside a formal certification and keeping the evidence current by hand is the real bottleneck:

  • Track governance evidence with Vanta (coming soon)Collects and monitors compliance evidence on a schedule and maps it to frameworks, so an AI inventory and its transparency disclosures stay audit-ready without manual chasing. Worth it once you are running a SOC 2 or ISO 27001 program; for a single chatbot the free notice here plus a dated screenshot is all the proof you need.

If you buy through a link above we may earn a commission, at no extra cost to you. It never changes which option we call the cheaper or better fit; the math on this page is the same either way.

Get the next cost breakdown by email

We publish a new honest, tool-backed breakdown like this every few days. Leave your email and we will let you know when the next one goes up. One confirmation link, nothing else until you click it.

A short email when a new cost breakdown is published. No newsletter, unsubscribe in one click.

One field: your email. Then confirm one link.

Free. We email you only when that page actually changes, at most one email per change. One-click unsubscribe, and we never share your address.