AI book for children AI book for teens AI book for families Have you seen our book series yet? AI for kids, teens and adults Discover the books DueDog AlGrano tenfold BatCap And our iPhone apps: no cloud, no accounts See the apps

EU AI Act Art. 50: Chatbot Transparency In Force Since August 2026

eu-ai-act compliance dsgvo

Does a chatbot on a company website have to identify itself as AI? Yes, since 2 August 2026 Article 50 of the EU AI Act (Regulation (EU) 2024/1689) requires exactly that, before or at the very start of every conversation. These transparency duties are no longer a preview, they are applicable law that national supervisory authorities can enforce from that date.

The Digital Omnibus of summer 2026 pushed back the deadlines for high-risk AI, but it did not touch Article 50. The transparency obligations took effect on schedule on 2 August. Anyone reading the high-risk delay as a delay of the transparency rules is mistaken, and we set out that distinction in our piece on the high-risk deadlines.

Stand: 2026-08-25. Updated from a preview to the current legal position: Article 50 paragraph structure corrected, the transition period to 2 December 2026 added.

What Article 50 Requires Since 2 August 2026

Article 50 sets out four transparency duties. Two fall on providers, two on deployers. That split decides who has to act in any given case.

Art. 50(1): Providers, Interactive AI Disclosure

Providers of AI systems that interact directly with natural persons must design those systems so that users are informed they are dealing with an AI. The only exception is where this is obvious from the context, which in practice covers almost nothing. A live-chat widget on a business website is not obviously an AI without an explicit label.

Implementations that satisfy the duty, based on our reading:

  • A visible AI Assistant or Powered by AI badge on the chat widget
  • An automated opening line: I am an AI assistant for Example Company, how can I help?
  • A persistent label in the interface header that stays visible for the whole session

A note buried in the footer or the terms of service does not count. The information must reach the user before or at the start of the interaction.

Art. 50(2): Providers, Machine-Readable Marking of Generated Content

Providers of AI systems that generate synthetic audio, image, video, or text must mark the outputs in a machine-readable format that is detectable as artificially generated or manipulated. The statute requires the technical solutions to be effective, interoperable, robust, and reliable as far as this is technically feasible. C2PA-compatible metadata is currently the most widely used practical standard.

There is an important transition period here. For generative systems that were already on the market before 2 August 2026, the marking duty applies only from 2 December 2026, according to the European Commission guidelines. For any system newly placed on the market since 2 August 2026 the duty applies at once. Content generated before 2 August does not have to be labelled retroactively.

Art. 50(3): Deployers, Emotion Recognition and Biometric Categorisation

Deployers of emotion recognition systems or biometric categorisation systems must inform the people exposed to them. This duty is easy to miss in an SMB, because it does not sit on the chatbot but on software that, for example, scores a job interview or sorts customers by biometric traits. Anyone operating such a system is a deployer under Art. 50(3).

Art. 50(4): Deployers, Deepfakes and Public-Interest Text

Deployers who use AI to generate or manipulate image, audio, or video content that constitutes a deep fake must disclose that the content is artificially generated or manipulated. The same applies to AI-generated text published to inform the public on matters of public interest, unless a human holds editorial responsibility and reviews the content.

For most SMBs this is the relevant dividing line. An AI-generated blog post with no human review falls under it, whereas a text that a marketing team has checked and stands behind generally does not.

Provider or Deployer: Who Does What

The Regulation draws a line between two roles. Providers develop an AI system and place it on the market or put it into service. Deployers operate an AI system under their own authority in a professional context. Most SMBs are deployers: they buy a finished tool or run an open-weight model.

The classification is not always clean. If you install an open-weight model via Ollama yourself, wire it to your own chat frontend, and put it into service, then for that system you act, on our reading, as a provider as well, and you carry the design duty under Art. 50(1). If instead you merely operate a finished SaaS chat tool, you are a pure deployer and must make sure the disclosure the provider built in is actually switched on and visible. If it is missing, the interface-level fix falls to you. There is no gap: the party closest to the end user is always accountable.

The Local LLM Misconception

A common assumption holds that running AI locally on your own hardware exempts you from Article 50, because no data leaves your network. On our reading of the Regulation, that is wrong.

Article 50 conditions its duties on the user-facing interaction, not on where inference takes place. If your locally hosted model talks to customers or staff through a web interface, that triggers the disclosure obligation, whether the server sits in Frankfurt or your basement.

The upside: for operators of local AI infrastructure the fix is structurally simpler. You control the interface and can change it today. No SaaS update to wait for, no support ticket, no contract clause to renegotiate. Adding a label to Open WebUI or a custom frontend takes an afternoon.

Practical Checklist

Based on our reading of Article 50 and the AI Office guidance:

Step 1: Inventory. List every system where an AI talks directly to people or produces content for the public: chat widgets, email autoresponders with AI text, phone bots, internal helpdesks, HR assistants, document Q&A tools.

Step 2: Disclosure at each touchpoint. A visible label, an automated first message, or both. The disclosure must appear before or at the start of every session.

Step 3: Review content workflows. Does your organisation generate AI text, images, audio, or video for external publication? Then Art. 50(2) and 50(4) apply. Mind the 2 December 2026 deadline for systems that were already running.

Step 4: Check emotion and biometric systems. Do you run software that recognises emotions or categorises people by biometric traits? Then inform the people exposed, Art. 50(3).

Step 5: Document your measures. Article 50 does not expressly require documentation, but a record of which systems were reviewed and changed, and when, is valuable in an audit. National supervisory authorities are becoming active in enforcement.

Enforcement Exposure

Breaches of the transparency duties can, on our reading of the sanction framework, attract fines of up to EUR 15 million or up to 3% of worldwide annual turnover, whichever is higher. National authorities are expected to apply proportionate standards to SMBs, but the obligation is real and enforceable since 2 August.

Why Local AI Simplifies Compliance

Organisations on local AI infrastructure hold the advantage on Article 50: no dependency on a cloud vendor's release cycle, full control of the interface, no opaque intermediate layers. While SaaS customers wait for their vendor to build the label in, a local operator can act at once.

We audit your AI systems against the Article 50 requirements and implement the disclosure with you. Talk to us about your stack.

Frequently asked questions

Does a chatbot on my company website have to disclose it is an AI?

Yes. Since 2 August 2026, Article 50(1) of the EU AI Act requires that users are informed before or at the start of the interaction that they are talking to an AI system. A chat widget is not obviously AI without an explicit label, so a visible badge or an automated first message satisfies the duty.

Does Article 50 apply to AI run locally on our own hardware?

Yes. Article 50 attaches to the user-facing interaction, not to where inference happens. Whether the model runs in a data centre or on a Mac Studio in your own server room makes no difference to the disclosure obligation.

By when must AI-generated text or images be marked in machine-readable form?

For systems placed on the market since 2 August 2026, the Article 50(2) marking duty applies immediately. For generative systems that were already on the market before that date, the European Commission guidelines allow a transition period until 2 December 2026.

Share this article