All guides

Jul NaN, 2026 · 19 min read

Chatbot disclosure requirement under EU AI Act Article 50

Minimalist illustration of a conversation interface with a speech bubble containing a subtle AI circuit icon, clean sans

Short answer: Under EU AI Act Article 50, providers of AI systems intended to interact directly with natural persons—chatbots included—must design and develop them so that users are informed they are interacting with an AI system. The duty applies whether or not the system is high-risk, and falls away only where the AI nature is obvious to a reasonably well-informed, observant and circumspect person. Disclosure must be clear and accessible. The binding application date is 2 August 2026.


A chatbot disclosure requirement is a legal obligation to inform users when they are communicating with an artificial intelligence system rather than a human. Under the EU AI Act, Article 50(1) places this obligation on the *provider* of an AI system intended to interact directly with natural persons, and it comes into force on 2 August 2026. Deployers carry separate transparency duties under Article 50(3) and 50(4).


What Article 50 Actually Requires

Article 50 of Regulation (EU) 2024/1689 sits in Chapter IV, headed "Transparency obligations for providers and deployers of certain AI systems." It bundles four duties, each attached to a different actor and kind of system. It prescribes no format or wording; it sets an outcome: the relevant people must be informed, clearly and accessibly.

The Four Paragraphs and Who Each One Binds

  • 50(1) — providers. AI systems intended to interact directly with natural persons must be designed and developed so the persons concerned are informed they are interacting with an AI system, unless this is obvious to a natural person who is reasonably well-informed, observant and circumspect. A narrow exception covers systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards.
  • 50(2) — providers, including of general-purpose AI systems, of systems generating synthetic audio, image, video or text. Outputs must be marked in a machine-readable format and be detectable as artificially generated or manipulated. Excepted: assistive or standard-editing functions that do not substantially alter the input data or its semantics.
  • 50(3) — deployers of emotion recognition or biometric categorisation systems. Inform the people exposed, and process personal data in line with the GDPR.
  • 50(4) — deployers. Disclose that image, audio or video content is a deepfake, and disclose AI-generated or AI-manipulated text published to inform the public on matters of public interest—unless the text underwent human review with editorial responsibility. Narrow exceptions cover evidently artistic, creative or satirical works.

A chatbot is squarely a 50(1) case. The duty sits with whoever provides it, not with every business that switches it on.

Article 50 Is Independent of the High-Risk Rules

This is the most common misreading, so it is worth stating plainly: Article 50 is not part of the high-risk regime. Those rules live in Chapter III, built around Article 6 and Annex III. Article 50 lives in Chapter IV and stands on its own.

Two consequences follow. First, a system does not have to be high-risk for Article 50 to apply—an ordinary support chatbot nowhere near Annex III is still covered by 50(1), because the test is direct interaction, not risk classification. Second, being high-risk does not by itself trigger Article 50. The two regimes can overlap in one product, but neither implies the other, and each must be assessed separately.

The Binding Requirement: Inform Users of AI Interaction

Article 50(1) requires that persons be informed they are interacting with an AI system. This is a transparency obligation, not a consent requirement: users do not opt in, they are simply told. Note the wording: systems must be *designed and developed* so that people are informed. That is a product-design obligation, which is why it lands on the provider rather than on whoever embeds the system.

Timing: Before or During Interaction

The outcome required is that the person knows they are dealing with an AI system, and being told afterwards informs nobody in time. Most teams disclose at the start of the conversation—a welcome message, a persistent label, or a banner.

Format Flexibility: No Single Mandated Method

Article 50(1) does not mandate HTML attributes, JSON-LD headers, banners, or any specific technology. Disclosure can be text in the chat interface, a tooltip, a persistent label, or a combination. The constraint is clarity and accessibility—the user must understand, in plain language, that they are speaking with an AI system. Machine-readable *marking* is separate: that is the 50(2) duty for synthetic content.


Does Your Chatbot Trigger Article 50?

Most chatbots that talk to people do fall under Article 50(1). The question is not how consequential the conversation is—it is whether the system is intended to interact directly with natural persons, and whether its AI nature is already obvious.

The Real Gate: Direct Interaction, Then Obviousness

Two questions, in order.

One: is the system intended to interact directly with natural persons? If people converse with it—typing, speaking, exchanging turns—the answer is almost always yes. That covers support bots, sales assistants, onboarding guides, in-product copilots, and voice agents. A model that only scores records in a back-office batch job, with no natural person on the other end, is not a 50(1) case.

Two: is the AI nature already obvious? The exemption is written from the point of view of a natural person who is reasonably well-informed, observant and circumspect—an objective standard, not a claim about what your power users happen to know, and not met by an onboarding email sent weeks earlier.

Obviousness is a narrow escape hatch, not the main rule. If you are building an argument for why users must surely have realised, that argument is the disclosure you should have shipped instead.

Customer Support vs. Decision-Making Chatbots

Both are in scope, and the distinction people usually draw between them is not the one Article 50 draws. A chatbot answering questions about features, troubleshooting, or billing is intended to interact directly with natural persons. That is enough. It does not matter that it allocates nothing and decides nothing—50(1) has no such threshold.

What varies between a support bot and a hiring-screening bot is which *other* obligations stack on top. A screening tool may well be high-risk under Chapter III and carry a much heavier load. Both owe the same 50(1) disclosure.

Examples: Which Chatbots Are In Scope

  • Product support or FAQ chatbot: Answers questions about features, billing, or how-to. Direct interaction. 50(1) applies to its provider.
  • Hiring screening chatbot: Conducts initial interviews or scores candidates. 50(1) applies—and Chapter III high-risk duties may apply on top.
  • Loan or benefits assistant: Discusses eligibility with an applicant. 50(1) applies—and again, Chapter III may apply separately.
  • Voice agent on a phone line: Speech rather than text changes nothing, and obviousness is harder to argue for a convincing synthetic voice, not easier.

Examples: Where the Duty May Be Met by Context

  • A widget labelled as an AI assistant throughout the UI: The duty is not avoided—it is met. The label *is* the disclosure. Keep evidence of it.
  • No natural person in the loop: A batch classifier with no conversational surface is outside 50(1). Assess the other paragraphs separately.
  • Genuinely unmistakable contexts: Where a reasonably well-informed, observant and circumspect person could not plausibly think they were talking to a human, the exemption may apply. Treat this as a narrow, documented, counsel-reviewed exception, not a default.

Article 50 can also reach providers and deployers outside the EU where a system is placed on the EU market, put into service in the EU, or its output is used in the EU.


Article 50 Applicability & Disclosure Workflow

Use this framework to determine whether Article 50(1) applies, who bears the duty, and what method to implement.

StepQuestionYesNo
1Is your chatbot intended to interact directly with natural persons?Proceed to Step 2.50(1) likely does not apply. Assess 50(2)–(4) and Chapter III separately.
2Is the AI nature already obvious to a reasonably well-informed, observant and circumspect person?The duty may be met by context—document the reasoning, review with counsel.Proceed to Step 3. Assume this is you unless you can show otherwise.
3Is there an EU nexus—EU market, put into service in the EU, or output used in the EU?Proceed to Step 4.Article 50 is unlikely to reach you. Re-check on EU market entry.
4Are you the provider (you develop it and place it on the market under your own name or mark)?50(1) is your duty. Proceed to Step 6.Proceed to Step 5.
5Are you a deployer using someone else's chatbot?50(1) sits with the provider. Check whether *you* trigger 50(3) or 50(4).Clarify your role (see the next section).
6Does your system also generate synthetic audio, image, video or text?50(2) marking may apply to you as provider, on top of 50(1).Proceed to Step 7.
7Choose and deploy a disclosure method, then verify it is live.Test that it is present from the start of the interaction. Log date and method.Update your evidence log whenever disclosure changes.

Worked example:

You build a SaaS platform with an in-product support chatbot and sell it to EU customers.

  • Steps 1–3: Yes, customers type questions and the bot answers; no, the AI nature is not obvious (the widget opens with a friendly first name and no AI label); yes, EU customers use the platform.
  • Step 4: You develop the chatbot and ship it under your own name, so you are the provider. 50(1) is your duty—not your customers'.
  • Step 5: Not applicable. Calling a third-party model through an API does not move the duty off you.
  • Step 6: The bot writes free-text answers, so assess 50(2) marking alongside 50(1).
  • Step 7: You add a persistent chat label ("AI assistant") plus a first-turn line: "You're chatting with an AI assistant. Ask for a human any time." Verify it renders on every entry point and log the deployment date.

Provider vs. Deployer: Who Discloses?

The AI Act splits responsibility between the provider (who develops the system and places it on the market under its own name or mark) and the deployer (who uses it under its own authority). For a chatbot the split is not a grey area: Article 50(1) is the provider's duty. Deployers carry the separate duties in 50(3) and 50(4).

Definition: Who Is the Provider?

A provider is the legal entity that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. If your company builds the chatbot your customers embed, you are the provider—and 50(1) is designed and developed into your product, not delegated to your customers' terms of service.

Building on a third-party model does not change this. Calling a general-purpose model through an API does not remove duties attached to the system you provide. Modifying or fine-tuning such a model does not automatically make you *its* provider, but significant modifications can require a separate assessment—run that edge case past counsel.

Definition: Who Is the Deployer?

A deployer is the legal entity using an AI system under its own authority. If you embed a chatbot someone else provides, you are its deployer, and your own Article 50 duties are those in paragraphs 3 and 4. You do not carry the 50(1) duty on the provider's behalf.

That is a legal allocation, not a practical excuse: if the provider's disclosure is missing or broken in your deployment, your users are uninformed and your product is what they are looking at. Build the chatbot and run it yourself, and both sets of duties are yours.

Shared Responsibility Scenarios

  • You build and run your own chatbot: You are both. 50(1) is yours as provider; check 50(2)–(4) for anything else the system does.
  • You embed a third-party chatbot: The vendor is the provider and carries 50(1). Verify the disclosure works in your integration and make it a contractual requirement. If you configure the bot to publish AI-generated text informing the public on matters of public interest, 50(4) may land on you.
  • You license your chatbot to other companies: You are the provider and 50(1) travels with the product. Ship the disclosure in the product rather than leaving it to licensees.
  • You white-label someone else's chatbot: Placing a system on the market under your own name or mark can make you its provider. Assess this with counsel—it changes who owns 50(1).

What Each Party Should Document

Providers: the determination that the system is intended to interact directly with natural persons; the disclosure designed into the product (exact text, placement, behaviour); any reliance on the obviousness exemption and the reasoning; whether the system generates synthetic content and how 50(2) marking is applied.

Deployers: which paragraphs apply to them—50(3) or 50(4)—and why; verification that the provider's 50(1) disclosure is live in their deployment; the disclosure method implemented for their own duties; any changes to the system, configuration, or disclosure over time.


How to Implement Disclosure

Article 50(1) does not mandate a technology or format. Disclosure must be clear, accessible, and present from the start of the interaction.

In-UI Disclosure: Banners, Labels, and Welcome Messages

The most straightforward approach is visible text in the interface:

  • Chat label: At the top of the chat window, display "AI Assistant" or "Powered by AI."
  • Welcome message: On open, show: "Hello! I'm an AI assistant. Ask for a human any time."
  • Banner: A persistent banner above the chat input: "You are interacting with an AI system."

Trade-off: Visible disclosure is easy to understand and leaves a clear audit trail, but it takes up screen space. A persistent label costs less real estate than a banner and survives long conversations better than a first-turn message alone.

Machine-Readable Marking: A Different Obligation

Machine-readable marking is not how you satisfy 50(1). It is the substance of 50(2), which applies to providers of systems generating synthetic audio, image, video or text: the output must be marked in a machine-readable format and detectable as artificially generated or manipulated. A chatbot writing free-text answers may be in scope for both paragraphs.

Important: Ad-hoc metadata such as a `data-ai-disclosure` attribute or a JSON-LD block is advisory documentation, not signed provenance and not C2PA certification. It does not discharge 50(2), and it does not replace the visible disclosure 50(1) calls for.

Trade-off: Marking answers a different question than "does this user know they are talking to an AI?" Implement both, and keep them separate in your records. For systems already on the market, a limited transition may apply to the marking obligation—check the current position rather than assuming it covers you.

Terms of Service and Privacy Policy Integration

You can describe your Article 50 posture in your terms or privacy policy—for example: "Our support assistant is an AI system. You can ask to be transferred to a human at any point in the conversation."

Trade-off: This creates a written record, but most users never read terms of service, so it alone is unlikely to satisfy the "informed, clearly and accessibly" outcome. Treat it as supporting documentation and combine it with visible disclosure.

Timing: When Disclosure Must Appear

The person needs to know as the interaction begins. If the user clicks "Start Chat," disclosure can appear in the widget header and the first message. If the bot appears without user initiation, disclosure must be in that first contact. Disclose at the start of every conversation, not once per session, and keep a persistent label visible throughout.

Accessibility Requirements

Disclosure must be accessible to all users, including those with disabilities:

  • Text must be readable: Sufficient contrast, clear fonts, adequate size.
  • Text must be in plain language: "AI system" is clear; "algorithmic decision support mechanism" is not.
  • Disclosure must not be hidden: Not buried in a collapsed menu or behind a link the user must find.
  • Disclosure must work everywhere: Test mobile, tablet, and desktop, and make sure screen readers can read it.
  • Voice interfaces need an audible equivalent: A visual-only label does nothing for a caller.

Evidence and Audit Readiness

Article 50 does not require certification or pre-approval, but you must be able to demonstrate your compliance effort if asked. Keep records of the scope decision (which paragraphs apply, in which role, and why), the disclosure method deployed, verification that it is live, and changes over time. An append-only log is the safest approach.

What to Document: Scope, Method, Verification

Scope decision:

  • Date of the decision, the chatbot's name and version, and the use case.
  • Your role for this system: provider, deployer, or both.
  • The reasoning: Is it intended to interact directly with natural persons? Is the AI nature obvious to a reasonably well-informed, observant and circumspect person? Does it generate synthetic content? Is there an EU nexus?
  • Conclusion: which paragraphs of Article 50 apply, and who decided.

Disclosure method:

  • The method chosen (for example, "persistent chat label," or "marking of generated text").
  • The exact text or code deployed, and screenshots showing how it appears to users.
  • The date it was deployed, and by whom.

Verification:

  • Test results confirming disclosure appears on all user paths (desktop, mobile, browsers, every entry point).
  • Evidence that disclosure is accessible (for example, a screen reader test).
  • User feedback showing users understand it.

Append-Only Logging for Audit Trails

An append-only log can only be added to, never edited, creating a tamper-evident trail of decisions and changes. Example structure:

DateEventDetailsOwnerStatus
2024-11-01Scope decisionSupport chatbot; direct interaction; not obvious; we are provider; Art. 50(1) appliesJane (PM)Approved
2024-11-15Disclosure method selectedPersistent chat label + first-turn messageJohn (Eng)Implemented
2024-11-20Disclosure deployedLabel: "AI assistant"; first turn: "You're chatting with an AI assistant."John (Eng)Live
2024-11-22Verification completedTested on Chrome, Safari, mobile; screen reader passedSarah (QA)Passed
2024-12-10System updateUpgraded model version; re-tested disclosureJohn (Eng)Still live

This log is evidence that you thought the requirement through, implemented it, and kept it current.

Verification Checklist: Is Disclosure Live?

Before claiming compliance, verify:

  • [ ] Disclosure appears every time a user starts a conversation.
  • [ ] Disclosure appears on every entry point, including proactive or outbound messages.
  • [ ] Disclosure text is clear and uses plain language.
  • [ ] Disclosure is visible on all devices and browsers tested.
  • [ ] Disclosure is present before the user submits any input.
  • [ ] Disclosure is accessible to screen readers and other assistive technology.
  • [ ] Disclosure is not hidden behind a menu, link, or collapsed section.
  • [ ] If the system generates synthetic content, 50(2) marking is assessed separately.
  • [ ] You have screenshots or recordings showing disclosure in action.

Updating Disclosure If the System Changes

If you change the chatbot (new model version, new use case, new region, new output modality), re-evaluate which parts of Article 50 apply and update disclosure if needed. Log the date, what changed, whether the same paragraphs still apply and your role is unchanged, any change to disclosure text or method, and re-verification that it is live.


FAQ

Does Article 50 apply to all chatbots?

Article 50(1) applies to AI systems intended to interact directly with natural persons, which covers chatbots very broadly—including ordinary customer-support and FAQ bots. There is no high-risk threshold and no test about influence over decisions. The duty falls away only where the AI nature is obvious to a reasonably well-informed, observant and circumspect person.

Does my chatbot have to be high-risk for Article 50 to apply?

No. Article 50 sits in Chapter IV and is independent of the high-risk regime in Chapter III. A system nowhere near Annex III can still owe a 50(1) disclosure, and a high-risk system does not owe one merely by being high-risk. Assess the two regimes separately.

What counts as 'clear and accessible' disclosure?

It must be understandable in plain language (for example, "This is an AI system"), visible without the user having to search for it, and accessible to users with disabilities. It can be a banner, a chat label, a welcome message, or a combination.

Can I use machine-readable marking instead of visible disclosure?

No—they answer different obligations. Marking is the substance of 50(2) for synthetic content. 50(1) is about a person understanding they are talking to an AI, and most users never inspect page source. Implement both where both apply.

What is the difference between provider and deployer obligations under Article 50?

The provider develops the system and places it on the market under its own name or mark; the deployer uses it under its own authority. Paragraphs 50(1) and 50(2) bind providers; 50(3) and 50(4) bind deployers. If you both build and run the chatbot, both sets apply.

What happens if I do not comply by 2 August 2026?

The AI Act enforcement framework is still being operationalised. Non-compliance can result in regulatory action, but specific enforcement practice is not yet settled. The safest approach is to implement disclosure before the deadline and keep records. Consult qualified legal counsel about your situation.

Do I need approval or certification for my disclosure?

No. Article 50 does not require certification, pre-approval, or third-party validation. You implement disclosure, verify it is live, and keep records.


*This article is guidance, not legal advice, and nothing here guarantees compliance. Article 50 assessments turn on your system, your role, and your market. Consult qualified counsel for your case.*

See exactly what applies to your product

Run the free check

Sources

This is compliance tooling, not legal advice. Consult counsel for your specific case.