Somewhere on your website there is probably a chat bubble in the corner of the screen. A customer types a question, gets an answer within seconds, and never thinks twice about who, or what, replied. Since 2 August 2026, that silence is a legal problem. Under Article 50 of the EU AI Act, if that reply came from an AI system rather than a person, your business now has to say so, clearly, before or during that first interaction.
This is not a future deadline to plan around. The obligation has applied since 2 August 2026, and national authorities can already enforce it. If you run a customer-facing chatbot, a booking assistant, or any AI tool that talks directly to the public, this is worth nine minutes of your time today.
Everything About Article 50 of the EU AI Act
TL;DR: Since 2 August 2026, any AI system that interacts directly with people must make clear that it’s AI, unless that fact is already obvious to a reasonably well-informed user, and the Commission reads that exemption narrowly. Most public-facing SME chatbots will not qualify for it. A separate, narrower transition to 2 December 2026 exists, but it only covers the technical duty to machine-readably mark AI-generated content, not the disclosure duty itself. Penalties reach €15 million or 3% of turnover for large firms; SMEs get a more favourable calculation, covered below, but the disclosure duty applies regardless of your size.
What actually changed, and when
There has been a lot of coverage this year about parts of the EU AI Act being delayed. It’s easy to assume this rule was pushed back too. It wasn’t. The Digital Omnibus package that pushed the Annex III high-risk compliance timeline back to December 2027 specifically left Article 50’s transparency duties on their original schedule. The disclosure requirement for chatbots and other systems that interact directly with people took effect on 2 August 2026, full stop, regardless of what happened to other parts of the Act.
Article 50 actually sets out four separate transparency duties, each attaching to a different kind of system: disclosure for AI that interacts directly with people, machine-readable marking for AI that generates synthetic audio, image, video or text, disclosure obligations for emotion-recognition and biometric-categorisation systems, and labelling for deepfakes.
For an SME running a customer support chatbot, the first of those, direct-interaction disclosure, is almost certainly the one that applies to you, and it is the one already in force with no transition period attached.
- ✓Your chatbot or assistant is accessible to the general public
- ✓Users could reasonably include people of any age or level of AI familiarity
- ✓The interaction happens by text or voice with no other obvious sign it's AI
- ✓You're not completely certain a user would instantly realise it's a machine
- −The tool is built only for technical users who are knowingly testing an AI model
- −The interface is explicitly framed as an AI demo, not a general support channel
- −Every likely user already knows, with almost no doubt, that it's AI
- −You'd be comfortable defending that assumption to a regulator, in writing
What counts as compliant disclosure
The rule itself is not complicated to satisfy. The information has to be provided clearly and distinguishably, at the latest by the time of the first interaction.
In practice, that usually means the chatbot identifies itself as AI in its opening message, before the customer has asked their first question, rather than burying a disclosure somewhere in a privacy policy nobody reads.
A voice assistant can do the equivalent with a short spoken line at the start of a call. For longer or more sensitive conversations, a persistent visual badge or a periodic reminder is sensible practice on top of the opening disclosure, even though the Act sets the bar at the first interaction.
What is not enough is designing a chatbot to sound convincingly human and hoping nobody asks.
Commission guidance reads the “obvious from context” exemption narrowly, confining it to situations where there is almost no doubt left about the artificial nature of the interaction, and explicitly weighs who is likely to be using the system.
- A tool built for developers who know they’re testing a model might reasonably qualify.
- A support widget on a public retail website, used by people of every age and every level of familiarity with AI, is a much harder case to argue exempt, no matter how obviously scripted the responses feel to you.
If you have to think about whether your chatbot’s AI nature is “obvious enough” to skip disclosure, it almost certainly isn’t. Add the line. It costs nothing and removes the argument entirely.
What happens if you don’t comply
Article 50 breaches sit in the middle tier of the AI Act’s penalty structure, capped at €15 million or 3% of worldwide annual turnover, whichever is higher, for a large undertaking. That is the figure most coverage of this topic leads with, and it sounds alarming for a business turning over a few million euros a year. It is worth reading the next part properly rather than skimming past it.
Article 99(6) specifically reverses that calculation for SMEs and startups: the lower of the two figures applies, not the higher. That is a materially different, and considerably less frightening, exposure than the headline number suggests.
It does not mean the obligation doesn’t apply to you, or that enforcement won’t happen. National market surveillance authorities are already empowered to act, and the published maximums exist for serious or repeated breaches rather than a single, quickly-corrected oversight. But it does mean the disclosure requirement is simply a same-week fix, not a five-figure legal project.
Building or buying an AI support assistant? Compliant disclosure is built in from day one, not bolted on afterwards, and stays current as the guidance develops.
What this means if you’re evaluating an AI support tool
If you haven’t deployed a chatbot yet and are weighing whether to, this is one more line item to check before you sign anything, alongside training data quality and ongoing maintenance.
Ask any AI support vendor directly whether disclosure is configured by default, how it is worded, and whether they treat it as your responsibility to add or theirs to build in. One AI Act compliance-checker tool reports that transparency obligations are the second most common issue its users flag, behind only general AI-literacy requirements, so you are far from the only business working through this right now.
A done-for-you assistant that is trained, deployed and maintained by someone else should absorb this kind of regulatory change as part of the ongoing service, the same way it absorbs a connected app changing its login method or a new question type appearing in your inbox.
That is a really different proposition from a self-built chatbot where compliance is one more thing sitting on your own to-do list, next to the marketing calendar and the payroll run.
See the AI Customer Support Assistant
Trained on your own documentation, disclosure built in from the first message, and maintained as the rules evolve.
Frequently Asked Questions About the EU AI Act's Chatbot Disclosure
Does the EU AI Act's chatbot disclosure rule apply to my business?
If your business uses a chatbot, virtual assistant, or any AI system that interacts directly with customers in the EU, Article 50(1) almost certainly applies to you, regardless of your company’s size or where you are based. The obligation falls on the provider of the AI system, and it applies whenever the output is used in the EU, so a UK or US business serving EU customers is in scope too. There is no small-business exemption from the disclosure duty itself, only from certain penalty calculations, covered below.
When did this rule come into force, and is there a grace period?
The core disclosure duty under Article 50(1) has applied since 2 August 2026, with no grace period. A separate, narrower transition does exist, but it only covers Article 50(2), the requirement to machine-readably mark AI-generated content such as synthetic audio, image, or video, and only for systems that were already on the market before 2 August 2026. Those providers have until 2 December 2026 to bring that specific marking capability into conformity. If your chatbot does not yet identify itself as AI, that is not covered by any grace period and should be fixed now, not in December.
What happens if I don't comply?
Article 50 breaches sit in the middle tier of the AI Act’s penalty structure under Article 99(4), which caps fines at fifteen million euros or three per cent of worldwide annual turnover, whichever is higher for a large undertaking. For SMEs and startups specifically, Article 99(6) reverses that calculation: the lower of the two figures applies, not the higher, which meaningfully changes the real-world exposure for a smaller business. National market surveillance authorities enforce these rules, and the headline figures are maximums for serious or repeated breaches, not a starting point for a first-time, non-deliberate oversight.
Are there any situations where I don't need to disclose?
The Act exempts cases where it is already obvious to a reasonably well-informed, observant and circumspect person that they are talking to an AI system, taking into account who is likely to be using it. In practice this exemption is read narrowly. A tool built only for professional developers who clearly know they are testing an AI model might qualify. A customer-facing support chatbot on a public website, used by people of varying ages and levels of familiarity with AI, is very unlikely to qualify, and should carry an explicit disclosure regardless of how obviously robotic it might seem to you.
This article explains general regulatory obligations as understood at the time of writing and does not constitute legal advice. Rules, guidance, and enforcement practice around the EU AI Act are still developing; if your compliance position is unclear or the stakes are significant, speak to a qualified lawyer.