Short answer

Since 2 August 2026, a chatbot or voice bot that talks to people in the EU has to tell them they are talking to an AI, at the latest at the first interaction, unless that is already obvious. The rule is Article 50 of the EU AI Act. It also covers deepfakes and AI written text on matters of public interest. Breaking it can cost up to 15 million euros or 3% of worldwide turnover, and small companies pay the lower of the two.

2 Aug 2026Article 50 applies to chatbots, deepfakes and AI news text
€15M or 3%Maximum fine, whichever is higher (lower for SMEs)
2 Dec 2026Watermark deadline for generative AI placed on the market before August

Most small businesses meet this rule the moment they add a support widget, an AI sales assistant or an AI phone agent to their site. You do not need to have built the model yourself. If people in the EU can reach the bot, the rule reaches you too, even if your company is in the United States.

This guide covers who carries which duty, the exact wording you can put in front of users, where it has to appear, and the few cases where you can skip it.

What Article 50 actually requires

Article 50 has four duties. Two sit with the provider (the company that builds the AI system) and two sit with the deployer (the business that uses it with the public). Many small companies are both, for example when they build their own assistant on top of a model API.

DutyWhoWhat it means in practice
Tell people they are talking to AI (Art. 50(1))ProviderThe chatbot, avatar or voice agent must be designed so users are informed, unless it is obvious to a reasonably well informed person.
Mark AI generated media (Art. 50(2))ProviderSynthetic audio, images, video and text must carry a machine readable marker that shows they were made or changed by AI.
Disclose emotion recognition or biometric categorisation (Art. 50(3))DeployerIf you run a system that reads emotions or sorts people by biometric traits, you must tell the people exposed to it.
Label deepfakes and AI news text (Art. 50(4))DeployerDeepfake images, audio or video must be disclosed. AI written text published to inform the public about matters of public interest must be disclosed unless a human reviewed it and a person holds editorial responsibility.

The information has to be clear and distinguishable, and it has to reach the person at the latest at the time of the first interaction or exposure. A line buried on page nine of your Terms of Service does not do that.

Does it apply to a business outside the EU?

Yes, if the output of your AI system is used in the EU. The AI Act reaches providers and deployers established outside the Union when their system's output is used inside it. A US store whose support bot answers a shopper in Madrid is in scope for that conversation. The simplest way to stay safe is to show the disclosure to everyone rather than trying to detect where each visitor is.

Wording you can use today

There is no required sentence. The test is whether a normal person understands, at first contact, that they are dealing with an AI. These examples pass that test and fit most sites.

Website chat widget, first message

Hi, I'm the Outline Technologies assistant. I'm an AI, not a person. I can answer questions about orders and returns, or pass you to our team.

Voice or phone agent, first sentence

Hello, you're speaking with an automated AI assistant for Outline Technologies. You can ask for a human at any time.

AI generated image or video in a post

This image was created with AI.

An article written with AI and published without editorial review

This article was written by an AI system and has not been reviewed by an editor.

Keep the label next to the thing it describes. A persistent "AI" tag in the chat header, plus the opening line, is better than a single sentence that scrolls away.

Where the disclosure must appear

  • In the interface itself. The opening message of the chat, the first sentence of the call, or a caption on the image. Not only in a policy page.
  • Before or at the first interaction. Showing it after the user has already shared personal details is too late.
  • In a form people can perceive. Read it aloud in voice products. Make sure a screen reader announces it in chat widgets.
  • Again in your legal pages. Your privacy policy should say which AI tools process chat messages. An AI transparency notice explains the rest in one place.

When you can skip it

The chatbot duty does not apply when it is obvious from the circumstances that the user is dealing with an AI. Treat that exception narrowly. A product called "AI Writer" whose whole purpose is generating text is an obvious case. A support chat that uses a human first name and a photo of a person is the opposite, and it is exactly what the rule targets.

The text duty for deployers does not apply when a human has reviewed the text and a person or company holds editorial responsibility for publishing it. The marking duty for providers does not cover tools that only assist with standard editing, or that do not substantially change what the user put in.

What changed with the AI Omnibus

The EU's Digital Omnibus on AI entered into force on 27 July 2026. It pushed back several high risk obligations, but it did not move the chatbot duty or the deepfake duty, which apply from 2 August 2026. The one Article 50 change is a four month grace period for the machine readable marking duty in Article 50(2): generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply.

Fines

Breaking Article 50 can lead to fines of up to 15 million euros or 3% of total worldwide annual turnover for the previous year, whichever is higher. For small and medium sized businesses and start ups the cap works the other way round: the fine is capped at whichever of the two is lower. National market surveillance authorities enforce it, so the first cases will come from the country where users complain.

A five step checklist for a small business

  1. List every place a customer can meet AI on your site, app, phone line and social accounts.
  2. Add a first message or first sentence that says it is an AI, in plain words.
  3. Add a visible "AI" label to the chat header or voice menu so it stays in view.
  4. Caption AI images and video in marketing where they could pass for real.
  5. Publish an AI transparency notice and update your privacy policy to name the AI tools that process messages.

You can write both pages for free with the AI transparency notice generator and the AI content disclaimer generator. For the wider picture of which pages an AI product needs, see legal pages every AI tool needs in 2026.

Frequently asked questions

Yes, if people in the EU can use it and it is not already obvious that it is an AI. The information must reach them at the latest at the first interaction, so put it in the opening message.

It applies when the output of your AI system is used in the EU. A US business whose chatbot answers visitors in the EU is covered for those conversations.

No. The disclosure has to be clear and reach the person at the first interaction or exposure. Policy pages are a good second place, not the only place.

Up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. For small and medium sized businesses the cap is whichever of the two is lower.

The marking duty for providers of generative AI applies from 2 August 2026. Systems already on the market before that date have a grace period until 2 December 2026.

Only text published to inform the public on matters of public interest, and only when no human reviewed it under someone's editorial responsibility. Labelling AI help is still a good habit for trust.

The bottom line

If a customer can talk to an AI on your site, say so in the first message, keep a visible AI label in the chat, and explain the details in an AI transparency notice. It takes an afternoon and removes one of the easiest fines in the AI Act.

Write your AI transparency notice free

Answer a few questions and get a notice written for your product, ready to publish.

Open the generator

Sources

  1. EU AI Act, Article 50: Transparency obligations for providers and deployers of certain AI systems
  2. EU AI Act, Article 99: Penalties
  3. European Commission: Transparency obligations under Article 50 of the AI Act (FAQ)
  4. White & Case: EU AI Omnibus enters into force, amending the AI Act
  5. Gibson Dunn: EU AI Act Omnibus agreement, postponed high risk deadlines and other key changes
Cite this article

Shanti, A. (2026). AI Chatbot Disclosure Rules: What EU AI Act Article 50 Requires. FreeTOS.org. https://freetos.org/blog/ai-chatbot-disclosure-eu-ai-act-article-50

This article explains the rules in plain language. It is not legal advice. Last reviewed 27 September 2026.