EU AI Act Article 50: disclosing the chatbot on your website

Since 2 August 2026, people chatting with an AI system must be told so. The legal duty in Article 50(1) sits with the provider of the chatbot, not automatically with every website that embeds one. Here is who has to do what, and a practical checklist if you run Intercom, Zendesk or a custom GPT widget.

Updated 1 October 202611 min readBy the Dazr Compliance team

How does the chatbot on your site work?

You are the deployer

The vendor is the provider and must build in the disclosure. Your job is to check that it is visible and not switched off or overwritten by your own branding.

  • Open the widget as a visitor, on desktop and mobile. Is there an AI label in the first message and near the input?
  • Ask the vendor how they meet Article 50(1), and keep the answer.
  • Keep dated screenshots of the disclosure as evidence.

Indicative, based on the Commission's Article 50 guidelines of 20 July 2026. Not legal advice.

  • Article 50(1) obliges providers to design chatbots so that people are told they are dealing with AI, unless that is obvious. It applies from 2 August 2026 and the Digital Omnibus did not change it.
  • If you build your own chatbot (for example a GPT-based widget developed in-house or by an agency for you) and run it under your name, you are the provider. If you switch on Intercom's or Zendesk's AI agent, the vendor is the provider and you are the deployer.
  • Deployers have their own Article 50 duties only in specific cases: emotion recognition or biometric categorisation (50(3)), deepfakes and AI-written public-interest text (50(4)).
  • In practice every website owner should still make sure the label is visible: a clear first message plus a persistent "AI" badge. Terms and conditions alone are not enough.

What Article 50 actually says

Article 50 of the AI Act (Regulation (EU) 2024/1689) is a short list of transparency duties for "certain AI systems". They apply whether or not the system is high-risk. The paragraph that matters for chatbots is the first one:

"Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use."

Three things stand out:

  • The addressee is the provider. The duty is a design duty: the system must be built so that people are informed. Paragraph 1 does not mention deployers.
  • The exception for "obvious" cases is narrow. The Commission's Article 50 guidelines of 20 July 2026 say it should be read restrictively, and they list "AI chatbots embedded in online platforms or assistance support tools (helpdesks)" as an example where the exception does not apply.
  • Paragraph 5 sets the form: the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction", and must meet applicable accessibility requirements.

Many pages that rank for this topic say that "businesses using chatbots must disclose them under Article 50". That mixes up the roles. The legal duty in 50(1) belongs to whoever is the provider. As we explain below, a website owner is often the deployer, and is sometimes the provider without realising it.

Are you the provider or the deployer?

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. A deployer uses an AI system under its authority in a professional context. The Commission's guidelines give two examples that matter for websites:

  • A company that offers a chatbot under its own name to other businesses, which can plug it into their processes without modifying it, is the provider. That is the position of chat vendors that sell AI agents as a feature.
  • A company or public body that has developed a chatbot in-house and puts it into service for its own use, under its own name, is also a provider. And a company that takes an existing generative AI system, modifies it (for example with new training data) and puts it into service under its own name becomes the provider of that new system.
Your set-upLikely roleWhat that means
Intercom, Zendesk or a similar help-desk tool with the vendor's AI agent switched onDeployer (the vendor is the provider)The vendor must build in the disclosure. You should check that it is visible and not switched off or overwritten by your own branding.
Live chat answered only by people (Tawk.to, plain Zendesk Chat)Not in scope of 50(1)No AI system interacts with the visitor. If you add AI-suggested replies that a human sends, the visitor still deals with a human.
Custom widget built by your team or agency on an LLM API (OpenAI, Mistral, Anthropic...) and shown as "your" assistantProviderYou must design the disclosure in. The model provider's own duties as a general-purpose AI model provider do not cover your interface.
A vendor's chatbot that you substantially modify (own training data, fine-tuning) and run under your brandPossibly provider of a new systemPer the guidelines' example, modification plus own name makes you a provider. Simple configuration, such as a knowledge base or tone of voice, is not addressed explicitly. Treat it cautiously.

Why deployers should care anyway: if the label does not show on your site, your visitors are the ones who are misled. Consumer law also applies separately. The guidelines point out that under the Unfair Commercial Practices Directive and the Consumer Rights Directive, the fact that a service is AI-driven may be a main characteristic that has to be disclosed, "irrespective of whether the interaction is considered 'obvious'".

Where deployers do have duties

Paragraphs 3 and 4 of Article 50 are addressed to deployers. For a typical SME website, they become relevant in three situations:

  • Emotion recognition or biometric categorisation (50(3)). If you deploy such a system, you must inform the people exposed to it. Note the definition: an emotion recognition system infers emotions "on the basis of their biometric data" (Article 3(39)). Sentiment scoring of typed chat text is not based on biometric data. A voice bot that infers mood from the caller's voice may well be, and emotion recognition is banned outright in workplaces and education (Article 5(1)(f)).
  • Deepfakes (50(4), first subparagraph). If your chatbot or marketing team generates realistic images, audio or video of real people, places or events, you must disclose that the content is artificial.
  • AI-generated text on matters of public interest (50(4), second subparagraph). If you publish AI-written text "with the purpose of informing the public on matters of public interest", you must say so, unless a human reviewed it and someone holds editorial responsibility. A product FAQ is not public-interest information. An AI-written news update about a regulation might be.

Machine-readable marking of generated content (watermarks, metadata) under 50(2) is a provider duty again. If your custom chatbot can generate images or audio, you are the one who must ensure the outputs are marked, as far as technically feasible.

How and when to disclose

The Commission's guidelines describe what works and what does not. Recommended techniques include:

  • a first-turn greeting that says the assistant is AI;
  • a plain-language label close to the input field, ideally persistent throughout the conversation;
  • visual cues such as an "AI" badge or icon, as a complement to the text;
  • for voice bots, a spoken statement at the start ("This is an AI-powered assistant"), with reminders in long calls.

The guidelines also list techniques that are insufficient on their own: disclosure only in terms and conditions, URLs or documentation; machine-readable marks the user cannot perceive; vague labels such as a generic "assistant"; and human-like personas that may mislead. A chatbot called "Sophie" with a stock photo of a smiling employee and no AI label is exactly what the rule targets.

Timing: at the latest at the first interaction. For a chat widget, that means the moment the conversation opens, not after three messages. Accessibility: if your website already has to meet accessibility rules (the Web Accessibility Directive for public bodies, the European Accessibility Act for many consumer services), the disclosure must meet them too. Screen readers must be able to read the label, so do not rely on a coloured icon alone.

Dates, the Digital Omnibus and fines

  • 2 August 2026: Article 50 applies. There is no grandfathering for chatbots: systems already running before that date had to comply from that day.
  • Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026): it did not change paragraphs 1 to 6 of Article 50. It rewrote paragraph 7 (codes of practice and implementing acts) and added a transition in Article 111(4). Generative systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty in 50(2). The guidelines stress that this grace period covers marking only: a system that is both conversational and generative must disclose the AI interaction from 2 August 2026.
  • Fines: breaches of Article 50 can be fined up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher (Article 99(4)(g)). For SMEs, and since the Omnibus also for small mid-caps, the cap is whichever is lower. Enforcement is national: each Member State designates market surveillance authorities. For AI systems built on a general-purpose AI model from the same provider, the AI Office supervises.

See our full AI Act timeline after the Omnibus for every other date.

Checklist for SMEs with a website chatbot

  • Inventory every conversational touchpoint: website widget, WhatsApp or Messenger bots, voice/IVR, email auto-responders driven by an LLM, and in-app assistants. Our free website audit lists third-party chat widgets it finds on a page (it recognises Intercom, Zendesk, Drift and Tawk.to scripts). It tells you a chat tool is loaded. It cannot tell whether the vendor's AI features are switched on, so check that yourself.
  • Decide your role per touchpoint: vendor AI agent (you are the deployer) or built or commissioned by you under your name (you are the provider). Write the reasoning down.
  • Vendor tools: open the widget as a visitor, on desktop and mobile. Is there an AI label in the first message and near the input? Did your custom greeting, bot name or avatar overwrite it? Ask the vendor how they meet Article 50(1), and keep the answer.
  • Custom builds: hard-code a first-turn disclosure that the prompt cannot remove, add a persistent badge, and test that it survives every language and channel you offer.
  • Avoid human impersonation: no human first names plus photos for bots, and no "I'm Sophie from support" unless it is followed by "an AI assistant".
  • Offer a route to a person where it matters (complaints, cancellations, vulnerable users). The AI Act does not require this, but consumer and sector rules often do.
  • Accessibility: the label is real text (not only an icon), readable by screen readers, with enough contrast.
  • Generated media: if the bot can output images, audio or video, confirm marking under 50(2) (vendor or you), and label deepfakes under 50(4).
  • GDPR alongside: update the privacy notice for chat transcripts, check the vendor's DPA and transfer basis, and load the widget only after consent if it sets non-essential cookies.
  • Evidence: keep dated screenshots of the disclosure, the vendor's statement and your role assessment. Re-check after every widget or prompt update.
  • AI literacy (Article 4): brief the staff who configure the bot. Since the Omnibus, this means taking measures to support AI literacy, not guaranteeing a level.

Sample disclosure wording (EN/NL)

Keep it short, specific and early. Adapt it to your tone of voice, but keep the words "AI" and "assistant" or "chatbot" together.

First message in the chat

English

Hi! I'm an AI assistant, not a person. I can answer questions about orders and our products. Type "agent" at any time to reach our team.

Nederlands

Hoi! Ik ben een AI-assistent, geen medewerker. Ik help je met vragen over bestellingen en producten. Typ "medewerker" als je iemand van ons team wilt spreken.

Persistent label near the input field

English

AI assistant · answers are generated automatically and may contain mistakes

Nederlands

AI-assistent · antwoorden worden automatisch gegenereerd en kunnen fouten bevatten

Voice or phone bot (spoken at the start)

English

You're speaking with an automated AI assistant. Say "employee" to be transferred to a colleague.

Nederlands

Je spreekt met een geautomatiseerde AI-assistent. Zeg "medewerker" om doorverbonden te worden met een collega.

Hand-over to a human

English

You're now chatting with Anna, a member of our support team.

Nederlands

Je chat nu met Anna van ons supportteam.

Track Article 50 like any other control

In Dazr Compliance, the EU AI Act framework turns this checklist into recurring controls. Attach the screenshots and vendor statements as evidence, set a review date, and show an auditor the history in a read-only view.

FAQ

Do I have to disclose that my website chatbot is AI?

The legal duty in Article 50(1) is on the provider of the chatbot. If you built it or had it built and run it under your name, that is you. If you use a vendor's AI agent, the vendor must design the disclosure in, but you should check that it actually shows on your site. Consumer law may also require you to mention it.

Is a small "AI" icon enough?

Usually not on its own. The Commission's guidelines recommend a plain-language first-turn message and a label near the input field. Icons and colours are a complement. The information must be clear and distinguishable at the first interaction and accessible.

Does the Digital Omnibus delay the chatbot rules?

No. Regulation (EU) 2026/1744 delayed the high-risk rules but left Article 50(1) to (6) unchanged. Only the machine-readable marking duty in 50(2) has a transition, until 2 December 2026, for generative systems placed on the market before 2 August 2026.

Our chatbot only suggests replies that a human agent sends. Is that in scope?

The visitor interacts with a human who uses an AI tool, not directly with an AI system, so Article 50(1) is unlikely to apply. Article 50(4) can apply if you publish AI-generated text on matters of public interest without human review, which is not the case for an agent who reviews each reply.

Who enforces Article 50?

National market surveillance authorities designated by each Member State. The AI Office supervises AI systems that are built on a general-purpose AI model from the same provider. Fines go up to EUR 15 million or 3% of worldwide turnover, and for SMEs the lower of the two applies.

Sources (as of 1 October 2026)

This guide explains the law as of 1 October 2026 and is not legal advice. Check your specific set-up with counsel or your national authority.