Chatbot transparency under the EU AI Act: meeting Article 50 from 2 August 2026

Compliance8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

From 2 August 2026, Article 50 of the EU AI Act applies, and its first paragraph affects almost every organization with a chatbot or voicebot: users must know they are communicating with AI. The obligation sounds simple. Add a disclosure and you are done. In practice, more questions come up. Who is responsible when the bot comes from a vendor? Does it apply to internal chatbots? And what happens when an employee takes over a conversation halfway through? This article covers the chatbot obligation in detail, including the implementation choices we see organizations struggle with.

One thing to know up front: the postponement arranged through the Digital Omnibus concerns the machine-readable marking of AI content under Article 50(2), for systems already on the market before 2 August 2026. The chatbot obligation is not part of that. It takes effect on 2 August 2026.

What does Article 50(1) actually say?

Providers of AI systems intended to interact directly with natural persons must design and develop those systems so that the persons concerned are informed that they are dealing with an AI system. The obligation does not apply where this is already obvious, given the circumstances and context of use, to a reasonably well-informed, observant and circumspect person. There is also an exception for legally authorized law enforcement systems, but that is irrelevant for most businesses.

Two things stand out. First, the obligation rests with the provider: the party that develops the system or places it on the market or puts it into service under its own name. Second, it is a design requirement. This is not about a sentence in your privacy statement, but about how the system itself is built. Article 50(5) adds that the information must be provided in a clear and distinguishable manner, at the latest at the time of the first interaction.

When is it "obvious from the context"?

The exception looks broad, but we advise against leaning on it. A window labelled "AI assistant" with a robot-style icon already says a lot. Even so, it remains a judgement call you must be able to substantiate when a supervisor asks. The European Commission has adopted final guidelines on Article 50 that help with that assessment, and a Code of Practice on transparency of AI content is in progress.

The grey area sits mainly in channels where context says little. A voicebot on the phone is not automatically recognizable as AI, especially now that speech synthesis comes close to human speakers. A bot in a WhatsApp conversation looks the same as an employee. And in hybrid channels, where AI and humans alternate, the customer does not know who is answering at any given moment without a disclosure. In all these cases, an explicit disclosure is the defensible route.

Implementing the disclosure in practice

Among the organizations we support, a number of choices keep coming back that together form a defensible implementation. The bot states at the start of every conversation that the user is talking to an AI assistant, in the user's language and before the first substantive reply. A voicebot speaks that disclosure at the start of the call. Naming and design support the disclosure: no human name with a photo-style avatar, but a name and image that fit a digital assistant. On handover to an employee, the system announces it explicitly, and the other way around too, so it is clear at every moment who or what is answering.

Also record how the disclosure is implemented, and keep that as evidence. A screenshot of the disclosure flow, the configuration of the opening message and a test report are worth more during an audit or a supervisor's inquiry than a policy document stating that you are transparent.

Who is responsible for a purchased bot?

Many chatbots are built on a vendor platform, with an external language model underneath. The question of who the provider is then requires care. If you buy a ready-made bot and use it under the vendor's name, the design obligation rests with that vendor and you are the deployer. If you build your own bot on a platform and offer it to your customers under your own name, you move into the provider role, with the design obligation that comes with it.

In practice this means: agree in the contract with your vendor who delivers the transparency feature, and verify that it is switched on. We regularly see that a platform offers the disclosure feature, but that it was switched off during implementation because the opening message had to be "more customer friendly". That puts the risk back with you.

Does this apply to internal chatbots too?

The text of Article 50 refers to natural persons, without distinguishing between customers and employees. An internal HR bot or IT service desk bot therefore falls under the same obligation in principle. In practice, context is often clearer with internal tooling: employees usually know the service desk assistant is a bot. Still, the disclosure is the simplest route here as well, especially since its cost is negligible. One opening sentence is enough.

Enforcement and fines

Violating the transparency obligations can lead, under Article 99(4)(g) of the AI Act, to a fine of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs, including start-ups, Article 99(6) caps the fine at the lower of the two amounts. Supervision rests with the national market surveillance authorities, which can also issue warnings and other measures besides fines. How enforcement will play out in practice remains to be seen, but waiting for the first fines is not a strategy: the obligation is clear enough to implement now, and customers and auditors are already asking about it.

Anchoring it in your AI management system

Organizations with an ISO 42001 management system can anchor the chatbot obligation there directly. Include interactive AI systems in your AI inventory, record per system whether the transparency feature is implemented, and include the check in your internal audit. That way the disclosure becomes a controlled characteristic of every system you roll out, rather than a one-off action. Without an AIMS, a simple register achieves the same: which bots are running, who is the provider, where the disclosure sits, and who checked it when.

Ready for 2 August

Within Article 50, the chatbot obligation is the most visible and at the same time the easiest to arrange. Inventory your interactive AI systems, determine your role per system, implement the disclosure, document how it works and agree responsibility with your vendor. For most organizations this takes days, not months. The 2 August 2026 deadline is fixed, so those days are best spent now.

Source: this article is based on Regulation (EU) 2024/1689 (the AI Act), in particular Article 50(1) and (5) and Article 99(4)(g). The full legal text is available at https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Frequently asked questions

Does every chatbot need to disclose it is AI from 2 August 2026?+

Providers must design interactive AI systems so that users know they are communicating with AI, unless this is already obvious from the context to a reasonably well-informed person. Because that exception is hard to substantiate, an explicit disclosure at the start of the conversation is the safe route in practice.

Has the chatbot obligation been postponed by the Digital Omnibus?+

No. The postponement to 2 December 2026 only covers the machine-readable marking obligations of Article 50(2), and only for AI systems placed on the market before 2 August 2026. The obligation to disclose that a user is talking to AI applies from 2 August 2026.

Who is responsible when the chatbot comes from a vendor?+

The design obligation rests with the provider: the party that develops the system or offers it under its own name. If you build your own bot on a platform and offer it under your own name, you move into the provider role yourself. Agree contractually who delivers the transparency feature and verify that it is switched on.

Does Article 50 also apply to internal chatbots for employees?+

The obligation applies towards natural persons, without distinguishing between customers and employees. With internal tooling the context is often clearer, but an opening disclosure remains the simplest and cheapest way to comply.

What is the penalty for violating the transparency obligations?+

Under Article 99, fines can reach EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Supervision rests with the national market surveillance authorities.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us