Yes, in most cases. Where EU users are involved, Article 50 of the EU AI Act requires people to be told they are interacting with an AI system, and that duty still starts on 2 August 2026. Firms serving only UK customers rely on UK GDPR transparency and consumer law. Mickai records every disclosure in the Open Audit Record.
Do you have to tell customers they are talking to an AI?
Yes, if any of your customers could be in the EU, and as a matter of practice almost certainly yes everywhere else. Article 50 of the EU AI Act makes the disclosure a legal duty from 2 August 2026. In the UK there is no single line of statute that says "label your chatbot", but three separate bodies of law arrive at the same answer from different directions, and none of them help the firm that stayed quiet.
Two questions get muddled here, and they are worth separating. The first is whether a regulator can fine you for not disclosing. The second is whether a customer, or an ombudsman, can later say the interaction was unfair because the customer believed a person was on the other end. The second question is the one that costs firms money, and it does not wait for a commencement date.
What does Article 50 of the EU AI Act actually require?
Article 50(1) puts the duty on providers: an AI system intended to interact directly with natural persons must be designed and developed so that those persons are informed they are interacting with an AI system. The exception is where that fact is obvious to a reasonably well-informed, observant and circumspect person, taking account of the circumstances and context of use. A narrow carve-out covers systems authorised by law to detect, prevent, investigate or prosecute criminal offences.
Two further parts matter for a contact centre. Article 50(2) requires providers of systems generating synthetic audio, image, video or text to mark the output in a machine-readable format so it is detectable as artificially generated or manipulated. Article 50(5) sets the timing and the manner: the information must be given in a clear and distinguishable way at the latest at the time of the first interaction or exposure. Not on page four of a policy. Not after the customer has read out an account number.
Article 50 also reaches deployers, not only vendors. Firms using emotion recognition or biometric categorisation must inform the people exposed to it, and deepfake content must be disclosed as artificially generated or manipulated. Article 50(7) asks the AI Office to encourage codes of practice on marking and detection, so the mechanics of machine-readable marking will settle separately from the statute itself. We track that work as it lands in our note on the Article 50 transparency guidelines.
The scope catches UK firms. The Act reaches providers and deployers established outside the EU where the output of the system is used in the EU. A Manchester contact centre answering a customer in Dublin is inside it, which is the question we work through in does the EU AI Act apply to UK companies selling into the EU.
Does the December 2027 delay change the disclosure duty?
No. The delay moved the high-risk obligations, not the transparency ones. Stand-alone high-risk systems under Annex III moved to 2 December 2027, and high-risk systems embedded in regulated products under Annex I to 2 August 2028. Article 50 stayed where it was. The Commission's own regulatory framework page is the place to confirm the current dates before you commit a plan to them.
Worth being blunt about, because I have watched programme plans slide as a single block. Someone reads a headline about the AI Act being pushed back, the roadmap moves to 2027, and the chatbot notice quietly moves with it. It should not. If your disclosure work currently sits in the same workstream as your high-risk conformity assessment, split it out and give it the earlier date. We set out what actually bites in August 2026 against December 2027.
Does UK law require the same disclosure?
Not in the same words, but you land in a similar place. Three sources stack up.
UK GDPR transparency comes first. Articles 13 and 14 require you to tell people how their personal data is processed, and the fairness limb of Article 5(1)(a) covers whether the processing is what a reasonable person would expect. Where an automated system profiles a customer or makes a decision with legal or similarly significant effects, Article 22 and the related right to meaningful information about the logic involved apply. The ICO's guidance on AI and data protection sets out how it expects firms to approach this.
Consumer law comes second. The unfair commercial practices regime now carried in the Digital Markets, Competition and Consumers Act 2024, enforced by the Competition and Markets Authority, prohibits misleading actions and misleading omissions. Where a customer would have behaved differently had they known they were dealing with software, silence starts to look like an omission of material information.
Sector rules come third. Under the FCA's Consumer Duty, firms must support their customers' understanding, and communications must be clear, fair and not misleading. A customer who believes a person has heard their complaint, when no person has, has not understood the interaction.
When is it obvious enough that no notice is needed?
Less often than people hope. The Article 50(1) test is not "we assumed it was obvious". It is what a reasonably well-informed, observant and circumspect person would take from the circumstances and the context.
A small widget on a self-service help page, labelled as an automated help search, is probably obvious. A conversational agent that opens with a human first name, uses a typing indicator, apologises in the first person and mirrors the customer's tone is not obvious, and it gets less obvious the better it gets. An inbound voice line is the hardest case of all, because the customer has no visual cue and a fluent voice carries a strong presumption of a person.
My working rule is simple. If you would need a paragraph to argue that it was obvious, write the notice. One line of copy is cheaper than the argument.
How should the notice be worded and where should it sit?
Plain language, in the channel the customer is actually in, before the first substantive exchange. Something close to: "You are talking to an automated assistant. It can help with billing, readings and appointments. Say or type 'agent' at any point and I will pass you to a person." That does three jobs at once. It discloses, it sets the expected scope, and it gives an exit.
Three things I would avoid. Do not give the assistant a bare human first name as its identity with no qualifier anywhere near it. Do not treat a cookie banner or a link to terms as the disclosure, because consent to data processing is a different thing from knowing who you are speaking to. Do not leave it to the transcript email afterwards.
Handover deserves its own notice, in both directions. When a person takes the conversation over, say so and say when. When the assistant takes it back, say that too. The moment the party on the other end changes is exactly where "clear and distinguishable" earns its keep, and it is the moment most implementations skip.
How do you prove the disclosure was shown?
This is where most firms are thin. Writing the notice is easy. Showing, eighteen months later, that one named customer in one conversation saw one specific version of it is the part that fails under examination.
A screenshot of today's interface proves nothing about last March. Copy gets edited, tests get run, flows get rebuilt, and the record of what was live when is usually scattered across a content system, a release log and somebody's memory. So decide now what you record per conversation: the exact disclosure text and its version, the timestamp, the channel, the system version that answered, and every handover with its direction and time.
In the Mickai Sovereign Intelligence Operating System (SIOS), a disclosure is a recorded event rather than a design intention. The Open Audit Record seals each consequential action under ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024, and an auditor verifies an exported record offline with a public key, using tools that are not ours. Consequential actions wait for a named person to approve them.
Be precise about what that buys you. The record is tamper-evident, not tamper-proof. I cannot stop someone editing a file. What I can do is make the edit fail verification, so alteration is detectable rather than invisible. That is the standard a regulator can work with: not an unalterable artefact, but a chain you can demonstrate.
It runs on hardware the customer owns, offline capable, with no data egress, so conversation transcripts stay inside the estate. That is not an argument against the cloud, which remains a sensible place for work that is not regulated. It is an argument against having to take anyone's word for what happened to a customer conversation.
Frequently asked questions
Is the EU AI Act chatbot disclosure deadline still 2 August 2026?
Yes. The amendments that pushed high-risk duties to 2 December 2027 and 2 August 2028 did not move Article 50. The transparency obligations, including telling people they are interacting with an AI system, still start on 2 August 2026. If your plan moved the whole AI Act programme back, pull the disclosure work forward again.
Do we still need a notice if a human agent takes over the chat?
Yes, and you need a second one. Article 50(5) requires the information to be clear and distinguishable at the first interaction, and a change of party mid-conversation is the point at which customers are most easily misled. Say when a person takes over, and say when the assistant takes it back. Record both events with timestamps.
Does UK GDPR require us to say a chatbot is AI?
Not in those words. Articles 13 and 14 require transparency about processing, and Article 5(1)(a) requires fairness, which covers whether the interaction matches a reasonable person's expectations. Where the system profiles or decides, Article 22 and the right to meaningful information about the logic involved apply. The ICO's AI and data protection guidance sets out its expectations.
Does the rule apply to voice bots and telephone lines?
Yes. Article 50(1) covers AI systems intended to interact directly with natural persons and does not distinguish by channel. Voice is arguably the harder case, because the customer has no visual cue and a fluent synthetic voice carries a strong presumption of a person. Disclose in the first utterance, before the menu, the authentication and the account number.
What happens if we do not disclose that a customer is talking to AI?
Under the AI Act, breaches of Article 50 sit in the tier carrying fines of up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher, under Article 99(4) of the AI Act. In the UK the exposure is different: ICO enforcement on transparency and fairness, CMA action on misleading omissions, and complaints or redress where a customer was misled.
Related briefings
Data protection and UK GDPR
- UK GDPR and AI: Does Your Data Have to Stay in the UK?
- UK Data Storage vs AI Processing: What Is the Difference
- Controller or Processor? AI Suppliers and UK GDPR Roles
- Right to Erasure in an AI Knowledge Base: How to Comply
- Employee Pasted Client Data Into AI: Is It a Breach?
Governance, audit and oversight
- Tamper-Evident vs Immutable Log: The Real Difference
- Human on the Loop vs In the Loop: AI Oversight Explained
Part of a series of 60 briefings on deploying and governing AI in UK regulated organisations, archived with a DOI at 10.5281/zenodo.22975756.
Evaluating AI for a regulated organisation? Mickai runs on hardware you own, offline. Consequential actions wait for a named person to approve them, and what the AI did is sealed into a signed record an auditor can check without us. Applications for the invitation-only closed beta are open. Apply for the closed beta.
Written by Micky Irons, founder and chief executive of Mickai LTD.
Top comments (0)