Article 50 is described everywhere as “the transparency obligations”, as if it were one duty. It is four, they fall on different parties, and only the first is the one people mean when they say a chatbot has to admit it is a chatbot.
What Article 50(1) requires
Article 50(1) of Regulation (EU) 2024/1689 requires providers to ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system. The full text is on EUR-Lex.
The scope trigger is intended to interact directly with natural persons. That is an intended-purpose test, not a test of what happened in a particular session. A support assistant, a voice agent answering a phone line, an in-product conversational feature: all plainly within it. A model called server-side to classify documents, with no interactive surface, is not — nobody is interacting with it. A system that generates text a human then sends is the harder case, and it turns on whether the system itself is what the person is interacting with.
There are two carve-outs in the paragraph. The first is the obviousness exception, below. The second is for AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and unless those systems are available for the public to report a criminal offence.
This page explains the provision. Whether a specific product is “intended to interact directly” with people, and whether the disclosure you give is adequate, are fact-specific questions — this is not legal advice and you should take advice on your own product.
The “obvious” exception
The duty does not apply where it is obvious from the point of view of a reasonably well-informed, observant and circumspect natural person, taking into account the circumstances and the context of use. That formula is borrowed from consumer law, where it describes the average consumer, and importing it here has a consequence worth stating: it is an objective standard, assessed in context, not a question of whether the particular user in front of you happened to work it out.
The practical difficulty is that the exception has been getting narrower as the technology has got better, without anything in the text changing. A visibly scripted decision-tree bot on a bank's website in 2020 was arguably obvious. A fluent voice agent that handles interruptions is not obvious to anyone, which is precisely why the provision exists. Relying on the exception is therefore a claim that gets weaker over time, and builds in an unattractive asymmetry: the better the product, the less available the excuse.
Context does real work in both directions. A user who opened a page labelled “AI assistant” and clicked a button marked “chat with AI” is in a different position from someone who received an outbound call. It is not settled how much surrounding labelling is enough, and no guidance or case law resolved it at the time of writing.
It binds the provider, not the deployer
Article 50(1) is addressed to providers, and it requires the system to be designed and developed so that people are informed. Article 50(3) and 50(4) are addressed to deployers. That split is the single most useful thing to know about Article 50, and it is what the “one bucket” framing destroys. The provider/deployer distinction itself is on the provider versus deployer page.
The consequence for a team building on top of a model API is that they are usually the provider of the interactive system even though they did not train the model. You place a conversational product on the market under your own name; the disclosure duty is yours, and it is not discharged by the model vendor. Conversely, a company that buys a white-labelled chatbot and deploys it may be a deployer of that system — but if it puts it on the market under its own name or trade mark, Article 25 can make it a provider instead. That mechanism is on the Article 25 page.
Timing, form and accessibility
Article 50(5) governs how all of the Article 50 information is given. It must be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and it must conform with the applicable accessibility requirements.
- At the latest at first interaction. A disclosure in a privacy policy, or revealed on request, is late. The natural place is the opening state of the conversation or the surface the user arrives at.
- Clear and distinguishable. Not buried in a paragraph of terms, and distinguishable from the AI-generated content itself — a bot that says “I am an AI” as its first generated message is arguably weaker than a persistent interface label, because the generated text is the thing whose reliability is in question.
- Accessible. A visual-only badge is a problem for a voice interface and for screen-reader users. Article 50(5) points at the Union accessibility requirements rather than leaving this to taste.
What Article 50(1) is not
It is not an obligation to label the output. That is Article 50(2), the machine-readable marking duty on providers of systems generating synthetic audio, image, video or text — a separate obligation with separate exceptions, covered on the machine-readable marking page. A chatbot that discloses it is an AI can still owe marking on synthetic content it produces.
It is not the deepfake duty, which is Article 50(4) and falls on deployers — see the deepfake labelling page. It is not the high-risk transparency duty in Article 13, which is about instructions for use supplied to deployers of high-risk systems, not about telling end users anything. And Article 50(6) is explicit that Article 50(1) to (4) do not affect the requirements and obligations in Chapter III or other Union or national law: a high-risk system that also interacts with people owes both.
On timing, Article 50 applies from 2 August 2026 under Article 113. Non-compliance with Article 50 sits in the Article 99(4) penalty tier — up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher, for undertakings — rather than the higher tier reserved for prohibited practices. See the penalty tiers page.
The 2 August 2026 date survived the amendment, and that is worth knowing rather than assuming. The digital omnibus on AI was enacted as Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. It postponed the high-risk regime — stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems to 2 August 2028 — but left the Article 50 transparency obligations at 2 August 2026. The practical consequence is that the chatbot disclosure duty now applies well over a year before most of the high-risk regime it is often bundled with. Confirm against the consolidated AI Act text on EUR-Lex.
Top comments (0)