AI disclosure · EU · updated
Article 50(1): telling people they are talking to an AI
Since 2 August 2026, a chatbot, voice assistant or agent that talks to people in the EU has to tell them it is an AI. The AI Act says: “Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.” (AI Act, Art. 50(1), applies from 2 August 2026). The duty sits with the provider who designs the system; Article 50(5) sets when: at the latest at the first interaction.
When the person has to be told
“The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure.”
Nothing in Regulation (EU) 2026/1744 moved this date: its transitional period, Article 111(4), covers the marking duty of Article 50(2) only.
Who the duty is on
“‘provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;”
A business that puts a vendor's chatbot on its own site uses it under its own authority, which is what the Act calls a deployer; who counts as the provider of a given system is a legal question about that system.
“‘deployer’ means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;”
What the Commission's guidelines give as examples
The Commission adopted guidelines on Article 50 on 20 July 2026. Among the techniques they list:
“Textual disclosure (User Interface (UI)-based): Prominent, plain-language labels or banners (e.g. “You are interacting with an AI system”) and first-turn greetings in chatbots that may be combined, as appropriate, with persistent badges or labels visible throughout the interaction as proportionate to the specific context and risks.”
“A single, prominent notification before the first interaction of the AI system with a particular natural person is likely to suffice in most instances to meet the obligation in Article 50(1) AI Act.”
What the guidelines say is not enough on its own
“Unclear or ambiguous signals (e.g. generic references to “assistant”) or human-like representations that may mislead users;”
“Generalised disclosures that are not sufficiently specific to the AI system’s outputs and interactions (e.g. on a platform providing a variety of services or individual inputs, a general disclosure like “Services on this website use AI” is insufficient);”
“Disclosures contained only in terms and conditions, URLs, or documentation (such disclosures may complement, though not replace, in-context disclosure);”
“Technical or capability-based descriptions: statements solely referring to underlying technologies (e.g. “this system uses LLMs”) without explaining the function or implications of the system for the user and its artificial origin.”
Fines
“Non-compliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher: … (g) transparency obligations for providers and deployers pursuant to Article 50.”
“In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.”
Check a page from outside
$ npx --allow-git=root github:agentwares/agent-disclosure site https://your-site.example/Fetches the page once and reads its text, aria labels, titles, placeholders and the inline settings of the chat vendors it can name (Intercom, Zendesk, Drift, HubSpot, Crisp, Tidio, Ada, Botpress, Voiceflow, Dialogflow, Copilot Studio, Salesforce and more). It reports disclosure found: <where> or no disclosure found in <what was checked>, sorts what it finds by strength, and flags the kinds point (38) of the guidelines names. A vendor's greeting loads after the page does; save the page with the chat open and run site saved.html to check it.
A signed readiness report
The free checks print everything they find. The Article 50 readiness report ($49, one-time, no account) is the same checks for up to 10 URLs and 25 artefacts, dated and hash-signed, as PDF and JSON, to keep or hand over.
Keep a dated record of every check, and of every disclosure and marking you ship
okgate keeps every tool call your agents make in a hash-chained audit log with daily Merkle roots on a public page: 90 days on Pro ($99/month), 365 days with a compliance export on Team ($299/month).
A record of your disclosure and marking checks, kept the same way, is not built yet. I want that record