Key takeaways
- Since 2 August 2026, any AI chatbot that talks with people in the EU must tell them it is an AI, at the latest when the first conversation starts.
- The Digital Omnibus did not delay this rule. It only moved the high-risk deadlines to December 2027 and August 2028.
- Helpdesk and support chatbots do not count as obviously AI, so they need a clear label.
- A line in your terms, a human name like Sarah or the word assistant on its own is not enough. Say AI in plain words.
- Fines reach 15 million euros or 3% of worldwide turnover, and businesses outside the EU are covered when they chat with EU customers.
Ask an AI about this article
EU AI Act Article 50 requires every AI chatbot that talks with people in the EU to tell them they are talking to an AI, clearly and from the start of the first chat. If your AI agent runs on Spur, every AI reply can carry a "replied by Spur AI" line, so customers can tell AI replies from your team's.
The rule has applied since 2 August 2026 and covers support bots on websites, WhatsApp and Instagram. Breaking it can cost up to 15 million euros or 3% of worldwide turnover.
This guide covers what the law says, whether your bot is in scope, who has to add the label, what a valid label looks like on each channel, and a checklist to work through. It is a practical summary of the law and the Commission's guidance, not legal advice.
What is EU AI Act Article 50?

EU AI Act Article 50 is the transparency article of the EU AI Act, Regulation (EU) 2024/1689. It sets four duties, and only the first one is about chatbots. The text of Article 50 splits them like this:
- Article 50(1), interactive AI. Providers must build AI systems that talk with people so those people are told they are dealing with an AI, unless that is obvious.
- Article 50(2), machine-readable marking. Providers of generative AI must mark AI-generated audio, images, video and text so software can detect it.
- Article 50(3), emotion recognition and biometric categorisation. Deployers must tell people when these systems are used on them.
- Article 50(4), deepfakes and public-interest text. Deployers must label deepfakes, and AI text published to inform the public on matters of public interest unless a human reviewed it.
Article 50(5) then sets the rule for all four: the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure," and it must meet accessibility requirements.
For a business running a support or sales bot, 50(1) and 50(5) together are the rule that matters. The rest of this guide is about those two.
Not sure your bot is ready for EU customers? Our AI chatbot best practices cover the basics that sit underneath any compliance work.
Where chatbots sit in the EU AI Act risk tiers
A customer service chatbot almost always sits in the transparency tier of the EU AI Act, which many guides call "limited risk." The Commission's overview of the AI Act sorts AI into four levels and names chatbots as its example for this one:
- Unacceptable risk: practices the Act bans outright, such as manipulative techniques and social scoring. Banned since 2 February 2025.
- High risk: AI used in areas like hiring, education, credit scoring and access to essential services. Its strict rules apply from 2 December 2027.
- Transparency risk: chatbots, AI agents, deepfakes and generative AI. Article 50 is the rule here.
- Minimal risk: spam filters and AI in video games. The Act adds no new duties.
A chatbot only moves up to high risk when it is used for one of those listed decisions, for example screening job applicants or deciding who gets credit. Answering order, product and returns questions keeps it in the transparency tier, so disclosure is the main duty.
Does Article 50 apply to your chatbot?

Your chatbot is covered if it passes four tests. The Commission's Article 50 FAQ lists them as cumulative:
- It is an AI system. Rule-based bots fall outside. The Commission's guidelines name "traditional out-of-office emails" and "rule-based quick message answers" as examples that are not AI.
- It is built for a genuine two-way exchange. A spam filter or a form that only collects data does not count.
- The interaction is direct. The AI itself replies to the person. A tool that drafts replies for your agents, who then review and send them, is outside the rule.
- The other side is a human. Customers, shoppers and professionals all count. Machine-to-machine calls do not.
The guidelines name "chatbots/conversational agents" in "customer support, complaints management, e-commerce" as clear examples in scope. AI agents that take actions such as bookings or purchases are covered too, and they should say who they act for.
What about blended replies?
Many teams run a mix: the AI answers first, and a person takes over when needed. The guidelines say products that blend AI responses with human content "fall within the scope" and need disclosure for the AI-generated outputs. The only exception is AI output that a human properly reviews and sends as the main person in the conversation.
So if a teammate edits an AI draft and sends it, it is their message. If the AI sends on its own, it needs the label. A clean chatbot to human handoff makes that line easy to see for both the customer and your team.
Does it apply if your business is outside the EU?
Yes, if the output of the AI system is used in the EU. Under Article 2 of the AI Act, the regulation covers providers and deployers in third countries "where the output produced by the AI system is used in the Union." That means an Indian or US brand whose AI agent answers shoppers in France or Germany is covered for those conversations.
Provider or deployer: who adds the AI label?

The duty in Article 50(1) sits with the provider, but the deployer controls most of what the customer sees. The two roles come from Article 3 of the AI Act:
- Provider: the company that develops the AI system and places it on the market under its own name. A chatbot platform that sells an AI agent to businesses is a provider. So is a company that builds its own bot in-house and runs it under its own brand.
- Deployer: the business that uses the AI system under its authority. A store that switches on an AI agent to answer its customers is a deployer.
The guidelines add one important case. If you take an existing AI system, modify it, and put it into service under your own name, you become the provider of that new system.
In practice, most businesses that use a platform are deployers, and the platform has to build the disclosure into the product. But the deployer chooses the bot's name, avatar and greeting. A platform can ship a perfect AI label, and a deployer can still undo it by naming the bot "Sarah", giving it a human photo and switching the label off.
The safe reading is to treat disclosure as a shared job. Check that your platform shows a clear AI notice at the first message, and don't change any setting in a way that hides it. If you resell a white label chatbot platform under your own brand, assume you carry the provider's duty yourself.
When "obvious" lets you skip the disclosure
The obvious-AI exception is narrow, and a customer support bot will almost never qualify. Article 50(1) drops the duty only where AI involvement is obvious to "a natural person who is reasonably well-informed, observant and circumspect."
The guidelines say this exception "should be interpreted restrictively" and should be limited to cases "where there is almost no doubt left" for an average person in the audience. They also say general public awareness that chatbots exist "does not imply that they recognise them in interactions."
Examples the Commission treats as obvious:
- Code review assistants used only by professional developers.
- Internal assistants for trained staff who know they are using AI.
- Assistants built into home appliances that only operate that appliance.
Examples the Commission says are not obvious and need a label:
- AI chatbots in helpdesks and support tools, where users "may perceive" the replies "as human-generated."
- Realistic avatars or human-sounding voices that people may not tell apart from a person.
Factors that weaken any obviousness claim include a profile picture of a human, fluent human-like writing, and an audience that includes older people, children or people with low AI literacy. A public store chat can have all three, so plan to disclose.
Wondering where AI should stop and your team should step in? Here is how human agents and AI chatbots split the work in customer service.
What a compliant AI disclosure looks like

A compliant disclosure tells the person, in plain words, that they are talking to an AI, at or before the first reply, in a spot they cannot miss. Article 50 does not prescribe a format, so the Commission's guidelines are the best guide.
Timing
Tell people at the latest when the first interaction starts. The guidelines say information "should, at least, be provided once at the start of an interactive session," and their example of a first interaction is "launching a conversation with a chatbot." One prominent notice per session is usually enough.
Repeat it in riskier contexts. The guidelines list financial advice, insurance, legal help, health advice and complaints handling, and conversations with vulnerable people. The bot must also disclose whenever someone asks if they are talking to a human, or seems confused about it.
Wording and placement
Formats the guidelines suggest:
- A first-turn greeting that says the chat is AI, such as "You are chatting with an AI assistant."
- A persistent "AI" badge or label, ideally near the input field.
- For email sent by an AI agent, an AI label at the top.
- For voice, a spoken line at the start, such as "This is an AI-powered assistant."
Disclosures the guidelines call insufficient on their own:
- A line in the terms and conditions, a URL or the documentation.
- Machine-readable metadata the user cannot see.
- Vague names such as "assistant" or a human-like persona.
- Site-wide statements like "Services on this website use AI."
- Technical wording like "this system uses LLMs."
Clear means noticeable, easy to understand and accessible. Distinguishable means it stands apart from the rest of the message. Small grey footer text that blends into the chat is a weak choice.
How to label AI replies on WhatsApp, Instagram and live chat
Each channel gives you different places to put the notice, so the label has to travel inside the conversation. The rule is the same everywhere: the person learns it is AI before or with the first AI reply.
Website live chat. You control the widget, so you have the most options. Put a short line above the input box before the visitor types, and make the bot's first message say it is an AI. If you are new to the mechanics, see how live chat works on a website first.
WhatsApp. There is no banner or widget around a WhatsApp chat that you control. The disclosure has to be inside the messages: an opening line in the first AI reply, plus a short label on each AI message. Template messages your team writes and sends are not AI interactions, but an AI agent replying to the customer afterwards is. Our WhatsApp Business API guide explains how those conversations are set up.
Instagram and Messenger DMs. These work like WhatsApp: the label lives in the messages. Keep it short and plain so it doesn't look like spam. Instagram's own limits still apply too, and our guide to Instagram automated behaviour covers what Meta allows.
Email. If an AI agent writes and sends replies on its own, put an AI label at the top of each AI email, which is the guidelines' own example.
Voice and phone. Say it out loud at the start of the call. The guidelines say audio tones alone are not enough.
Whatever the channel, don't put an AI label on messages your team writes. A label on everything teaches customers to ignore it, and a label that only shows on AI replies tells them exactly who answered.
Want every AI reply on WhatsApp, Instagram and live chat signed automatically? Spur's AI agent adds a "replied by Spur AI" line to its own replies and leaves your team's replies unlabelled.
AI disclosure wording you can copy
You can copy these lines as they are. Swap in your brand name and keep the word "AI" in every one of them. Adding a way to reach a person isn't required by Article 50, but it answers the next question most customers have.
First message on WhatsApp, Instagram or live chat:
Hi, I'm [Brand]'s AI assistant. I can help with orders, returns and product questions. Type "agent" any time to talk to a person.
Label on each AI reply: "replied by [Brand] AI"
When a customer asks "Are you a real person?":
No, I'm an AI assistant for [Brand]. Would you like me to connect you with someone from our team?
Top of an email written and sent by AI: "This reply was written by [Brand]'s AI assistant."
Opening line on a voice call: "Hi, this is [Brand]'s AI-powered assistant. You can ask for a person at any time."
The same opening line in five EU languages
Write the notice in the language the customer is chatting in, or they may not understand it. Use the local word for AI: KI in German and IA in French, Spanish and Italian. Here is the opening line in five widely spoken EU languages:
- German: Hallo, ich bin der KI-Assistent von [Brand]. Ein Mitarbeiter aus unserem Team kann jederzeit übernehmen.
- French: Bonjour, je suis l'assistant IA de [Brand]. Un membre de notre équipe peut prendre le relais à tout moment.
- Spanish: Hola, soy el asistente de IA de [Brand]. Una persona de nuestro equipo puede atenderte en cualquier momento.
- Italian: Ciao, sono l'assistente IA di [Brand]. Una persona del nostro team può subentrare in qualsiasi momento.
- Dutch: Hallo, ik ben de AI-assistent van [Brand]. Een medewerker van ons team kan het op elk moment overnemen.
EU AI Act compliance checklist for chatbots

Work through these eight steps for each AI agent that can reach a person in the EU.
- List every place AI talks to customers. Website chat, WhatsApp, Instagram, Messenger, email and phone. Include AI agents that send messages or take actions on a customer's behalf.
- Rule out what is not in scope. Rule-based keyword replies, menus and agent-assist tools where a human sends the final message fall outside Article 50(1). Write down why.
- Decide your role. Are you a deployer using a platform, or a provider because you built the bot or sell it under your own name? Ask your vendor in writing how their product handles Article 50.
- Write the first-message disclosure. One plain sentence in the bot's first reply, in the customer's language, such as "Hi, I'm the AI assistant for [Brand]."
- Label each AI message. Use a short consistent label like "replied by [Brand] AI." Keep the word "AI" in it. A name like "Support Bot" or "Concierge" is weaker.
- Check the persona. Remove human photos and human first names from AI agents, or pair them with a clear AI label.
- Handle the hard moments. Instruct the bot to confirm it is an AI whenever asked, to repeat the notice in sensitive conversations like complaints, refund disputes or health questions, and to offer a person when the customer wants one.
- Keep dated records. Screenshot each channel's disclosure, note who changed disclosure settings and when, and review after every bot change.
If you are comparing vendors on this point, our Chatbase alternatives roundup is a good starting list to put these questions to.
EU AI Act Article 50 deadlines

EU AI Act Article 50 has applied since 2 August 2026, and the chatbot duty was not delayed. The key dates:
- 1 August 2024: the AI Act entered into force.
- 2 February 2025: bans on prohibited AI practices started.
- 2 August 2025: rules for general-purpose AI models started.
- 2 August 2026: Article 50 transparency duties, including chatbot disclosure, started.
- 2 December 2026: end of the grace period for Article 50(2) machine-readable marking, only for generative systems already on the market before 2 August 2026.
- 2 December 2027: high-risk rules for Annex III systems such as hiring and credit scoring.
- 2 August 2028: high-risk rules for AI built into regulated products.
The last two dates moved because of the Digital Omnibus on AI, which entered into force on 27 July 2026. The Omnibus delayed high-risk obligations, but the Commission's FAQ is explicit that the only Article 50 grace period is the marking one in 50(2). The chatbot disclosure in 50(1) applies now.
The Commission published its final guidelines on Article 50 on 20 July 2026. A separate Code of Practice on AI-generated content, which the Commission and the AI Board assessed as adequate in July 2026, covers marking and labelling under 50(2) and 50(4). For chatbot disclosure under 50(1), businesses choose their own measures, guided by the guidelines.
EU AI Act Article 50 fines and enforcement
Breaking Article 50 can cost up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. That is the middle tier in Article 99 of the AI Act, which names Article 50 transparency duties directly.
For SMEs, the cap flips to whichever of the two amounts is lower. The Commission says proportionality also applies to small mid-cap companies. Authorities must weigh how serious the breach was, how long it lasted, the company's size, and whether it cooperated and fixed the problem.
Enforcement is mostly national. Each EU country's market surveillance authority handles Article 50, and the AI Office steps in only for a narrow set of systems, such as those built on general-purpose AI models by the same company that made the model.
Article 50 and other EU rules
Article 50 adds to existing consumer and data protection law and does not replace it. The guidelines point to three overlaps worth knowing:
- Unfair Commercial Practices Directive. Passing an AI off as a person can also be a misleading practice under consumer law.
- Consumer Rights Directive. If AI is a main feature of a paid service, it may have to be disclosed before the customer signs up, whether or not the AI is "obvious."
- GDPR. Disclosing AI does not cover your duty to tell people how their chat data is processed. That still belongs in your privacy notice.
How Spur labels AI replies

Spur's AI agent can sign each AI reply with a "replied by" line on WhatsApp, Instagram and live chat. For accounts created since June 2026 it is on by default and reads "replied by Spur AI."
A few things make it useful for Article 50:
- It only marks AI replies. Messages your team sends from the inbox carry no AI label, so the customer can see exactly when a person took over.
- It shows on the first AI reply. The label is part of every AI message, so the customer sees it from the start of the conversation.
- You choose the name. Pick a name that keeps the word "AI," such as "Spur AI" or "AI Assistant," so the label stays explicit.
Add a one-line greeting that says the customer is chatting with an AI, and you cover both the first-message notice and the per-message label. The Shopify AI chatbot guide shows how the same agent answers order and product questions from your store data.
Ready to put a labelled AI agent on WhatsApp, Instagram and your website? Start with Spur and train it on your store, your FAQs and your policies.
Final thoughts
EU AI Act Article 50 asks for one simple thing from chatbots: tell people they are talking to an AI, plainly, before they could think otherwise. The hard part is not the wording. It is making sure no setting, persona or channel quietly hides it.
Audit every AI touchpoint, put the disclosure in the first message, label each AI reply, and keep a dated record. That covers the rule most businesses face today, and it builds the kind of trust that keeps customers talking to your bot.
Frequently asked questions
Yes. Article 50(1) covers AI systems that interact directly with people, and the Commission's guidelines name customer support, complaints and e-commerce chatbots as examples. Rule-based bots that only match keywords or menus are not AI systems and fall outside it.
Yes, whenever their AI chats with people in the EU. Article 2 covers businesses in other countries when the AI's output is used in the Union. The UK is not in the EU, so chats with UK customers are not covered, but a UK or US business must disclose AI to its EU customers.
Yes. Article 50 has no size threshold, so a small online store with an AI chatbot must disclose it like any large company. Size matters only for fines: under Article 99(6), the cap for SMEs is the lower of 15 million euros or 3% of turnover, not the higher.
It should say in plain words that the customer is talking to an AI, for example "Hi, I'm [Brand]'s AI assistant." A human name alone, such as "Hi, I'm Ava," is not enough. The guidelines call vague names like "assistant" unclear, so the word "AI" has to be there.
Not strictly. The guidelines say one prominent notice at the start of each session usually suffices, with reminders in sensitive contexts. A short label on each AI reply is still a good idea when AI and humans share one conversation, because it shows exactly which replies came from AI.
No. The Digital Omnibus on AI delayed high-risk rules to December 2027 and August 2028. Article 50 has applied since 2 August 2026, with one grace period to 2 December 2026 that covers only machine-readable marking for generative systems already on the market.
Up to 15 million euros or 3% of worldwide annual turnover, whichever is higher, under Article 99(4) of the AI Act. For SMEs the cap is whichever is lower, and national authorities weigh the size of the business and how quickly it fixed the problem.
Some do. Since 1 July 2019, California's bot disclosure law has banned bots that hide being a bot to push a sale or sway a vote, unless they clearly disclose it. Other US states have their own rules, so a US business serving EU customers should follow Article 50 and check its own state too.
Sources
Checked against the original source. Dates are when we last verified each one.
- Guidelines on transparency obligations for providers and deployers of AI systems European Commission. Retrieved 5 October 2026
- Transparency obligations under Article 50 of the AI Act (FAQ) European Commission. Retrieved 5 October 2026
- AI Omnibus enters into force European Commission. Retrieved 5 October 2026
- Code of Practice on Transparency of AI-generated Content European Commission. Retrieved 5 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) EUR-Lex. Retrieved 5 October 2026
- Article 50: Transparency obligations EU Artificial Intelligence Act. Retrieved 5 October 2026
- Article 99: Penalties EU Artificial Intelligence Act. Retrieved 5 October 2026
- Article 2: Scope EU Artificial Intelligence Act. Retrieved 5 October 2026
- Business and Professions Code section 17941 (bot disclosure) California Legislative Information. Retrieved 5 October 2026
Was this article useful?



