The AI Act classifies AI systems into four risk categories. One of them covers systems that pose transparency risks, and those systems are governed by Article 50. The obligations apply two years after the AI Act entered into force, which means 2 August 2026.
If your organisation runs a chatbot, a voice assistant, or any AI tool that talks to customers or staff, Article 50 applies to you. Here is what it requires and what to do before the deadline.
Background
On 20 July 2026 the European Commission published guidelines on how to implement Article 50.
The guidelines are not binding, but they set out the Commission's reading of Article 50, shaped by a public consultation and by the Member States sitting in the AI Board, which coordinates the national authorities responsible for enforcement. The guidelines are therefore the benchmark those authorities will work from, which makes them the sensible basis for planning.
On 24 July 2026 Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal and entered into force on 27 July, postponing important deadlines for the high-risk AI regime. The transparency obligations under Article 50, however, were left substantively unchanged.
Article 50: Four Obligations, Two Roles
Article 50 contains four transparency obligations plus a set of horizontal requirements. Two are addressed to providers, two to deployers:
- Article 50 para. 1: Providers of AI systems that interact directly with people (e.g. chatbots and voice assistants) must design and develop them so that people are told they are dealing with an AI.
- Article 50 para. 2: Providers of generative systems must mark output in a machine-readable format and make a means of detection available.
- Article 50 para. 3: Deployers of emotion recognition and biometric categorisation systems must inform the people exposed that the system is running. Note that emotion recognition in the workplace and in education is banned outright under Article 5.
- Article 50 para. 4: Deployers must label deep fakes, and AI-generated text published to inform the public on matters of public interest.
Article 50 para. 5 adds horizontal requirements to all four. The information must be clear and distinguishable, provided at the latest at the time of the first interaction or exposure, and conform to applicable accessibility requirements.
Information tucked into a manual, several menu levels deep, or sitting in terms of use does not meet the standard.
Focusing on Article 50 para. 1
Article 50 para. 1 binds the provider: whoever develops the system and places it on the market or puts it into service under their own name. For example, if a business licensed a chatbot from a vendor, the design duty is the vendors. If a company, on the other hand, built it in-house, or modified a third-party system and deployed it under their own name, the duty is theirs.
Either way, you are separately a controller or a processor for the personal data flowing through the tool. Provider and deployer under the AI Act do not map onto controller and processor under the GDPR. You have to run the analysis twice, and the answers can differ.
Four elements must all be present. The tool must:
- qualify as an AI system (which rules out simple rule-based automated replies)
- be intended to interact, meaning a genuine two-way exchange rather than data collection
- interact directly, normally in real time
- interact with people, whether consumers or professionals.
The guidelines give examples of systems that fall within scope, such as
“AI-enabled voice assistants, chatbots/conversational agents in various contexts (e.g. public service, customer support, complaints management, e-commerce, finance, healthcare, education etc.)”. (Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689)
Important: A privacy notice mentioning a chatbot does not discharge Article 50 para. 1, and an AI label does not discharge Articles 13 and 14 GDPR.
The guidelines do allow some consolidation and expressly contemplate folding Article 50 para. 3 notifications into the information you already give data subjects. What they do not allow is the AI-specific content vanishing into a long document.
What Does Not Count As Disclosure
The guidelines list techniques that fail on their own:
- a notice only in terms and conditions, a URL or documentation
- machine-readable marks users cannot perceive during the interaction
- vague labels, such as a generic reference to an “assistant”
- blanket statements such as “Services on this website use AI”
- technical descriptions such as “this system uses LLMs”
The Exception, and Why It Is Narrower Than It Sounds
No disclosure is needed where the artificial nature of the interaction is obvious to a person who is reasonably well-informed, observant and circumspect. The guidelines read this narrowly. There must be almost no doubt left for an average member of the intended and reasonably foreseeable audience, and you cannot rely on it where children, older users or people with lower digital literacy may be present.
In practice this rules out most customer-facing conversational tools. A helpdesk chatbot or a support assistant does not qualify, because users may take the replies for human-written. The same applies to realistic avatars and human-sounding voices.
An internal assistant used for HR, legal, procurement or IT support may qualify, but only where staff are properly trained and AI-literate. That ties the exception to the separate AI literacy obligation in Article 4, in force since February 2025.
Internal rollouts also raise employee data protection questions and, in several member states, works council or employee representative involvement before go-live.
Where a Single Notice Is Not Enough
The guidelines identify contexts requiring periodic reminders: interactions with vulnerable users, sustained or emotionally significant interactions, and settings with a heightened risk of being misled, listing financial advice, insurance, legal assistance, health advice and complaints handling. These are precisely the contexts where users volunteer health, financial or other sensitive information mid-conversation, which raises the parallel questions Article 50 does not touch at all: the lawful basis for processing conversation content, retention of chat logs, special category data arriving unbidden, and whether a DPIA is required.
If Companies Don’t Comply With Article 50
Article 50 is enforced by national market surveillance authorities. The guidelines confirm this does not touch the powers of data protection or consumer protection authorities on the same facts.
Fines reach EUR 15 million or 3 percent of total worldwide annual turnover, whichever is higher. For SMEs, whichever is lower.
What To Do Now
If your organisation uses AI in any customer-facing or employee-facing process, you need to act quickly to meet the deadlines for a set of obligations that cut across data protection, consumer and product law at once. Involve your DPO or privacy counsel and your AI Officer at this stage rather than later to:
- Map your AI systems and roles: Checking legal bases, reviewing vendor documentation and drafting transparency information are the same activities as a GDPR compliance exercise, applied to a new instrument.
- Put the documentation where it belongs: Records of processing, DPIAs, vendor agreements and notices are where the Article 50 evidence will naturally sit, and where an authority will look for it.
No comments