Do you have to tell people they're talking to an AI? The EU's answer
From August 2, 2026, EU users must be told at the first message that they're talking to an AI. What counts as real disclosure, and what doesn't, concretely.
By Norbelys Chirinos, Co-founder
Founder-reviewed ·How we research and correct articles
Article 50 of the EU AI Act is the shortest, most concrete rule in the whole regulation, and it’s the one that reaches the most products. From August 2, 2026, it’s binding law across all 27 member states: if a person is interacting with an AI system, or is looking at AI-generated or manipulated content published on a matter of public interest, they have to be told. Not eventually. Not in a terms-of-service clause. At the point of interaction.
The broader enforcement picture explains why this date matters; this piece is about what actually satisfies the rule if you build the thing being disclosed.
The two obligations Article 50 actually creates
Article 50 bundles a few distinct duties. The two that reach the most companies:
- Chatbot and conversational-AI disclosure. Anyone deploying a system designed for direct interaction with a natural person must make it clear the person is talking to an AI, “unless this is obvious from the circumstances.” For a support widget, sales assistant, or AI agent, it essentially never counts as obvious — the obligation applies.
- AI-generated content disclosure for public-interest text. If you publish AI-generated or AI-manipulated text on a matter of public interest, you have to disclose that it’s artificially generated — with an exemption if a natural or legal person with editorial responsibility has reviewed the content before publication.
There’s a third strand covering synthetic image/audio/video (deepfake-style) content and emotion-recognition/biometric-categorization systems, which has its own disclosure logic, but chatbots and generated text are what most SaaS and content teams will actually run into.
What “immediately informed” means in practice
The regulation’s own language is specific: for a conversational AI system, the disclosure has to happen “at the latest at the time of the first interaction,” and the Commission’s guidance is that for a chatbot specifically, this means before or at the very start of the conversation — not after several exchanges, not gated behind a settings page.
What a compliant chatbot disclosure looks like
Disclose before or at the first message
The user needs to know they're talking to an AI system before they've invested a real exchange in the conversation — not three messages in, and not only if they ask.
Make it perceivable in the interaction itself
A line in your terms of service or privacy policy doesn't satisfy this. The disclosure has to live where the interaction happens: in the chat UI, in the greeting message, in a persistent visual marker.
Use plain language, not a euphemism
"Assistant," "virtual agent," or a friendly human-sounding name isn't disclosure on its own if a reasonable user could still believe they're texting a person. State plainly that it's an AI system.
Don't rely on a watermark alone
Machine-readable markings (metadata watermarks) and human-visible labels are treated as separate duties under the Act's own recitals. A watermark a human can't see doesn't satisfy the human-facing disclosure requirement.
A practical, low-friction pattern that shows up across compliance guides for this: a small persistent badge near the chat surface (“AI Assistant” or similar), paired with the AI system’s first message stating plainly that it’s automated. Two layers, both visible, neither buried.
What does NOT satisfy the rule
The editorial-review exemption, and where it stops
For AI-generated text on matters of public interest, the obligation doesn’t apply if the content has gone through human review and a named natural or legal person holds editorial responsibility for publishing it — the logic being that at that point it’s functionally the publisher’s content, reviewed and vouched for, not raw model output presented as-is. This exemption is narrow: it covers edited, reviewed public-interest text specifically, not chatbot interactions (which have no equivalent carve-out) and not synthetic audio/video.
If your content pipeline uses AI drafting with a human editor who reviews and takes responsibility before anything publishes, that’s the scenario the exemption is built for. If AI output goes out with no review step, the exemption doesn’t reach it.
Retroactivity: what about content published before August 2
Content published or systems already deployed before August 2, 2026 don’t need retroactive labeling under the Commission’s own FAQ guidance — the obligation attaches going forward. What matters is whether a system is “placed on the market or put into service” and used from that date onward; ongoing use of a chatbot that was already live is in scope even if the system itself predates the deadline.
Article 50 quick answers
Does this apply if my company isn't based in the EU?
Yes. Scope follows where the AI system's output reaches — if EU users interact with your chatbot or see your AI-generated content, Article 50 applies regardless of where you're incorporated.
What's the penalty for non-compliance?
Up to €15 million or 3% of global annual turnover, whichever is higher, under the Act's general penalty tier for non-prohibited-practice infringements.
Does a 'this may be AI-generated' disclaimer in my footer count?
Only if it's actually perceivable in the specific interaction or content a user is looking at. A site-wide footer disclaimer decoupled from the actual AI-driven feature is unlikely to satisfy the requirement on its own.
Do I need to label AI-assisted content that a human then edited?
For public-interest text specifically, editorial review by a responsible person is an explicit exemption. For chatbot interactions, there's no equivalent carve-out — the disclosure duty applies regardless of how much a human shaped the underlying system.
None of this requires guessing at intent — the rule is unusually literal for EU tech regulation: say it plainly, say it early, say it where the person can actually see it. If you’re deciding what to build this quarter to get there, the builder’s checklist turns this into concrete implementation steps rather than legal description.
Where this touches AI-assisted outreach, and where it doesn’t
Article 50’s text scopes to conversational AI systems and public-interest content — a cold email drafted with AI help and reviewed before it sends isn’t the chatbot scenario, and it isn’t public-interest content either, so the article itself doesn’t reach it. But the editorial-review exemption above runs on a principle worth keeping regardless: content only escapes the disclosure duty once a person has actually reviewed it and taken responsibility for it, rather than model output going out as-is. That’s the same discipline Norbelys builds into how an AI operator is allowed to send on your domain — drafting can be automated, but nothing reaches a recipient without a human confirming it first. It’s not an Article 50 compliance claim; it’s the same underlying instinct regulators keep converging on, applied a layer earlier than the statute requires it. Pair that with an actual right to erasure rather than a soft delete, and the pattern across Norbelys’s compliance-relevant features is the same one this whole rule is built on: provable controls a person actually exercised, not a policy page nobody reads.