AI Disclosure Duty: What Has Applied Since 2 August 2026

Since 2 August 2026, every company must disclose when customers are speaking or writing to an artificial intelligence. The obligation comes from Article 50 of the EU AI Act, it applies regardless of company size, and it is the first rule of this regulation that hits ordinary mid-sized businesses directly in daily operations. Anyone running a website chatbot, a phone assistant or AI-answered customer enquiries is affected.
Key takeaway: Article 50 of the EU AI Act has applied since 2 August 2026. Anyone using a chatbot, voice bot or AI assistant in customer contact must make it clearly recognisable at first contact that the response comes from a machine. A note in the legal notice or privacy policy is not enough. Systems already running before the cut-off date have a retrofit deadline of 2 December 2026. Violations can be penalised with up to 15 million euros or 3 percent of worldwide annual turnover.
What has applied since 2 August 2026?
The transparency obligations under Article 50 have been binding since that date. The core in one sentence: people must know they are dealing with an AI, and they must know it before disclosing something they might have phrased differently to a human.
The regulation distinguishes four cases:
| Case | Who is obliged | What is required |
|---|---|---|
| AI systems for direct interaction (chatbot, voice bot) | Provider | Disclosure that this is AI, unless obvious |
| Systems generating content (text, image, audio, video) | Provider | Machine-readable marking of the output |
| Emotion recognition, biometric categorisation | Deployer | Information of the affected persons |
| Deepfakes and AI texts on matters of public interest | Deployer | Visible disclosure |
For the typical mid-sized company, row one is the practically relevant case. Row two becomes important as soon as AI-generated content is published.
Timing matters: the information must be available at the first interaction at the latest, clearly and distinguishably. A note that only appears after three exchanged messages does not satisfy the obligation.
Wasn't the AI Act postponed?
Partly, but not this part. This is currently the most common misunderstanding, and an expensive one.
In spring 2026 the EU postponed several AI Act deadlines through the Digital Omnibus procedure. Affected are primarily the obligations for high-risk systems: the requirements from Annex III move to December 2027, those from Annex I to August 2028. That postponement made headlines and left many with the impression that the AI Act had been defused across the board.
Article 50 was explicitly excluded from this deferral. The transparency obligations have applied since 2 August 2026 as originally planned. Anyone who relied on the Omnibus headlines has been behind for two days.
The distinction has a practical reason: the high-risk rules require elaborate conformity assessments for which technical standards are still missing. Labelling a chatbot, by contrast, takes an hour.
Am I affected by the disclosure duty?
Three questions are enough for a first assessment. One yes is sufficient:
- Do customers, applicants or suppliers communicate with a system that formulates answers itself rather than playing back prepared text blocks?
- Does your company publish text, images or audio that were wholly or largely generated by an AI?
- Does a system analyse voices, faces or emotions of individuals?
Not affected are classic forms, rule-based menus without a generative component, and internal tools without external contact, provided no employees are deceived. A contact form remains a contact form.
Company size is irrelevant. There is no de minimis threshold and no exemption for small businesses.
How must a chatbot be labelled?
Visibly, understandably, and inside the dialogue itself. The disclosure belongs where the conversation happens, not in a legal document nobody opens.
A short sentence as the first message in the chat window has proven effective. It should contain two things: the fact that an AI is answering, and the route to a human.
An example covering both:
You are chatting with an AI assistant. It answers questions about products, prices and appointments. If you would rather speak to a person, simply type "agent" or call us at the number provided.
What is not sufficient:
- a sentence in the legal notice or privacy policy
- a bot name such as "Anna" or "Max" without further indication, since it rather suggests a human
- a note displayed only after the conversation
- a symbol-only marking whose meaning is not self-evident
The "unless obvious" exception should not be overstretched. It applies where a reasonable user recognises the machine anyway. With a modern language model producing natural sentences, that is precisely no longer the case. When in doubt, label it.
What applies to voice bots on the phone?
The same obligation, only with less room. On the phone there is no chat window to write a note into, so the disclosure must be spoken.
In practice that means a greeting clarifying the nature of the counterpart right away, for example: "Hello, this is the digital assistant of Muster Medical Practice. I can book appointments and take prescription requests. For anything else I will connect you with the team."
Three points often forgotten in practice:
- The note must come before the first substantive question, not after.
- The route to a human should work at every stage of the conversation, not only at the start.
- If the call is recorded or transcribed, data protection information is added. That is a separate GDPR obligation and does not replace the AI disclosure.
Do AI texts and images have to be marked?
Yes, but the obligation is split between two parties. Providers of generative systems must mark their outputs in machine-readable form, for instance through watermarks or metadata. This duty falls on the makers of the models and tools, not on the mid-sized company using them.
As a deployer you are obliged when you publish deepfakes or distribute AI-generated texts on matters of public interest. An AI-written piece about a political debate falls under this; an automatically generated product description in a shop generally does not.
For most companies this means: check which tools you use and whether their outputs are marked. And label voluntarily where readers would otherwise be misled. That is the better position anyway should case law tighten the boundaries later.
Am I a provider or a deployer?
This is the pitfall on which most responsibility questions hang. In principle, the provider is whoever develops an AI system and places it on the market; the deployer is whoever uses it.
The role can shift, however: anyone offering a purchased system under their own name or trademark counts as a provider themselves and takes on the more extensive obligations. A chatbot presented as "your personal adviser from Muster GmbH" can push you into that role even if the technology comes from a service provider.
That is why two points belong in every contract with an AI service provider: a clear assignment of roles, and written assurance that the labelling is technically implemented. If in doubt, have it reviewed by a lawyer. This article does not constitute legal advice.
What applies to chatbots already running?
Systems already in use before 2 August 2026 have a retrofit deadline until 2 December 2026. It concerns primarily the technical side, meaning the machine-readable marking of generated content.
One should not rest on that deadline. Visibly labelling a chatbot is not a development project but a text change taking a few minutes. Postponing it means four months in an attackable position without gaining anything.
What does a violation cost?
The range is up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises including start-ups, the regulation provides for mitigation: here the lower of the two values applies.
These figures are the statutory maximum, not the standard case. More realistic for most businesses is a different kind of damage: a warning letter from competitors, a notice from the supervisory authority, or simply the loss of trust when a customer realises they unknowingly spoke to a machine.
How do I implement this in five steps?
- Take inventory. List every system that communicates with people or generates content: website chat, phone assistant, WhatsApp channel, automatic email replies, text generators in marketing.
- Clarify roles. Determine for each system whether you are provider or deployer, and obtain the service provider's assurance in writing.
- Draft the disclosure. One sentence per system, in your customers' language, with the route to a human. No legalese.
- Build it in. As the first chat message, as a spoken greeting, as a visible note in the interface. Not in the legal notice.
- Document it. Record which system is labelled how and since when. It takes ten minutes and is the difference between "we implemented it" and "we can prove it".
How ArkeonTech handles this
All chatbots and voice agents we build ship in a state where the system identifies itself as AI at first contact and can hand over to a human at any time. The disclosure is part of the configuration, not an afterthought, and the wording is agreed with the client so it fits their tone of voice.
Anyone running an existing bot built by someone else can have it briefly reviewed by us. Whether a given disclosure meets the requirements can usually be answered in a few minutes.
Frequently asked questions about the disclosure duty
Is a note in the legal notice or privacy policy enough? No. Article 50 requires the information to be available at the first interaction at the latest and to be clearly recognisable. A legal document the user would have to open actively does not meet that. The disclosure belongs in the dialogue itself, as the first chat message or as a spoken greeting on the phone.
Must I label my chatbot if it is obvious that it is a bot? The regulation exempts cases where the use of AI is obvious to a reasonable user. With modern language models one should not rely on that exception, because their very strength is human-sounding phrasing. A bot name like Anna or Max reinforces the opposite impression. When in doubt, label it.
Does the disclosure duty also apply to internal AI tools? For purely internal tools without external contact, Article 50 generally does not apply as long as no employees are deceived about their use. As soon as a system communicates with applicants, suppliers or customers, the obligation applies. Independently of this, employment law and works council requirements may exist.
Who is liable if the service provider forgets the labelling? That depends on the allocation of roles. Providers and deployers have different obligations, and anyone offering a purchased system under their own name can become a provider themselves. Roles should therefore be expressly assigned in the contract and the technical implementation of the labelling assured in writing.
Do I have to label emails that an AI pre-drafted? If a human reviews, adjusts and takes responsibility for the reply, no automated dialogue in the sense of the provision arises. It is different when an agent responds independently without anyone proofreading. Then the system communicates directly with the recipient and the disclosure obligation applies.
What applies to AI-generated images on my website? Machine-readable marking is the provider's duty, meaning the image generator's. As a deployer you must disclose visibly if you publish deepfakes. An illustrative article image generally does not fall under this. Voluntary labelling is still sensible where an image would otherwise be taken for a real photograph.
Conclusion
Article 50 is the first rule of the EU AI Act that does not demand a compliance project but a decision: tell your customers they are talking to a machine. The effort is about an hour, the benefit considerably greater, because transparency at this point does not cost conversion in our experience. It only prevents the awkward discovery at the wrong moment.
For a broader overview of all AI Act obligations for mid-sized companies, see our article EU AI Act 2026: What German SMEs with AI agents need to know.
This article reflects the state of information as of 4 August 2026 and does not constitute legal advice. For a binding assessment of your individual case, please consult a qualified lawyer.
Sources
- Regulation (EU) 2024/1689 (EU AI Act), Articles 50 and 99
- Fraunhofer Academy: EU AI Act Art. 50 transparency obligations take effect (2026)
- TÜV Rheinland Consulting: Transparency obligations in the EU AI Act, Art. 50
- Cloud Security Alliance: EU AI Act Article 50 Transparency Obligations Take Effect (July 2026)
AI chatbot for sales & support
Answers customer enquiries in seconds, qualifies leads and hands over to your team - live in 2-4 weeks.
More Articles

AI Agents in Customer Service: Revolutionizing Digital Communication in 2025
Discover how AI agents are revolutionizing customer service in 2025, enabling 24/7 intelligent communication and boosting business efficiency.

AI Automation for SMEs: A Guide to Boosting Efficiency in 2025
Our 2025 guide for SMEs on using AI agents to increase efficiency, reduce operational costs, and overcome labor shortages. Calculate your ROI.
