This article is not legal advice. It describes what the text says and where it is contested. If your exposure is material, take advice from a lawyer who works on EU technology regulation.
Key Takeaways
For busy support leads:
- 1The date is 2 August 2026. The European Commission's guidance states that "these transparency rules apply from 2 August 2026". The high-risk parts of the Act were deferred; Article 50 was not.
- 2The obligation sits on providers, not deployers. Article 50(1) binds whoever builds the AI system. If you white-label a bot under your own brand or modify it substantially, Article 25 can make you a provider too.
- 3There is an exception, and most coverage skips it. The duty does not apply where it is already obvious to a reasonably well-informed person that they are talking to an AI.
- 4The penalty ceiling is not what small companies should plan around. Article 99(6) caps fines for SMEs and start-ups at whichever figure is lower, so the binding number for a small company is the percentage, not the 15 million euro headline.
- 5The practical fix is one clear sentence in the bot's first message, placed inside the conversation rather than in your terms.
The EU AI Act entered into force in 2024 and has been phasing in since. Most attention has gone to the high-risk regime, which the Digital Omnibus (Regulation (EU) 2026/1744) pushed back to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. Article 50, the transparency chapter, was not deferred. Its date is 2 August 2026.
What Article 50(1) actually says
Here is the operative sentence in full, because the second half is routinely dropped:
Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.
Two things follow that a lot of commentary skips.
The duty is on providers. A provider is whoever develops the system and places it on the market. A support team running a third-party widget is a deployer, and Article 50(1) is not addressed to deployers. Deployer duties appear in Article 50(3) and 50(4), which cover emotion recognition, biometric categorisation, deepfakes, and AI-generated text published on matters of public interest.
That does not always let a company off. Article 25 can make a deployer into a provider, including where you put the system out under your own name or trademark, or modify it substantially. A white-labelled chatbot carrying your branding is exactly the case worth asking your lawyer about. Article 99(4)(g) also places the Article 50 penalty tier on providers and deployers alike.
There is an "obvious" exception. If a reasonably well-informed, observant and circumspect person would already understand they are talking to an AI given the context, the disclosure duty does not bite. A widget visibly labelled "AI Assistant" may well satisfy that. The problem is that "obvious" is a judgement you cannot audit for yourself, and one plain sentence removes the argument entirely, which is why most teams should just write the sentence.
Does it reach a company outside the EU?
On the Commission's reading, yes, in most realistic support scenarios.
Article 2(1)(c) extends the Act to "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union". The trigger is where the output is used, not where you are incorporated or hosted.
How far "used in the Union" stretches for a company that does not target the EU at all is genuinely argued over. But if you knowingly serve EU customers, you are not in the interesting part of that argument.
The transitional deadline, and what it does not cover
There is a transitional deadline in December 2026, and it is narrower than most summaries suggest.
It sits in Article 111(4), inserted by the Digital Omnibus. It gives providers who placed a generative AI system on the market before 2 August 2026 until 2 December 2026 to comply with the Article 50(2) marking obligation, which is the machine-readable watermarking of synthetic content.
It does not extend the deadline for telling a person they are talking to a bot, and it does not apply to systems placed on the market on or after 2 August 2026.
The penalty figures, read properly
The Commission lists fines of up to 15 million euros, or up to 3 percent of total worldwide annual turnover for companies, and up to 750,000 euros for EU institutions, bodies and agencies. The same page adds "proportionality for SMEs and SMCs".
That last line has a specific legal meaning rather than being a promise of leniency. Article 99(6) provides that for SMEs and start-ups the fine is capped at whichever of the percentage or the fixed amount is lower. For a small company the binding figure is therefore the percentage, not the 15 million euro ceiling. It is a cap-inversion rule, not a statement about how regulators will behave, and Member States set their own penalty regimes under Article 99(1).
The reason to write the disclosure sentence is not that a regulator is coming for you. It is that the sentence costs nothing and the argument about whether you needed it costs something.
What a disclosure usually looks like
The requirement is that the person is informed. In practice that means three things, and this is our reading rather than a published standard.
Inside the interaction. A line in your privacy policy does not inform someone during a conversation.
Clear rather than clever. "Hi, I am Aria, your virtual assistant" leans on personification. Saying plainly that this is an AI assistant does not.
Before the person invests effort. In the first message or on the widget itself.
Something along these lines is a reasonable starting point for most teams:
Hi. You are chatting with an AI assistant. I can answer questions about billing, your account and our product, and I can pass you to a human at any point. Just ask.
That sets accurate expectations and advertises the route to a human, which is worth doing for its own sake regardless of any regulation. If you have not defined that route yet, human handoff is the part worth getting right first.
A short check
The following covers Article 50 specifically. Other law applies to a chat widget independently, the GDPR above all, and is out of scope here.
| Check | What to look for |
|---|---|
| First message | Does it state, in plain words, that the user is talking to an AI? |
| Placement | Is that statement inside the chat, not only in the terms or privacy policy? |
| Timing | Does it appear before the user has typed anything substantial? |
| Human handoff | Is there a visible, working route to a person? |
| Voice channels | If you run an AI voice agent, does it disclose at the start of the call? |
| Who is the provider | Is the bot white-labelled under your brand, which may engage Article 25? |
| Emotion or biometric inference | If your tooling infers emotion or categorises people biometrically, Article 50(3) puts a disclosure duty on you as deployer |
That last row catches people out. Agent-assist tooling that scores customer sentiment can fall under Article 50(3), which is addressed to deployers rather than providers.
Where Corebee stands
We think disclosure should have been table stakes before it was law. If you use Corebee, the widget's first message is configurable, so adding a disclosure line is a settings change. If you use something else, the same check applies. The point of this post is the date and who the duty falls on, not the product.
If you want to see how a disclosed, handoff-first bot behaves, you can try Corebee free with no card.
Sources
- European Commission, Quick Facts: transparency rules for AI systems
- European Commission, FAQ on transparency obligations under Article 50
- Article 50 of the AI Act, full text
- Regulation (EU) 2026/1744, the Digital Omnibus on AI
Where this article describes what a disclosure looks like in practice, or characterises which arguments are contested, that is our reading and not a quotation from the regulation.