aliteq.

EU AI Act for Customer-Service Chatbots: The Article 50 Disclosure Checklist (2026)

Article 50 has applied since 2 August 2026. If your chatbot or voice agent talks to people in the EU, the first duty is simple: tell them it is an AI. Here is the full checklist, who owes what, and the fine tier.

TensorUpdated 1h ago9 min readWeb story
A large off-white speech bubble on a near-black background with a lavender shadow, a small blank lime-green circular badge pinned to its lower edge
Share

A chatbot that says "Hi, I'm here to help" without saying what it is can now be a compliance problem in the EU. The rule is short, and most of the work is wording and process.

This guide covers Article 50 of Regulation (EU) 2024/1689, the AI Act, for a company putting a chat or voice agent in front of customers. It's written from the US side: you may sell to the EU without any office there. We read the regulation text on EUR-Lex on 3 October 2026. We haven't done an EU compliance engagement, and we don't claim to. For what these agents cost to run, see our AI customer service cost per resolution and voice agent cost per minute.

Does Article 50 apply to a US company?

Yes, if your AI system is placed on the EU market or its output is used in the EU. The regulation's scope doesn't depend on where you are based.

Article 2(1) says the Act applies to "providers placing on the market or putting into service AI systems ... in the Union, irrespective of whether those providers are established or located within the Union or in a third country". It also covers providers and deployers in a third country "where the output produced by the AI system is used in the Union". A US company with a support chatbot that answers EU customers is within the wording. Whether a specific case is in scope is a question for counsel.

Article 113 sets the date: "It shall apply from 2 August 2026." The Commission's AI Act page says the Act "became applicable on 2 August 2026", and gives chatbots as its own example: people "should be made aware that they are interacting with a machine".

This is a summary of the law and official guidance, not legal advice.

The four duties in Article 50

Article 50 has four transparency duties. Two fall on the provider and two on the deployer, and a support chatbot usually meets the first two.

Scorecard of the four Article 50 duties of the EU AI Act: 50(1) providers tell people they are talking to AI; 50(2) providers mark synthetic output in a machine-readable way; 50(3) deployers of emotion recognition or biometric categorisation inform people; 50(4) deployers disclose deepfakes and public-interest AI text. A support chatbot usually meets 50(1) and 50(2).
Article 50 of Regulation (EU) 2024/1689, read on EUR-Lex 3 October 2026. · aliteq research
  • 50(1), provider. Providers "shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect". A friendly avatar called "Max" isn't obviously a machine to everyone, so don't lean on the exception.
  • 50(2), provider. Providers of systems "generating synthetic audio, image, video or text content" must ensure outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated". It doesn't apply to the extent a system performs "an assistive function for standard editing" or doesn't "substantially alter the input data".
  • 50(3), deployer. Deployers of an emotion recognition or biometric categorisation system must inform the people exposed to it. A voice agent that scores a caller's mood is the case to watch.
  • 50(4), deployer. Deployers must disclose deepfake image, audio or video content, and AI-generated text published to inform the public on matters of public interest, unless a human reviewed it and someone holds editorial responsibility. A support chatbot rarely does either.

Article 50(5) sets the timing and format for all four: the information goes to people "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", and "shall conform to the applicable accessibility requirements". Article 50(6) adds that this doesn't replace other transparency rules in EU or national law.

This is a summary of the law and official guidance, not legal advice.

Are you the provider or the deployer?

If you build a chatbot on a model API and ship it under your own name, you may be the provider of that chatbot. That is our reading of the definitions, not a settled answer, so ask counsel.

Article 3 defines a provider as one who "develops an AI system ... or that has an AI system ... developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge". A deployer is one "using an AI system under its authority" for professional use. The model vendor is the provider of the model. You may be the provider of the chatbot product wrapped around it.

Three cases show how it can split:

  • You build a support bot on a model API and put it on your site as "Acme Assistant". Our reading: you may be the provider of the bot, which carries the 50(1) duty.
  • You buy a ready-made chat widget and switch it on. Our reading: the widget company may be the provider and you the deployer. Check the contract for who promises the disclosure.
  • A vendor runs the voice agent for you under your brand. Roles depend on whose name is on the system and who controls it. Get the answer in writing.

An enterprise customer may ask you for the answer. Our AI security questionnaire guide covers how to answer these in vendor reviews, and our security hub covers the wider compliance questions.

This is a summary of the law and official guidance, not legal advice.

The key dates

Article 50 applies now. The only added time is for the 50(2) marking duty on older generative systems.

Timeline of EU AI Act dates: in force 1 Aug 2024; Article 50 transparency applies 2 Aug 2026; the Article 50(2) marking grace period for systems already on the market ends 2 Dec 2026; high-risk Annex III rules apply 2 Dec 2027; Annex I rules 2 Aug 2028.
Regulation (EU) 2024/1689 Article 113 and Regulation (EU) 2026/1744, read 3 October 2026. · aliteq research

Regulation (EU) 2026/1744, the "Digital Omnibus on AI", added Article 111(4): providers of generative systems "that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026". Its recitals call this "a transitional period of four months". We found no change to the text of Article 50 itself in that regulation.

The same regulation pushed the high-risk rules back, to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. Don't confuse that delay with Article 50. Pages that say the Omnibus delayed transparency are out of date, because the date of application for Article 50 stayed at 2 August 2026.

This is a summary of the law and official guidance, not legal advice.

The seven-step disclosure checklist

The Regulation fixes the principle and the timing, not the wording. The steps below are our practical reading, so treat them as a starting point and confirm them with counsel.

Seven-step disclosure checklist for an AI chatbot serving EU customers: work out if you are the provider, disclose AI in the first message, keep a persistent label, offer a human handoff, ask the model vendor about marking, log disclosures, and sign a data processing agreement and check the region.
Practice suggestions built on Article 50(1) and 50(5). Not legal requirements. · aliteq research

Work out your role. If you built it and ship it under your own name, you may be the provider. Get counsel's view.

Disclose in the first message. A plain line such as: "You're chatting with an AI assistant, not a person." Article 50(5) says at the latest at first interaction.

Keep a persistent label. A badge or header that stays visible for the whole conversation, not only the opening line.

Voice agents: say it at the start of the call. Something like: "This is an automated AI assistant." Do it in the first seconds, before the caller shares anything.

Offer a human. A clear route to a person, and a clear message when none is available.

Log it. Keep the disclosure text, version and date for each channel, so you can show what customers saw.

Sort the data side. Sign the data processing agreement with the model vendor and check where data is processed.

A few details matter.

  • Wording. Plain and short beats clever. A person with a screen reader needs it too, since 50(5) says the information must meet accessibility requirements. Put it in text, not only in an image.
  • Voice. There is no required phrase. The principle is the same as chat: the caller learns it's an AI at the start. A recording-notice line you already play is a natural place.
  • Handoff. Article 50 doesn't require a human handoff. We suggest it because a customer who can't tell what they are dealing with, and can't reach a person, is the one who complains.
  • Logs. Article 50 doesn't set a logging duty. The logging duty in Article 26 applies to high-risk uses, which a support bot usually isn't. Your own record of what was shown is cheap evidence.
  • Marking output. Ask the model vendor in writing how it handles 50(2) marking for the text or audio your bot produces. Don't assume.

This is a summary of the law and official guidance, not legal advice.

Voice agents and the first seconds of a call

For a voice agent, the notice has to be spoken, and it has to come first. A caller can't see a badge.

The practical rule from Article 50(5) is "at the latest at the time of the first interaction". On a call, the first interaction is the greeting. A voice agent that opens with a name and a question, and discloses a minute later, is too late on our reading. If the agent also reads emotion from the caller's voice, 50(3) adds a separate notice duty on the deployer.

Voice also changes cost. Longer greetings add seconds to every call, which is a small per-minute charge. Our voice agent cost per minute guide shows how to price those seconds.

What breaking Article 50 can cost

The ceiling for an Article 50 breach is EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For an SME it is whichever is lower.

Article 99(4)(g) lists "transparency obligations for providers and deployers pursuant to Article 50" in the tier with those figures: "up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher". At the ECB reference rate of 2 October 2026 (EUR 1 = USD 1.1225), EUR 15 million is about $16.8 million. For SMEs, including start-ups, Article 99(6) says each fine is up to the percentage or amount "whichever thereof is lower".

Those are ceilings. Article 99(1) says penalties must be "effective, proportionate and dissuasive" and take SMEs into account, and 99(7) tells authorities to weigh the nature, gravity and duration of the breach. We haven't found any fine for an Article 50 breach to report. Member States set the enforcement rules and name the authorities.

This is a summary of the law and official guidance, not legal advice.

How it connects to GDPR and data residency

Article 50 is about telling people. It doesn't say where data may go. If your chatbot handles EU personal data, GDPR applies on top, and Article 50(3) itself says personal data must be processed in line with the GDPR.

Three habits follow:

For more on the automation costs we've priced, start at the AI automation hub.

The Commission has published two voluntary or explanatory documents. They are worth reading before you finalize wording.

  • Guidelines on transparency obligations for providers and deployers of AI systems. The Commission's page says they clarify "the scope of application, relevant legal definitions, the transparency obligations and the exceptions". We haven't read the guidelines in full, so we don't quote them here.
  • Code of Practice on Marking and Labelling of AI-generated Content. A voluntary tool for providers and deployers of generative AI, which includes icons for disclosing AI-generated content.

aliteq sells none of these services and earns nothing from these links. This article summarizes official texts read on 3 October 2026 and isn't legal advice.

Quick answers

Do I have to tell people my chatbot is an AI under the EU AI Act?
Yes, in most cases. Article 50(1) requires the provider to design the system so people are informed they're interacting with an AI system, unless that is obvious to a reasonably well-informed person. Article 50(5) says the information must come at the latest at the first interaction.
Does the EU AI Act apply to a US company?
It can. Article 2 covers providers placing AI systems on the EU market whether they're established in the EU or a third country, and providers and deployers in a third country where the system's output is used in the EU. Whether your case is covered is a question for counsel.
When does Article 50 apply?
From 2 August 2026, the Act's general date of application. The one extra window is for Article 50(2) marking: generative systems placed on the EU market before 2 August 2026 have until 2 December 2026, under Article 111(4) added by Regulation (EU) 2026/1744.
What is the fine for breaching Article 50?
Up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher, under Article 99(4)(g). For SMEs and start-ups the lower of the two applies. These are maximums, and the actual fine depends on the case.
Do voice agents have to disclose that they are AI?
The same duty applies to systems that interact directly with people, and the notice must come at the latest at the first interaction. On a phone call, that is the opening seconds. The text doesn't prescribe wording, so a short spoken line at the start is the safe reading.
Am I the provider or the deployer of my chatbot?
A provider develops a system, or has one developed, and puts it on the market "under its own name or trademark". If you build a bot on a model API and ship it as your own product, you may be the provider. This is our reading of Article 3, so confirm it with counsel.

Found this useful? Share it

Share
Tensor

Local AI & Automation Editor

Tensor

I'm US-based, I run more models at home than I'll admit to, and I've quantized more than I've finished reading about. I write about running AI on your own hardware and, lately, about what it costs a company to do the same — tokens per day, GPUs per month, and the GDPR questions nobody's sales deck answers.

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading