EU AI Act chatbot disclosure requirements, explained
Short answer: if your chatbot or voice assistant talks to real people, you must make it clear they're interacting with an AI — clearly, at or before the first interaction — unless that's already obvious to a reasonably well-informed person. This has been enforceable since August 2, 2026, with fines up to €15 million or 3% of global turnover.
What Article 50(1) actually says
Article 50(1) of Regulation (EU) 2024/1689 (the AI Act) requires providers to ensure that AI systems "intended to interact directly with natural persons" are designed so those people are informed they're interacting with an AI system — "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect."
Two built-in exceptions: AI systems legally authorized for detecting, preventing, or prosecuting crime (with safeguards), and systems that are obviously AI to a reasonable person already — a voice-select IVR menu ("press 1 for billing") generally doesn't need a disclaimer; a conversational agent that can pass as a human support rep does.
Who this applies to
It applies to any provider or deployer placing a directly-interactive AI system on the EU market or whose output reaches EU users — regardless of where the company is based. Purely personal, non-professional use is excluded, but if you're running the chatbot for a business (even a side project generating any revenue), you're in scope as a deployer.
What "disclosure" looks like in practice
- Timing: the disclosure has to be there at or before the first interaction — not buried three clicks into a Terms of Service page, and not something a user has to go looking for.
- Clarity: Article 50(5) requires it be "clear and distinguishable" and meet accessibility requirements — a low-contrast one-line disclaimer in 9px grey text is a weak position to defend if challenged.
- Persistence: most practical guidance treats a one-time disclosure at the start of a session as the baseline, though a persistent visual indicator (a label on the chat widget itself) is a stronger, lower-risk pattern.
Common mistakes
- Relying on a human-sounding name. A chatbot named "Ava" or "Alex" doesn't disclose anything by itself — the obviousness exception is about what a reasonable person would conclude, not what's technically knowable.
- Disclosure only in the Terms of Service or Privacy Policy. These aren't read at the point of interaction, which is what the rule requires.
- Assuming "AI-powered" branding elsewhere on the site is enough. The requirement attaches to the interaction itself, not to marketing copy on a different page.
- Client-side-injected widgets that load after page render. If the disclosure text is added by JavaScript after the chat opens, users may already be typing before it appears — timing matters.
Penalties and enforcement
Article 50 obligations are enforced by each EU member state's national market surveillance authority. Non-compliance carries fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher (lower amount applies for SMEs). This enforcement power took effect August 2, 2026, alongside the transparency obligations themselves — the EU's "Digital Omnibus" simplification package pushed back the separate high-risk AI system regime (Annex III) to December 2027, but did not touch Article 50. See our note on what the Digital Omnibus did and didn't delay if you've seen conflicting claims about this.
Check your own site — our free scanner checks whether a public page discloses AI chat interaction and whether AI-generated media on the page carries a machine-readable marker. It's a heuristic check, not a certification.
Run the free scan →