Transparency obligations for chatbots and AI-generated content
EU AI Act Article 50 transparency: when you must tell users they're talking to AI, how to label deepfakes, and what counts as adequate disclosure.
Article 50 is the EU AI Act’s transparency chapter. It applies from 2 August 2026 — the Digital Omnibus did not postpone it (the broad high-risk postponement to December 2027 does not extend to Article 50). The only relief: AI systems that generate synthetic content and were already on the market before 2 August 2026 get a short grace period — to 2 December 2026 — for the machine-readable marking obligation in Article 50(2) (the Digital Omnibus cut that grace from six months to three). Systems first placed on the market on or after 2 August 2026 must mark synthetic content from that date — the December window is a grandfathering rule for already-live systems, not a blanket deferral. Article 50 binds providers and deployers of certain “limited-risk” AI systems — primarily chatbots, deepfakes, and other systems where the user might not realise AI is involved. (The Digital Omnibus was politically agreed on 7 May 2026 and is pending formal adoption.) This guide is the practical interpretation: when a disclosure is needed, what it must look like, and what “clearly and distinguishably” means.
The four Article 50 transparency duties
Article 50 imposes four distinct obligations:
1. Chatbots and AI systems interacting with natural persons (Article 50(1))
Providers must design AI systems interacting with natural persons so users are informed they’re interacting with AI. The exception: when this is “obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect” — i.e. when no normal person could mistake the chatbot for a human.
The exception is narrower than it looks. If your chatbot is named “Sarah” and responds in well-edited English, most users assume it’s a person. Add the disclosure.
2. Synthetic content generation (Article 50(2))
Providers of GPAI systems generating synthetic audio, image, video, or text content must mark the outputs in a machine-readable format detectable as artificially generated. The implementation is left to the provider — watermarking, metadata, C2PA, or other technical signals — but the obligation is real.
This catches most generative AI tools used in the EU (image generators, voice synthesis, text-to-speech, copilots).
3. Emotion recognition or biometric categorisation (Article 50(3))
Deployers of emotion-recognition or biometric-categorisation systems must inform natural persons of the system’s operation. This applies even when the use is not prohibited under Article 5.
(Note: emotion recognition in the workplace and educational settings is prohibited under Article 5, so this transparency duty mainly applies in remaining lawful contexts — retail, marketing research with consent, etc.)
4. Deepfakes and AI-generated public-interest content (Article 50(4))
Deployers of AI systems that generate deepfakes — meaning AI-manipulated image, audio, or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic — must disclose that the content has been artificially generated or manipulated.
There’s a narrow exception for “evidently artistic, creative, satirical, fictional or analogous work or programme” — but the burden is on you to show the work falls in the exception.
Deployers of AI systems that generate or manipulate text published for the purpose of informing the public on matters of public interest must also disclose AI involvement — unless the text was reviewed by a human or editorial controlled by a person who has editorial responsibility.
What “clearly and distinguishably” means
Article 50(5) requires that information be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. It must comply with applicable accessibility requirements.
In practice, supervisory authorities are likely to consider these as adequate:
- A visible label or badge near the chat input (“You’re talking to AI”)
- A persistent footer on AI-generated articles (“This content was generated by AI and reviewed by a human editor”)
- Visible metadata or a watermark on AI-generated images
- A clear “AI Assistant” name in the chat header (provided it doesn’t pretend to be a person)
Likely not adequate:
- A line buried in the privacy policy
- A disclosure that requires clicking through to a separate page
- A label only shown in the cookie banner
- A footnote in 8-point text at the page bottom
The bar is “clearly distinguishable to a reasonable observer,” not “technically present somewhere on the page.”
How this interacts with GDPR
For systems processing personal data, GDPR Article 13(2)(f) already requires informing data subjects about “the existence of automated decision-making, including profiling … and, at least in those cases, meaningful information about the logic involved.”
The AI Act Article 50 stacks on top:
- GDPR Art. 13 disclosure can sit in your privacy notice
- AI Act Art. 50 disclosure must be at the point of interaction
These are different surfaces — privacy notice for GDPR detail, in-product disclosure for AI Act presence. Build both.
Sector-specific notes
Customer support chatbots: disclosure required. Best practice is a static label in the chat header (not a pop-up that can be dismissed). For B2B, even when “obvious” to the buyer, the disclosure protects you for downstream users (employees of the buyer).
Marketing copy generated by AI: Article 50(4) applies if the content is published “for the purpose of informing the public on matters of public interest.” Most ordinary product marketing is not “public interest.” Editorial content is. Disclosure where it’s editorial.
AI voice agents: Article 50(1) and (2) both apply. Tell the caller they’re talking to AI; mark the audio file with machine-readable indicators.
AI-generated images in editorial use: Article 50(4) deepfake provision applies if the image resembles real persons / events. Disclosure is non-negotiable in news contexts.
Deepfake detection by competitors: the Article 50(2) machine-readable marking is meant to be detectable. Don’t try to defeat your own watermark; competitors and supervisory authorities will check.
Enforcement and penalties
Breaches of Article 50 fall in Tier 2 under Article 99: up to €15 million or 3% of global turnover for most entities, capped lower for SMEs. Enforcement maturity will build after the application date, but the timing depends on national authorities, Commission guidance, and market-surveillance priorities.
What to do this quarter
If you operate any of the following, build the disclosure design now:
- A customer-facing chatbot — add the visible AI badge
- A copilot or generative writing tool — add the AI-generated marking
- A voice assistant — confirm both the in-call disclosure and machine-readable audio marking
- A deepfake-capable image or video generator — mandatory marking, mandatory disclosure at publication
Don’t wait until 2 August 2026 to ship the disclosure design. Build it now and let the engineering iterate.