Does your chatbot need an AI disclosure?
Article 50 of the EU AI Act has applied since 2 August 2026. The Digital Omnibus postponed the high-risk rules — transparency it left alone. If your store runs a chatbot, generates ad visuals or writes copy with AI, some of that output needs labelling. The scope is narrower than the headlines suggest — product descriptions stay out — but fines reach €15 million or 3% of worldwide turnover, enforced by national market surveillance authorities.

The dates and numbers that matter
Five facts organise the whole topic — each returns later in the article:
- 2 August 2026 — Article 50 of Regulation 2024/1689 (the AI Act) starts to apply: transparency obligations for providers and deployers of AI systems. The Digital Omnibus did not move this date.
- 2 December 2026 — the only grace period ends: providers of generative systems placed on the market before 2 August get extra time to implement machine-readable marking (paragraph 2).
- €15 million or 3% of turnover — the ceiling for fines under Article 50 (whichever is higher); for SMEs and start-ups the lower of the two applies.
- 20 July 2026 — the European Commission adopted its guidelines on Article 50, a practical manual for applying these obligations.
- Enforcement is national — in Poland, for example, the new KRiBSI authority applies fines from 28 October 2026 under the act of 3 July 2026 on AI systems.
Does my chatbot have to tell customers they're talking to AI?
Yes — Article 50(1) requires AI systems that interact directly with people to be designed so the person knows they are dealing with AI. Formally this duty sits with the provider of the tool. In practice it lands on the business deploying the chatbot: you pick the tool and you configure the messages. Integrating someone else's model does not make you the provider — but you do need to check the tool lets you meet the requirement.
There is an exception: no notice is needed where the AI nature of the interaction is obvious to a reasonably observant person in the circumstances. It is safer to assume your store's customers see nothing obvious — especially when the bot answers fluently and signs off with a human name.
Paragraph 5 sets the form: clear, distinguishable, at the latest at the first interaction, and accessible. A short opening line ("You're chatting with an AI assistant") does the job better than a clause buried in the terms of service.
Do AI-generated product descriptions need to be labelled?
As a rule, no. The disclosure duty covers text published "to inform the public on matters of public interest" (Article 50(4)). A product description, a sales email or a category page does not fall within that definition.
Even where the rule does reach — say, an advice article about legal changes — there is a further carve-out. No duty arises where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. A company blog with a named author and an editing step qualifies.
Mind paragraph 6, though: Article 50 does not switch off other laws. Where consumer law demands honest communication, generating the copy with AI changes nothing.
Do AI images in ads count as deepfakes?
Everything turns on the deepfake definition in Article 3(60): AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. A deployer using such material must disclose that it is artificial.
For e-commerce the line runs between illustration and the appearance of authenticity. A generated scene that looks like a real product shoot with a real model falls under the rule. An abstract illustrative graphic does not. For clearly artistic or satirical content, a disclosure that does not spoil the work is enough.
A separate duty sits with tool providers: their systems must mark outputs in a machine-readable way (paragraph 2) so AI content can be detected. Systems already on the market before 2 August 2026 have until 2 December 2026. When choosing a generator, ask the vendor directly about that marking — and whether they signed the Code of Practice on Transparency of AI-Generated Content, which the Commission has assessed as an adequate voluntary tool for demonstrating compliance.
Emotion recognition and biometric categorisation — does this concern me?
Rarely, but check. Article 50(3) requires deployers of emotion recognition or biometric categorisation systems to inform the people exposed to them — and to process personal data in line with the GDPR. If your customer-service analytics promises to "detect the caller's emotions", that is exactly this case. If you use no such features, tick the box consciously: after reviewing your tools' settings, not on assumption.
Since when does this apply — and what about older content?
The timing depends on your role and the type of content:
| What you do with AI | Your role | Obligation | From |
|---|---|---|---|
| Customer-service chatbot | you use a provider's tool | the customer must know it's AI (paras 1 and 5) | 2 Aug 2026 |
| Product descriptions, sales copy | deployer | as a rule, no Article 50 duty | — |
| Realistic AI images and video (deepfakes) | deployer | disclose the content is artificial (para 4) | 2 Aug 2026 |
| Public-interest articles without editorial review | deployer | disclose (para 4) | 2 Aug 2026 |
| Emotion analytics on customers | deployer | inform the people + GDPR (para 3) | 2 Aug 2026 |
| A generative tool you sell | provider | machine-readable marking (para 2) | 2 Aug 2026 / grace until 2 Dec 2026 |
Content generated before 2 August 2026 does not need retroactive labelling. The exception is public-interest text: there the publication date counts, so an AI-written piece drafted in July but published in September falls under the rules.
What are the penalties — and who enforces them?
Breaching Article 50 carries an administrative fine of up to €15 million or 3% of total worldwide annual turnover (Article 99), whichever is higher — and for SMEs and start-ups, whichever is lower. Enforcement sits with national market surveillance authorities, so the procedure and the exact institution depend on the member state. Poland, for instance, created a dedicated collegiate authority (KRiBSI) that applies fines from 28 October 2026 and can cut a fine by 20–70% in a settlement — in a specific track even by 90%.
How to get compliant in a few days
The work is smaller than it sounds. A sensible order:
- Inventory your AI uses — list where AI actually runs: chatbot, description generator, visuals, video, call analytics.
- Assign a role to each use — for every item, decide whether you are the deployer or (exceptionally) the provider.
- Map against paragraphs 1–4 — the table above shows which uses need action; for most companies the duty list comes out shorter than the inventory.
- Write the notices per paragraph 5 — clear, visible, at the first interaction; for a chatbot, one opening sentence.
- Question your tool vendors — does the system mark content machine-readably, and did the vendor sign the code of practice?
If you would rather first work out where AI makes sense in your business at all — before labelling anything — that is what our AI diagnosis covers: 2–3 weeks of work, €2,500–4,500 net, independent of tool vendors.


