AI for Business

Does your chatbot need an AI disclosure?

Article 50 of the EU AI Act has applied since 2 August 2026. The Digital Omnibus postponed the high-risk rules — transparency it left alone. If your store runs a chatbot, generates ad visuals or writes copy with AI, some of that output needs labelling. The scope is narrower than the headlines suggest — product descriptions stay out — but fines reach €15 million or 3% of worldwide turnover, enforced by national market surveillance authorities.

AuthorMarcin KamińskiPublished6 min read

The dates and numbers that matter

Five facts organise the whole topic — each returns later in the article:

  • 2 August 2026 — Article 50 of Regulation 2024/1689 (the AI Act) starts to apply: transparency obligations for providers and deployers of AI systems. The Digital Omnibus did not move this date.
  • 2 December 2026 — the only grace period ends: providers of generative systems placed on the market before 2 August get extra time to implement machine-readable marking (paragraph 2).
  • €15 million or 3% of turnover — the ceiling for fines under Article 50 (whichever is higher); for SMEs and start-ups the lower of the two applies.
  • 20 July 2026 — the European Commission adopted its guidelines on Article 50, a practical manual for applying these obligations.
  • Enforcement is national — in Poland, for example, the new KRiBSI authority applies fines from 28 October 2026 under the act of 3 July 2026 on AI systems.

Does my chatbot have to tell customers they're talking to AI?

Yes — Article 50(1) requires AI systems that interact directly with people to be designed so the person knows they are dealing with AI. Formally this duty sits with the provider of the tool. In practice it lands on the business deploying the chatbot: you pick the tool and you configure the messages. Integrating someone else's model does not make you the provider — but you do need to check the tool lets you meet the requirement.

There is an exception: no notice is needed where the AI nature of the interaction is obvious to a reasonably observant person in the circumstances. It is safer to assume your store's customers see nothing obvious — especially when the bot answers fluently and signs off with a human name.

Paragraph 5 sets the form: clear, distinguishable, at the latest at the first interaction, and accessible. A short opening line ("You're chatting with an AI assistant") does the job better than a clause buried in the terms of service.

Do AI-generated product descriptions need to be labelled?

As a rule, no. The disclosure duty covers text published "to inform the public on matters of public interest" (Article 50(4)). A product description, a sales email or a category page does not fall within that definition.

Even where the rule does reach — say, an advice article about legal changes — there is a further carve-out. No duty arises where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. A company blog with a named author and an editing step qualifies.

Mind paragraph 6, though: Article 50 does not switch off other laws. Where consumer law demands honest communication, generating the copy with AI changes nothing.

Do AI images in ads count as deepfakes?

Everything turns on the deepfake definition in Article 3(60): AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. A deployer using such material must disclose that it is artificial.

For e-commerce the line runs between illustration and the appearance of authenticity. A generated scene that looks like a real product shoot with a real model falls under the rule. An abstract illustrative graphic does not. For clearly artistic or satirical content, a disclosure that does not spoil the work is enough.

A separate duty sits with tool providers: their systems must mark outputs in a machine-readable way (paragraph 2) so AI content can be detected. Systems already on the market before 2 August 2026 have until 2 December 2026. When choosing a generator, ask the vendor directly about that marking — and whether they signed the Code of Practice on Transparency of AI-Generated Content, which the Commission has assessed as an adequate voluntary tool for demonstrating compliance.

Emotion recognition and biometric categorisation — does this concern me?

Rarely, but check. Article 50(3) requires deployers of emotion recognition or biometric categorisation systems to inform the people exposed to them — and to process personal data in line with the GDPR. If your customer-service analytics promises to "detect the caller's emotions", that is exactly this case. If you use no such features, tick the box consciously: after reviewing your tools' settings, not on assumption.

Since when does this apply — and what about older content?

The timing depends on your role and the type of content:

What you do with AIYour roleObligationFrom
Customer-service chatbotyou use a provider's toolthe customer must know it's AI (paras 1 and 5)2 Aug 2026
Product descriptions, sales copydeployeras a rule, no Article 50 duty
Realistic AI images and video (deepfakes)deployerdisclose the content is artificial (para 4)2 Aug 2026
Public-interest articles without editorial reviewdeployerdisclose (para 4)2 Aug 2026
Emotion analytics on customersdeployerinform the people + GDPR (para 3)2 Aug 2026
A generative tool you sellprovidermachine-readable marking (para 2)2 Aug 2026 / grace until 2 Dec 2026

Content generated before 2 August 2026 does not need retroactive labelling. The exception is public-interest text: there the publication date counts, so an AI-written piece drafted in July but published in September falls under the rules.

What are the penalties — and who enforces them?

Breaching Article 50 carries an administrative fine of up to €15 million or 3% of total worldwide annual turnover (Article 99), whichever is higher — and for SMEs and start-ups, whichever is lower. Enforcement sits with national market surveillance authorities, so the procedure and the exact institution depend on the member state. Poland, for instance, created a dedicated collegiate authority (KRiBSI) that applies fines from 28 October 2026 and can cut a fine by 20–70% in a settlement — in a specific track even by 90%.

How to get compliant in a few days

The work is smaller than it sounds. A sensible order:

  1. Inventory your AI uses — list where AI actually runs: chatbot, description generator, visuals, video, call analytics.
  2. Assign a role to each use — for every item, decide whether you are the deployer or (exceptionally) the provider.
  3. Map against paragraphs 1–4 — the table above shows which uses need action; for most companies the duty list comes out shorter than the inventory.
  4. Write the notices per paragraph 5 — clear, visible, at the first interaction; for a chatbot, one opening sentence.
  5. Question your tool vendors — does the system mark content machine-readably, and did the vendor sign the code of practice?

If you would rather first work out where AI makes sense in your business at all — before labelling anything — that is what our AI diagnosis covers: 2–3 weeks of work, €2,500–4,500 net, independent of tool vendors.

Common questions about labelling AI content

The law does not prescribe a language — it requires the information to be clear and distinguishable to the person (Article 50(5)). The practical reading: use the language of the store version the customer is browsing.

As a rule, no. The disclosure duty covers text published to inform the public on matters of public interest — commercial communication does not qualify. Ordinary rules on honest marketing still apply, AI or not.

Retouching and standard editing do not create a deepfake — the definition targets content resembling real persons, objects or events that could pass as authentic. A fully generated "photo shoot" with a realistic model is a different case: it needs disclosure.

The ceilings are shared (€15 million or 3% of turnover), but for SMEs and start-ups the lower of the two applies, and regulators must weigh their economic situation. Some member states add settlement mechanisms that reduce fines further.

The code of practice is a voluntary tool the Commission has assessed as adequate for demonstrating compliance with the detection-and-marking duties. It helps — but it does not replace the obligations themselves, especially the notices owed to your customers.

Machine-readable marking of outputs is the provider's duty (Article 50(2)). As a deployer you answer for your own duties: disclosing deepfakes and informing chatbot users. Still, write AI Act conformity of the tool into the vendor contract.

Related articles

Facing a similar decision?

Book a 30-minute diagnostic call. No commitment and no sales pitch — it ends with an assessment of your situation and a proposed first step.

Book a call

We reply within 24h