On July 20, the European Commission published its Article 50 transparency guidelines. The rules apply from August 2, 2026. For a website chatbot, the central requirement is direct: people must be informed that they are interacting with AI from the start of the first interaction, unless that fact is already obvious.
The short deadline makes this an implementation job, not a policy-reading exercise. Start with this chatbot AI disclosure checklist:
- Identify the provider, deployer, channels, and EU users in scope.
- Put an explicit AI notice in or before the first chatbot message.
- Keep an AI identity label visible after the greeting disappears.
- Use equivalent spoken disclosure for voice and phone experiences.
- Distinguish AI replies from human support replies during handoff.
- Localize the notice and meet the same accessibility standard as the chat.
- Test direct links, iframes, mobile layouts, reopened sessions, and screen readers.
- Save dated evidence of the copy and interface that customers actually received.
This is a practical reading of the new guidance, not legal advice. Use counsel to confirm how the AI Act applies to your organization, markets, and specific system.
Start With the Role, System, and Audience
The AI Act separates providers from deployers. A provider develops an AI system, has one developed, and places it on the EU market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority for a professional activity.
For a hosted chatbot, the platform company may be the provider while the business placing the bot on its website is the deployer. That description is only a starting point. Branding the system as your own, substantially modifying it, or combining components into a new system can change the analysis. Record the answer rather than assuming “we only bought software” settles it.
The Commission's Article 50 questions and answers also says providers outside the EU can be in scope when their system's output is used in the EU. A .com domain, US headquarters, or non-EU model provider does not by itself remove European users from the picture.
Build a one-page scope record with:
- the legal entity responsible for the chatbot;
- the platform, model providers, and other system components;
- the countries and languages in which people can reach it;
- every channel where the same AI identity appears;
- whether the interaction is direct and genuinely two-way;
- the owner who approves disclosure copy and interface changes.
Article 50(1) concerns AI systems designed for direct interaction with natural persons. The Commission describes chatbots, AI agents, and avatars as examples. Systems operating only in the background, machine-to-machine exchanges, and tools whose output reaches a person through a human intermediary are different cases. Do not stretch the chatbot notice into a universal answer for every AI use.
| Experience | First scope question | Evidence to keep |
|---|---|---|
| Public support chatbot | Does the AI conduct a direct two-way exchange? | Entry URL, first message, persistent label |
| AI sales assistant | Can a visitor reasonably mistake it for a person? | Launcher, avatar, name, opening transcript |
| Voice or phone bot | Is AI identity stated audibly at the start? | Call recording, script version, language |
| Human agent using AI drafts | Does the customer interact with AI directly? | Workflow diagram and human review rule |
| Static form or decision tree | Does it qualify as an AI system and genuine exchange? | System description and counsel's assessment |
Write a Notice a Customer Cannot Miss
The legal text requires information to be clear, distinguishable, and accessible. That rules out disclosure buried in terms, a privacy policy, an “about” screen, or a tooltip that most visitors never open.
A fictional outdoor retailer called Northline could use this opening:
Northline AI Assistant I'm an AI assistant. I can answer questions using Northline's help content and connect you with a support specialist when needed. [Ask a question] [Talk to support]
After the opening scrolls away, the header or message attribution could retain:
Northline AI Assistant · Automated replies
When a person takes over, the transition should remove ambiguity:
AI Assistant: I'm connecting you with Maya, a Northline support specialist. Replies marked “Maya” are now from a person. Maya · Support specialist: I have the order details. Let me check the warehouse status.
This pattern does four useful things. It names the system as AI, says what it does, offers a human route, and marks the identity change during handoff. It does not require a frightening warning or a paragraph of legal language.
Avoid vague openings such as “Hi, I'm Nova” or “Your virtual support companion is here.” A robot avatar or sparkle icon may suggest automation, but styling is weaker than plain words. The Commission says the “obvious” exception should be interpreted restrictively because it removes information a person would otherwise receive.
Place Disclosure at Every Real Entry Point
The official Article 50 text says the information must arrive no later than the first interaction or exposure. The Commission's newer FAQ sharpens that for conversational systems: notify people from the start of the first interaction.
Treat the first interaction as a product state, not a sentence in one greeting template. A visitor may bypass your homepage and open:
- a chatbot from a product page;
- an iframe on a partner site;
- a direct link copied from another conversation;
- a messaging or social channel;
- a restored session whose greeting is no longer visible;
- a phone number answered by a voice agent.
For a collapsed website widget, an “AI assistant” launcher label is useful early notice. Repeat the identity in the first expanded state so a small icon, truncated mobile label, or custom embed does not carry the whole burden.
For voice, speak the notice before the substantive exchange: “You’re speaking with Northline’s AI assistant.” Do not rely on a visual notice that a caller cannot see. If the call transfers to a person and later returns to automation, announce the new identity again.
Handoffs need special attention because mixed AI-human threads create the exact confusion disclosure is meant to prevent. The AI-to-human handoff guide explains how to carry context and escalation reasons; add speaker identity to that packet and to the customer-facing transcript.
Make the Notice Accessible and Localized
Article 50 requires the notice to conform to applicable accessibility requirements. A disclosure that exists in the DOM but is skipped by a screen reader is not a dependable notice. Neither is light-gray text that disappears in a custom theme.
Test the disclosure for:
- keyboard focus order when the widget opens;
- a sensible screen-reader announcement;
- text contrast and zoom at 200%;
- mobile layouts without clipping or ellipsis;
- reduced-motion settings if identity appears through animation;
- audible clarity in voice channels;
- comprehension in every supported language.
Translate meaning, not only words. “AI assistant,” “automated system,” and “virtual agent” do not carry identical expectations in every market. Ask a fluent reviewer to confirm that the local version plainly identifies AI and does not sound like a human job title.
Accessibility also improves operational reliability. A persistent text label survives missing images, blocked scripts, silent autoplay, and custom CSS more consistently than an icon. Pair visual and programmatic signals so one failure does not erase the notice.
Keep Disclosure Separate From Answer Quality
An AI label tells the customer who—or what—is replying. It does not prove that the answer is accurate, current, authorized, or complete.
Use separate controls for those risks:
Source control. Train the chatbot on approved, current material and preserve links or document metadata for sensitive claims. If source maintenance is the weak point, fix the pipeline described in the chatbot document AI guide.
Uncertainty behavior. Make the bot say when it cannot find enough evidence. “I couldn't verify that return exception” is more useful than a confident guess with an AI warning beneath it.
Action boundaries. Disclose whether the bot can only answer or can also submit forms, create tickets, change records, or call APIs. Customer confirmation and authorization remain separate requirements.
Human recovery. Give the visitor a visible path to a person when the answer affects money, access, safety, or a policy exception. Disclosure without recovery can feel like a disclaimer placed in front of a dead end.
The chatbot hallucination liability guide covers the evidence, source, and escalation controls behind high-consequence answers. Keep those controls even when every customer clearly understands that the speaker is AI.
Run the First-Interaction Test
Test what a person sees, not what the configuration screen says. Use a fresh browser session for every entry point and preserve a screenshot or recording.
| Test | Pass condition |
|---|---|
| New desktop visitor | AI identity is clear before or with the first reply |
| New mobile visitor | Notice is readable without clipping or extra navigation |
| Returning visitor | Restored chat still carries a visible AI label |
| Direct iframe or shared link | Disclosure does not depend on the parent homepage |
| Keyboard and screen reader | Notice is announced in a logical order |
| Voice call | Audible AI identity precedes the substantive exchange |
| Human handoff | AI and human messages have unmistakable attribution |
| Localized channel | A fluent reviewer confirms the translated meaning |
Then try to make the test fail. Hide the greeting by restoring an old conversation. Apply the darkest allowed widget theme. Open at the narrowest supported width. Block avatar images. Enter through an embed that removes the surrounding brand copy. These cases reveal whether disclosure is part of the interaction or merely decoration around the happy path.
Add the tests to release review whenever someone changes the chatbot name, avatar, launcher, greeting, theme, embed, channel, or handoff experience. A model update alone may not affect disclosure, but a redesign can remove it without touching the AI configuration.
Keep a Small Evidence Package
Compliance evidence should reconstruct the customer experience without requiring an investigator to trust the current production state.
Store:
- the approved disclosure text and translations;
- screenshots for desktop, mobile, iframe, and reopened sessions;
- a short voice recording when applicable;
- the release or configuration version;
- the date each channel was tested;
- the provider and deployer analysis;
- the owner and reviewer;
- known exceptions and their rationale.
A compact record might look like this:
disclosure_version: "2026-08-eu-1"
owner: "support-operations"
channels:
widget:
first_message: "I'm an AI assistant..."
persistent_label: "AI Assistant · Automated replies"
voice:
opening: "You're speaking with Northline's AI assistant."
locales_reviewed: ["en", "de", "et"]
tested_at: "2026-07-30"
evidence:
- "widget-mobile-en.png"
- "widget-screen-reader-en.txt"
- "voice-opening-de.wav"
Do not collect customer data merely to prove the notice appeared. Controlled test sessions usually provide cleaner evidence with less privacy risk. If production telemetry records disclosure delivery, keep the event minimal and define a retention period.
Do Not Misread the Grace Period
The Commission's FAQ says Article 50 applies from August 2, 2026. It describes a limited transition until December 2, 2026 for certain systems already on the market, but only for the machine-readable marking and detection obligation in Article 50(2).
That is not a general extension for chatbot interaction notices under Article 50(1). Teams waiting for December to add “AI assistant” to a customer conversation are combining two different obligations.
Finish the visible notice, persistent identity, accessibility check, channel audit, and evidence package now. If your system also generates images, audio, video, or text for publication, assess the separate marking and labelling rules with the people responsible for that content.
Clear AI identity is a small interface change with a large trust effect. It gives customers the context to judge an answer, decide whether to continue, and ask for a person. The strongest implementation makes that context obvious at entry, durable through the conversation, and testable after every design change.
No credit card required.



