SELINA.ai
Sign in

EU AI Act Article 50 Requirements: What the "You Are Talking to an AI" Rule Actually Demands

As of 2 August 2026, the transparency obligations under Article 50 of the EU AI Act are enforceable. If you ship a chatbot, a virtual assistant, a generative content tool, or anything that produces synthetic media, the eu ai act article 50 requirements now apply to you. Not eventually. Now. This piece walks through what the rule actually says, where the Commission drew the lines, and what you need to build before a national authority comes asking.

Key Takeaways

What Does Article 50 Actually Require?

Article 50 of Regulation (EU) 2024/1689 imposes transparency obligations on providers and deployers of certain AI systems. It is not about high-risk classification. It is not about model cards or technical documentation for regulators. It is about telling people what they are looking at or talking to. Four buckets:

  1. Chatbots and conversational agents. If your AI system directly interacts with a natural person, the system must be designed so that person knows they are dealing with AI. Not a human. Not an ambiguously branded "assistant." An AI system.
  2. Emotion recognition and biometric categorization. If your system infers emotional states or categorizes people by biometric data, you must inform exposed individuals that the system is operating and what categories it processes.
  3. Synthetic media (deepfakes). If your system generates or manipulates image, audio, or video content that resembles real persons, places, or events in a way that could be mistaken for authentic, you must label that content as artificially generated or manipulated.
  4. AI-generated text on public-interest matters. If your system generates text that is published to inform the public about matters of public interest, you must disclose that the text was generated by AI.

The obligations land on different actors depending on the bucket. Providers (you, if you built the system) bear the design obligation for chatbot disclosure and the technical obligation for machine-readable marking. Deployers (your customers, if they run the system in production) bear disclosure duties for emotion recognition and deepfake labeling at the point of use.

When Does the Chatbot-Disclosure Duty Actually Trigger?

It triggers when four cumulative criteria are met. The Commission's FAQ on Article 50 spells them out:

If all four are true, you must disclose. The threshold is lower than most teams assume. A customer-support widget that auto-responds before a human joins the conversation? That qualifies for the portion of the conversation handled by AI. A scheduling assistant that emails a third party on behalf of a user? That qualifies too, because the third party is a natural person receiving AI-generated communication.

What Counts as Adequate Disclosure?

The Commission and early commentary from law firms are converging on a "perceivable within the interaction" standard. Bratby Law's analysis puts it plainly: a disclosure buried in terms and conditions does not satisfy the duty. A metadata watermark alone does not satisfy it. A vague reference to an "assistant" does not satisfy it.

What does satisfy it: a clear, upfront statement at the start of the interaction that the user is communicating with an AI system. The Commission's final guidelines, adopted 20 July 2026, are non-binding but will serve as the primary reference for national authorities. They point toward disclosure that is timely (before or at the start of interaction), clear (plain language, not legal jargon), and accessible (appropriate for the medium, which means spoken disclosure for voice interfaces, visual disclosure for chat UIs).

For product leads: this means your onboarding flow, your first-message template, and any auto-generated outbound communication all need a disclosure line. If your system can initiate contact with people who never opted in (an agentic workflow emailing or calling someone), those people need to be told too.

What About Machine-Readable Marking for Generated Content?

Separate from the chatbot-disclosure duty, Article 50 requires providers of generative AI systems to mark their outputs in a machine-readable format so downstream tools can detect that the content is artificial. This applies to generated text, images, audio, and video. The practical guide from artificialintelligenceact.eu summarizes the split: the chatbot duty is about telling the person in the room; the marking duty is about embedding provenance metadata so the content can be identified as AI-generated wherever it travels.

The marking must be "sufficiently reliable, interoperable, effective and robust." The Commission has not mandated a single technical standard, but the Code of Practice on Transparency of AI-Generated Content, published in June 2026, points heavily toward C2PA-style content credentials. The Code still needs formal endorsement from the Commission and AI Board, but once endorsed, signatories will be able to rely on it as a compliance tool.

One important nuance: under the AI Omnibus's provisional agreement, generative AI systems already on the market before 2 August 2026 get until 2 December 2026 to implement machine-readable marking. Systems placed on the market on or after August 2 must mark from day one. And the grace period does not extend to the chatbot-disclosure duty at all. If your chatbot is live, the disclosure obligation is live.

Does This Apply to Agentic AI Systems?

Yes. The European Commission interprets the duty broadly: any AI system that directly interacts with people must identify itself, and this explicitly includes agentic AI systems that act autonomously. The logic is straightforward. If your agent books a restaurant by calling the venue, the person answering the phone is interacting with an AI system. The disclosure duty applies to that interaction, regardless of whether the agent's principal (your user) is in the loop.

This creates a real architectural problem for teams building autonomous agents. You cannot always predict which third parties the agent will contact or through which channel. The Commission's position, per Greenberg Traurig's analysis, is that if a provider cannot rule out contact with natural persons, the deployer must ensure disclosure in every likely-contact scenario. That means logging which interactions occurred, through what medium, and whether disclosure was delivered. For most agent-building teams, this consent-and-logging architecture is the compliance work they have not started yet.

Are There Any Exemptions?

A few, all narrow.

Bird & Bird's initial analysis of the Commission's final guidelines notes that minor assistive edits, like spell-check, grammar correction, or formatting, are generally exempt. The test is whether the AI changed the meaning or substance of the content. Fixing a typo: exempt. Rewriting a paragraph: not exempt.

There is an artistic and satirical exemption for synthetic media labeling, but the Commission interprets it narrowly. Content that is exclusively informative or commercial cannot benefit from reduced labeling obligations. A marketing video created with generative AI does not qualify as artistic expression for these purposes, even if it is aesthetically ambitious.

Content generated before 2 August 2026 does not need to be labeled retroactively, though the Commission encourages retroactive labeling where feasible.

And law enforcement gets a carve-out: disclosure can be deferred when it would compromise a criminal investigation or national security operation. This is not relevant to most product teams, but it is the only scenario where the chatbot-disclosure duty can be temporarily suspended rather than satisfied.

How Big Are the Fines?

Article 50 violations fall under the general AI Act penalty regime. For transparency violations specifically: up to €15 million or 3% of global annual turnover, whichever is higher. For SMEs and startups, the applicable figure is the lower of the two amounts, which is a meaningful concession but still substantial for a Series A company doing a few million in revenue.

Enforcement sits with national market surveillance authorities, not a single EU-level regulator. The AI Office can investigate systemic issues and has already shown appetite: earlier this year it opened an investigation into a major chatbot over alleged synthetic media and content violations, signaling that regulators will not wait for complaints to accumulate before acting.

Why Did So Many Teams Think This Was Delayed?

Because media coverage conflated two separate regulatory tracks. The Digital Omnibus pushed back deadlines for high-risk AI system obligations, and many compliance teams (and their legal counsel) read the headlines and assumed the entire AI Act timeline had shifted. It had not. Article 50's transparency obligations were never part of the postponement. They applied on schedule, 2 August 2026.

This confusion is widespread enough that artificialintelligenceact.eu's compliance data shows transparency obligations are the second most common compliance trigger after AI literacy requirements, affecting roughly 33% of surveyed organizations. For companies without any high-risk AI systems, Article 50 may be their only substantive compliance obligation under the entire Act.

What Should a Product Team Actually Build?

Here is the minimum viable compliance surface, based on the four categories and the Commission's guidelines:

For chatbot/conversational interfaces:

For generative content (text, image, audio, video):

For emotion recognition or biometric categorization:

For synthetic media (deepfakes):

Does Provenance Marking Have to Be a Compliance Tax?

No. If you are building a product where trust matters (and if you are reading this, you probably are), machine-readable provenance is a feature, not overhead. The same infrastructure that lets a regulator verify content origin lets your users verify it too. A person exposed to a realistic AI-generated image should be able to tell a machine made it. That is a trust argument that exists independent of Article 50. The regulation just makes it mandatory.

The Code of Practice is worth reading even if you are not a signatory. It lays out practical approaches to watermarking, metadata embedding, and labeling that represent current best practice. Once the Commission and AI Board formally endorse it, signatories will be able to point to Code compliance as evidence of satisfying Article 50 obligations. That is a useful compliance shortcut for teams that adopt it early.

What About the Privacy Tension?

There is a real design conflict between transparency and data minimization. The chatbot-disclosure trigger requires genuine two-way exchange rather than mere data collection. But some AI-powered tools sit in a gray zone: authentication systems, fraud-detection models, biometric verification flows. These may process personal data with minimal human interaction, yet still fall under Article 50(3) if they perform emotion recognition or biometric categorization. A fraud-detection system that analyzes voice patterns to assess stress could qualify.

For privacy-focused products, this creates an awkward intersection. You may have designed a system specifically to minimize data exposure. On-device inference, short retention windows for operational metadata, encrypted content at rest. And now you must surface a disclosure to the user that, in some cases, calls attention to processing they might not have noticed. The regulation does not care whether you are processing data in a privacy-preserving way. If the system interacts with a person or categorizes them biometrically, you disclose.

This is not a criticism of the regulation. Transparency and privacy serve different, complementary functions. But the engineering work to satisfy both simultaneously is nontrivial, and most teams have not started it.

What Happens If You Are Outside the EU?

Article 50 applies to providers and deployers that place AI systems on the EU market or whose systems' outputs are used within the EU. If your chatbot is accessible to EU residents, you are in scope. The territorial reach mirrors GDPR's approach: targeting or monitoring EU individuals brings you under the regulation regardless of where your servers sit.

For US-based teams in particular: the assumption that "we'll deal with EU compliance later" is the same assumption that aged poorly under GDPR. National authorities have enforcement powers, and the AI Office has already demonstrated willingness to investigate cross-border providers.

What Does the Timeline Look Like Going Forward?

The Stibbe timeline is the clearest summary available:

The high-risk system obligations (Articles 6-49) operate on a separate, later timeline that the Digital Omnibus extended. Do not confuse the two. Article 50 is live.

A Practical Compliance Checklist

For compliance leads who need to report status to their board this week:

  1. Inventory your AI-facing surfaces. Every chatbot, virtual assistant, auto-responder, scheduling agent, or customer-support widget that generates responses using AI is in scope for the chatbot-disclosure duty.
  2. Audit your disclosure language. Is it in the interaction itself, or buried in a ToS? Is it presented before the user engages, or after? Is it in plain language appropriate to the medium?
  3. Check your generative outputs. Any system producing text, images, audio, or video needs machine-readable provenance marking. If it is a new system (placed on market August 2 or later), this is required now. If it is a legacy system, you have until December 2.
  4. Map your agentic workflows. If any AI system you operate can initiate contact with third parties, identify every channel through which that contact might occur and verify that disclosure is delivered in each one.
  5. Review biometric and emotion-recognition features. If your product infers emotional states or categorizes by biometric data (including voice analysis, facial recognition, gait analysis), confirm that exposed individuals are informed.
  6. Document everything. National authorities will want evidence of compliance, not just assertions. Logging what disclosure was delivered, when, and to whom is the minimum defensible posture.

The Real Cost of Getting This Wrong

The fine ceiling (€15M / 3% of turnover) is the number that gets cited. The operational cost is more interesting. A national authority investigation means document requests, technical audits, and management attention diverted from product work. For a startup, an investigation is a distraction you cannot afford even if the fine is ultimately modest. For an enterprise, it is a procurement risk: your customers' compliance teams will ask whether your AI systems satisfy Article 50 before they renew.

The smartest move is to treat disclosure as a product feature, not a legal patch. A clear "You are talking to an AI" message does not degrade user experience. It sets expectations. Users who know they are talking to an AI calibrate their trust appropriately, ask different questions, and complain less when the system gets something wrong. Transparency, when done well, is a UX improvement that happens to also be legally required.

If you are building with AI and want a place to see how transparent disclosure works in practice, start a free 7-day trial of Selina, no card required.

Frequently Asked Questions

What are the four categories of AI systems covered by Article 50?

Article 50 covers chatbots and conversational agents, emotion-recognition and biometric-categorization systems, synthetic media generators (deepfakes), and AI-generated text published on matters of public interest. Each category has distinct disclosure obligations.

When does the chatbot-disclosure duty actually apply?

It triggers when four conditions are all met: there is a genuine two-way exchange, the AI communicates directly without a human intermediary, the interaction is with a natural person, and the response is generated by the AI itself rather than merely relayed.

Is putting the AI disclosure in the terms of service or a metadata watermark enough?

No. The Commission and legal commentary say disclosure must be perceivable within the interaction itself, so a line buried in terms and conditions or a metadata watermark alone does not satisfy the duty.

Did the Digital Omnibus delay push back the Article 50 obligations?

No, the Digital Omnibus delay applied to high-risk system obligations, not Article 50. The chatbot-disclosure duty has no grace period, though existing generative AI systems placed on the market before 2 August 2026 get until 2 December 2026 for machine-readable content marking only.

Does Article 50 apply to autonomous agentic AI systems that contact third parties?

Yes, the Commission interprets the duty broadly to include agentic AI systems, so if an AI agent contacts a person directly (for example, calling a venue to book a reservation), that interaction still requires disclosure regardless of whether the user is in the loop.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai