EU AI Act · use case
EU AI Act for Customer Service Chatbots: Article 50 Transparency Rules
Customer-facing chatbots are limited-risk under the EU AI Act. Article 50 disclosure has applied since 2 August 2026. Exact requirements, wording and where it becomes high-risk.
Classify my system in 3 minutesFree, no account. Pre-filled for this use case.
Risk tier
Limited risk
Limited risk (Article 50 transparency), unless used for an Annex III purpose
When it applies
Article 50 obligations have applied since 2 August 2026.
Regulation (EU) 2024/1689, Art. 50(1) and 50(2); Art. 4 AI literacy; Art. 5(1)(a) manipulation ban
A support chatbot, a sales assistant on a product page, an AI voice agent answering the phone: all of these are AI systems “intended to interact directly with natural persons”, which is the trigger for Article 50 of the EU AI Act. The obligation is light compared with the high-risk regime, but it is mandatory, it is enforceable with fines, and it has applied since 2 August 2026.
The rule in one sentence: users must be told they are dealing with AI, clearly, at the point of interaction, unless it is obvious to a reasonably well-informed person. Burying it in the Terms of Service does not count.
Classification
Why this classification applies
Article 50(1) requires providers to design systems intended to interact with people so that those people are informed they are interacting with AI, unless this is obvious from the circumstances and context. Article 50(2) adds that providers of systems generating synthetic text, audio, image or video must mark outputs in a machine-readable format where technically feasible.
Chatbots are not on the Annex III list by themselves. They become high-risk when their intended purpose is one of the listed ones: pre-qualifying job applicants, deciding on a loan or a benefit, triaging patients for care, or grading students. A support bot that routes tickets or answers product questions stays limited-risk.
Article 5 still applies: a bot that uses subliminal or manipulative techniques to distort decisions (for example dark-pattern pressure to buy or to cancel a refund request) can be a prohibited practice.
Obligations
What you have to do
- Display a clear, timely AI notice at the start of the interaction and keep it visible; re-disclose after a human hand-off (Art. 50(1)).
- If the bot generates text, images or audio that leave the interface (emails, documents, voice messages), mark them as AI-generated in a machine-readable way where feasible (Art. 50(2)).
- Make the notice accessible: readable by assistive technology, not conveyed by colour alone, in every language offered.
- Train the staff who configure and supervise the bot on its limits and on escalation (Art. 4 AI literacy).
- Do not deploy manipulative or deceptive conversational techniques (Art. 5(1)(a)).
- Keep the privacy policy and Terms of Service consistent with the disclosure (GDPR Arts. 13 and 14).
Paperwork
Documents to have on file
Get these documents drafted for your system
Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
Common mistakes
Where companies get this wrong
- A persona name and avatar (“Chat with Emma”) with no AI indicator. Regulators treat this as the paradigm case of non-compliance.
- Disclosure only on the first message of the very first session. Returning users and hand-offs need it too.
- A support bot that also collects and scores loan or job applications. That single feature moves the whole system into high-risk.
- Voice agents that never say they are automated. The obligation is channel-neutral.
FAQ
Frequently asked questions
Is “Powered by AI” in the footer enough?
No. The disclosure has to be clear and given at the latest at the time of the first interaction, in a way a reasonable user cannot miss. A visible label in the chat header and a first message that states it is an AI assistant is the accepted approach.
Does Article 50 apply if we use a third-party chatbot platform?
The platform provider must design the system so disclosure is possible; you, as the deployer, must make sure the notice is actually shown in your implementation. In practice both parties are exposed if it is missing.
What are the fines?
Breaches of Article 50 fall under the general tier: up to €15M or 3% of global annual turnover, whichever is higher (lower of the two for SMEs).
This page is general information about Regulation (EU) 2024/1689, updated 2026-09-22. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026. Leer en español.