Blog · AI Disclosure · 25 Sep 2026
Blog
AI Disclosure

AI disclosure:What your chatbothas to say

Article 50 of the EU AI Act requires that people know when they are talking to a machine. We show what that means in practice for website chat, messenger bots and phone assistants.

Get in touch
Enquiry
Nikolai Schöbel und Jeremias Burger, Co-Founder Scalableloops

Let's talk about your project.

First we check whether the project fits your business model. Then you get a proposal with phases and effort.

Get your AI assistant checked or call: +49 151 1576 5566
Blog · AI Disclosure

Article 50 of the AI Act, Regulation (EU) 2024/1689, has applied since 2 August 2026. For your business, it comes down to one sentence: if you talk to customers through an AI chat, a messenger bot or a phone assistant, you must make it clear and unambiguous, at the latest at the first interaction, that an AI is answering, unless this is already obvious to a reasonable person. Deceptively realistic AI images, videos and voices, known as deepfakes, must be disclosed. And anyone who provides an AI system that generates content must mark that content in a machine-readable way; for systems already on the market before 2 August 2026, a transition period runs until 2 December 2026.

In brief
  • Chatbots and voice assistants must identify themselves as AI at the latest at the first interaction.
  • Deepfakes, meaning deceptively realistic AI images, videos and audio recordings, must be disclosed by the deployer as artificially generated.
  • Providers of generative systems mark outputs in a machine-readable format; legacy systems have until 2 December 2026 to do so.
  • In Germany, the Federal Network Agency (Bundesnetzagentur) is the central market surveillance authority and offers a point of contact through its AI Service Desk.
Published 25 Sep 2026Nikolai Schöbel and Jeremias Burger9 min read
Nikolai SchöbelJeremias Burger

Nikolai Schöbel and Jeremias Burger

Co-founders of Scalableloops GmbH. Nikolai Schöbel leads online marketing and AI strategy, Jeremias Burger the AI architecture. Both build AI systems and train teams on them in their own agency work.

On this page
  1. What does Article 50 of the AI Act cover?
  2. Are you a provider or a deployer?
  3. What belongs in your chatbot's first message?
  4. When can you skip the notice?
  5. Which AI images, videos and voices must you label?
  6. What does machine-readable marking mean, and when does it apply?
  7. Who enforces the transparency obligations in Germany?
  8. Frequently asked questions
  9. How to get your AI assistant compliant
  10. Where the information on this page comes from
Basics

What does Article 50 of the AI Act cover?

Article 50 is headed “Transparency obligations for providers and deployers of certain AI systems”. Under Article 113 of the regulation, it has applied since 2 August 2026. It does not contain a general labelling requirement for every text an AI helped to write. Instead, it describes specific cases, and for each case it sets out clearly who has to act.

Three cases matter most for businesses that deal with customers: direct interaction with an AI system, meaning chat and phone (paragraph 1), machine-readable marking of generated content (paragraph 2) and disclosure of deepfakes (paragraph 4). Paragraph 3 covers emotion recognition and biometric categorisation systems, whose deployers must inform the people exposed to them. Paragraph 5 sets out when and how the information is given: at the latest at the time of the first interaction or exposure, in a clear and distinguishable manner, and in line with accessibility requirements.

CaseWho is obligedWhat to do
AI system talks directly to people (chat, messenger, phone)ProviderDesign the system so that people are told they are interacting with an AI, unless this is obvious
AI generates audio, images, video or textProviderMark outputs in a machine-readable format as artificially generated or manipulated
Emotion recognition or biometric categorisationDeployerInform the people concerned that the system is in operation
Deepfake (image, audio, video)DeployerDisclose that the content has been artificially generated or manipulated
AI text on matters of public interestDeployerDisclose, unless the text has undergone human review and someone holds editorial responsibility
2 Aug 2026

The date from which the transparency obligations under Article 50 apply.

Regulation (EU) 2024/1689, Art. 113
Roles

Are you a provider or a deployer?

The regulation distinguishes between two roles. A provider is anyone who develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark, whether for payment or free of charge (Art. 3(3)). A deployer is anyone who uses an AI system under their own authority in a professional context (Art. 3(4)).

In practice, this means: if you buy a ready-made chatbot and use it on your website, you are usually a deployer. If you have an assistant built specifically for you and offer it under your own name, your business may itself move into the provider role. The classification depends on the individual case, so it pays to look closely at the contract and the setup.

Whatever your role, the customer sees your chat window, your phone number, your name. If the notice is missing there, it reflects on your business. So check whether your service provider has built in the AI notice, and where you can set the first message yourself.

  1. 01

    Provider

    develops

    Develops an AI system or has one developed and places it on the market under its own name.

  2. 02

    Deployer

    uses

    Uses an AI system under its own authority in a professional context, for example as a chat on its own website.

In practice

What belongs in your chatbot's first message?

Article 50 does not prescribe any fixed wording. What counts is that the notice comes at the latest at the first interaction, is clear and distinguishable, and meets accessibility requirements. A sentence in your terms and conditions or privacy policy does not reach the customer at the moment of the conversation. The notice belongs where the conversation starts.

A greeting that handles three things in one go works well: it says that an AI is answering, what it can help with, and how to reach a human. That turns the obligation into a service, because the customer knows straight away what to expect.

For website chat: “Hello, you are chatting with our AI assistant. I can help with questions about appointments, services and opening hours. If you would rather speak to a member of staff, just type ‘human’.”

For a messenger bot, for example on WhatsApp: “Hello, you are messaging the digital assistant of [business]. This is an AI. I will take down your request and pass it on to our team.”

For a phone assistant: “Hello, you are speaking with the AI assistant of [business]. I will note your request and make sure someone calls you back.” There is no chat window on the phone, so the notice belongs in the spoken greeting, before the first question to the caller.

Less suitable are notices that are easy to miss: a small icon without text, a footnote below the input field, or a name that sounds like a real employee without any mention that it is an AI.

Exception

When can you skip the notice?

The obligation does not apply where it is obvious, from the point of view of a reasonably well-informed, observant and circumspect person, taking into account the circumstances and the context of use, that they are interacting with an AI system. This exception is narrow and leaves room for interpretation.

For businesses, the calculation is simple: one clear sentence in the greeting costs nothing and settles the question of whether the AI nature was obvious enough. If you leave the notice out, you carry the risk of that judgement.

Deepfakes

Which AI images, videos and voices must you label?

Under Article 3(60), a deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. Anyone who generates or manipulates such content with an AI system and uses it professionally must disclose that it has been artificially generated or manipulated.

For advertising and social media, this means: an AI photo that looks like a real shot from your workshop, or an AI voice that sounds like a real person, needs a visible or audible notice. For evidently artistic, creative, satirical or fictional works, a notice that does not hamper the display or enjoyment of the work is enough.

AI-generated text published to inform the public on matters of public interest must also be disclosed. This obligation does not apply if the text has undergone human review or editorial control and a person holds editorial responsibility for it.

Technology

What does machine-readable marking mean, and when does it apply?

Providers of AI systems that generate synthetic audio, image, video or text content must mark the outputs in a machine-readable format so that they can be detected as artificially generated or manipulated. This means things like watermarks and metadata that software can read. The obligation is aimed at the makers of the tools, not at the business that creates an image with them.

For generative systems placed on the market before 2 August 2026, a transition period until 2 December 2026 applies to this marking. The deadline covers only the machine-readable marking. It does not postpone the chatbot notice or the disclosure of deepfakes.

On 10 June 2026, the European Commission published a voluntary Code of Practice on marking and labelling AI-generated content. It describes methods such as watermarks and metadata for providers, and visible labels for deployers, including an EU icon.

2 Dec 2026

End of the transition period for machine-readable marking for systems that were on the market before 2 August 2026.

European Commission, press release IP/26/1328
Supervision

Who enforces the transparency obligations in Germany?

Under the German AI Market Surveillance and Innovation Promotion Act (KI-MIG), in force since 29 July 2026, the Federal Network Agency (Bundesnetzagentur) is the central point of contact, market surveillance authority and complaints body for the AI Act. In regulated sectors, the existing sector authorities keep their responsibilities, with the Bundesnetzagentur coordinating.

The Bundesnetzagentur has set up an AI Service Desk for companies. There you will find a dedicated page on the transparency obligations, an AI Compliance Compass for initial guidance, FAQs and a contact form. The authority also provides separate guidance for small and medium-sized enterprises and start-ups.

Under Article 99, breaches of Article 50 can be punished with fines of up to 15 million euros or up to 3 percent of worldwide annual turnover. For small and medium-sized enterprises, the lower of the two amounts applies in each case. According to the regulation, all relevant circumstances of the individual case are taken into account when setting the amount, such as the nature, gravity and duration of the infringement.

Frequently asked questions

Frequently asked questions

Do I have to label my website chatbot as AI?

Yes, if it communicates directly with customers and it is not obvious that an AI is answering. The notice must be clear and distinguishable and come at the latest at the first interaction. The safest place is the chat window's greeting message.

Is a notice in the privacy policy enough?

Article 50(5) requires the information to be given at the latest at the time of the first interaction. A sentence in the privacy policy usually does not reach the customer at that moment. So put the notice into the conversation itself.

Does the disclosure requirement also apply to an AI phone assistant?

Article 50(1) covers AI systems intended to interact directly with natural persons. A phone assistant that takes calls falls within this. The notice belongs in the spoken greeting.

What is the transition period until 2 December 2026?

It applies only to the machine-readable marking of AI-generated content under Article 50(2), and only for generative systems placed on the market before 2 August 2026. All other transparency obligations have applied since 2 August 2026.

Which authority is responsible in Germany?

Under the KI-MIG, the Federal Network Agency (Bundesnetzagentur) is the central market surveillance authority, point of contact and complaints body. Through its AI Service Desk, it offers guidance for companies.

How high are the fines for breaching Article 50?

Up to 15 million euros or up to 3 percent of worldwide annual turnover. For small and medium-sized enterprises, the lower amount applies in each case.

Next steps

How to get your AI assistant compliant

  1. 01

    List your touchpoints

    Note every place where an AI talks to customers: website chat, messenger, phone, email replies.

  2. 02

    Check the first message

    Read or listen to the greeting yourself. Does it say clearly that an AI is answering, and how to reach a human?

  3. 03

    Clarify your role

    Record whether you use a ready-made tool or offer your own system, and ask your service provider about the built-in AI notice.

  4. 04

    Review images and voices

    Check your advertising and social media for AI content that looks real, and add a notice there.

  5. 05

    Get guidance

    Use the Bundesnetzagentur's AI Compliance Compass. If you are unsure about your role, legal advice can help.

An honest first sentence in the chat costs nothing and builds exactly the trust an AI assistant needs in customer contact.

or call: +49 151 1576 5566

Further reading

Projekt-Detail

    Got a project in mind?

    We reply personally. First a use-case check, then an architecture proposal.

    Start your inquiry