Back to blog

EU AI Act: from 2 August 2026, your chatbot has to say it's an AI

Article 50 of the AI Act applies from 2 August 2026. Who carries the obligation, the checks to run, what you don't need to do, and the real penalties.

July 31, 2026Insights8 min read

Website chat window showing a notice that an AI assistant is replying

EU AI Act: from 2 August 2026, your chatbot has to say it's an AI

Article 50 of Regulation (EU) 2024/1689 — the AI Act — applies from 2 August 2026. It's the transparency rule: it requires disclosing when a person is interacting with an AI system, when content is a deepfake, and when emotion recognition systems are in use.

It isn't the heavy part of the regulation. The high-risk regime — technical documentation, risk management system, CE marking — was postponed a few days ago. Article 50 wasn't. And it affects far more companies than realise it, because the chat bubble in the bottom-right corner, the assistant replying on social, and the phone line answering in a synthetic voice are all AI systems interacting with people.

Here's what actually applies, who carries the obligation, what you don't need to do, and the checks to run before the deadline.

Note. We're not a law firm. What follows is the picture reconstructed from official sources, with the legal references in plain sight. Edge cases — proprietary AI products, white-label resale, regulated sectors — need a lawyer.


What applies on 2 August, and what was postponed

On 24 July 2026 the Regulation (EU) 2026/1744 — the digital omnibus on AI — was published in the Official Journal, pushing back the AI Act's most demanding deadlines.

Obligation Applies from
Transparency — Article 50 2 August 2026 (unchanged)
High-risk systems, Annex III (standalone) 2 December 2027 (postponed)
High-risk systems, Annex I (embedded in products) 2 August 2028 (postponed)
Machine-readable marking for systems already on the market 2 December 2026 (transition period)

The only carve-out touching Article 50 is technical: machine-readable marking of generated content — the marking inside the file, not the label in front of the viewer — applies from 2 December 2026 for generative systems already placed on the market before 2 August. That obligation sits with whoever builds the system, not with whoever uses it.

On 20 July the European Commission published its official guidelines on Article 50 and a voluntary code of practice on transparency of AI-generated content that can be used to demonstrate compliance. Neither is binding, but they are the first interpretive instrument covering the full scope of the article.


Does it affect you? Almost certainly

You don't need a proprietary model. One of these is enough:

  • the support chatbot on your site;
  • the assistant replying to comments and direct messages on Instagram or Facebook;
  • automated replies on WhatsApp Business;
  • a phone system answering in a synthetic voice and booking appointments;
  • videos with generated avatars;
  • AI-generated images, banners or backgrounds;
  • dubbing with a cloned voice.

The problem is that hardly anyone thinks they're in scope. According to the Politecnico di Milano SME Digital Innovation Observatory, 76% of Italian SMEs have not invested in AI and don't plan to. But AI now arrives inside a plugin, inside the ERP, inside the phone system subscription: nobody calls it artificial intelligence while selling it to you, and nobody mentions there's a deadline.


Provider or deployer: the distinction that decides who pays

The AI Act splits the world into two roles.

  • Provider — whoever develops an AI system, or has it developed, and places it on the market under their own name or trademark.
  • Deployer — whoever uses an AI system under their own authority, excluding personal non-professional use.

In plain terms: who builds it and who switches it on. Article 50 assigns obligations differently depending on the case.

Situation Who is on the hook What it requires
Chatbots and systems interacting with people Provider Design the system so the person knows they're talking to an AI
Synthetic content (text, images, audio, video) Provider Machine-readable marking of outputs
Deepfakes Deployer Disclose that the content is generated or manipulated
Text published to inform the public on matters of public interest Deployer Disclose it, unless there's substantive human review or editorial control
Emotion recognition and biometric categorisation Deployer Inform the people exposed to it, in line with the GDPR

Formally, disclosing the chatbot is the provider's obligation. But if the provider never built it in and that chatbot is live on your domain, the practical problem is yours: you're the one talking to your customers without saying what's on the other end.

One clarification that matters if you work with agencies and vendors: per the Commission's FAQ, a company integrating a third-party chatbot into its own site remains the deployer, and the provider is whoever developed the chatbot. It stays the deployer even when external vendors or freelancers are involved in running the system. It changes when you put your own brand on it: whoever places a system on the market under their own name becomes the provider, even if someone else wrote the code. That's the awkward part for anyone reselling a white-label assistant.


Seven checks to run before the deadline

An afternoon is enough. In order.

1. Open your own site anonymously and talk to the chatbot. Don't look at the admin panel — look at what a customer sees. It must be clear that there's an automated system on the other end, before or at the latest during the first exchange. If it isn't, three things to fix: the window title, the opening message, the small text under the input field.

2. Do the same on social and WhatsApp. An assistant auto-replying to direct messages is a system interacting with people. The first automated message needs a line saying so. One line, not a legal disclaimer.

3. Call your own number. If a synthetic voice answers, the first sentence has to say it's an automated assistant.

4. Review your avatar videos. If the avatar resembles a real person, or plausibly could be one, and the video could pass as authentic, you're in deepfake territory: disclosure is on whoever publishes. An obviously synthetic avatar is a different case. When in doubt, disclose.

5. Check whether you use emotion recognition or biometric categorisation. In most companies the answer is no. But if you analyse faces in video or classify people on a biometric basis, the obligation to inform those exposed is yours and it's absolute.

6. Write the register. One sheet, five columns: where the AI is, which tool, who the provider is, what we disclose, who checked and when. Nobody requires it in this form. But when the question comes from a client or an authority, the gap between having the sheet and not having it is enormous.

7. Email your vendors. Two blunt questions: does your system mark outputs in a machine-readable format under Article 50(2)? Is the "you're talking to an AI" notice built into the product, or do I have to add it? The written answer is your safety net.

Then a decision rather than a check: name who's accountable. One person who knows where AI sits in the company. If it's everyone, it's no one.


What you don't need to do

Plenty of inflated readings are circulating. Four boundaries.

You don't need "AI-generated" under every image. The Article 50(2) obligation is a technical marking inside the file, and it sits with whoever supplies the system. The visible label is required for deepfakes. A generated background for a banner, or a graphic pattern, is not a deepfake. Note, though, that misleading advertising is a separate matter and lives in consumer law.

You don't need to declare that your emails or posts were written with AI. The text obligation covers content published to inform the public on matters of public interest, and it doesn't apply where there has been substantive human review or editorial control with someone taking responsibility. A commercial newsletter you write and edit yourself isn't that case.

You don't need a high-risk conformity assessment. That's the one that scares everyone, and it was postponed: Annex III to 2 December 2027, Annex I to 2 August 2028. If someone is pitching you a high-risk compliance project today using the 2 August deadline, they're using a date that no longer exists.

You don't need to register anywhere. There's no portal, no notification to send, no general filing requirement for a private company with a chatbot on its site.


Penalties: what's actually at stake

Article 99 sets three tiers. For SMEs, including start-ups, the cap is the lower of the fixed amount and the percentage — the opposite of what applies to large companies.

Infringement Cap
Prohibited practices (Art. 5) €35 million or 7% of worldwide turnover
Operator obligations, including Article 50 €15 million or 3% of turnover
Incorrect or misleading information to authorities €7.5 million or 1% of turnover

Transparency sits in the €15 million / 3% band, not the €35 million one. Anyone telling you an undisclosed chatbot is worth €35 million is lumping everything together. For a mid-sized company, the real ceiling is 3% of turnover.


The Italian layer

Italy already has its framework in place. Law no. 132 of 23 September 2025, in force since 10 October 2025, designates the national authorities in Article 20: AgID promotes innovation and defines notification and monitoring procedures, ACN handles supervision, including inspections and penalties. ACN is the one that knocks on the door.

Two Italian provisions worth knowing:

  • Article 13 — anyone practising an intellectual profession must inform clients, clearly and completely, about the AI systems they use. It applies directly to professional firms and consultants.
  • Article 26 — introduced Article 612-quater into the criminal code: distributing AI-falsified images, video or voices without consent, causing unjust harm, carries one to five years' imprisonment. That's not an administrative cap, it's a criminal offence.

Disclosing AI is a feature, not a cost

The most common reaction to this deadline is defensive: what does it cost us, how little can we get away with writing. That's the wrong frame.

Saying that an automated assistant is answering, that it replies in two seconds at any hour, and that a human is one request away, isn't a disclaimer — it's the explanation of why the service works at eleven at night. The right text isn't "this service uses artificial intelligence systems pursuant to the Regulation", which is a sentence written by someone who's scared. It's a normal sentence saying what's there and what you get from it.

Disclosing AI is only a problem for whoever was hiding it. If what you built works, saying so is one more feature. If it only holds up while people believe they're talking to a human, the problem isn't Article 50 — and it wasn't Article 50 before either.

At We Coode we build AI agents and automations that run inside real business processes: transparency toward the end user is part of the design, not a patch applied at the deadline. If you have an assistant in production and want to get it right, or you're considering building one, let's talk.

Facing a similar problem?

Turn the insight into a concrete solution.

Let’s talk