As of August 2, 2026, any AI system that interacts directly with people in the EU must clearly tell them they are dealing with an AI, not a human, at the first point of contact. This comes from Article 50 of the EU AI Act, it applies to chatbots, voice agents, and AI avatars, and it reaches businesses outside the EU whenever their AI is used by people inside it. A disclosure buried in your terms of service does not count. The fix is usually simple, but ignoring it now carries real penalties.
If your business runs a chatbot, a virtual assistant, a voice agent, or any AI a customer can talk to, this is the rule to act on first. It is the most widely applicable transparency duty in the entire EU AI Act, it became live and enforceable two weeks ago, and unlike the more complex high-risk rules that were delayed to 2027, this one was deliberately kept on schedule. That makes it the natural starting point for any business trying to get compliant. Let us break down exactly what it requires.
What the rule actually says
The rule comes from Article 50 of the EU AI Act, the section covering transparency. In plain terms, it says that when an AI system interacts directly with a person, that person has to be told they are dealing with a machine, not a human. The disclosure has to happen at the first point of contact, in other words, up front, before or as the conversation begins, not discovered later. A person should never be tricked, even briefly, into thinking a chatbot is a human agent.
This applies regardless of how simple or advanced the system is. A basic scripted support bot and a sophisticated conversational AI agent are treated the same way here: both must disclose. And crucially, this duty applies whether or not your AI counts as high-risk under the rest of the Act. Even a business with no high-risk AI at all still has this obligation the moment it puts a chatbot in front of customers.
You may have seen headlines about the AI Act being delayed. That is only half the story. A package called the Digital Omnibus pushed back the deadline for complex high-risk systems, hiring algorithms, credit scoring, medical tools, to December 2027. But the transparency rules in Article 50 were deliberately left off that delay. They went live on August 2, 2026, on the original schedule, with enforcement power attached from the same day. Many businesses read "AI Act delayed" as a general reprieve and are now out of compliance. This rule is not delayed.
Who has to comply
The duty falls on any business that puts an interactive AI in front of people, whether you built the AI yourself or you are using a tool someone else built. If you deploy a chatbot on your website, a voice assistant on your phone line, or an AI avatar in your app, you are responsible for making sure the disclosure happens.
Geography does not get you out of it. The rule reaches providers and deployers established outside the EU whenever the output of their AI system is used by people inside the EU. So a business based anywhere in the world that serves European customers through a chatbot is within scope. This is the same extraterritorial reach that runs through the whole AI Act, often called the Brussels Effect, and it is why this matters far beyond Europe.
What compliance actually looks like
The good news is that complying with this specific rule is usually straightforward. The disclosure needs to be clear and visible at the start of the interaction. A persistent on-screen notice that the user is chatting with an AI assistant works. An opening message where the bot identifies itself as an AI works. What does not work is hiding the disclosure where people will not see it, a line buried deep in your terms of service does not satisfy the rule, because the whole point is that the user actually knows in the moment.
There is one sensible exemption worth knowing: the disclosure is not required where it is already obvious to a reasonable person that they are dealing with an AI. If the interaction is clearly and unmistakably with a machine, you do not have to state the obvious. But this is a narrow carve-out, and if there is any real chance a user might mistake your AI for a human, the safe and compliant choice is simply to disclose.
What is at stake
This is not a rule without teeth. Non-compliance with Article 50 can draw fines of up to 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher, with a lower figure applied proportionally to smaller companies and startups. Enforcement sits mainly with national market surveillance authorities across the EU member states. And some countries are going further with their own regimes on top of the EU baseline. The point is not to alarm you, it is that this is a real legal obligation with real consequences, and it is also one of the easiest to fix.
Your action this week
Here is the single step to take. Go to every point where your business uses an AI that talks to people, your website chatbot, any voice agents, in-app assistants, AI avatars, and check each one: does it clearly tell the user, at the start, that it is an AI? If yes, you are compliant on this rule; document that you checked. If no, add a clear disclosure now, a persistent on-screen label or an opening line where the AI identifies itself. It is a small change that closes off a real liability, and it is the first concrete step toward being ready for the rest of the AI Act. Next week, we cover the related rule on labelling AI-generated content.
Frequently asked questions
Does my chatbot really have to say it is an AI?
Yes, if it interacts with people in the EU. Since August 2, 2026, Article 50 of the EU AI Act requires that AI systems which talk directly to people disclose that they are AI, at the first point of contact. This applies to website chatbots, support bots, voice agents, and AI avatars, whether simple or sophisticated.
I am not based in the EU. Does this still apply to me?
If people in the EU use your AI, yes. The rule reaches businesses established outside the EU whenever the output of their AI system is used by people inside the EU. A chatbot serving European customers is in scope regardless of where your company is headquartered.
Is a disclosure in my terms of service enough?
No. The disclosure has to be clear and visible at the point of interaction, so the user actually knows in the moment that they are dealing with an AI. A line buried in your terms of service does not satisfy the rule. A persistent on-screen notice or an opening message where the AI identifies itself is what works.
What if it is obvious my system is an AI?
There is an exemption where it is already clear to a reasonable person that they are interacting with an AI. If the machine nature is unmistakable, you do not have to state the obvious. But this is narrow, so if there is any real chance a user could mistake your AI for a human, the safe and compliant choice is to disclose anyway.
What happens if I ignore this?
Non-compliance can carry fines of up to 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher, with a proportionally lower figure for smaller businesses. Enforcement is handled by national authorities across the EU. Given how simple the fix usually is, the cost of ignoring it is far higher than the cost of complying.
Follow the series, get compliant one rule at a time
This is Part 1 of our weekly guide to AI regulation, breaking down one rule at a time so compliance feels manageable instead of overwhelming. Explore more clear, honest guides on AISetApp and follow along each week.
Explore more on AISetApp- European Commission, final Guidelines on Article 50 of the EU AI Act, published 20 July 2026, and enforcement announcement of 2 August 2026
- EU AI Act (Regulation (EU) 2024/1689), Article 50 transparency obligations
- Cloud Security Alliance research note on Article 50 and the Digital Omnibus recalibration, July 2026
- Practitioner analyses of Article 50 scope, disclosure standards, and penalties, 2026
Reviewed August 2026. This is an explainer, not legal advice. The law is evolving; verify specifics with a qualified professional before acting.