AI Compliance

EU AI Act Article 50: What Enterprise AI Assistants, Chatbots and Agents Must Disclose

Article 50 of the EU AI Act has applied since 2 August 2026, whatever a system's risk class. Who counts as the provider when an enterprise builds its own assistant, what people must be told and when, how synthetic content is marked and labelled, and what evidence to keep.

Article 50 of the EU AI Act requires that people are told when they are dealing with an AI system unless that is obvious, that generative systems mark their output in a machine-readable way, and that deepfakes and AI-generated text published on matters of public interest are disclosed. It has applied since 2 August 2026. An enterprise that builds its own customer-facing assistant can be that system's provider as well as its deployer.

Article 50 applies now, whatever the risk class

Most EU AI Act attention goes to high-risk systems, and the Annex III obligations for those now start on 2 December 2027. Article 50 attaches to what a system does instead. A chatbot that answers customers, a voice agent that returns their calls and a tool that drafts campaign images are all in scope, whatever their risk class.

The Digital Omnibus, Regulation (EU) 2026/1744, left Article 50’s start date alone. The only relief is for marking: generative systems placed on the market before 2 August 2026 have until 2 December 2026 to meet Article 50(2). Systems only put into service in-house should confirm they qualify first. The chatbot disclosure in 50(1) has no grace period. The EU AI Act timeline covers the other dates.

The four duties at a glance

ParagraphWho is obligedWhat it requiresMain carve-outs
50(1)ProviderSystems that interact directly with people must tell them they are dealing with AIObvious from context to a reasonably well-informed, observant and circumspect person; certain law-enforcement uses
50(2)ProviderSynthetic audio, image, video and text must be marked in a machine-readable, detectable wayAssistive editing that does not substantially alter the input; certain law-enforcement uses
50(3)DeployerPeople exposed to emotion recognition or biometric categorisation must be informedCertain law-enforcement uses
50(4)DeployerDeepfakes, and AI-generated text published to inform the public on matters of public interest, must be disclosedText under human review or editorial control with editorial responsibility; lighter disclosure for evidently artistic, satirical or fictional work

Article 50(5) sets the manner for all four: clear and distinguishable, given at the latest at the first interaction or exposure, and accessible.

Provider or deployer? The in-house assistant question

Enterprises often assume they are only deployers because they license the model or the platform. Under Article 3(3), though, a provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name, and Article 3(11) counts supply for own use as putting into service.

The Commission’s Article 50 guidelines, approved in July 2026, apply that test directly. An organisation that builds a chatbot in-house and puts it into service under its own name is its provider. So is a company that modifies another provider’s generative system, for example with new training data, and puts it into service under its own name. A bank that launches an assistant built on an open-weight model and its own retrieval pipeline can be provider and deployer at once, and 50(1) and 50(2) are provider duties. Settle each system’s role with your legal team before launch.

Disclosure in practice

The guidelines are specific about what works:

  • Chat. A greeting or banner at the start of the conversation.
  • Voice. A spoken statement at the start of the call, with reminders in long calls. Tones alone are not enough.
  • Agents. An agent must say that it is AI and on whose behalf it acts. Replies that blend AI output with human content need disclosure unless people review them and send them as the main interlocutors.
  • Sensitive conversations. One notice usually suffices, but reminders are likely needed in financial advice, insurance, legal, health and complaints conversations. The system should also confirm it is AI whenever asked.
  • Not enough on their own. Terms and conditions, invisible metadata, a generic “assistant” label, or a site-wide line saying services use AI.

The “obvious” exception is read narrowly. The guidelines accept an internal assistant for trained, AI-literate staff as an example, but not helpdesk or platform chatbots that the general public, including vulnerable people, may use.

Marking and labelling synthetic content

The code of practice on transparency of AI-generated content, finalised on 10 June 2026 and found adequate by the Commission in July, shows how providers can meet Article 50(2). It expects at least two machine-readable layers, digitally signed and time-stamped metadata plus an imperceptible watermark. Free-form text can rely on a watermark alone, and text over 200 tokens must carry one. Detection should be free of charge, with an interoperable solution due by 2 February 2027. Under the guidelines, summaries and rewrites need marking, while grammar fixes and translation count as standard editing, and source code and machine-to-machine output are excluded. Marking can happen anywhere in the value chain, including upstream at the model. If you serve an open-weight model yourself, check whether anything in your stack applies a watermark; if nothing does, adding one falls to you as the system’s provider.

For deployers, the code offers a common EU icon for labels. The public-interest text duty covers text published to a broad audience, such as AI-edited corporate reports with investor information on a listed company’s website, not text shared within a closed, private group. The editorial exception needs real human review, at least fact-checking, and AI edits made after sign-off cancel it. A realistic avatar video of a CEO addressing staff appears in the guidelines as a deepfake that needs a label.

Evidence to keep

Treat each AI system that touches people as an entry in your AI system register, and keep:

  • The role analysis. Provider, deployer or both, and who owns each duty.
  • The disclosure design. Wording, placement, languages and accessibility checks, versioned like any other release.
  • Proof it was shown. Logs that the notice was displayed at the first interaction.
  • The marking configuration. Which generative models and output channels mark content, how, and how you test that marks survive.
  • Exceptions relied on. The reasoning, the date and the approver.

Self-hosting makes this easier to assemble, because prompts, outputs, model versions and interface logs sit in systems you control. The EU AI Act evidence pack guide shows how to package them.

How VDF AI supports Article 50 work

VDF AI runs assistants and agents inside your own infrastructure, with audit trails that record which model and version produced each output, for which user and workflow. That trail is the raw material for showing which systems generated content and when a notice was displayed. The AI transparency notice generator drafts plain-language, user-facing notices on infrastructure you control, and VDF AI Compliance sequences EU AI Act work from inventory to evidence. The legal analysis of each system’s role stays with your legal and compliance teams.

Sources and further reading


Launching a customer-facing assistant or agent in the EU? Talk to us about keeping its prompts, outputs and disclosure evidence inside your own infrastructure.

Frequently asked questions

Does Article 50 apply to internal AI assistants used by employees?

It can, because employees are natural persons. The exception for interactions that are obvious from context is read narrowly. The Commission's guidelines give an internal assistant used by trained, AI-literate staff as an example where it can apply, and helpdesk or platform chatbots as examples where it does not. Record the reasoning for each system.

Is a line in the terms of service enough to meet Article 50(1)?

No. Article 50(5) requires the information to be clear and distinguishable and given at the latest at the first interaction. The Commission's guidelines list terms and conditions, invisible metadata, a generic assistant label and a site-wide notice among disclosures that are not enough on their own.

Does signing the code of practice prove compliance with Article 50?

No. The Commission found the code adequate for Article 50(2), (4) and (5) in July 2026, but its opinion states that adherence does not constitute conclusive evidence of compliance. The code is a practical route to the marking and labelling duties, not a certificate, and it does not cover the chatbot disclosure in Article 50(1).

What is the fine for breaching Article 50?

Article 99(4) allows administrative fines of up to 15 million euros or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs, and since the Digital Omnibus for small mid-caps, the lower of the two amounts applies. National market surveillance authorities enforce most cases.

Filed under
EU AI ActAI complianceAI governanceenterprise AI agentsregulated AIon-premises AI
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading