On 2 August 2026, Article 50 of the EU AI Act starts to apply. If an AI system interacts directly with people, those people have to be told they are talking to an AI.
Most of what has been written about this is a law-firm client alert aimed at general counsel. This is the version for the person who actually runs the support queue — what changes, what does not, and who is on the hook.
Not legal advice
This is operational guidance written for support and CX teams, not legal advice. Article 50 has genuine grey areas — particularly around the obviousness exemption and what counts as a public-interest publication. Use this to have a better-informed conversation with your legal counsel, not to replace one.
What Actually Changes on 2 August 2026
Article 50(1) requires that AI systems intended to interact directly with natural persons are designed and developed so that those persons are informed they are interacting with an AI system — unless that is obvious from the point of view of a person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and context of use.
That covers web chat widgets, in-app messengers, automated phone systems and AI voice agents. It is a design-and-disclosure obligation, not a restriction on using AI.
| Obligation | Applies from | Falls on | Relevant to support? |
|---|---|---|---|
| Art. 50(1) — tell users they're talking to an AI | 2 Aug 2026 | Provider | Yes |
| Art. 50(2) — machine-readable marking of AI output | 2 Aug 2026 (grace to 2 Dec 2026 for systems already on market) |
Provider | Vendor's job |
| Art. 50(4) — disclose AI text published to inform the public | 2 Aug 2026 | Deployer | Usually not |
| High-risk obligations, standalone (Annex III) | 2 Dec 2027 | Provider + deployer | Deferred |
| High-risk obligations, embedded in products (Annex I) | 2 Aug 2028 | Provider + deployer | Deferred |
The 2026 Digital Omnibus deferred the high-risk obligations. It did not defer Article 50 — that date stands.
Are You On the Hook, Or Is Your Vendor?
This is the question support leaders actually need answered, and it is the one the legal alerts tend to skip past.
The Article 50(1) obligation sits on the provider. A provider is the party that develops an AI system, or has it developed, and places it on the EU market or puts it into service under its own name or trademark. A deployer is the party using it.
The practical test
If you licence an AI support agent from a vendor and run it as-is, you are normally a deployer — the Article 50(1) duty sits with the vendor who built it. If you built the agent in-house, or you white-label a vendor's system and ship it under your own brand, you are likely a provider, and the duty is yours.
Being a deployer is not the same as being risk-free, and it would be a mistake to read it that way:
- Article 50(4) does land on deployers — it applies where you publish AI-generated text to inform the public on matters of public interest.
- Consumer and contract law operate independently of the AI Act. In May 2026 the Higher Regional Court of Hamm held that a company can be liable for misleading statements made by its own chatbot, on the basis that the chatbot forms part of the company's corporate communication. Your vendor's compliance with Article 50 does not resolve that exposure.
- White-labelling changes your status. Putting your own name on a vendor's agent is one of the routes to becoming a provider.
What the Disclosure Has To Do
Article 50(1) does not prescribe wording. It requires that the person is informed. In practice that means three things:
- At first interaction. Before the conversation gets going, not at the end and not on request.
- In plain language. A line in your terms of service or privacy policy is not someone being informed.
- Where they will actually see it. In the chat surface itself, not a footnote elsewhere on the page.
On 20 July 2026 the European Commission published its final guidelines on the Article 50 transparency obligations, and a Code of Practice on Transparency of AI-Generated Content was assessed as adequate on 9 July 2026. The Code is voluntary, but signing up to it is one way to demonstrate compliance with the Article 50(2), (4) and (5) marking duties.
Do Not Lean On the Obviousness Exemption
Article 50(1) does not require disclosure where interacting with an AI is obvious to a reasonably well-informed, observant and circumspect person in the circumstances and context of use.
That exemption exists, and it is narrower than it sounds. The whole direction of product design in AI support runs against it: a bot given a human first name, a human avatar, and a natural conversational register is a bot that has been deliberately made less obviously artificial. The better the agent, the weaker the argument.
If your AI agent is good enough that customers routinely mistake it for a person, you have engineered your way out of the exemption you were relying on.
What Does Not Apply To You
Worth knowing, because over-scoping compliance costs real money:
- Support conversations are not normally "informing the public." Article 50(4) targets AI-generated text published to inform the public on matters of public interest. A one-to-one support exchange is a private interaction. AI-written help-centre articles on matters of public interest are a separate question worth assessing.
- High-risk obligations are deferred. Standalone Annex III systems now apply from 2 December 2027; systems embedded in regulated products under Annex I from 2 August 2028. General customer support is not typically an Annex III high-risk use in any case.
- Article 50 does not mandate a human escalation route. It is a transparency duty, not a right-to-a-human duty.
But build the escalation path anyway
Article 50 does not require it, and it is still the right call. A working human handoff limits the liability exposure created when an agent gives a customer a wrong answer, and Gartner expects AI-related regulation to increase assisted service volume by 30% by 2028 — the demand is coming whether or not this particular article compels it.
If You're Not in the EU
You are likely still in scope. Article 2 extends the Act to providers and deployers established outside the Union where the output produced by the AI system is used in the Union. A US company whose support chatbot serves EU customers is covered on the same terms as an EU one.
What It Costs to Get Wrong
Under Article 99(4)(g), breaching the Article 50 transparency obligations can attract administrative fines of up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Realistically, a first enforcement wave against a disclosure line in a chat widget is not where regulators are likely to start. Treating the deadline as optional on that basis is a different decision from treating it as low-risk, and worth making deliberately rather than by default.
The Pre-Deadline Checklist
- Establish whether you are a provider or a deployer. Licensing a third-party agent and running it as-is normally makes you a deployer. Building it in-house or shipping it under your own brand normally makes you a provider.
- Inventory every customer-facing AI touchpoint. Web chat, in-app messenger, email auto-reply, SMS, voice IVR, and any AI-drafted reply sent under a human agent's name. Assess each separately — the last one catches people out.
- Check the disclosure is present, plain and early. At first interaction, in the chat surface, in language a customer would actually understand.
- Stop relying on the obviousness exemption. Especially if your agent has a human name or avatar.
- Confirm the human escalation path works. Not required by Article 50; still the highest-value thing on this list.
- Get your vendor's position in writing. See the questions below.
Six Questions to Ask Your AI Support Vendor
Any vendor selling into the EU should be able to answer these without escalating to their legal team. How quickly they answer tells you something on its own.
- For this deployment, do you act as provider under the AI Act — and will you confirm that in writing?
- How does the product satisfy Article 50(1) out of the box? Is the disclosure on by default, or is it a setting a customer can switch off?
- Do you mark generated output in a machine-readable format under Article 50(2), and does the 2 December 2026 grace period apply to your system?
- Will you indemnify us for a transparency breach originating in your system?
- Have you signed the Code of Practice on Transparency of AI-Generated Content?
- If we white-label the agent under our brand, does that make us the provider — and what changes for us if so?
Frequently Asked Questions
Does the EU AI Act apply to my customer support chatbot?
If it interacts directly with people in the EU, Article 50(1) applies from 2 August 2026. Under Article 2 the Act also reaches providers and deployers established outside the Union where the output produced by the AI system is used in the Union — so a US company serving EU customers is in scope.
Am I liable, or is my AI vendor?
The Article 50(1) disclosure duty falls on the provider — the party that develops the system, or has it developed, and places it on the EU market or puts it into service under its own name or trademark. Licence a third-party agent and you are normally a deployer, and the duty sits with your vendor. That is not the same as being risk-free: Article 50(4) lands on deployers in other circumstances, and consumer and contract law can still attribute your chatbot's statements to you.
What exactly does the disclosure have to say?
Article 50(1) does not prescribe wording — it requires that the person is informed they are interacting with an AI system. In practice: a clear statement at the point of first interaction, in plain language, in the chat surface rather than buried in terms of service.
Was Article 50 delayed by the Digital Omnibus?
No. The 2026 Digital Omnibus deferred the high-risk obligations — standalone Annex III systems to 2 December 2027, and high-risk systems embedded in regulated products under Annex I to 2 August 2028 — but Article 50 still applies from 2 August 2026. The only element with extra time is the Article 50(2) machine-readable marking duty for generative systems already on the market before 2 August 2026, which has a grace period to 2 December 2026.
Do support conversations count as text published to inform the public?
Generally no. Article 50(4) applies to deployers publishing AI-generated text to inform the public on matters of public interest. A support conversation is normally a private interaction between a company and an individual. AI-written help-centre content on matters of public interest should be assessed separately.
What are the penalties for breaching Article 50?
Under Article 99(4)(g), up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Does Article 50 require me to offer a human agent?
No — it is a transparency obligation, not a right-to-a-human obligation. A working escalation path is still worth building: it limits the separate exposure created when an agent gives a customer a wrong answer, and Gartner expects AI-related regulation to increase assisted service volume by 30% by 2028.