
Article 50 (1) of the EU AI Act requires that people can recognize when they are talking to an AI system. The wording addresses providers: they ensure that systems "intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system".
The provision has applied since August 2, 2026. Under Art. 74 (1) EU AI Act, it is enforced by the national market surveillance authorities; the Commission's Q&A expressly speaks of enforcement overwhelmingly by the national market surveillance authorities. Under Art. 75 (1) EU AI Act, the AI Office has its own competence only for AI systems based on a general-purpose AI model from the same provider. Regulation (EU) 2026/1744 deletes the Commission's power to adopt implementing acts in Article 50 (7) and grants providers of existing systems a transitional period of four months for the marking obligation under paragraph 2; it does not change paragraphs 1, 3, and 4. Which other deadlines have shifted is explained in the article on the Digital Omnibus.
The obligation does not apply if the AI nature is obvious anyway. The wording: "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use." Recital 132 of the EU AI Act repeats this standard.
Anyone relying on it should know the standard: in its questions-and-answers paper on Article 50 (as of 24 Jul 2026), the European Commission expressly states that the exception is to be interpreted narrowly. The benchmark is not your own IT department but an averagely informed user.
According to the same paper, the disclosure obligation applies when four characteristics coincide: it is an AI system, it is designed for a genuine two-way exchange with people, the interaction is direct, and natural persons are affected.
A second exception concerns systems authorized by law to detect, prevent, investigate, or prosecute criminal offenses. Under Art. 50 (1) sentence 2 EU AI Act, it does not apply if the system is available to the public for reporting a criminal offense — for example, in an online reporting process with a chatbot. It is of no relevance for chatbots in service and sales.
Article 50 (5) governs form and timing: the information must be provided "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" and must conform to the applicable accessibility requirements. In its Q&A, the Commission puts it this way: people are to be informed "from the start of the first interaction".
Two conclusions can reliably be drawn from this. First: the notice belongs at the beginning of the conversation, not at the end. Second: a note solely in the privacy policy or in the terms of use is evidently not sufficient for this, because it does not reflect the time of the first interaction.
In abstract and general terms, this means: an introductory sentence in the chat window that expressly names the machine nature — for example, "You are chatting with an AI assistant, not a human" — reflects the timing and clarity required by paragraph 5; a product name or a symbol alone does not. Whether a specific implementation is sufficient remains a question of the individual case.
These requirements are specified in more detail by the guidelines on implementing the transparency obligations published on July 20, 2026. According to the Commission, they determine the scope of the obligations under Article 50 and require providers to design AI systems in such a way that people are expressly informed when they interact directly with an AI system. In its Q&A, the Commission summarizes the standard for the form as follows: information must be provided from the start of the first interaction in a clear and distinguishable manner and in line with the accessibility requirements. Article 50 does not govern whether the notice must be repeated during the conversation; anyone who decides on a wording should check the guidelines in the original.
Article 50 contains four substantive obligations aimed at different addressees:
Paragraph 4 is the most relevant in practice for communications departments. Under Art. 3 no. 60 EU AI Act, deepfakes are image, audio, or video content generated or manipulated by AI that resembles real persons, objects, places, entities, or events and would falsely appear to a person to be authentic or truthful; they must be disclosed. For evidently artistic, creative, satirical, fictional, or analogous works and programs, the obligation is limited to appropriate disclosure that does not hamper the enjoyment of the work.
For AI-generated texts published to inform the public on matters of public interest, an important counter-exception applies: the disclosure obligation does not apply if the content has undergone human review or editorial control and a natural or legal person bears editorial responsibility.
The regulation distinguishes: under Art. 3 no. 3 EU AI Act, a provider is anyone who develops an AI system or has it developed and places it on the market or puts it into service under their own name or trademark — whether for payment or free of charge. Under Art. 3 no. 4, a deployer is anyone who uses an AI system under their own authority.
Anyone who buys and uses a ready-made chatbot solution typically meets the characteristics of a deployer. They then have no disclosure obligation of their own under paragraph 1 — their obligations follow from paragraphs 3 and 4, insofar as their conditions are met.
In practice, this does not mean that the deployer can sit back. If the notice provided by the provider is switched off or obscured, the system used can ultimately no longer meet the transparency requirements; whether such a change shifts the allocation of roles is a question of the individual case. A sensible approach is to secure the display of the notice contractually and to check it whenever the configuration changes. This is a recommendation for drafting contracts, not a legal obligation under Article 50 (1).
In its Q&A, the Commission also clarifies that employees who use a system under instructions are not independent deployers — the organization remains responsible. For high-risk systems, Art. 25 (1) lit. a EU AI Act expressly regulates the change of role: anyone who puts their name or trademark on a high-risk system already placed on the market is deemed to be a provider. For systems subject only to Article 50, there is no such rule; here, it remains a question of the individual case.
For systems placed on the market before August 2, 2026, the transitional provision inserted by Regulation (EU) 2026/1744 provides for a deadline until December 2, 2026. It is narrowly drawn and is often understood too broadly.
Only the obligation under Article 50 (2) is covered — the machine-readable marking of synthetic content. The party subject to the obligation is the provider of the generative system. The point of reference is the placing on the market, not the use and not the time at which the content is generated. According to the Commission's Quick Facts (as of 29 Jul 2026), content created before August 2, 2026, does not have to be labeled retroactively.
Anyone who wants to check the scope of the deadline needs only three questions: Was the system placed on the market before August 2, 2026? Is it about machine-readable marking under paragraph 2? And does your own organization act as the provider in this respect? Only if all three questions can be answered yes does the start of the obligations shift.
Not covered are paragraph 1, paragraph 3, and paragraph 4. There is therefore no grace period for the chatbot notice or for deepfake labeling — both have applied since August 2, 2026.
Article 50 (6) expressly clarifies that other transparency obligations laid down in Union or national law for deployers of AI systems remain unaffected. For a chatbot, this as a rule means: the information obligations under Art. 13 and 14 GDPR also apply as soon as personal data is processed — inputs, chat histories, identifiers. The AI notice does not replace the data protection information, and vice versa.
In addition, there is the provider identification under Section 5 of the German Digital Services Act (DDG). It concerns the identity of the service provider, not the machine nature of the conversation partner, and likewise does not replace the AI notice. Important for citation: since May 14, 2024, the legal basis has been the DDG, no longer Section 5 TMG. Section 18 MStV may also apply if journalistic-editorial content is published.
The Code of Practice on Transparency of AI-generated Content, published on June 10, 2026, is voluntary but confirmed by the Commission and the AI Board as an appropriate instrument; according to the Commission, around 190 organizations had signed it by the end of July 2026. It can be signed by both providers and deployers of generative systems; its focus is on the marking and labeling of content, not on the chatbot notice under paragraph 1.
Check questions can be derived from the requirements — they do not contain binding design rules. Does the notice appear with or before the first message and not only after the first input? Is it perceptible without an additional click? Does it expressly name the machine nature and not just via a product name? And does the implementation meet the accessibility requirements referred to in paragraph 5 — contrast, readability by screen readers, keyboard operability?
For deepfakes and published AI texts, the same idea applies on the output side: the labeling must appear where the content is perceived, not in a legal notice or a change log. Whether a specific design is sufficient is a question of the individual case; the authoritative source of interpretation is the Commission guidelines of July 20, 2026.
Since July 29, 2026, there has been a national legal basis: the act implementing Regulation (EU) 2024/1689 (BGBl. 2026 I no. 223, promulgated on July 28, 2026) assigns market surveillance to the Bundesnetzagentur (Federal Network Agency), which is also the point of contact and the complaints body. Existing sectoral market surveillance authorities remain competent alongside it.
The ICT survey of the Federal Statistical Office shows how widespread the starting situation is: in 2025, 26 percent of companies in Germany with 10 or more employees used AI technologies — 23 percent of those with 10 to 49, 36 percent of those with 50 to 249, and 57 percent of those with 250 or more employees (table status as of 24 Nov 2025).
Anyone who wants to communicate the obligation internally will find the basic terms in the AI glossary and its place in the regulation's system in the article on the four AI risk categories. It should be possible to prove that such training has taken place — what that involves is described in the article on proof of mandatory training.
As a rule, yes. Article 50 (1) EU AI Act requires that people are informed when they interact with an AI system. The exception applies only if this is obvious to a reasonably well-informed, observant, and circumspect person — and, according to the Commission, is to be interpreted narrowly.
There is little to support that. Article 50 (5) requires the information "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure". A note that users only find elsewhere does not reflect this point in time.
No. The transitional period covers only the machine-readable marking of synthetic content under Article 50 (2) and is aimed at providers of systems placed on the market before August 2, 2026. The chatbot notice under paragraph 1 and deepfake labeling under paragraph 4 apply without a grace period.
According to its wording, Article 50 (1) is addressed to the provider. Anyone who merely uses a ready-made system typically meets the characteristics of a deployer under Art. 3 no. 4 EU AI Act; paragraphs 3 and 4 apply to them. It remains sensible to secure the display of the notice contractually and not to switch it off.
No. Article 50 (4) concerns published texts that inform the public on matters of public interest. The obligation does not apply if the content has undergone human review or editorial control and a person bears editorial responsibility.
Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.