Article 50 of the AI Act, applicable from 2 August 2026, requires clarity when a person interacts with an AI system or is exposed to certain generated or manipulated content. For an SME this is not “all high-risk rules at once”: it is mainly notices on chatbots, labels on deepfakes and, in specific cases, on public-interest text.
General information, not legal advice. Dates and duties should be checked on the concrete case.
What Article 50 of the AI Act says
Article 50 of Regulation (EU) 2024/1689 is the transparency chapter for certain systems, not high-risk classification. It applies from 2 August 2026 (Art. 113; Commission FAQ, updated 24 July 2026).
In short, by role:
| Who | What | Source |
|---|---|---|
| Provider | Design systems that talk to people so it is clear they are AI, unless that is obvious | Art. 50(1) |
| Provider | Mark synthetic content (text, audio, image, video) in a machine-readable way | Art. 50(2) |
| Deployer | Inform people exposed to emotion recognition or biometric categorisation | Art. 50(3) |
| Deployer | Disclose deepfakes and certain public-interest texts generated or manipulated by AI | Art. 50(4) |
The information must be clear and distinguishable, at the latest at first contact, and accessible (Art. 50(5)).
The Commission published guidelines and an official FAQ and, on 2 August 2026, a notice on entry into application.
The chatbot must identify itself: when and how
If a system is meant for a direct dialogue with people (chatbot, agent, avatar, voice responder), the provider must design it so the user knows they are talking to AI, unless that is already obvious to a reasonably well-informed, observant person (Art. 50(1)).
The Commission lists four cumulative criteria: it must be an AI system; there must be a genuine two-way exchange, not mere data collection or isolated automated replies; the interaction must be direct (the AI speaks to the person, not through a human intermediary); it must address natural persons.
What is out of scope. Background-only systems, machine-to-machine communication, no direct contact with people.
What to do in practice on your site or app.
- A visible line before or at the opening of the chat: for example “You are speaking with an artificial intelligence system, not a person.”
- Do not hide it in the footer or the terms.
- If you use SaaS (a widget, Copilot on a customer portal, a voice agent), check that the vendor shows it. If it is missing, add it: design is the provider’s duty, but the customer sees your channel.
- The “it is obvious” exception is to be read narrowly, the Commission writes: a name like “Assistant” is not enough if it looks like a human agent.
An internal Copilot, with a product name and an evident interface, is often in the “obvious” scenario for employees. A website chatbot that mimics an adviser is not.
What deployers must do (not only providers)
In most SMEs the role is deployer: you use systems under your authority (Art. 3 definitions). The Article 50 duties that sit on deployers are paragraphs 3 and 4, not “rewrite the model.”
Emotion recognition / biometric categorisation (para. 3). If you use them, exposed people must be told the system is operating — in real time or after the fact. This is not the typical SME using ChatGPT for drafts.
Deepfakes (para. 4). A deepfake, under Art. 3(60), is generated or manipulated image/audio/video that appears authentic. If you publish it (an ad, a CEO video, a voice clone), disclose it in a way a person can perceive; the provider’s technical watermark is not enough. A narrow exception exists for evidently artistic, satirical or fictional works: disclosure must not spoil the work, but it must exist.
Public-interest text (para. 4). If you publish AI-generated or manipulated text to inform the public on matters of public interest (politics, health, security, public services, economic developments relevant to public debate), disclose it — unless there is substantial human review / editorial control, with someone who takes responsibility. Spell-check is not enough.
An internal newsletter or a customer email draft, reread and signed by a person, is not the same as a public statement left “as the model produced it.”
What is not required (and dates not to confuse)
- Annex III high-risk duties have not started. That deadline moved to 2 December 2027 (simplification package described by the Commission in the deployer guide). August 2026 is transparency and enforcement, not “all HR/credit obligations.”
- No retroactive labelling of content generated before 2 August 2026. The Commission encourages it; it does not require it (FAQ).
- A narrow grace period only for Art. 50(2) (machine-readable marking): for systems already on the market before 2 August 2026, providers have until 2 December 2026. Chatbot identification and deployer disclosure: from 2 August 2026.
- Not every AI text in the company must be stamped. You need publication + informing the public + public interest, or a deepfake, or a direct interaction that is not obvious.
Enforcement is mainly for national market-surveillance authorities. Fines under the regulation can, in the abstract, reach €15 million or 3% of worldwide turnover; for SMEs the Commission recalls proportionality. That is not a reason to freeze projects: it is a reason to put three notices in the right place.
FAQ
Does Article 50 of the AI Act ban company chatbots?
No. It requires that, if the system talks to people and it is not obvious, you say so at first contact.
If I use ChatGPT or Copilot only internally, must I label every output?
Not automatically. The deployer duty on text covers public-interest publications without substantial editorial review. The “chatbot must identify itself” duty covers direct interaction with people, typically customers or external users.
Is the vendor watermark enough?
For deepfakes, no: the Commission says deployers cannot rely only on the provider’s machine-readable mark. A visible or audible disclosure is required.
Does this also apply in Italy with Law 132/2025?
Yes: the AI Act applies directly. Law 132/2025 does not replace it.
Sources
- EUR-Lex: Regulation (EU) 2024/1689 – AI Act
- AI Act Explorer: Article 50
- European Commission: FAQ on Article 50 transparency (24 July 2026)
- European Commission: transparency rules from 2 August 2026
Dig deeper in the series
- Deployer AI Act: who it is and what to do
- Deployer vs provider: SME checklist
- Law 132/2025 in Italy
- AI agents vs chatbots
- Mandatory AI literacy
If you have a chatbot, an agent, or generated content facing customers and want an operational pass (what to show on the first message, what to label, what not to), we can do it on the real perimeter. Write to info@zendata.it or visit zendata.it.
Pietro Ciattaglia, CEO of Zendata AI, Rome

