Skip to content

AI Act Article 50: what chatbot apps must disclose from August

Filip LuchianencoUpdated 6 min read

Last updated: 2026-10-03

On August 2, 2026, Article 50 of the EU AI Act, Regulation (EU) 2024/1689, began to apply. AI Act Article 50 requires the provider of an AI system "intended to interact directly with natural persons" to design it so that people "are informed that they are interacting with an AI system, unless this is obvious", and requires providers of generative AI to mark outputs "in a machine-readable format". On July 20, 2026, the European Commission published its guidelines on Article 50, reference C(2026) 5054 final, which name chatbots, AI companions and AI agents as in scope and set out what a compliant disclosure looks like. Mobile apps offer all three.

When does AI Act Article 50 apply?

Article 50 applies from August 2, 2026, the general application date in Article 113.

One duty has a later date. The Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026, added Article 111(4): providers of generative AI systems "that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026." The guidelines (paragraph 153) state that systems "that are partly interactive and partly generative" get the extra time "only with regard to the marking obligation". An image-generating chat app released in 2025 therefore owed the chat disclosure from August 2 and owes the output mark from December 2.

Paragraph Who must act Duty Applies from
50(1) Provider of an AI system that interacts directly with people Inform each person that they are interacting with an AI system, unless obvious August 2, 2026
50(2) Provider of a system generating synthetic audio, image, video or text Mark outputs in a machine-readable format, detectable as AI-generated August 2, 2026; December 2, 2026 for systems on the market before August 2, 2026
50(3) Deployer of emotion recognition or biometric categorization Inform the persons exposed August 2, 2026
50(4) Deployer publishing deep fakes or AI text on matters of public interest Disclose that the content is AI-generated or manipulated August 2, 2026
50(5) All of the above Provide the information "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" August 2, 2026

Sources: Article 50; Article 111(4) as added by Regulation (EU) 2026/1744.

Who is the provider when an app uses a third-party model?

A company that offers a chatbot "on the Union market under its own name or trademark" is the provider responsible for Article 50(1), free or paid, inside or outside the EU, according to the guidelines (paragraphs 10 and 11). Paragraph 27 (page 11) states that Article 50 "does not explicitly apply to GPAI models" (general-purpose AI models) and refers to "downstream AI system providers" and their obligations under Article 50(1) and (2).

The guidelines name mobile applications in one example, a police chatbot. Applying the provider definition to apps is my reading: the publisher of an app released under its own name, whose chat screen calls a model API from OpenAI, Anthropic or Google, is the provider of that chat system and owes the disclosure.

What does the AI disclosure have to look like?

Article 50(5) requires the disclosure "at the latest at the time of the first interaction". Paragraph 143 of the guidelines states that it "should, at least, be provided once at the start of an interactive session". Paragraph 37 (page 15) gives examples of appropriate techniques: a banner such as "You are interacting with an AI system", a first-turn greeting, a persistent badge, a disclosure near the input field, and a spoken statement at the start of a voice session.

Paragraph 38 (page 16) lists techniques that are "not necessary and, when used alone, insufficient":

  • "Disclosures contained only in terms and conditions, URLs, or documentation"
  • "Machine-readable markings (e.g. metadata or watermarks) that are not perceivable by users at the point of interaction"
  • "Unclear or ambiguous signals (e.g. generic references to 'assistant') or human-like representations that may mislead users"
  • "Generalised disclosures", where "a general disclosure like 'Services on this website use AI' is insufficient"
  • "statements solely referring to underlying technologies (e.g. 'this system uses LLMs')"

Paragraph 40 states that "periodic reminders and context-aware disclosures are likely to be necessary" for children, the elderly and persons with disabilities, for "sustained and evolving interactions in sensitive or immersive contexts", and where users risk "forming emotional attachments or dependencies (e.g. AI companions)". The same paragraph requires disclosure whenever a user asks the system about its nature. Where children may use the system, paragraph 34 states that notifications "must be child-friendly, age-appropriate, easy-to-understand". On minors and chatbots, see Italy's Character.AI decision under the GDPR and California's SB 1119.

When is it "obvious" that the user is talking to an AI?

The provider must "assess and demonstrate" obviousness to a person who is "reasonably well-informed, observant and circumspect" (guidelines, paragraph 42), and paragraph 45 (page 18) states that it "should be limited to cases where there is almost no doubt left about the nature of the interaction". Where the general public can access the system, including children or older users "for whom the interaction is less obvious", "the exception cannot be relied upon".

The guidelines' examples where the exception applies are mostly professional tools, such as code assistants and diagnostic tools for trained clinicians. Among their examples where the duty applies: "AI chatbots embedded in online platforms or assistance support tools (helpdesks) whereby users directly interact and receive AI outputs ... they may perceive as human-generated" (page 19). A support chat inside a banking, retail or travel app matches that example. The guidelines give no example for an app named "AI Chat"; under paragraph 42 the provider bears the burden of showing the interaction was obvious.

What about AI-generated images and text in apps?

Article 50(2) covers providers of systems "generating synthetic audio, image, video or text content": outputs must be "marked in a machine-readable format and detectable as artificially generated or manipulated", except where the system performs "an assistive function for standard editing".

The Code of Practice on Transparency of AI-generated Content, final since June 10, 2026, covers marking and labeling under Article 50(2), (4) and (5), with "about 190" signatories by the end of July 2026. For the chatbot disclosure, the FAQ states that providers "can determine adequate compliance measures themselves, while taking into account" the guidelines.

Who enforces Article 50, and what are the fines?

Member States' market surveillance authorities enforce Article 50, alongside the AI Office and the European Data Protection Supervisor within their competence (guidelines, paragraph 151). They act on their own initiative or on a complaint, which "every affected person or any other natural or legal person having grounds to consider such violations has the right to lodge"; footnote 49 cites Article 85 for that right. Article 85 lets any natural or legal person "having grounds to consider that there has been an infringement" complain to the relevant market surveillance authority, "without prejudice to other administrative or judicial remedies". The Commission's list of single points of contact, updated September 7, 2026, names Germany's Bundesnetzagentur, France's DGCCRF and Spain's AESIA, each with designation "pending final adoption", and Italy's National Cybersecurity Agency; six Member States had no entry.

Under Article 99(4)(g), breach of Article 50 is subject to fines "of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher". For SMEs and, after the Omnibus, small mid-caps, the cap is whichever is lower. Paragraph 50 of the guidelines states that for "a subscription-based chatbot, an AI companion application, or a virtual coaching service", EU consumer law may require disclosure of the AI functionality before contract, "irrespective of whether the interaction is considered 'obvious'". A web search on October 3, 2026 returned law-firm and vendor commentary on Article 50 and zero announced enforcement actions.

What does a CITT scan and capture show for Article 50?

The Article 50(1) disclosure is a screen element, so its evidence is a record of the app's screens. When I scan an Android app, the static report lists the LLM API hosts in the dex or resources (api.openai.com, api.anthropic.com and generativelanguage.googleapis.com) and any OpenAI or Anthropic API key in the build, each with its file and line. That is presence: the build contains a model API host or key, and only a run shows a chat screen calling it.

A capture on a test device records each request the app sends: the host (a model provider's API or the app's own backend), the identifiers in it, and whether it was sent before or after the app's consent prompt, with a screenshot at each step the test driver takes. When an app relays chat through its own server, the model behind that server is outside what a capture shows. CanITrustThat (CITT) is building two Article 50 checks: a recorded first chat session that shows whether a label or first-turn notice appeared before the first reply, and a check of generated images for C2PA and IPTC marks. Whether the "obvious" exception applies is a legal assessment; the scan records the code and traffic that assessment uses. See what a scan checks and the limits of a scan.

I run these investigations for lawyers and for researchers working with lawyers, on one app or a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.