New transparency requirements in the AI ​​Regulation come into force

Do you use an AI chatbot on your website?
Then users must be clearly informed

AI chatbots, virtual assistants, and automated customer service bots have become a natural part of many companies' websites. The technology can streamline customer service, ensure faster responses, and make support available outside of normal business hours.

But the user must be able to tell whether they are communicating with a human or an AI system.

This follows from Article 50 of the EU AI Regulation, which sets out a number of transparency obligations for companies developing or using certain AI systems. The transparency requirements in Article 50 apply from 2 August 2026 and include, among other things, interactive AI systems such as chatbots and virtual assistants.

The rules for autonomous high-risk AI systems covered by Annex III, on the other hand, have been postponed until 2 December 2027 as a result of the EU's digital omnibus on AI.

The aim of the rules is to reduce the risk of deception, manipulation, fraud and misinformation. Citizens and customers need to know when they are interacting with AI or are presented with content generated or manipulated using AI. This should enable them to make informed decisions and adjust their trust in the system.

What does Article 50 require?

Article 50 contains different transparency requirements depending on the type of AI system used and whether the company is the provider or operator of the system.

The rules cover four general situations:

  1. Direct interaction between a person and an AI system
  2. AI-generated or AI-manipulated content
  3. Emotion recognition and biometric categorization
  4. Deepfakes and certain AI-generated texts on matters of public interest


For most companies that use a chatbot or customer service bot on their website, the requirement for direct interaction with an AI system is particularly relevant.

Chatbots and customer service bots: The user needs to know it's AI

According to Article 50(1), providers must design AI systems that interact directly with individuals in a way that ensures that users are informed that they are communicating with an AI system.

It could be, for example:

  • a chatbot on the company's website
  • a virtual customer service assistant
  • a voicebot or telephone AI assistant
  • another AI-based system that communicates directly with the customer

The requirement is aimed at situations where there is real, direct two-way communication between the AI ​​system and a natural person. Systems that only operate in the background, perform passive data collection or communicate with other machines are not covered by this particular requirement.

The information about the use of AI must be provided clearly and distinctly at the first interaction or exposure at the latest. The user should therefore be able to see directly in the chat window or the introductory message that it is an AI bot, already when the chat is opened or at the latest before the first actual exchange. It will not be sufficient for the information to appear solely in the company's general terms and conditions or privacy policy if the user is not presented with it at the first interaction at the latest.

A text can be formulated as follows, for example:

“You are chatting with our AI assistant.”

“This customer service uses AI to answer your questions.”

The specific wording can be adapted to the company's Solution and target group, but the information must be clear, understandable and easy to spot.

Provider or installer: Who is responsible?

Article 50 distinguishes between providers and deployers of AI systems.

A provider is basically the organization that develops, markets or uses an AI system under its own name or trademark.

An implementer is an organization that uses an AI system under its own authority, for example, a company that integrates an AI chatbot from an external vendor on its website.

The technical obligation to design the system so that users are informed is generally the responsibility of the provider. However, a company using an external chatbot should check that the information is actually displayed correctly on the company's own website and that the division of responsibilities has been clarified with the supplier.

Other transparency requirements

Article 50 also contains specific requirements for the labelling of AI-generated or manipulated content. This applies, among other things, to deepfakes, certain texts on matters of public interest, and the use of emotion recognition and biometric categorization. Companies using such Solutions should therefore investigate whether a separate information or labelling obligation applies.

EU icons for labeling AI content

The labelling of AI-generated or AI-manipulated content is voluntary, provided that the chosen labelling otherwise meets the relevant requirements. The EU has published three examples of icons that can be used to label fully AI-generated content, partially AI-manipulated content and content where additional information can be added. The icons are free to use. [1]

The icons are not a general AI certificate and are not mandatory for chatbots. For chatbots, it is crucial that the user is clearly informed that they are communicating with an AI system, at the latest upon the first interaction.

What can non-compliance cost?

Failure to comply with the transparency requirements may result in administrative fines of up to 15 million euros or 3 percent of the company's total global annual turnover in the preceding financial year, whichever is higher. Small and medium-sized enterprises are treated proportionately.

Checklist: Does your chatbot comply with Article 50?

Companies deploying AI on their website or in customer service should check the following:

  • Map the AI ​​Solutions: Identify your company's chatbots, voicebots, virtual assistants and other relevant AI systems.
  • Determine the company's role: Consider whether the company is a provider, operator, or both.
  • Test the chatbot: Make sure the user is clearly informed about the use of AI at the very least during the first interaction. The information should be easy to find, understandable, and accessible.
  • Check the supplier: Check whether the supplier has incorporated the necessary information, whether the information is preserved when integrated on your website, and how responsibility for compliance with Article 50 is distributed.
  • Document the assessment: Describe which requirements apply and how the company has implemented and controlled them.

conclusion

Companies with a chatbot or customer service bot should ensure that users are clearly informed that they are communicating with an AI system, at the latest upon the first interaction. It should also be checked that the information is displayed correctly in the specific Solution and that the division of responsibilities with any external supplier is clarified and documented.

Please contact us if you have any questions about the transparency requirements in the AI ​​Regulation or would like help assessing your AI Solutions.

[1] Reference to EU AI icons: https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content

We throw ourselves around with knowledge...

Order your free material here and receive it in a few minutes in your inbox. To be safe, check your SPAM folder if necessary.

Get material ordered on the website sent

Contact Unitas – your partner in security and compliance

Unitas provides reliable advice in compliance, IT and information security. With a pragmatic approach, we help companies in regulated industries manage security and operational responsibility effectively. Contact us to discuss how we can help you.

Form for contact page