A person messaging a company’s support line in the European Union is now legally entitled to know whether the entity typing back is a person or a machine. As of early August 2026, a transparency provision buried inside the bloc’s sweeping artificial intelligence law began to bite, requiring that interactive AI systems identify themselves as AI rather than pass silently for human staff. The rule is narrow in what it demands but broad in reach, touching any business whose automated assistant converses with someone inside the EU.
The obligation sits in Article 50 of the AI Act, the transparency chapter of a regulation that has been phased in over several years. The chatbot disclosure duty is one piece of a wider package that also covers synthetic media and machine-written text. Regulators have framed the change less as a restriction on what AI can do and more as a floor on what users must be told before they engage with it.
What Article 50 actually requires
The core demand is straightforward: a system that interacts directly with people must inform them that they are dealing with an AI, not a human, unless that fact is already obvious to a reasonably well-informed user. The European Commission, which oversees enforcement, has said the disclosure must be “clear and distinguishable” and delivered at the latest at the point of first contact. A notice tucked into a lengthy terms-of-service document or a privacy policy does not satisfy the requirement, according to guidance published by the Commission as the rules began to apply on August 2.
The rule also folds in an accessibility dimension, requiring that the disclosure comply with applicable accessibility standards so that users relying on assistive technology receive the same notice. In practice, that pushes companies toward visible, plainly worded labels at the top of a chat window rather than fine print that a screen reader might skip or that a hurried user would never see.
Deepfakes and machine-written text are covered too
Chatbots are only the most visible target. The same transparency chapter requires that AI-generated or AI-manipulated images, audio, and video, commonly called deepfakes, be labeled as artificially produced. Text generated by AI and published to inform the public on matters of public interest must also carry a disclosure, with a carve-out where a human editor has genuinely reviewed the material and a person or organization holds editorial responsibility for it.
That editorial exception matters for news outlets and publishers that use automated tools to help draft copy. The law does not treat every keystroke assisted by software as something that must be flagged; it aims at content presented to the public as if it were the unmediated product of a person when it was in fact machine-produced. The distinction turns on meaningful human oversight rather than on whether software was involved at any stage.
How the penalties are structured
The enforcement teeth are significant. Breaches of the transparency obligations can draw fines reaching several million euros or a percentage of a company’s worldwide annual turnover, whichever is higher, a structure common across the AI Act that scales the consequences to the size of the offender. For the largest technology firms, a turnover-based penalty can dwarf a fixed cap. Legal analysts have noted that the figures are designed to make non-compliance a board-level concern rather than a rounding error, a point underscored in practitioner commentary on the August timeline.
Enforcement in the early months is expected to lean on guidance and codes of practice rather than immediate maximum fines, a pattern the EU has followed with earlier digital rules. Companies operating multiple consumer-facing bots have been reviewing their interfaces to add first-contact labels, adjust scripts so an assistant does not imply it is human, and document who is responsible for AI-generated output.
Why the reach extends beyond Europe
The obligation applies to AI systems whose output is used within the EU, which means a firm based elsewhere can fall under the rule if its chatbot serves European customers. That extraterritorial reach echoes the design of the bloc’s data-protection regime, which reshaped privacy practices well outside Europe because global companies found it simpler to apply one standard everywhere than to maintain separate systems by region. The same dynamic could push AI disclosure labels into interfaces seen by users far from the EU, simply because splitting the experience by geography is costly and error-prone.
Regulators elsewhere have been watching. Several jurisdictions have floated or adopted their own bot-disclosure requirements, though few match the breadth of the EU framework. The practical effect for many multinationals is a convergence toward telling users, plainly and early, when they are talking to software.
What changes for everyday users
For the average person contacting a bank, retailer, or airline, the most visible result is a short line of text or a badge stating that the assistant is automated. That will not stop companies from routing routine questions to bots, and it does not guarantee an easy path to a human agent. What it does establish is a baseline expectation that the identity of the responder is not concealed, removing the ambiguity that has surrounded increasingly fluent conversational systems.
The longer-term significance may lie in normalization. As machine-written summaries, synthetic images, and automated voices spread across services, a consistent labeling habit gives users a reference point for judging what they are reading, seeing, or hearing. The EU has effectively legislated that ambiguity into a disclosure, betting that transparency at the moment of first contact is easier to enforce than trying to police the content itself.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview