Chatbot Disclosure Rules: What Applies from August 2026
Last updated on August 10, 2026 at 14:23 PM.The chatbot disclosure obligation is the legal requirement under Art. 50(1) of the EU AI Act, stipulating that users must be able to recognise—before or at the point of first interaction—that they are communicating with an AI, not a human being. The obligation takes effect on 2 August 2026 for every company deploying AI chatbots, voicebots or automated customer communication. Non-compliance carries fines of up to €15 million or 3 % of global annual turnover. This article provides sample disclosure texts, an implementation checklist and the legal foundations for an AI transparency check—from inventory to contractual safeguards with third-party providers.

Why AI transparency is now a legal obligation for businesses
A policy no one can follow is worse than no policy, because it creates the illusion of control. What actually holds is the combination of an honest audit of what people are already doing, rules written to be used rather than filed, and integrations built to keep data where it belongs. That is the difference between AI governance that survives contact with daily work and a document that reassures the board and protects no one.
At the same time, 85 % of consumers demand greater transparency around AI use. The gap between adoption and trust is measurable—and the EU AI Act closes it with binding transparency obligations. Chatbots are among the most widespread AI applications in direct customer contact, and that is precisely where Art. 50 applies.
Art. 50 of the AI Regulation does not only concern high-risk systems—it covers every chatbot that interacts with users. 33 % of all companies using the EU AI Act Compliance Checker are affected by transparency obligations. The deadline is fixed: 2 August 2026. Failure to disclose by then risks sanctions—in a regulatory environment that does not treat violations as minor offences.
What does the chatbot disclosure obligation under Art. 50 EU AI Act mean?
The chatbot disclosure obligation under Art. 50(1) of the EU AI Act requires providers of AI systems intended for direct interaction with natural persons to design those systems so that users are informed they are interacting with an AI. The obligation applies equally to chatbots, voicebots, virtual assistants, social bots and AI agents. What matters is not the complexity of the system but the fact of interaction.
Who is a provider, who is a deployer?
The allocation of roles determines who bears which obligation. The provider develops an AI system or commissions its development and places it on the market under its own name. The deployer uses an AI system under its own authority—for example, a chatbot on its own website. Companies that use a third-party chatbot service are deployers. The disclosure obligation under paragraph 1 primarily falls on the provider, but without contractual safeguards the liability risk remains with the deployer. Relying on a service provider's assurance without fixing it in a contract means making a promise you cannot control yourself.
Exception—when does the disclosure requirement not apply?
The disclosure requirement only lapses when it is obvious to a "reasonably well-informed, observant and circumspect" person that they are interacting with AI. In practice, this exception is almost never applicable to chatbots. The Commission Guidelines make clear: as soon as a system responds in natural language and thereby simulates human communication, disclosure is the default. Anyone invoking the exception bears the burden of proof.
AI disclosure text examples for website chatbots and automated customer communication
The AI disclosure text must be clear, distinguishable and accessible—no later than at the point of first interaction. Hidden notices in the footer, in terms and conditions, or as briefly flashing overlays do not meet the requirement. Placement is regulated just as much as content: the user must be able to perceive the notice before making their first input.
Sample disclosure texts by channel
| Channel | Sample disclosure text | Placement |
|---|---|---|
| Website chatbot | "You are communicating with an AI assistant. To speak with a human, select 'Contact a team member'." | First message in the chat window, before user input |
| Email auto-responder | "This reply was generated automatically by an AI system. For follow-up questions, reach our team at [contact]." | Header of the email |
| Telephone voicebot | "Please note: you are speaking with an AI-powered voice assistant." | Audio notice before the conversation begins |
| Social media bot | "This account is operated by an AI system." | Profile description + first message |
| Messenger chatbot (WhatsApp, etc.) | "Hello! I'm an AI assistant from [company]. How can I help you?" | First automated message |
Accessibility requirements
Accessibility is not optional—it is part of the obligation. The notice requires sufficient contrast, must be readable by screen readers, and must not rely solely on visual cues—an icon alone is not enough. For international chatbots, multilingual support must be considered: the EU label is localised, with "AI" as the English-language marker. If you operate a chatbot in three languages, you need the notice in three languages.
Chatbot disclosure under GDPR and the AI Regulation—two frameworks, one implementation
The GDPR requires transparency about data processing (Art. 13/14 GDPR); the EU AI Act requires transparency about the AI nature of the system. Both must be fulfilled in parallel, but both can be consolidated into a single disclosure toolkit. Treating the obligations separately doubles the effort without adding legal value.
GDPR obligations when deploying a chatbot
Every chatbot that processes personal data triggers the information obligation under Art. 13 GDPR: controller, purpose, legal basis, retention period. If the chatbot makes decisions with legal effect—such as a credit check or an automated contract rejection—Art. 22 GDPR additionally applies, granting the right to human review. The AI Regulation does not replace these obligations; it supplements them.
Synergies in implementation
A combined notice can satisfy both requirements: AI nature and data-protection information in a single structured block. A company with 5 chatbot touchpoints—website, WhatsApp, email, telephone, social media—saves approximately 60 % of implementation time by using a standardised disclosure toolkit compared to individual one-off implementations. The toolkit consists of a core text (AI disclosure) and channel-specific modules (data protection, contact alternative, accessibility).
| Approach | Effort (estimated) | Consistency |
|---|---|---|
| Individual disclosure texts per channel | 100 % | Low—deviations likely |
| Standardised toolkit with modules | approx. 40 % | High—centrally maintained |
| No systematic approach | Incalculable | None—compliance risk |
AI transparency check—implementation checklist for August 2026
A structured AI transparency check identifies all affected systems and ensures compliance before the deadline takes effect. There is more talk about whether AI is dangerous than there is clarity about which of your own tools actually process which data. That gap is where trouble lives. Sorting it out is unglamorous work—knowing what is in use, who is responsible, and what leaves the building—but it is the kind of governance and compliance groundwork that turns a diffuse worry into something you can point at and manage.
- Create an AI inventory: Record all AI systems with user interaction—chatbots, voicebots, automated email systems, social bots. Internal tools that communicate externally also belong on the list.
- Clarify roles: For each system, determine whether the company is provider or deployer. Different roles entail different obligations—and different liability scenarios.
- Draft disclosure texts: Create a clear, accessible disclosure text for each channel and implement it technically. The text must be visible before the user's first input.
- Contractual safeguards: For third-party chatbots, contractually ensure that the provider fulfils the disclosure obligation under Art. 50(1). Without a contract clause, the risk remains with the deployer.
- Documentation and review: Establish a review process that regularly verifies whether notices are correctly displayed—particularly after updates, relaunches or provider changes.
| Phase | Timeframe | Action |
|---|---|---|
| Analysis | Immediately | AI inventory, role clarification, gap analysis |
| Conception | Q3 2026 | Disclosure texts, data-protection synergies, accessibility |
| Implementation | By 01.08.2026 | Technical deployment, testing, training |
A documented AI transparency strategy makes obligations plannable and protects against fines. Companies that prefer not to handle implementation in-house can develop it with a specialist communications agency such as Crispy Content®.
Fines and liability risks for missing AI disclosure
Violations of the transparency obligations under Art. 50 are subject to fines of up to €15 million or 3 % of global annual turnover—whichever amount is higher. This is not a theoretical risk. The EU demonstrated with the GDPR that it enforces fines at this scale. Reduced caps apply to SMEs and start-ups, but "reduced" does not mean "irrelevant".
| Violation category | Maximum fine | Example |
|---|---|---|
| Prohibited AI practices (Art. 5) | €35 million / 7 % turnover | Manipulative AI systems |
| Transparency obligations (Art. 50) | €15 million / 3 % turnover | Missing chatbot disclosure |
| Other violations | €7.5 million / 1.5 % turnover | Incomplete documentation |
National supervisory authorities enforce the fines. In Germany, the responsible authority is yet to be formally designated—the Bundesnetzagentur is considered the most likely candidate. Regardless: most companies discover their AI problem the hard way: an employee pastes a customer list into a public chatbot, and suddenly the question is not what the tool can do, but where the data went. Shadow AI is not a minor detail on the risk register—it is the risk. The work of putting AI usage on GDPR-compliant ground through audits, policies and secure integrations starts before the first prompt, not after the first incident.
Trends—how AI transparency obligations will evolve
Transparency requirements for AI systems will tighten in the coming years, not ease. Those who implement the bare minimum today will need to retrofit tomorrow. Those who build the right structure today will only need an update.
Standardised EU label for AI content
The European Commission is developing a uniform visual label—"AI" in English, "KI" in German—for AI-generated content. The Code of Practice in its final version of June 2026 defines technical standards for watermarks and metadata. The label will not remain optional. It will become the visible standard by which consumers identify AI content—regardless of channel.
AI agents and autonomous systems
The Commission Guidelines confirm: AI agents fall under Art. 50(1). If a provider cannot predict whether an agent will interact with humans—for instance, autonomous systems that initiate contact independently—disclosure must occur in every interaction. This affects not only chatbots in the traditional sense but also AI-powered outreach systems, automated appointment scheduling and autonomous negotiation bots.
Consumer expectation as a driver
The EY AI Sentiment Study 2026 illustrates the discrepancy clearly: adoption high, trust low. Transparency thus becomes a competitive advantage—not because the law demands it, but because the market rewards it. Companies that proactively disclose strengthen their brand credibility in an environment where distrust is the default.
AI transparency as a trust investment—not just an obligation
The chatbot disclosure obligation from August 2026 is not bureaucratic overhead—it is an opportunity to build trust in digital customer communication. Companies that conduct the AI transparency check now, implement disclosure texts and document their processes do not merely comply with Art. 50 EU AI Act and GDPR requirements—they position themselves as a reliable brand in a market where 85 % of consumers expect greater openness about AI use. Methods provide guarantees. And a disclosure built on a clean inventory, clear roles and verified contracts is a guarantee that holds.
Sources
- Future of Life Institute (2026): The EU AI Act's Transparency Rules: A Practical Guide to Article 50. URL: https://artificialintelligenceact.eu/transparency-rules-article-50/ (accessed 20.07.2026).
- HÄRTING Rechtsanwälte (2025): Transparenzpflichten in der KI-Verordnung (Art. 50): KI-Inhalte richtig kennzeichnen. URL: https://haerting.de/wissen/transparenzpflichten-in-der-ki-verordnung/ (accessed 20.07.2026).
- European Commission (2026): AI Act – Regulatory Framework. URL: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai (accessed 20.07.2026).
- Bitkom (2026): Künstliche Intelligenz in Deutschland – Studienbericht 2026. URL: https://www.bitkom.org/Bitkom/Publikationen/Kuenstliche-Intelligenz-in-Deutschland (accessed 20.07.2026).
- TÜV-Verband (2025): KI-Verbraucherstudie: Verbraucher wollen Sicherheit und Transparenz. URL: https://www.tuev-verband.de/pressemitteilungen/ki-verbraucherstudie (accessed 20.07.2026).
- EY (2026): KI in Deutschland: Nutzung hoch, Vertrauen gering – AI Sentiment Studie 2026. URL: https://www.ey.com/de_de/insights/ai/ki-in-deutschland-nutzung-hoch-vertrauen-gering (accessed 20.07.2026).
- Ideenfabrik (2026): KI-Kennzeichnungspflicht ab August 2026. URL: https://www.ihre-ideenfabrik.de/magazin/datenschutz/pflicht-zu-ki-kennzeichnung-das-muessen-sie-tun/ (accessed 20.07.2026).
Gerrit Grunert
Gerrit Grunert is the founder and CEO of Crispy Content®. In 2019, he published his book "Methodical Content Marketing" published by Springer Gabler, as well as the series of online courses "Making Content." In his free time, Gerrit is a passionate guitar collector, likes reading books by Stefan Zweig, and listening to music from the day before yesterday.