ConsentPixel – Privacy · Verified

EU AI Act · Explainer

EU AI Act Article 50 for Websites: What Actually Applies

Since 2 August 2026, the EU AI Act's transparency rules have been enforceable — and a lot of website owners have read the headlines about "AI disclosure" and "watermarking" and quietly panicked. Most of that panic is misplaced. Article 50 has four obligations, and for the overwhelming majority of ordinary websites, only one of them applies — and it's straightforward. This is the plain-English guide to which part is actually your job, what "disclosure" has to look like, and, just as importantly, what isn't your responsibility.

This guide is about one thing: disclosing an AI chatbot under Article 50(1) — the obligation nearly every website with a chatbot has to meet. The EU AI Act has three other transparency rules (content marking, emotion recognition, deepfake labelling) and a wider set of risk tiers, deadlines and fines. For that full picture, start with the complete EU AI Act website guide. Then come back here for the chatbot detail.
CPConsentPixel Team September 2026 12 min read Information, not legal advice
2 Aug 2026
Article 50 transparency obligations became enforceable across the EU
€15M / 3%
Maximum penalty — or 3% of worldwide annual turnover, whichever is higher
1 of 4
Obligations that apply to most ordinary websites — the AI-interaction disclosure

Key takeaways

  • Article 50 has four obligations, not one. They apply to different situations. Most websites are only touched by the first: disclosing AI interactions.
  • If your site has a chatbot, AI search, or an AI assistant, you must tell EU visitors they're interacting with AI — clearly, at the point of interaction, not buried in your terms.
  • The disclosure duty is yours even if you didn't build the AI. It falls on the deployer — the business running the tool on its site.
  • Content watermarking is a different obligation, and usually not yours. Marking AI-generated media is the AI provider's job, not a consent-layer task.
  • It reaches non-EU businesses. If your site serves EU visitors and uses AI they interact with, Article 50 applies regardless of where you're based.

What Article 50 is

Article 50 is the transparency section of the EU AI Act (Regulation (EU) 2024/1689). While much of the AI Act deals with "high-risk" AI systems and phases in over several years, Article 50 is about something simpler and more universal: making sure people know when they're dealing with AI. Its obligations became enforceable on 2 August 2026, and violations sit in the penalty tier of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

Here's the reassuring part, and the reason this article exists: Article 50 is often described as if it's a sweeping new compliance burden, but for a normal business website it's usually one clear, doable task. The trick is knowing which of its four obligations applies to you — because most of them don't.

Why regulators find this easy to enforce. Transparency obligations are among the simplest privacy rules for authorities to check — they can just visit your website, use your chatbot, and see whether a disclosure appears. There's no forensic investigation required. That's worth knowing because it means the practical enforcement risk is real and visible, not theoretical — but it also means compliance is equally visible once you've done it.

The four obligations, decoded

Article 50 contains four distinct transparency duties. They apply to different actors and different situations. Read them as a filter — most sites stop at the first row.

Article 50 obligationApplies when…Whose jobMost sites?
50(1) — AI interaction disclosureYour site has AI that visitors interact with (chatbot, AI search, AI assistant)The deployer (you)✅ Usually yes
50(2) — AI content markingYou provide a generative-AI system that produces synthetic media/textThe AI provider✗ Rarely
50(3) — Emotion / biometric disclosureYou run emotion-recognition or biometric-categorization AIThe deployer✗ Niche
50(4) — Deepfake / public-interest labelingYou publish AI-generated deepfakes or AI text on matters of public interestThe deployer✗ Media mostly

The pattern is clear once you see it laid out: 50(1) is the one that touches ordinary websites, and it's the one that behaves like a consent-layer task — surface a disclosure, at the right moment, and (ideally) keep proof you did. The other three are either for AI providers (companies that build generative-AI systems) or for specific niches like media publishing and biometric systems.

Do visitors interact with AI on your site? YES NO Article 50(1) applies Disclose the AI interaction — clearly, at first interaction, not buried in your terms. Likely nothing — for now 50(2)/(3)/(4) apply only to AI providers, biometrics, or media. Re-check when you add a chatbot.

Which one applies to your site

Run yourself through this quickly:

1Does a visitor ever interact with AI on your site?A support chatbot, an AI-powered search, an AI assistant, AI-driven recommendations they engage with. If yes → 50(1) applies to you. This is the common case.
2Do you build and offer a generative-AI system to others?If you're an AI product company whose tool generates images, audio, video, or text → 50(2) content-marking applies. If you just use such a tool, this isn't your obligation — it's the tool-maker's.
3Do you run emotion recognition or biometric categorization?Sentiment analysis on video, facial-expression tracking, biometric sorting → 50(3) applies. Most sites don't do this.
4Do you publish AI-generated deepfakes or AI text on public-interest matters?Mostly relevant to media, news, and content platforms → 50(4). Not most businesses.

For the large majority of business websites — e-commerce, SaaS, services, healthcare, professional sites — the honest answer is: only 50(1), and only if you run an AI feature visitors interact with. If you don't run any such feature, Article 50 may not require anything of you at all right now (though that can change the moment you add a chatbot).

What counts as "AI you interact with"

Since 50(1) is the obligation that matters for most sites, it's worth being concrete about what triggers it. The duty applies when a visitor directly interacts with an AI system. In website terms, that typically means:

  • AI chatbots and assistants — the support widget that answers in natural language, an AI concierge, an AI-powered help agent.
  • AI-powered live chat — where an AI handles or drafts responses, whether or not a human is also involved.
  • AI search — a search box that uses AI to interpret queries and generate answers rather than just matching keywords.
  • AI recommendations a visitor engages with — interactive recommendation features that respond to what the visitor does.

The unifying test is interaction: the visitor is communicating with, or actively engaging, an AI system. There's a sensible exception written into the law — disclosure isn't required where it would be obvious from the context that the person is dealing with AI. But "obvious" is a high bar and a risky thing to assume; a modern chatbot can feel human enough that visitors genuinely don't know, which is exactly the situation the rule exists for.

A useful boundary. Article 50(1) is about AI the visitor interacts with. Passive AI working in the background that the visitor never engages — say, an internal fraud model scoring a transaction — is a different question (and may raise GDPR issues instead). If in doubt about a specific feature, that's a good moment for counsel. This article is about the common, clear case: a visitor-facing AI they talk to or use.

What the disclosure must look like

The law doesn't hand you exact wording, but it does set a standard. The disclosure must be clear, distinguishable, and provided at the latest at the time of the first interaction. Unpacking that into practical requirements:

1Clear and understandablePlain language a normal visitor grasps immediately — "You're chatting with an AI assistant," not a dense legal clause.
2DistinguishableIt has to stand out as its own notice, not be lost inside other text. A visitor should be able to tell this is a disclosure, not marketing copy.
3Timely — at first interactionBefore or at the moment the visitor starts engaging the AI. A disclosure they only find after they've had a conversation is too late.
4Not buriedDisclosure hidden in your Terms & Conditions or privacy policy does not satisfy this. It has to be where and when the interaction happens.

The "not buried in the terms" point is the one sites get wrong most often. It mirrors a principle that runs through privacy law generally: a disclosure a visitor has to go hunting for isn't really a disclosure. (We make the same argument in a different context in your privacy policy is not a consent banner — a policy tucked in the footer can't do a job that has to happen at the moment of interaction.)

The practical shape of compliance
Because the disclosure has to appear at first interaction and be clearly distinguishable, the natural home for it is the consent layer a visitor already meets on arrival — surfaced alongside, or within, the consent banner rather than as yet another pop-up. That's the approach ConsentPixel takes: the Article 50(1) AI-interaction disclosure is built into the consent banner and shown to EU visitors, with the wording configurable to describe your specific AI features. If you want the step-by-step of enabling it, that's on the EU AI Act feature page; this article is about understanding the obligation itself.

What isn't your job — the watermarking line

This is the part that saves most site owners the most worry, so it's worth stating plainly. Article 50(2) — the content-marking / watermarking obligation — is the one behind scary headlines about "labeling all AI content." For an ordinary website, it is almost certainly not your obligation.

Here's why. 50(2) requires that synthetic content (AI-generated images, audio, video, text) be marked in a machine-readable format so it can be detected as artificial. But that duty falls on the provider of the generative-AI system — the company that built the model — not on you for using it. If you generate a blog image with an AI tool, marking that output is the tool-maker's engineering problem, embedded in how the tool works. It's a product and editorial matter, not a consent-layer or website-owner task.

One timing nuance on 50(2)
For generative-AI systems already on the EU market before 2 August 2026, a transitional grace period applies for the machine-readable marking requirements, with an effective deadline that may fall around 2 December 2026. This is relevant to AI providers maintaining existing tools — not to ordinary websites using them. If you're not building and offering a generative-AI system, 50(2) and its deadline aren't your concern.

So the clean mental model is: disclosing that a visitor is interacting with AI is your job (50(1)); watermarking AI-generated content is the AI vendor's job (50(2)). Keeping those two separate is most of what it takes to not over-worry about Article 50.

Non-EU sites and the GDPR overlap

Two final things that surprise people.

Article 50 reaches beyond the EU. The AI Act applies to providers placing AI systems on the EU market and to deployers whose AI outputs are used in the EU — regardless of where the business is established. A US, UK, or Australian company whose website is used by EU visitors and runs an AI feature those visitors interact with falls within scope. You can't escape it purely by being based elsewhere, the same way CIPA reaches sites outside California when Californians visit.

Article 50 sits on top of the GDPR, it doesn't replace it. When your AI processes personal data, the GDPR's usual requirements still apply — a lawful basis for the processing, and its transparency rules (Articles 12–14). So an AI chatbot that collects personal data can trigger both an Article 50 disclosure duty (tell them it's AI) and a GDPR consent-or-lawful-basis question (may we process this data). They're two duties at one moment, which is exactly the kind of thing AI-aware consent is meant to handle in one place.

What counts as "interacting with AI"?

Article 50(1) applies when a person interacts directly with an AI system. That sounds broad, but it has an edge, and knowing which side of it your feature sits on is the whole question. In website terms, the disclosure duty is triggered by:

  • AI chatbots and virtual assistants — the support widget that answers in natural language, an AI concierge, an AI help agent.
  • AI-powered live chat — where AI handles or drafts the replies, whether or not a human is also in the loop.
  • AI voice agents — a phone or on-site voice assistant driven by AI.
  • AI search and assistants that respond conversationally — a search box that interprets a question and generates an answer, rather than matching keywords.

The unifying test is interaction: the visitor is communicating with the AI, and could reasonably be unsure whether they're dealing with a person or a machine. Passive AI the visitor never engages — a fraud model scoring a transaction in the background, say — is a different question (and usually a GDPR one), not an Article 50(1) chatbot disclosure. (For the broad four-obligation map, see the pillar guide.)

The "obvious" exception — and why your helpdesk bot doesn't qualify

Article 50(1) has one carve-out: you don't need to disclose when it's already obvious, to a reasonably well-informed and observant person, that they're dealing with AI. Site owners lean on this far too heavily, so be precise about how narrow it is.

The European Commission's own guidance uses a customer-support chatbot as an example of something that is not obvious — precisely because a modern conversational bot can read as human. So a helpdesk assistant, a support widget, or any bot that talks in fluent natural language almost never qualifies for the exception. The safe rule of thumb: if a visitor could reasonably think they might be talking to a person, the exception doesn't apply — tell them it's AI.

Don't rely on "it's obvious" without documenting why
If you do decide a feature is genuinely obvious (for example, a clearly labelled "AI Image Generator" tool where no one could think a human is drawing), write down your reasoning and keep it. Relying on the exception without a documented basis is one of the failure patterns regulators and plaintiffs look for.

Exact wording: compliant vs non-compliant chatbot disclosure

Article 50 doesn't hand you a script, but it sets a standard: the disclosure must be clear, distinguishable, and given at the latest at the first interaction. Here's wording that meets it — adapt the bracketed parts to your site.

Chatbot first-message disclosure

"Hi — I'm an AI assistant (not a human) here to help with [company] questions. I can connect you to a person any time."

Pre-chat notice on the launcher

"You're about to chat with an AI assistant. Your messages will be processed by an AI service to answer you."

Short label on the chat widget itself

"AI-powered support" — shown on the widget button, before it's opened.

What separates a compliant disclosure from a decorative one comes down to a few specifics regulators point to:

Do: explicitly say "AI" or "bot," and make clear it's not a human. Show it at (or before) the first message. Keep it visible and distinguishable, not greyed-out. Serve it in the visitor's language.
Don't: use vague labels like "virtual assistant" or "smart helper" that don't unambiguously convey non-human status, and don't give the bot a human name and avatar with no AI notice.

What fails Article 50(1)

This is the list to check your own site against — and the section most likely to win a featured snippet, because few competitors state it plainly. Each of these is a real-world way sites think they've disclosed but haven't:

  • Disclosure buried in Terms & Conditions or the privacy policy. Article 50(1) requires the notice at the interaction, not in a document three clicks away.
  • A bot name alone ("Emma," "Alex") — worse when paired with a human avatar, which actively implies a person.
  • A faint, tiny, or briefly flashing "Powered by AI" footer no one reads.
  • English-only notice for a multilingual EU audience. The disclosure should appear in the languages you serve.
  • Relying on the "obvious" exception for a natural-language helpdesk bot — the guidelines' own example of not obvious.
  • Disclosing after the fact — a notice the visitor only sees once the conversation is underway is too late.

First-interaction timing — what "at the latest at the first interaction" means

The timing rule is stricter than most sites realize. "At the latest at the time of the first interaction" means the visitor must know it's AI before or at the very start — before they type their first message, not after they've had a short exchange. In practice that means the disclosure lives on the chat launcher or in the opening message, not in a notice that appears mid-conversation.

How the consent banner helps here. Because your consent banner appears on first page load — before any chat interaction — surfacing the AI notice there (or in the banner's details panel) reaches EU visitors ahead of the interaction, which is exactly what the timing standard asks for. That's the approach ConsentPixel takes; the how-to lives on the EU AI Act feature page.

The disclosure in every language you serve

An Article 50(1) disclosure has to be understandable to the person reading it, which for an EU audience means it can't be English-only. If your site serves visitors in French, German, Spanish, Italian and so on, the "you're talking to an AI" notice needs to appear in those languages too. This is a small detail that competitors routinely omit — and a common reason an otherwise-fine disclosure fails for part of your audience.

Provider vs deployer: who owes the chatbot disclosure?

Here's the point that catches site owners off guard: the disclosure duty for a chatbot falls on you as the deployer — even if you didn't build the bot. If you add a third-party AI chat tool (Intercom Fin, Tidio, Drift, Crisp, Zendesk AI and the like) to your site, you're the deployer, and making sure the "this is AI" notice actually shows on your site is your responsibility, not the vendor's. "The chatbot company handles compliance" is not a safe assumption. (The broad provider-vs-deployer split across all obligations is covered in the pillar guide; here it matters specifically because the interaction disclosure is a deployer duty.)

The other three obligations (briefly) — and where to read them

This page is about 50(1). For completeness: Article 50(2) covers machine-readable marking of AI-generated content (largely the AI vendor's job, with a grace period to 2 December 2026 for pre-existing systems); 50(3) covers emotion-recognition and biometric disclosure; and 50(4) covers deepfake and AI public-interest labelling. If any of those might apply to you, the full treatment — with the timeline and fines — is in the complete EU AI Act website guide. The one that watermarking headlines scare people about, 50(2), is usually the AI tool-maker's responsibility, not yours as an ordinary website.

The moat: disclosure is not consent — the CIPA overlap

Here's the angle no EU-focused competitor covers, and it matters enormously for any site with US visitors. Telling people your chatbot is AI satisfies Article 50 — but it does nothing about what the chatbot does with the conversation. An AI chat widget typically sends what a visitor types to a third-party vendor, and under California's Invasion of Privacy Act (CIPA), intercepting and transmitting a visitor's communication before consent can be an unlawful wiretap, with statutory damages of $5,000 per violation under Cal. Penal Code §637.2.

So a US-facing chatbot has two obligations that a disclosure only half-solves: disclose it's AI (Article 50) and don't intercept the conversation before consent (CIPA). We unpack that overlap — and how the same prevention-first setup handles both — in AI chatbots and privacy law: what CIPA, GDPR and the AI Act all require. This is information, not legal advice.

Start by seeing what your site actually does

Article 50 turns on what's running on your site. Scan your site to see the trackers and third-party tools firing on your pages — the visibility that makes disclosure decisions concrete rather than guesswork. About 10 seconds, no account.

Scan your site free →

Frequently asked questions

Do I need to disclose my AI chatbot under the EU AI Act?

If EU visitors interact with it, yes — Article 50(1) requires you to tell them they're dealing with an AI, clearly and at the latest at the first interaction, from 2 August 2026. The duty falls on you as the deployer even if a third party built the bot. The only exception is where it's genuinely obvious it's AI, which a natural-language support bot generally is not. This is general information, not legal advice.

What wording counts as a compliant AI chatbot disclosure?

A clear, plain-language notice that explicitly says it's AI and not a human, shown at or before the first message — for example, "Hi, I'm an AI assistant (not a human) here to help." Vague labels like "virtual assistant," a human name and avatar with no AI notice, or a disclosure buried in your terms do not meet the standard. Serve it in the languages your EU audience uses.

Is my customer-support bot covered by the "obvious" exception?

Almost certainly not. The European Commission's guidance uses a support chatbot as an example of something that is not obvious, because a fluent conversational bot can read as human. If a visitor could reasonably think they might be talking to a person, disclose. Only clearly non-human, obviously-AI tools qualify — and even then, document your reasoning.

Does a US company need Article 50 for its chatbot?

If people in the EU can use the chatbot, yes — the AI Act follows the user, not your headquarters, so a US, UK or Australian company with EU visitors is in scope. Separately, a US-facing chatbot also raises a CIPA question about intercepting conversations before consent, which is a different obligation a disclosure doesn't solve.

Is a "Powered by AI" footer enough to comply?

Usually not. A faint or easily-missed footer doesn't meet the "clear and distinguishable" standard, and if it isn't seen at the first interaction it fails the timing rule too. The disclosure needs to be visible where and when the visitor engages the AI — on the launcher or in the opening message.

What's the fine for not disclosing an AI chatbot?

Article 50 violations sit in the penalty tier of up to €15 million or 3% of worldwide annual turnover, whichever is higher (for SMEs, whichever is lower), under Article 99(4). National market surveillance authorities have enforcement power from 2 August 2026, and transparency breaches are among the easiest for regulators to check — they can simply use your site. This is general information, not legal advice.

Information, not legal advice. These sections explain Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689) for general educational purposes and do not constitute legal advice. How the obligation applies depends on your specific AI use and audience; the $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. Consult qualified counsel for your situation.

The bottom line

Article 50 of the EU AI Act sounds bigger than it usually is for an ordinary website. It has four obligations, but for most business sites only one is in play: if visitors interact with AI on your site, tell them — clearly, at the moment of interaction, not buried in your terms. That's 50(1), it's been enforceable since 2 August 2026, and it behaves like a consent-layer task.

The obligations that generate the scariest headlines — watermarking AI content — mostly aren't yours; they fall on the companies that build generative-AI tools, not on you for using them. Keeping "disclose AI interactions" (your job) separate from "watermark AI content" (the vendor's job) resolves most of the confusion.

So the practical path is short: work out whether visitors interact with AI on your site, and if they do, make sure the disclosure appears clearly and on time. Do that, and you've handled the part of Article 50 that actually applies to you.

Handle the disclosure the right way

ConsentPixel surfaces the Article 50(1) AI-interaction disclosure inside your consent banner — shown to EU visitors, at first interaction, with wording you configure. See how it fits alongside your tracker consent, from one pixel.

Scan your site free →
No account needed for the scan · then a 14-day free trial, no credit card required
CP

The ConsentPixel Team

Privacy & Consent Compliance

ConsentPixel — Privacy · Verified is a consent platform delivered as a single JavaScript pixel: it blocks third-party trackers until affirmative consent, surfaces the EU AI Act Article 50(1) AI-interaction disclosure in the banner, honors opt-out signals, and logs each decision as immutable evidence. This article is educational and not legal advice.

Information, not legal advice. This article summarizes Article 50 of the EU AI Act (Regulation (EU) 2024/1689) for general educational purposes and does not constitute legal advice or create an attorney–client relationship. Obligations depend on your role (provider vs deployer), your specific AI use, and your visitors, and the surrounding guidance continues to develop. Dates and thresholds reflect publicly reported information as of September 2026; verify current requirements and consult qualified counsel for your situation. ConsentPixel — Privacy · Verified is not a law firm, and no single tool by itself makes a website compliant with any law.

Scroll to Top