EU AI Act Article 50 for Websites: What Actually Applies
Since 2 August 2026, the EU AI Act's transparency rules have been enforceable — and a lot of website owners have read the headlines about "AI disclosure" and "watermarking" and quietly panicked. Most of that panic is misplaced. Article 50 has four obligations, and for the overwhelming majority of ordinary websites, only one of them applies — and it's straightforward. This is the plain-English guide to which part is actually your job, what "disclosure" has to look like, and, just as importantly, what isn't your responsibility.
Key takeaways
- Article 50 has four obligations, not one. They apply to different situations. Most websites are only touched by the first: disclosing AI interactions.
- If your site has a chatbot, AI search, or an AI assistant, you must tell EU visitors they're interacting with AI — clearly, at the point of interaction, not buried in your terms.
- The disclosure duty is yours even if you didn't build the AI. It falls on the deployer — the business running the tool on its site.
- Content watermarking is a different obligation, and usually not yours. Marking AI-generated media is the AI provider's job, not a consent-layer task.
- It reaches non-EU businesses. If your site serves EU visitors and uses AI they interact with, Article 50 applies regardless of where you're based.
What this guide covers
What Article 50 is
Article 50 is the transparency section of the EU AI Act (Regulation (EU) 2024/1689). While much of the AI Act deals with "high-risk" AI systems and phases in over several years, Article 50 is about something simpler and more universal: making sure people know when they're dealing with AI. Its obligations became enforceable on 2 August 2026, and violations sit in the penalty tier of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
Here's the reassuring part, and the reason this article exists: Article 50 is often described as if it's a sweeping new compliance burden, but for a normal business website it's usually one clear, doable task. The trick is knowing which of its four obligations applies to you — because most of them don't.
The four obligations, decoded
Article 50 contains four distinct transparency duties. They apply to different actors and different situations. Read them as a filter — most sites stop at the first row.
| Article 50 obligation | Applies when… | Whose job | Most sites? |
|---|---|---|---|
| 50(1) — AI interaction disclosure | Your site has AI that visitors interact with (chatbot, AI search, AI assistant) | The deployer (you) | ✅ Usually yes |
| 50(2) — AI content marking | You provide a generative-AI system that produces synthetic media/text | The AI provider | ✗ Rarely |
| 50(3) — Emotion / biometric disclosure | You run emotion-recognition or biometric-categorization AI | The deployer | ✗ Niche |
| 50(4) — Deepfake / public-interest labeling | You publish AI-generated deepfakes or AI text on matters of public interest | The deployer | ✗ Media mostly |
The pattern is clear once you see it laid out: 50(1) is the one that touches ordinary websites, and it's the one that behaves like a consent-layer task — surface a disclosure, at the right moment, and (ideally) keep proof you did. The other three are either for AI providers (companies that build generative-AI systems) or for specific niches like media publishing and biometric systems.
Which one applies to your site
Run yourself through this quickly:
For the large majority of business websites — e-commerce, SaaS, services, healthcare, professional sites — the honest answer is: only 50(1), and only if you run an AI feature visitors interact with. If you don't run any such feature, Article 50 may not require anything of you at all right now (though that can change the moment you add a chatbot).
What counts as "AI you interact with"
Since 50(1) is the obligation that matters for most sites, it's worth being concrete about what triggers it. The duty applies when a visitor directly interacts with an AI system. In website terms, that typically means:
- AI chatbots and assistants — the support widget that answers in natural language, an AI concierge, an AI-powered help agent.
- AI-powered live chat — where an AI handles or drafts responses, whether or not a human is also involved.
- AI search — a search box that uses AI to interpret queries and generate answers rather than just matching keywords.
- AI recommendations a visitor engages with — interactive recommendation features that respond to what the visitor does.
The unifying test is interaction: the visitor is communicating with, or actively engaging, an AI system. There's a sensible exception written into the law — disclosure isn't required where it would be obvious from the context that the person is dealing with AI. But "obvious" is a high bar and a risky thing to assume; a modern chatbot can feel human enough that visitors genuinely don't know, which is exactly the situation the rule exists for.
What the disclosure must look like
The law doesn't hand you exact wording, but it does set a standard. The disclosure must be clear, distinguishable, and provided at the latest at the time of the first interaction. Unpacking that into practical requirements:
The "not buried in the terms" point is the one sites get wrong most often. It mirrors a principle that runs through privacy law generally: a disclosure a visitor has to go hunting for isn't really a disclosure. (We make the same argument in a different context in your privacy policy is not a consent banner — a policy tucked in the footer can't do a job that has to happen at the moment of interaction.)
What isn't your job — the watermarking line
This is the part that saves most site owners the most worry, so it's worth stating plainly. Article 50(2) — the content-marking / watermarking obligation — is the one behind scary headlines about "labeling all AI content." For an ordinary website, it is almost certainly not your obligation.
Here's why. 50(2) requires that synthetic content (AI-generated images, audio, video, text) be marked in a machine-readable format so it can be detected as artificial. But that duty falls on the provider of the generative-AI system — the company that built the model — not on you for using it. If you generate a blog image with an AI tool, marking that output is the tool-maker's engineering problem, embedded in how the tool works. It's a product and editorial matter, not a consent-layer or website-owner task.
So the clean mental model is: disclosing that a visitor is interacting with AI is your job (50(1)); watermarking AI-generated content is the AI vendor's job (50(2)). Keeping those two separate is most of what it takes to not over-worry about Article 50.
Non-EU sites and the GDPR overlap
Two final things that surprise people.
Article 50 reaches beyond the EU. The AI Act applies to providers placing AI systems on the EU market and to deployers whose AI outputs are used in the EU — regardless of where the business is established. A US, UK, or Australian company whose website is used by EU visitors and runs an AI feature those visitors interact with falls within scope. You can't escape it purely by being based elsewhere, the same way CIPA reaches sites outside California when Californians visit.
Article 50 sits on top of the GDPR, it doesn't replace it. When your AI processes personal data, the GDPR's usual requirements still apply — a lawful basis for the processing, and its transparency rules (Articles 12–14). So an AI chatbot that collects personal data can trigger both an Article 50 disclosure duty (tell them it's AI) and a GDPR consent-or-lawful-basis question (may we process this data). They're two duties at one moment, which is exactly the kind of thing AI-aware consent is meant to handle in one place.
What counts as "interacting with AI"?
Article 50(1) applies when a person interacts directly with an AI system. That sounds broad, but it has an edge, and knowing which side of it your feature sits on is the whole question. In website terms, the disclosure duty is triggered by:
- AI chatbots and virtual assistants — the support widget that answers in natural language, an AI concierge, an AI help agent.
- AI-powered live chat — where AI handles or drafts the replies, whether or not a human is also in the loop.
- AI voice agents — a phone or on-site voice assistant driven by AI.
- AI search and assistants that respond conversationally — a search box that interprets a question and generates an answer, rather than matching keywords.
The unifying test is interaction: the visitor is communicating with the AI, and could reasonably be unsure whether they're dealing with a person or a machine. Passive AI the visitor never engages — a fraud model scoring a transaction in the background, say — is a different question (and usually a GDPR one), not an Article 50(1) chatbot disclosure. (For the broad four-obligation map, see the pillar guide.)
The "obvious" exception — and why your helpdesk bot doesn't qualify
Article 50(1) has one carve-out: you don't need to disclose when it's already obvious, to a reasonably well-informed and observant person, that they're dealing with AI. Site owners lean on this far too heavily, so be precise about how narrow it is.
The European Commission's own guidance uses a customer-support chatbot as an example of something that is not obvious — precisely because a modern conversational bot can read as human. So a helpdesk assistant, a support widget, or any bot that talks in fluent natural language almost never qualifies for the exception. The safe rule of thumb: if a visitor could reasonably think they might be talking to a person, the exception doesn't apply — tell them it's AI.
Exact wording: compliant vs non-compliant chatbot disclosure
Article 50 doesn't hand you a script, but it sets a standard: the disclosure must be clear, distinguishable, and given at the latest at the first interaction. Here's wording that meets it — adapt the bracketed parts to your site.
"Hi — I'm an AI assistant (not a human) here to help with [company] questions. I can connect you to a person any time."
"You're about to chat with an AI assistant. Your messages will be processed by an AI service to answer you."
"AI-powered support" — shown on the widget button, before it's opened.
What separates a compliant disclosure from a decorative one comes down to a few specifics regulators point to:
What fails Article 50(1)
This is the list to check your own site against — and the section most likely to win a featured snippet, because few competitors state it plainly. Each of these is a real-world way sites think they've disclosed but haven't:
- Disclosure buried in Terms & Conditions or the privacy policy. Article 50(1) requires the notice at the interaction, not in a document three clicks away.
- A bot name alone ("Emma," "Alex") — worse when paired with a human avatar, which actively implies a person.
- A faint, tiny, or briefly flashing "Powered by AI" footer no one reads.
- English-only notice for a multilingual EU audience. The disclosure should appear in the languages you serve.
- Relying on the "obvious" exception for a natural-language helpdesk bot — the guidelines' own example of not obvious.
- Disclosing after the fact — a notice the visitor only sees once the conversation is underway is too late.
First-interaction timing — what "at the latest at the first interaction" means
The timing rule is stricter than most sites realize. "At the latest at the time of the first interaction" means the visitor must know it's AI before or at the very start — before they type their first message, not after they've had a short exchange. In practice that means the disclosure lives on the chat launcher or in the opening message, not in a notice that appears mid-conversation.
The disclosure in every language you serve
An Article 50(1) disclosure has to be understandable to the person reading it, which for an EU audience means it can't be English-only. If your site serves visitors in French, German, Spanish, Italian and so on, the "you're talking to an AI" notice needs to appear in those languages too. This is a small detail that competitors routinely omit — and a common reason an otherwise-fine disclosure fails for part of your audience.
Provider vs deployer: who owes the chatbot disclosure?
Here's the point that catches site owners off guard: the disclosure duty for a chatbot falls on you as the deployer — even if you didn't build the bot. If you add a third-party AI chat tool (Intercom Fin, Tidio, Drift, Crisp, Zendesk AI and the like) to your site, you're the deployer, and making sure the "this is AI" notice actually shows on your site is your responsibility, not the vendor's. "The chatbot company handles compliance" is not a safe assumption. (The broad provider-vs-deployer split across all obligations is covered in the pillar guide; here it matters specifically because the interaction disclosure is a deployer duty.)
The other three obligations (briefly) — and where to read them
This page is about 50(1). For completeness: Article 50(2) covers machine-readable marking of AI-generated content (largely the AI vendor's job, with a grace period to 2 December 2026 for pre-existing systems); 50(3) covers emotion-recognition and biometric disclosure; and 50(4) covers deepfake and AI public-interest labelling. If any of those might apply to you, the full treatment — with the timeline and fines — is in the complete EU AI Act website guide. The one that watermarking headlines scare people about, 50(2), is usually the AI tool-maker's responsibility, not yours as an ordinary website.
The moat: disclosure is not consent — the CIPA overlap
Here's the angle no EU-focused competitor covers, and it matters enormously for any site with US visitors. Telling people your chatbot is AI satisfies Article 50 — but it does nothing about what the chatbot does with the conversation. An AI chat widget typically sends what a visitor types to a third-party vendor, and under California's Invasion of Privacy Act (CIPA), intercepting and transmitting a visitor's communication before consent can be an unlawful wiretap, with statutory damages of $5,000 per violation under Cal. Penal Code §637.2.
So a US-facing chatbot has two obligations that a disclosure only half-solves: disclose it's AI (Article 50) and don't intercept the conversation before consent (CIPA). We unpack that overlap — and how the same prevention-first setup handles both — in AI chatbots and privacy law: what CIPA, GDPR and the AI Act all require. This is information, not legal advice.
Start by seeing what your site actually does
Article 50 turns on what's running on your site. Scan your site to see the trackers and third-party tools firing on your pages — the visibility that makes disclosure decisions concrete rather than guesswork. About 10 seconds, no account.
Scan your site free →Frequently asked questions
Do I need to disclose my AI chatbot under the EU AI Act?
If EU visitors interact with it, yes — Article 50(1) requires you to tell them they're dealing with an AI, clearly and at the latest at the first interaction, from 2 August 2026. The duty falls on you as the deployer even if a third party built the bot. The only exception is where it's genuinely obvious it's AI, which a natural-language support bot generally is not. This is general information, not legal advice.
What wording counts as a compliant AI chatbot disclosure?
A clear, plain-language notice that explicitly says it's AI and not a human, shown at or before the first message — for example, "Hi, I'm an AI assistant (not a human) here to help." Vague labels like "virtual assistant," a human name and avatar with no AI notice, or a disclosure buried in your terms do not meet the standard. Serve it in the languages your EU audience uses.
Is my customer-support bot covered by the "obvious" exception?
Almost certainly not. The European Commission's guidance uses a support chatbot as an example of something that is not obvious, because a fluent conversational bot can read as human. If a visitor could reasonably think they might be talking to a person, disclose. Only clearly non-human, obviously-AI tools qualify — and even then, document your reasoning.
Does a US company need Article 50 for its chatbot?
If people in the EU can use the chatbot, yes — the AI Act follows the user, not your headquarters, so a US, UK or Australian company with EU visitors is in scope. Separately, a US-facing chatbot also raises a CIPA question about intercepting conversations before consent, which is a different obligation a disclosure doesn't solve.
Is a "Powered by AI" footer enough to comply?
Usually not. A faint or easily-missed footer doesn't meet the "clear and distinguishable" standard, and if it isn't seen at the first interaction it fails the timing rule too. The disclosure needs to be visible where and when the visitor engages the AI — on the launcher or in the opening message.
What's the fine for not disclosing an AI chatbot?
Article 50 violations sit in the penalty tier of up to €15 million or 3% of worldwide annual turnover, whichever is higher (for SMEs, whichever is lower), under Article 99(4). National market surveillance authorities have enforcement power from 2 August 2026, and transparency breaches are among the easiest for regulators to check — they can simply use your site. This is general information, not legal advice.
Information, not legal advice. These sections explain Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689) for general educational purposes and do not constitute legal advice. How the obligation applies depends on your specific AI use and audience; the $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. Consult qualified counsel for your situation.
The bottom line
Article 50 of the EU AI Act sounds bigger than it usually is for an ordinary website. It has four obligations, but for most business sites only one is in play: if visitors interact with AI on your site, tell them — clearly, at the moment of interaction, not buried in your terms. That's 50(1), it's been enforceable since 2 August 2026, and it behaves like a consent-layer task.
The obligations that generate the scariest headlines — watermarking AI content — mostly aren't yours; they fall on the companies that build generative-AI tools, not on you for using them. Keeping "disclose AI interactions" (your job) separate from "watermark AI content" (the vendor's job) resolves most of the confusion.
So the practical path is short: work out whether visitors interact with AI on your site, and if they do, make sure the disclosure appears clearly and on time. Do that, and you've handled the part of Article 50 that actually applies to you.
Handle the disclosure the right way
ConsentPixel surfaces the Article 50(1) AI-interaction disclosure inside your consent banner — shown to EU visitors, at first interaction, with wording you configure. See how it fits alongside your tracker consent, from one pixel.
Scan your site free →Information, not legal advice. This article summarizes Article 50 of the EU AI Act (Regulation (EU) 2024/1689) for general educational purposes and does not constitute legal advice or create an attorney–client relationship. Obligations depend on your role (provider vs deployer), your specific AI use, and your visitors, and the surrounding guidance continues to develop. Dates and thresholds reflect publicly reported information as of September 2026; verify current requirements and consult qualified counsel for your situation. ConsentPixel — Privacy · Verified is not a law firm, and no single tool by itself makes a website compliant with any law.