6 min read ·
The Article 50 Controls Your Startup Chatbot Needs
Map your startup chatbot to EU AI Act Article 50 duties for first-interaction disclosure, synthetic-output marking, evidence and 2026 deadlines.

Since 2 August 2026, a provider of an AI system that directly interacts with people generally must tell them they are interacting with AI. The notice must be clear, distinguishable, accessible and provided no later than the first interaction—not buried in terms of service. A generative chatbot can also trigger a separate duty to make synthetic outputs machine-readable and detectable as AI-generated, so an “AI assistant” banner may not complete the work.
Choose your startup’s workflow and outputs; the checker identifies the Article 50 controls to review.
Article 50 Workflow Check
Change any answer to update the likely controls.
Default shown: a startup offers a generative chatbot under its own name and the AI communicates directly with users.
Source: EU AI Act Article 50 and the European Commission’s non-binding Article 50 guidelines and FAQ.
Determine Your Role Before Designing The Notice
Article 50 assigns obligations by role and workflow, not by company size or ownership of the underlying model.
| Startup Activity | Likely Treatment | Article 50 Issue |
|---|---|---|
| Offers an AI chatbot under its own product name | Provider | Interaction disclosure; output marking if it generates synthetic content |
| Develops and operates an internal chatbot under its own name | Provider | The same provider duties can apply without an external sale |
| Uses an AI system to create deepfakes or publish public-interest text | Deployer | Visible content labelling may apply |
| Gives support staff an AI copilot, with a human reviewing and sending each response | Generally outside the direct-interaction rule | Reassess if AI communicates directly with the customer |
| Runs a conventional rule-based response flow | May fall outside the definition of an AI system | Document the classification rather than relying on the product label |
A company can hold more than one role. The Commission’s non-binding guidelines treat a company offering a chatbot under its own name as a provider. They apply the same treatment to an organisation that develops an in-house chatbot and puts it into service under its name. Modifying an existing system and putting the resulting system into service under your own name can likewise make you a provider of the new system (European Commission guidelines).
Using somebody else’s foundation model therefore does not automatically transfer product-level responsibility to the model vendor. Map the complete system delivered to users, not just the model API beneath it.
The rules can also reach providers outside the EU when their systems are placed on the EU market or their outputs are used in the EU. Incidental, unforeseeable or unauthorised downstream use should not by itself bring an otherwise out-of-scope provider within the rules, but a startup deliberately serving EU users should not treat foreign incorporation as an exemption (European Commission Article 50 FAQ).
Make The AI Interaction Explicit Before It Begins
Article 50(1) applies where an AI system supports a genuine, direct exchange with a natural person. Chatbots, voice assistants and customer-facing AI agents are standard examples. Backend machine-to-machine calls are excluded.
Mediated communication can also fall outside this rule when a support employee properly reviews the AI output and sends it as the human interlocutor. Merely allowing possible human intervention does not remove a direct AI interaction from scope (European Commission guidelines).
For a typical text chatbot, use plain copy such as:
You are interacting with an AI assistant. Its answers may be inaccurate; contact our team for human support.
The first sentence addresses the Article 50 disclosure. The second gives useful product-risk context, but it does not replace the first.
Place the statement in the opening message or prominently next to the chat input before the interaction begins. The Commission guidelines recommend plain-language banners or labels, first-turn greetings and, where proportionate, persistent badges. Voice systems should make a spoken disclosure at the beginning.
A generic label such as “assistant,” a notice available only in documentation, or “this service uses LLMs” on a site with several features is insufficient by itself. The notice needs to identify the experience in which the person is interacting with AI.
A single prominent notice before the first interaction is likely to suffice in most cases. The guidelines call for periodic or context-aware reminders in riskier settings, including long or sensitive interactions, interactions with vulnerable people, and situations in which users may become confused about whether they are dealing with a person. Disclosures must also conform to applicable accessibility requirements and account for foreseeable audiences, including children where relevant.
The Act has an exception where the AI interaction is obvious to a reasonably well-informed, observant and circumspect person. The guidelines interpret that exception restrictively and say it should be limited to cases where there is almost no doubt about the artificial nature of the interaction. A product name, robot icon or synthetic avatar is therefore a weak basis for omitting a one-line notice (European Commission guidelines).
Treat Synthetic-Output Marking As A Separate Control
Article 50(2) requires providers of systems generating or manipulating synthetic text, audio, images or video to make outputs both:
- marked in a machine-readable format; and
- detectable as artificially generated or manipulated.
The technical solution must be effective, interoperable, robust and reliable, subject to technical feasibility, implementation costs and the generally acknowledged state of the art. Article 50 contains exceptions for systems performing only assistive standard editing that does not substantially alter the input or its semantics, and for specified law-enforcement uses (European Commission guidelines).
The guidelines also treat some material as outside Article 50(2), including source code, outputs used exclusively for machine-to-machine communication without human exposure, and intermediate outputs confined to closed-loop industrial or production workflows. Where such a workflow produces a final synthetic text, audio, image or video output, the guidelines say that final output must be marked and detectable.
This is not the same as displaying “AI” beside a chat window. Ask the model or infrastructure vendor what metadata, watermark, fingerprint or other marker it supplies, and what detection method is available. Then test the complete product path across streaming, copying, export and downstream formatting.
The guidelines allow a provider to rely on an upstream or third-party marking solution only if it complies. Responsibility still rests with the provider of the AI system. Vendor documentation is evidence to examine, not a substitute for testing the startup’s finished product.
Visible content labels are a further deployer obligation in narrower cases—notably deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest. For public-interest text, the Act provides an exception where the text has undergone human review or editorial control and a person holds editorial responsibility. An ordinary private chatbot response is not automatically a public-interest publication.
Keep Five Compliance Artifacts With The Release
Before release, create five artifacts tied to the product version:
- Role memo: Explain why the company is a provider, deployer, both or neither for each workflow.
- Interaction map: List every web, mobile, voice, email and agent surface where AI may reach a person directly.
- Disclosure specification: Record the exact copy, position, timing, language and accessibility behaviour.
- Output-marking test: Record supported formats, detection methods, vendor dependencies, transformations that remove marks and regression tests.
- Evidence file: Keep screenshots, recordings, product versions, vendor documentation and test results.
Run the disclosure test in a clean browser or new account. A first-time user should not be able to send or receive an AI message without seeing or hearing the notice. Test every supported locale and accessibility mode, not only the default web flow.
For output marking, retain samples from each supported format and route. Test streaming responses, copied text, downloads, API-delivered outputs and any formatting or post-processing layer that could remove the marker. Record both successful detection and known limitations rather than asserting that the control works everywhere.
Apply The Correct 2026 Deadline
There is no legacy grace period for the chatbot interaction disclosure. Article 50 has applied since 2 August 2026.
The limited extension to 2 December 2026 covers only Article 50(2) marking and detection for systems placed on the market before 2 August 2026. It does not postpone the first-interaction notice (European Commission Article 50 FAQ).
Article 50 is only the transparency layer. A chatbot used in hiring, credit, healthcare or another regulated workflow may trigger other AI Act or sector-specific duties. The Commission guidelines are non-binding, and authoritative interpretation ultimately belongs to the Court of Justice of the European Union. Use these controls as the minimum product review, then have counsel assess the system’s complete use case, role allocation and market scope.