EU AI Act Article 50 is live. What must your customer-facing AI agent tell people?
Article 50's transparency duties apply from 2 August 2026. What a customer-facing agent must tell people, what was deferred, and a disclosure checklist.

The short answer
From 2 August 2026, a customer-facing AI agent used in the EU must tell people they are dealing with AI, unless that is obvious, at the latest when the conversation starts. Deepfakes must be labelled, and AI-written text on matters of public interest must be disclosed unless a person reviewed it under editorial control.
Key takeaways
- Article 50 of the EU AI Act applies from 2 August 2026, and the Digital Omnibus did not defer it apart from a short grace period for machine-readable marking.
- Providers of systems that talk to people must make sure users are told they are interacting with AI, unless it is obvious from the context.
- The disclosure has to be clear and given at the latest at the first interaction, so a line buried in the terms of service is not enough.
- AI-generated text published on matters of public interest is exempt from labelling where it has had human review and someone holds editorial responsibility.
- Our view: disclose in the first message, offer a route to a person, and log both, whatever your legal analysis concludes.
In this article
What became law on 2 August 2026?
The transparency duties in Article 50 of the EU AI Act. Since 2 August 2026, providers of AI systems that interact directly with people must make sure those people are told they are dealing with AI, unless that is obvious from the context.1 For most companies, the system in question is a chatbot or a customer-facing agent on a website, app or messaging channel.
Article 50 has four parts. Paragraph 1 covers systems that interact with people. Paragraph 2 requires providers of generative systems to mark synthetic audio, images, video and text in a machine-readable way. Paragraph 3 covers emotion recognition and biometric categorisation. Paragraph 4 requires deployers to disclose deepfakes and AI-generated text published to inform the public on matters of public interest.2
This post is about the first and fourth parts, because those are the ones a typical support, sales or order-status agent touches. It is not legal advice. Read it as a checklist to take to your counsel, not a substitute for one.
What the Digital Omnibus deferred, and what it did not
Very little of Article 50 was deferred. The Digital Omnibus package, approved by the Council on 29 June 2026, moved the deadline for standalone high-risk systems to December 2027 but left Article 50 on its original timetable, according to a Cloud Security Alliance research note published on 29 July.2 The note describes one narrow exception: a grace period to 2 December 2026 for the machine-readable marking duty in paragraph 2. Sidley's reading of the provisional agreement limits that relief to generative systems already on the market before 2 August 2026.1
So, on the position as of 5 August 2026, the Omnibus delayed other AI Act obligations but not this one: the providers' duty to disclose chatbots and agents applies now. Sidley's June 2026 briefing for clients reaches the same conclusion on timing and recommends mapping the AI use cases that could trigger Article 50 before the date.1
The penalties are material. Breaches of the Article 50 duties can be fined up to €15 million or 3% of worldwide annual turnover, whichever is higher, as the Cloud Security Alliance note sets out.2
Article 50 after the Digital Omnibus
Applies from 2 August 2026
- Telling people they are interacting with AI
- Informing people exposed to emotion recognition
- Labelling deepfakes
- Disclosing AI-written public-interest text without editorial review
Grace period to 2 December 2026
- Machine-readable marking of synthetic content by providers of generative systems
Who has the duty: you or your vendor?
It depends on who the provider is. Paragraph 1 puts the duty on the provider of the AI system, the organisation that develops it or has it developed and puts it into service under its own name.3 If you buy a helpdesk vendor's agent and switch it on, the vendor is likely the provider. If you build an agent on a model API and run it on your site under your brand, you may well be the provider yourself.
The Act also reaches beyond the EU. Under Article 2, it applies to providers and deployers outside the EU where the output of the AI system is used in the EU.3 A company based elsewhere that answers EU customers through an agent should assume the duty applies.
Our view: do not spend long on the provider question for customer-facing agents. Whoever the provider is, the customer sees your brand. Make sure the disclosure is there, and write into the vendor contract who is responsible for it.
What must the agent actually say?
That the person is interacting with an AI system, clearly, and no later than the first interaction. The Cloud Security Alliance note highlights the requirement that the information is given in a clear and distinguishable way at the latest at the first interaction, and that it meets accessibility requirements.2
In practice, that means the first message of every conversation, not a footer link or a clause in the terms. A short sentence is enough: "I'm an AI assistant for Fabrikam. I can check orders and answer product questions, and I can pass you to a person at any time." That example is illustrative; Fabrikam is a fictional company.
The "obvious from the context" exception is narrow in practice. A chat window with a human name and a photo is the opposite of obvious. Our view: if your agent has a persona, the persona needs the disclosure more, not less.
Voice and messaging channels
The same rule applies on a phone line or a messaging app. A voice agent should say it is an AI at the start of the call. On messaging channels, the disclosure goes in the first reply, and channel rules may add their own requirements. Our note on running an order-status agent on WhatsApp covers the platform's terms for business bots.
Disclosure checklist for a customer-facing agent
- First message
State that the customer is talking to an AI, in plain words.
- Route to a person
Say how to reach a person, and make it work.
- Every channel
Web, app, messaging and voice each carry the disclosure.
- Accessible format
Readable by screen readers and in the customer's language.
- Contract
Name who is responsible for disclosure with each vendor.
- Log it
Record that the disclosure was shown in each conversation.
Does AI-written content on your site need a label?
Usually not, if a person reviews it. Paragraph 4 requires deployers to disclose AI-generated or manipulated text published to inform the public on matters of public interest. Disclosure is not required where the content has been subject to human review or editorial control and someone holds editorial responsibility.1
Most marketing pages, product descriptions and help articles are not public-interest publishing in the Act's sense, and most are reviewed by someone anyway. Deepfakes are different: realistic AI-generated images, audio or video of people or events must be labelled, with lighter treatment for work that is clearly artistic, satirical or fictional.1
We disclose anyway. Every Sigzen AI article ends with a line saying it was drafted with AI from sources our editors chose, then fact-checked and edited by people. Our view: readers and buyers increasingly expect to know, and a plain disclosure costs nothing.
What operations teams should do this week
List every place a customer can talk to an AI on your behalf: website chat, in-app help, messaging channels, phone lines and email auto-replies. For each, check the first message, the route to a person and whether the conversation log shows the disclosure.
The route to a person matters beyond compliance. Customers who cannot reach a person stop trusting the agent, and they already use outside AI tools when company chatbots fall short, as our note on Gartner's customer survey describes. Our escalation design for support agents sets out when an agent should hand over and how to test it before launch.
For new builds, put disclosure and escalation into the acceptance criteria from the start. Every agent we build, described on our AI automation page, has a named owner, an exception queue handled by people and logs of what it did.
Sources
- Sidley Austin, EU AI Act transparency obligations: preparing for compliance by 2 August 2026 (Jun 2026)
- Cloud Security Alliance, research note on EU AI Act Article 50 transparency: application date and penalty ceiling (Jul 2026)
- EUR-Lex, Regulation (EU) 2024/1689, the Artificial Intelligence Act (Jul 2024)


