Article50.io
Question · Art. 50(1)

Do I Need Article 50 Compliance If I Only Use a Chatbot?

· Updated · 9 min read

Yes, in most cases. Article 50(1) of the EU AI Act applies to any AI system intended to interact directly with people, whatever its risk classification, so an ordinary AI customer-support chatbot is covered. The legal duty sits with the chatbot's provider (Art. 3(3)), but if the bot runs on your website, you are the one who controls whether visitors actually see the disclosure.

Why "only a chatbot" still counts

People often assume the AI Act only matters for high-risk AI, such as systems used in hiring, credit scoring or medical devices. That is a misreading of how the Act is built. It sets up several separate layers of rules:

  • Prohibited practices (Art. 5): uses that are banned outright.
  • High-risk systems (Chapter III): heavy requirements for risk management, documentation and human oversight.
  • Transparency obligations (Art. 50): lighter duties that depend on what the system does, not on how risky it is.

A chatbot does not need to be high-risk for Article 50 to apply. The test in Article 50(1) is functional: is the AI system intended to interact directly with natural persons? An AI support agent answering questions in a chat bubble clearly is.

The layers can also stack. Article 50(6) says paragraphs 1 to 4 "shall not affect the requirements and obligations set out in Chapter III", and "shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems". In practice, a high-risk system that also chats with people has to meet both sets of rules, and a chatbot that is not high-risk still has to meet Article 50. For how transparency duties relate to the rest of the Act, see transparency obligations under Article 50.

Article 50 has applied since 2 August 2026. Breaches fall under Article 99(4): fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. For SMEs and start-ups the lower of the two applies (Art. 99(6)), and Art. 99(6a) extends that lower cap to small mid-caps. See what happens if you ignore Article 50.

Provider or deployer: who owns the chatbot duty?

Article 50(1) is written for providers. Providers must make sure AI systems that interact directly with people are "designed and developed" so that those people are told they are interacting with an AI system. So the key question is: who is the provider of the chatbot on your site?

Definition: Under the EU AI Act, the provider is whoever develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark (Art. 3(3)). The deployer is whoever uses an AI system under its authority (Art. 3(4)). Article 50(1), the chatbot disclosure duty, is a provider obligation.

How this works out depends on how you got your chatbot. There are three common setups.

1. You embed a vendor's AI agent (Intercom Fin, Zendesk AI and similar)

The vendor builds the AI system and places it on the market under its own name, so the vendor is most likely the provider. You use it under your authority on your site, which makes you a deployer.

On paper, the Article 50(1) duty is the vendor's. In practice, you control the page. You choose the bot's name, avatar, greeting and colours, and whether a vendor's built-in disclosure setting is turned on. If the widget goes live on your site as "Sarah from Support" with no mention of AI, visitors see an undisclosed AI on your site. Regulators, customers and journalists will see your brand, not the vendor's. The practical fix costs almost nothing: make sure a disclosure is visible in the chat window yourself, rather than relying on the vendor's defaults.

Rebranding is a grey area. Article 25(1) says that a deployer who puts its own name or trademark on a high-risk AI system already on the market is treated as its provider. That rule is written for high-risk systems. Whether heavy white-labelling of an ordinary chatbot shifts the Article 50(1) role in the same way is not settled. This is one more reason not to rely on the vendor alone.

2. An agency builds a custom bot for you

Article 3(3) covers anyone who "has an AI system … developed" and puts it into service under its own name. If an agency builds a GPT-based bot and you launch it on your site under your brand, you are likely the provider, not the agency. The Article 50(1) design duty is then most likely yours. Put the disclosure in the build brief and the acceptance checklist. For the agency side of this, see Article 50 for agencies.

3. You build your own bot on an LLM API

This is the case most businesses get wrong. The reasoning goes like this:

  • The company behind the LLM API provides a general-purpose AI model. That is not the same thing as your chatbot.
  • Article 3(68) defines a "downstream provider" as a provider of an AI system that integrates an AI model, "regardless of whether the AI model is provided by themselves … or provided by another entity based on contractual relations". So building on someone else's model does not stop you from being the provider of the system you build.
  • "Putting into service" includes supplying an AI system "for own use in the Union for its intended purpose" (Art. 3(11)). A bot you build and run on your own website counts, even though you never sell it.

Put together, a business that builds a chatbot on an LLM API and runs it under its own name is very likely the provider of that chatbot. The Article 50(1) duty is then directly yours. See also Article 50 for AI startups.

The "obvious from context" exception is narrow

Article 50(1) does not require a disclosure where it is obvious "from the point of view of a natural person who is reasonably well-informed, observant and circumspect", taking into account the circumstances and context of use, that the person is dealing with an AI.

Do not build your compliance on this exception. Most website chat widgets are designed to feel human: a first name, a friendly photo or avatar, typing indicators, and a seamless handover to a human agent in the same window. A branded chat bubble called "Sarah" is not obviously an AI. If anything, it suggests the opposite.

When a disclosure is needed, Article 50(5) requires it to be given in a clear and distinguishable manner, at the latest at the time of the first interaction, and in line with applicable accessibility requirements. A line in your terms of service is unlikely to be enough. For placement, see Article 50(1) chatbot disclosure, explained. For wording you can adapt, use the free AI chatbot disclaimer template.

When your chatbot does more than chat

If your AI only answers visitors in a chat window, Article 50(1) is the main rule to think about. Other paragraphs can apply once the same AI produces content that goes beyond the conversation:

  • Publishing AI-written articles or posts. Under Article 50(4), deployers who publish AI-generated or manipulated text to inform the public on matters of public interest must disclose it. This does not apply where the text has gone through human review or editorial control and someone holds editorial responsibility. See does Article 50 apply to AI-generated text?
  • Realistic images, audio or video that count as deep fakes (Art. 3(60)) also trigger Article 50(4). See deepfake disclosure.
  • If you are the provider of a system that generates synthetic text, images, audio or video (setup 3 above), Article 50(2) may also require machine-readable marking of its outputs. For systems already on the market before 2 August 2026, Article 111(4), inserted by the Digital Omnibus (Reg. 2026/1744), gives providers until 2 December 2026 to comply with 50(2).

What to do this week

  • Work out which of the three setups above describes your chatbot, and write down who you think the provider is.
  • Check your chatbot as a visitor would see it before the first message: is there a clear statement that it is an AI?
  • If you use a vendor widget, check whether its AI disclosure setting is actually switched on for your site, and whether your custom name and avatar hide it.
  • Make sure the disclosure stays in place when the bot hands over to a human agent, and back again.
  • Check whether the same AI also publishes content, such as articles or images, that could fall under Article 50(2) or 50(4).

A free Article50.io scan loads one public page of your site and flags a detectable chat widget (for example, Intercom, Drift, Zendesk or Crisp, or custom chat markup) where no AI-disclosure wording appears on the page or in the widget as it first loads. The scan does not decide whether you are the provider or the deployer, does not judge whether "obvious from context" applies, and cannot see anything behind a login. A clean scan does not mean you are compliant. It is a quick first check, not a verdict.

Frequently asked questions

Does Article 50 apply to a chatbot that is not high-risk?

Yes. Article 50(1) applies to AI systems intended to interact directly with people, regardless of whether they are classified as high-risk. An ordinary AI customer-support chatbot is covered. Article 50(6) confirms that the transparency obligations sit alongside the high-risk rules in Chapter III rather than replacing them, so a system can be subject to both, or only to Article 50.

If I use Intercom Fin or Zendesk AI, is the disclosure the vendor's responsibility?

Formally, Article 50(1) places the duty on the provider, which for an off-the-shelf AI agent is most likely the vendor. But you control how the widget appears on your site, including its name, avatar and settings. If visitors cannot see that they are talking to an AI, the gap is on your website. The safest approach is to make sure a clear disclosure is visible in the chat window yourself.

Am I the provider if I build a chatbot on the OpenAI or Anthropic API?

Very likely, although this is a legal judgement rather than settled law. Under Article 3(3), a provider develops an AI system, or has one developed, and puts it into service under its own name. Article 3(68) confirms that integrating a model supplied by someone else does not stop you being the provider of the resulting AI system. The API company provides the underlying model. You provide the chatbot, and with it the Article 50(1) duty.

Is a chatbot named "Sarah" obviously an AI?

No. The exception in Article 50(1) only applies where a reasonably well-informed, observant and circumspect person would already know they are dealing with an AI. A human name, a friendly avatar and typing indicators point the other way. Unless the context really makes it obvious, give a clear disclosure at the latest at the first interaction. The free AI chatbot disclaimer template is a starting point.

Does a rules-based chatbot need an Article 50 disclosure?

Article 50(1) covers AI systems. A purely scripted decision-tree bot may fall outside it. However, many support widgets now have AI features, and some vendors switch them on by default. Check what your widget actually does before concluding it is not an AI system.

This article is general information, not legal advice.

Check your site automatically

Article50.io is an automated Article 50 transparency assessment platform that scans websites for potential EU AI Act transparency obligations and provides remediation guidance, implementation instructions, and compliance-ready disclosure language.

The free scan shows your single most severe finding in about 30 seconds — no signup, public pages only.

More from the blog

Automated technical guidance, not legal advice. Citations refer to Regulation (EU) 2024/1689.