The short answer
Under Article 50(1) of the EU AI Act, the duty to tell people they are talking to an AI falls on the provider — the company that built the chatbot and put it on the market under its own name — not on the business that deploys it on its website. If you bought your chatbot from a vendor, this is the vendor’s obligation to implement and yours to not undermine. It became applicable on 2 August 2026.
Most of what has been written about the AI Act and chatbots gets the allocation backwards, and the mistake is expensive in both directions: a business that thinks it is responsible spends money on a problem it does not have, and a vendor that thinks it is not responsible ships a non-compliant product to every customer at once.
What Article 50(1) actually says
Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed.
Article 50(5) adds the timing: the information must be given clearly and distinguishably, at the latest at the time of the first interaction. Not in a privacy policy. Not on request. At the first interaction.
Provider or deployer — the definitions decide it
Article 3 is unambiguous, and the two definitions do the work:
- A provider is whoever “develops an AI system … and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.”
- A deployer is whoever is “using an AI system under its authority”.
So if you are a hotel that embedded a vendor’s widget, you are the deployer. The vendor developed the system and placed it on the Union market under its own name, so the vendor is the provider, and 50(1) binds providers. The obligation is theirs.
This has a consequence vendors tend not to advertise: a disclosure a customer can switch off does not discharge the duty. If your assistant lets a business rename it, remove the badge and instruct it to claim to be a human employee, the provider has not ensured that people are informed — it has offered them the option. The verb in 50(1) is “shall ensure”.
What deployers still have to do
Not nothing. Three duties genuinely sit with the business deploying the assistant, and none of them can be discharged by the vendor:
- Article 4, AI literacy. Applicable since 2 February 2025. You must ensure a sufficient level of AI literacy among the staff who operate the system. For a small team this is a training note and a record that it happened, not a programme.
- Article 50(4). If you publish AI-generated text to inform the public on matters of public interest, you disclose that it is AI-generated. This is a deployer duty, and it is the one people confuse with 50(1).
- Not turning the thing into a high-risk system. The point below.
The way a support chatbot becomes a high-risk AI system
A website assistant that answers questions about opening hours and refund policy is not high-risk. The same assistant becomes high-risk the moment someone points it at an Annex III purpose — screening job applicants, assessing creditworthiness, deciding access to education or to essential services, or inferring emotions in a workplace or classroom, which is prohibited outright under Article 5 rather than merely high-risk.
Then conformity assessment, a quality management system, technical documentation, registration and post-market monitoring attach — and they attach to the provider. Which is why any vendor that has read this carefully prohibits those uses in its contract rather than in its FAQ. Ours is in the Acceptable Use Policy, and it is the clause we would terminate an account over.
One control, three jurisdictions
The useful thing about the disclosure duty is how cheaply it generalises. The same implementation satisfies:
- EU AI Act Article 50(1), as above.
- California Business and Professions Code §17941, which makes it unlawful to use a bot to mislead someone about its artificial identity in order to incentivise a sale — and whose safe harbour is simply disclosing that it is a bot.
- Utah’s AI Policy Act, which requires disclosure on request and proactively in regulated occupations.
Build the badge once and three regimes are satisfied. It is genuinely rare for compliance work to compose this neatly, and it is an argument for doing it properly rather than minimally.
Where we are on it
We are the provider, so this is our obligation. Our in-widget disclosure is in build and is not shipped yet — which we say on the AI transparency statement rather than implying otherwise. Writing a post about who is responsible for a duty while quietly not meeting it would be a strange way to make the argument.
If you are evaluating chatbot vendors, it is a fair question to ask them directly: who do you think Article 50(1) binds, and can a customer turn your disclosure off? The answer tells you how carefully they have read the thing that now governs their product.
The short version
- Article 50(1) binds the vendor. It applied from 2 August 2026.
- A disclosure the customer can remove does not discharge it.
- Deployers owe AI literacy, public-interest disclosure, and staying out of Annex III.
- One badge satisfies the EU, California and Utah. Build it once.
This is a reading of the law, not legal advice, and we are not lawyers. The primary sources are linked throughout so you can check us.