Blog
EU AI Act · Customer Support

AI Chatbot Transparency Rules in Customer Support

From 2 August 2026, if your customers are chatting with an AI, they have a right to know it. That is the effect of Article 50 of the EU AI Act (Regulation (EU) 2024/1689) — and it is the one 2026 deadline that did not move. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since July 27, 2026) pushed the Annex III high-risk obligations out to December 2, 2027 — and deliberately left Article 50 on schedule.

So while much of the AI Act conversation has relaxed into 2027 planning, support teams running customer-facing chatbots have an obligation that applies now. The good news: for most teams, compliance is measured in hours, not months. This guide covers what Article 50 actually asks of a support operation, where the gray zones are, and a 5-minute check to confirm you’re covered.

This post is deliberately narrow — chatbot disclosure only. For the full picture of AI across your support operation — triage, prioritization, suggested replies, and when a service desk AI crosses into high-risk territory — see our EU AI Act guide for service desk AI. For the legal text itself, clause by clause, there’s the Article 50 decoder.

See How

What Article 50 Requires from Support Teams

The core rule is short. Article 50(1): AI systems intended to interact directly with people must be designed so that those people are informed they are interacting with an AI system — unless that is obvious to a reasonably well-informed, observant person, taking the circumstances and context of use into account. Article 50(5) adds the how: the information must be given in a clear and distinguishable manner, at the latest at the first interaction, and must meet applicable accessibility requirements.

Translated into a support channel, that means three design patterns — and well-run teams implement all three, because together they cost minutes and close the question for good:

Note the pattern in all three: none of them require new technology. They are copy and configuration changes in the chatbot you already run. What counts as a “chatbot” here is broader than a website widget, though — a voice bot on your phone line, a WhatsApp assistant, or an in-product help agent all interact directly with people. (If you’re unsure where your tools sit on the spectrum, see AI assistants vs. AI agents.)

What’s Exempt — and What’s Gray

“Obvious from the circumstances.” The disclosure is waived where a reasonably well-informed, observant person would already realize they’re talking to AI. In practice this exemption is narrower than it looks: your judgment of “obvious” is made on behalf of every customer you serve, including the least tech-savvy ones. Since the label-plus-first-message pattern is nearly free, relying on the exemption is rarely worth the argument.

Purely internal tools. An AI assistant that only your own agents use — drafting suggestions, knowledge-base search, ticket summarization — sits differently. Your employees know it’s AI because you deployed it and trained them on it, which is about as “obvious from the circumstances” as it gets. Internal tools still belong in your AI inventory and your AI literacy program — but they are not where the customer-disclosure risk lives.

Human-in-the-loop drafting — the honest gray zone. The most common setup in modern support is neither a pure bot nor a pure human: AI drafts the reply, a human agent reviews, edits, and sends it. Who is the customer interacting with? On a plain reading, the human — they decided what got sent — so the Article 50(1) chatbot disclosure isn’t triggered the same way. But be honest with yourself about where the line is. If “review” means an agent bulk-approving suggested replies without reading them, the interaction starts to look like AI talking directly to the customer with a human rubber stamp attached. There is no case law on this yet. The defensible position: keep the human genuinely in the loop, write down your policy on when disclosure is and isn’t shown, and revisit it as guidance emerges. If your support runs on Jira Service Management, our companion post walks through exactly where JSM’s AI features sit under these rules.

Sentiment Analysis: One Extra Disclosure, One Hard Ban

Many support stacks also score customer sentiment or urgency. Two rules sit next to Article 50(1) here. First, Article 50(3): if you deploy an emotion recognition system, the people exposed to it must be informed. The Act’s definition is biometric-based — tone-of-voice analysis on a support call is in scope; plain text sentiment scoring of a ticket generally is not.

Second, the hard line: inferring emotions of employees in the workplace — including your own support agents — from biometric signals is prohibited under Article 5(1)(f), in force since February 2, 2025 and carrying the Act’s highest fine tier. Pointing sentiment analytics at customers to triage tickets is fine; pointing emotion inference at the people answering them is not. The service desk AI decoder and the employment & HR decoder cover the boundary in detail.

Marking Synthetic Content — Article 50(2)

Separate from the conversation-level disclosure, Article 50(2) requires providers of generative AI systems to mark synthetic output — audio, image, video, or text — as artificially generated in a machine-readable way. This is a provider obligation: it lands on whoever builds and supplies the generative system, which for most support teams means their chatbot vendor.

The Digital Omnibus touched this one clause, and only narrowly: generative AI systems already on the market before August 2, 2026 get a grace period until December 2, 2026 to implement the machine-readable marking. Systems placed on the market on or after August 2, 2026 must mark their output from day one — there is no grace period for new systems.

As a deployer, your action item is a single email: ask your chatbot vendor where they stand on Article 50(2) marking, and whether they’re relying on the grace period. If they are, ask for their December date. File the answer — it’s compliance evidence.

Penalties and Who Enforces Them

Enforcement sits with national market surveillance authorities — each member state designates its own, so the practical enforcement posture will vary by country, especially in the early months.

On fines, keep the tiers straight. The Act’s headline numbers — up to €35 million or 7% of global turnover — apply to the Article 5 prohibited practices, which have been in force since February 2, 2025. Transparency obligations sit in the lower band: under Article 99(4), non-compliance is punishable by fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. Realistically, a missing chatbot label is unlikely to draw a maximum fine on day three — but it is the single most visible compliance gap you can have. Every customer, competitor, and journalist who opens your chat widget can see it, and complaints to a surveillance authority are free to file.

The 5-Minute Compliance Check

Run this today. Most items are a yes/no you can answer from your own website.

  1. List every customer-facing conversational AI. Web chat widget, help-center bot, WhatsApp or social messaging bots, AI voice bots on the phone line — including pilots and anything a team launched as a “beta.”
  2. Open each one and check the first screen. Is there a visible AI label in the header and a first-message disclosure? If not, that’s a copy change you can ship this week.
  3. Trigger a human handover. Does the wording clearly mark the transition to a human agent — and back, if the AI resumes?
  4. Email your chatbot vendor about Article 50(2) marking. On the market before August 2, 2026 → grace until December 2, 2026. Launched later → marking from day one. Get their answer in writing.
  5. Check accessibility. Article 50(5) requires the disclosure to be clear, distinguishable, and accessible — can a screen-reader user perceive it?
  6. Record each chatbot in your AI inventory. System, owner, vendor, disclosure status, marking status, next review date. This is the item that makes the other five auditable — a disclosure you can’t evidence is a disclosure you’ll re-verify from scratch at every audit.
Try Free

Frequently Asked Questions (FAQ)

Our chatbot is obviously a bot — do we still need a disclosure?

Article 50(1) waives the disclosure only where it’s obvious to a reasonably well-informed, observant person, taking the circumstances and context into account. A robot avatar or a name like “SupportBot” may qualify — or may not, depending on who your customers are. A persistent label plus a first-message disclosure costs nothing and removes the argument entirely, which is why most support teams add both rather than rely on the exemption.

Do AI-drafted replies sent by human agents fall under Article 50?

When a human agent genuinely reviews, edits, and sends an AI-drafted reply, the customer is interacting with the human — the Article 50(1) chatbot disclosure isn’t triggered in the same way. It’s a gray zone, though: if the review is a rubber stamp or replies go out automatically, the interaction looks much more like AI talking directly to the customer. Document where your line is and keep the human genuinely in the loop.

Didn’t the Digital Omnibus delay this?

No. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026 and in force since July 27, 2026 — moved the Annex III high-risk deadline to December 2, 2027 but left Article 50 on schedule: it applies from August 2, 2026. The only concession is the Article 50(2) marking grace period to December 2, 2026, and only for generative AI systems already on the market before August 2, 2026. Full breakdown of what the Omnibus changed →

Model Inventory for Jira gives you the register that item 6 asks for — every AI system your company runs, including customer-facing chatbots, recorded with owners, risk classification, and an immutable audit trail, inside the Jira you already have. No new vendor, no security review. Learn more →

This article is a practical explanation, not legal advice. Always confirm requirements against the official text of Regulation (EU) 2024/1689 as amended and, where the stakes warrant it, qualified counsel.

Know every chatbot you run

Model Inventory for Jira gives you a compliance-ready AI registry with risk classification, EU AI Act field mapping, and guided onboarding — inside your existing Jira.

Try Free for 30 Days