Skip to content

Regulation

Article 50 is live: a 10-point AI disclosure checklist

AI disclosure requirements under Article 50 of the EU AI Act have applied since August 2, 2026: people must be told when they are dealing with an AI system, and some AI content must be labeled. If your chat, voice or email agents reach people in the EU, this checklist covers the points we check before an agent goes live.

By the KDS security engineering teamPublished 5 min read

Key takeaways

  • Article 50 has applied since August 2, 2026 to AI agents that talk to people, including agents launched before that date.
  • Tell people they are dealing with AI at the start of each conversation, in the same channel and in plain words.
  • A notice only in your terms, a footer link or hidden metadata is not enough under the Commission's guidelines.
  • California, Utah and South Korea also have AI disclosure rules, each with a different trigger.
On this page

What Article 50 asks of AI agents

Article 50 of the AI Act (opens in a new tab) requires providers to design AI systems that interact with people so those people are informed they are dealing with AI, unless it is obvious from the context. The notice must be clear, distinguishable and accessible, and it must come at the latest at the first interaction. If you build or commission an agent and run it under your own name, the Commission's guidelines (opens in a new tab) usually treat you as its provider.

Deployers have separate duties for deepfakes, AI-generated text on matters of public interest and emotion recognition. Our Article 50 guide explains every paragraph, the exceptions and the dates. The checklist below focuses on the agents most companies run: chat, voice and email.

The 10-point AI disclosure checklist

  1. List every agent that talks to people. Include website chat, phone agents, email or messaging agents and any agent that calls or writes to third parties during a task. Rule-based auto-replies that use no AI are outside Article 50(1).
  2. Decide who the provider is. If you built or commissioned the agent and run it under your name, plan as the provider. If a vendor supplies a ready-made agent, ask in writing how its design meets Article 50.
  3. Disclose in the first turn. The first chat message or the first sentence of a call should say the assistant is AI, before it asks for any details.
  4. Use the channel people are in. A spoken notice on calls, text in chat and a label at the top of emails. The guidelines say a sound alone, a footer link or the terms of use are not enough.
  5. Say on whose behalf the agent acts. The guidelines expect AI agents that call or write to people to disclose both that they are AI and who they represent.
  6. Keep it visible. Show a persistent "AI assistant" label in chat. Repeat the notice in long calls, after a hold and when the agent's role changes.
  7. Answer the direct question. When someone asks whether they are talking to a person, the agent must say it is AI. Offer a hand-off to your team at the same time.
  8. Remove human disguises. Drop human photos, staff names and scripts that suggest a person is typing or speaking. According to the guidelines, these make the AI nature less obvious.
  9. Make it accessible. Use plain words, the customer's language and labels that screen readers announce. Adapt the wording if children, older people or people with disabilities are likely to use the service.
  10. Log it and test it. Record the disclosure version and when it was given. Test that prompt injection (tricking an AI with hidden instructions) cannot make the agent claim to be human.

Why wording and placement matter

The Commission's guidelines are specific about what fails. A notice hidden in terms and conditions, a manual or behind menus is easy to miss, so it is not clear. A general notice that covers a whole platform is too vague. Machine-readable marks that people cannot see inform nobody in the conversation.

One prominent notice at the start is likely enough in most cases. The guidelines expect reminders in higher-risk contexts, for example financial, insurance, legal or health advice and complaints handling. The same applies when vulnerable people may be involved. The Commission's Article 50 FAQ (opens in a new tab) adds that the obvious-from-context exception should be read narrowly.

AI disclosure requirements outside the EU

Other jurisdictions have their own triggers. Three examples:

  • California. The state's bot disclosure law (opens in a new tab) (Business and Professions Code sections 17940–17943) makes it unlawful to use an automated online account to mislead a person in California about its artificial identity in order to encourage a sale or influence a vote. A clear and conspicuous disclosure avoids liability. It has applied since July 1, 2019.
  • Utah. A business that uses generative AI in a consumer transaction must disclose it when a person clearly asks. People in regulated occupations must disclose it up front in high-risk interactions: verbally at the start of a spoken exchange and in writing before a written one (Utah Code 13-77-103 (opens in a new tab)).
  • South Korea. The AI Basic Act has been in force since January 22, 2026. Businesses offering high-impact or generative AI must notify users in advance that AI is used, according to the U.S. International Trade Administration (opens in a new tab), which also reports a one-year grace period during which fines are generally deferred.

A clear notice at the start of every conversation is the simplest way to cover these different triggers with one design. Local details still differ, so check each market you serve.

Dates and fines to keep in mind

The Digital Omnibus on AI (opens in a new tab) did not move the Article 50 start date. It gave providers of generative AI systems placed on the market before August 2, 2026 until December 2, 2026 to add machine-readable marking to outputs. The disclosure duty for agents that talk to people received no extra time. Our post on what still applies after the Digital Omnibus lists the other changes, and our EU AI Act guide covers the full regulation.

Breaches of Article 50 can bring fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs (small and medium-sized enterprises), the lower of the two amounts is the cap.

How we apply this checklist

Every agent we build says it is an AI at the start of the interaction, and a person can take over at any time. Before launch, our attack testing includes attempts to make the agent deny that it is AI. In our AI receptionist, the disclosure is the first sentence of each call. Our AI transparency statement describes how we apply the same rules to our own work.

Sources

  1. 1.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Articles 50 and 99, EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
  2. 2.Guidelines on transparency obligations for providers and deployers of AI systems, European Commission, 2026-07-20 (opens in a new tab)
  3. 3.Transparency obligations under Article 50 of the AI Act, European Commission, 2026-07-24 (opens in a new tab)
  4. 4.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
  5. 5.Business and Professions Code, Division 7, Part 3, Chapter 6: Bots (sections 17940–17943), California Legislative Information, 2019 (opens in a new tab)
  6. 6.Utah Code 13-77-103: Required disclosures, Utah State Legislature, 2025-05-07 (opens in a new tab)
  7. 7.South Korea AI Basic Act, International Trade Administration, U.S. Department of Commerce, 2026-05-29 (opens in a new tab)
  8. 8.Korea's AI Basic Act, Ministry of Science and ICT, Republic of Korea, 2024-12-26 (opens in a new tab)

Get a free 30-minute assessment

Tell us which calls, chats or tasks take up your team's time. A senior engineer will show you what an agent could handle and what it would take to launch it safely.

Frequently asked questions

What are the AI disclosure requirements under the EU AI Act?

Under Article 50, providers must design AI systems that interact with people so those people know they are dealing with AI, unless it is obvious. Generative AI outputs must carry machine-readable marks. Deployers must disclose deepfakes, AI-generated text published on matters of public interest and the use of emotion recognition or biometric categorization. These rules have applied since August 2, 2026.

Is an AI notice in our privacy policy enough?

No. The Commission's guidelines say that a notice only in terms and conditions, a manual or a linked document is easy to miss, so it does not meet the clear and distinguishable standard. It can support an in-context notice but cannot replace it. Put the disclosure in the conversation itself, for example in the first chat message or the first sentence of a call.

Do internal AI assistants for employees need a disclosure?

Not in every case. The guidelines give an internal assistant used by trained, AI-literate staff as an example where the AI nature can be obvious, so the exception may apply. You still need to assess this and be able to explain your reasoning. A short AI label in the tool costs little and removes the question for staff and for any authority that asks.

Do U.S. companies have to follow Article 50?

They do if they place AI systems on the EU market or if the output of their AI system is used in the EU, according to the Commission's guidelines. A U.S. company whose chat or voice agent serves customers in the EU should plan for Article 50. U.S. state laws, such as California's bot disclosure law and Utah's generative AI rules, can apply at the same time.

Services and use cases

  • Clinic reception desk in the evening with a phone lighting up as a call comes in

    Use case

    AI receptionist

    An AI receptionist that answers every call, books appointments 24/7 and transfers urgent callers to your staff. Built for clinics and service businesses.

    See how the AI receptionist works
  • Customer support lead calmly reviewing a short list of escalated tickets at her desk

    Use case

    AI customer support

    AI customer support agents that resolve order, return and account questions from start to finish and hand complex cases to your team with full history.

    See how the AI support agent works
  • Service

    AI agent development

    Custom AI agent development for support, sales, front desk and back-office work. Voice and chat agents built and attack-tested by a cybersecurity team.

    Explore AI agent development
  • Service

    AI security and red teaming

    AI security consulting for AI agents and LLM apps: red teaming, prompt injection testing, shadow AI discovery and EU AI Act and ISO/IEC 42001 readiness.

    Explore AI security consulting

Free 30-minute assessment

Find the one workflow worth automating first.

Tell us how your team works. We'll come back with two or three AI opportunities, the risks to watch and a rough payback estimate. No obligation.

  • A senior engineer replies within one business day
  • We can sign an NDA before you share details
  • No fixed packages, every quote tailored to you
What can we help with?
About your company

Company size

When would you like to start?

How can we reach you?

Encrypted in transit · read only by our team · never sold

Free 30-minute AI assessmentGet it →

Before you go

Find out where AI can save your team time

Book a free 30-minute assessment. A senior engineer reviews one workflow with you and sends back the opportunities, the risks and a rough payback estimate.