Regulation
Article 50 is live: a 10-point AI disclosure checklist
AI disclosure requirements under Article 50 of the EU AI Act have applied since August 2, 2026: people must be told when they are dealing with an AI system, and some AI content must be labeled. If your chat, voice or email agents reach people in the EU, this checklist covers the points we check before an agent goes live.
By the KDS security engineering teamPublished 5 min read
Key takeaways
- Article 50 has applied since August 2, 2026 to AI agents that talk to people, including agents launched before that date.
- Tell people they are dealing with AI at the start of each conversation, in the same channel and in plain words.
- A notice only in your terms, a footer link or hidden metadata is not enough under the Commission's guidelines.
- California, Utah and South Korea also have AI disclosure rules, each with a different trigger.
On this page
What Article 50 asks of AI agents
Article 50 of the AI Act (opens in a new tab) requires providers to design AI systems that interact with people so those people are informed they are dealing with AI, unless it is obvious from the context. The notice must be clear, distinguishable and accessible, and it must come at the latest at the first interaction. If you build or commission an agent and run it under your own name, the Commission's guidelines (opens in a new tab) usually treat you as its provider.
Deployers have separate duties for deepfakes, AI-generated text on matters of public interest and emotion recognition. Our Article 50 guide explains every paragraph, the exceptions and the dates. The checklist below focuses on the agents most companies run: chat, voice and email.
The 10-point AI disclosure checklist
- List every agent that talks to people. Include website chat, phone agents, email or messaging agents and any agent that calls or writes to third parties during a task. Rule-based auto-replies that use no AI are outside Article 50(1).
- Decide who the provider is. If you built or commissioned the agent and run it under your name, plan as the provider. If a vendor supplies a ready-made agent, ask in writing how its design meets Article 50.
- Disclose in the first turn. The first chat message or the first sentence of a call should say the assistant is AI, before it asks for any details.
- Use the channel people are in. A spoken notice on calls, text in chat and a label at the top of emails. The guidelines say a sound alone, a footer link or the terms of use are not enough.
- Say on whose behalf the agent acts. The guidelines expect AI agents that call or write to people to disclose both that they are AI and who they represent.
- Keep it visible. Show a persistent "AI assistant" label in chat. Repeat the notice in long calls, after a hold and when the agent's role changes.
- Answer the direct question. When someone asks whether they are talking to a person, the agent must say it is AI. Offer a hand-off to your team at the same time.
- Remove human disguises. Drop human photos, staff names and scripts that suggest a person is typing or speaking. According to the guidelines, these make the AI nature less obvious.
- Make it accessible. Use plain words, the customer's language and labels that screen readers announce. Adapt the wording if children, older people or people with disabilities are likely to use the service.
- Log it and test it. Record the disclosure version and when it was given. Test that prompt injection (tricking an AI with hidden instructions) cannot make the agent claim to be human.
Why wording and placement matter
The Commission's guidelines are specific about what fails. A notice hidden in terms and conditions, a manual or behind menus is easy to miss, so it is not clear. A general notice that covers a whole platform is too vague. Machine-readable marks that people cannot see inform nobody in the conversation.
One prominent notice at the start is likely enough in most cases. The guidelines expect reminders in higher-risk contexts, for example financial, insurance, legal or health advice and complaints handling. The same applies when vulnerable people may be involved. The Commission's Article 50 FAQ (opens in a new tab) adds that the obvious-from-context exception should be read narrowly.
AI disclosure requirements outside the EU
Other jurisdictions have their own triggers. Three examples:
- California. The state's bot disclosure law (opens in a new tab) (Business and Professions Code sections 17940–17943) makes it unlawful to use an automated online account to mislead a person in California about its artificial identity in order to encourage a sale or influence a vote. A clear and conspicuous disclosure avoids liability. It has applied since July 1, 2019.
- Utah. A business that uses generative AI in a consumer transaction must disclose it when a person clearly asks. People in regulated occupations must disclose it up front in high-risk interactions: verbally at the start of a spoken exchange and in writing before a written one (Utah Code 13-77-103 (opens in a new tab)).
- South Korea. The AI Basic Act has been in force since January 22, 2026. Businesses offering high-impact or generative AI must notify users in advance that AI is used, according to the U.S. International Trade Administration (opens in a new tab), which also reports a one-year grace period during which fines are generally deferred.
A clear notice at the start of every conversation is the simplest way to cover these different triggers with one design. Local details still differ, so check each market you serve.
Dates and fines to keep in mind
The Digital Omnibus on AI (opens in a new tab) did not move the Article 50 start date. It gave providers of generative AI systems placed on the market before August 2, 2026 until December 2, 2026 to add machine-readable marking to outputs. The disclosure duty for agents that talk to people received no extra time. Our post on what still applies after the Digital Omnibus lists the other changes, and our EU AI Act guide covers the full regulation.
Breaches of Article 50 can bring fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs (small and medium-sized enterprises), the lower of the two amounts is the cap.
How we apply this checklist
Every agent we build says it is an AI at the start of the interaction, and a person can take over at any time. Before launch, our attack testing includes attempts to make the agent deny that it is AI. In our AI receptionist, the disclosure is the first sentence of each call. Our AI transparency statement describes how we apply the same rules to our own work.
Sources
- 1.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Articles 50 and 99, EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
- 2.Guidelines on transparency obligations for providers and deployers of AI systems, European Commission, 2026-07-20 (opens in a new tab)
- 3.Transparency obligations under Article 50 of the AI Act, European Commission, 2026-07-24 (opens in a new tab)
- 4.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
- 5.Business and Professions Code, Division 7, Part 3, Chapter 6: Bots (sections 17940–17943), California Legislative Information, 2019 (opens in a new tab)
- 6.Utah Code 13-77-103: Required disclosures, Utah State Legislature, 2025-05-07 (opens in a new tab)
- 7.South Korea AI Basic Act, International Trade Administration, U.S. Department of Commerce, 2026-05-29 (opens in a new tab)
- 8.Korea's AI Basic Act, Ministry of Science and ICT, Republic of Korea, 2024-12-26 (opens in a new tab)

