← All articles

Chatbots and AI content: what Article 50 asks of you

Since 2 August 2026, Article 50 of the AI Act has required a chatbot to say it is an AI and generated content to be marked, but both duties sit with the tool's provider. What falls to the retailer is the deepfakes it publishes, and 2 December 2026 changes almost nothing about that.

Dots Papers cover for the article on AI Act Article 50: what it asks of an online shop's chatbot and AI-generated content

In brief

  • Article 50 of the AI Act has applied since 2 August 2026. The Digital Omnibus did not postpone it: what it pushed back were the obligations on high-risk AI.
  • Telling people “you are talking to an AI” and marking generated content are duties of the tool’s provider. The 2 December 2026 deadline covers that marking only, for systems placed on the market before 2 August.
  • The retailer, as deployer, discloses the deepfakes it publishes: a generated model more real than life, or a photo that flatters the product.
  • Product descriptions written with AI do not need a label, unless, according to the Commission, they carry health, safety or sustainability claims.

Since 2 August 2026, Article 50 of the AI Act has required a chatbot to say it is an AI from the first exchange, and the 2 December deadline changes nothing about that. Yet the regulation places that duty, like the invisible marking of generated content, on the tool’s provider. What falls to the retailer is the visible label on the deepfakes it publishes.

Try this before reading on. Open your shop in a private window and start the chatbot: does its first message say it is an AI, or just “Hi, I’m Lea, your personal adviser”? Then open the page of your best seller: a model who never existed, a product that looks better than the one you ship? Those two checks tell you where you stand.

Does this apply to you?

  • Does your site have a chatbot, a voice agent or an assistant that answers customers? It must present itself as an AI: the duty sits with the provider, the setting with you.
  • Do you publish generated images, videos or voices that realistically show people or products? Those that could pass for real need a label, and adding it is your job.
  • Have you had an assistant built that you run under your own brand? You could then be the provider, and carry the disclosure and marking duties too.

What AI Act Article 50 requires, and of whom

Regulation (EU) 2024/1689, the AI Act, has applied for the most part since 2 August 2026. We set out the wider picture in our piece on the AI Act for online shops. Its Article 50 sets four transparency duties: telling people they are interacting with an AI (paragraph 1), marking the output of generative AI in a machine-readable format (paragraph 2), informing people exposed to an emotion recognition or biometric categorisation system (paragraph 3), and disclosing deepfakes as well as certain texts published on matters of public interest (paragraph 4). Paragraph 5 requires the information to be clear, distinguishable and accessible, at the latest at the first interaction or exposure.

These duties do not fall on the same parties. The provider develops an AI system, or has it developed, and places it on the market or puts it into service under its own name. The deployer uses it under its own authority, in a professional capacity. Paragraphs 1 and 2 are addressed to the provider, paragraphs 3 and 4 to the deployer. A shop that subscribes to a chatbot or an image generator is, in the usual case, a deployer.

On 10 June 2026 the Commission published a voluntary code of practice on marking and labelling, found adequate in July, then on 20 July guidelines on Article 50. Most of the cases cited below come from those guidelines.

2 December 2026 only concerns marking

Regulation (EU) 2026/1744 of 8 July 2026, known as the Digital Omnibus, postponed the obligations on high-risk AI systems to 2 December 2027 for Annex III and to 2 August 2028 for Annex I. It did not postpone transparency. On Article 50, the measure that matters for a shop is a four-month transition: providers of systems that generate audio, images, video or text, placed on the market before 2 August 2026, have until 2 December 2026 to comply with paragraph 2, the marking duty.

That transition covers neither the interaction notice nor the deployer. According to the guidelines, a system that both converses and generates must have said it is an AI since 2 August. Both dates are in our e-commerce compliance deadlines.

Where is the real risk for a shop?

Your copy rarely causes trouble. According to the guidelines, advertising copy and product descriptions are not published to inform the public on a matter of public interest: your AI-written descriptions need no notice. The Commission sets aside claims about health, consumer safety or sustainability. As we read it, a skincare page promising an effect on the skin therefore moves out of the simple case. For those texts, human review removes the need for a notice if it is genuine: a competent person checking the substance, not a spell-check, and someone who takes responsibility for publishing. Such claims also have rules of their own, which we covered for green claims.

Images need more care. A deepfake is image, audio or video content generated or manipulated by AI that resembles existing people, objects, places or events and could falsely appear authentic. The guidelines include realistic human avatars and consumer goods: a generated image of a product that could mislead about how it looks or its quality is one, whereas a real product against a generated background is not, as long as the image stays true to the product. No intention to deceive is needed, and a dress that looks better in the photo than in real life disappoints on delivery anyway. As we read it, a fully generated model wearing your dress meets the criteria. Correcting a colour or swapping a background for purely aesthetic reasons has, in the Commission’s view, only a minor effect.

That leaves the chatbot settings. The duty sits with the provider, but it is your site the customer is looking at. The guidelines list customer service chatbots among those that must present themselves as AI, and treat as insufficient a notice only in the terms and conditions, a bare “assistant”, a human-like representation that may mislead or a vague “this site uses AI”. If the tool lets you hide that message, or give the bot a first name and a photo, your setting decides what the customer understands.

Here is how we read the most common uses in a shop.

Use Duty and who carries it What you do
Subscription customer service chatbot Tell people they are talking to an AI, from the first exchange (provider, since 2 August 2026) Check the message shows, do not hide it, avoid a human name and photo
Chatbot built for you, under your brand Interaction notice and, if it generates, output marking (you, if you are the provider) Have your role assessed, then deal with both duties
Human agent helped by AI Outside paragraph 1 if the person reviews and sends the reply themselves Make sure the review is real
AI-written product descriptions Machine-readable marking (provider). No visible label for an ordinary description Check the substance of any health, safety or sustainability claims
Product photo on a generated background Marking (provider). Not a deepfake if the product stays true to life Check the product is not flattered
Realistic model or avatar, cloned voice Visible deepfake label (you, since 2 August 2026) Put the notice on or next to the image, from first exposure
Tool that infers age or emotion from a face Inform the people exposed (you, if the tool meets the definition) Have the classification checked, as virtual try-on may be an ancillary feature

The notices to show

The regulation imposes no wording. Here are the ones we suggest, written to avoid the signals the Commission treats as insufficient.

  • The chatbot’s first message, if your tool lets you write it: “Hello, I am our shop’s assistant, an artificial intelligence program. I can answer your questions about our products and your orders.” If someone on your team can take over, say how to reach them.
  • Under a generated model or avatar that could pass for real: “Image generated by artificial intelligence.”
  • Under a real photo that AI has transformed beyond an aesthetic touch-up: “Image modified by artificial intelligence.”
  • In a video or audio message with a realistic synthetic voice: “Voice generated by artificial intelligence.”, on screen or announced at the start.

Put the label on the image or right next to it, visible as soon as the image is, not on a legal notice page. The Commission offers a royalty-free icon to go with it, optional, which does not prove compliance on its own.

Could you be a provider without knowing it?

It is enough to develop the system or have it developed, then put it into service under your own name or trademark. The guidelines cite an organisation that builds a chatbot in-house for its own use, and a company that modifies an existing generative system, for instance with new training data, then puts it into service under its name: both are providers.

At the other end, a subscription chatbot configured with your catalogue and instructions leaves you, in principle, a deployer. In between, the texts do not settle every case. If an agency built you a bespoke assistant, run under your brand, and the contract says nothing about who does what, have a lawyer look at it: the interaction notice and the marking could be yours.

The inventory, with a spreadsheet and your contracts

  1. List every use of AI that reaches a customer: chatbot, voice agent, product descriptions, images, videos, voices, tools that analyse a face. Purely internal tools can wait for a second pass.
  2. Note who built each tool and under whose name it is presented: standard subscription, or bespoke build.
  3. Run your generated images through the definition of a deepfake. Those that meet it get a visible label from first exposure.
  4. Have your health, safety and sustainability texts checked for substance by a competent person who takes responsibility for publishing them, or add the notice.
  5. Ask each provider for a written commitment on the interaction notice and on marking, with its compliance date if its tool was on the market before 2 August.

What should you ask a chatbot or content generation provider?

Article 50 puts most of the technical work on the people who make the tools. As we read it, for a small business, compliance therefore depends mainly on choosing the provider and reading the contract. Before you sign or renew, ask to see:

  • an interaction notice shown by default from the first message, which a simple setting cannot remove, readable on mobile and with a screen reader;
  • documentation of its machine-readable marking, by content type, with the date it went live, and an assurance that your exports do not strip those marks;
  • a clause stating who the provider is, what it guarantees under Article 50 and how it will tell you about any change;
  • its position on the code of practice: a signatory, which the public list lets you check, or otherwise how it demonstrates compliance.

The next deadline is 2 December: generative tools released before 2 August must mark what they produce by then. If you would like your AI tool contracts and your images reviewed before that date, write to us: it is work we do within our artificial intelligence expertise.

Sources

Texts and pages consulted on 30 September 2026.

  1. Regulation (EU) 2024/1689 of 13 June 2024 on artificial intelligence (AI Act), Official Journal of the European Union, Article 3 (definitions 3, 4, 39, 40 and 60), Article 50, Article 113, recitals 16 and 132 to 134. View
  2. Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026, Article 1, points 39 and 40, recital 38. View
  3. European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, C(2026) 5054, 20 July 2026. View
  4. European Commission, questions and answers on the transparency obligations under Article 50 of the AI Act. View
  5. European Commission, Code of Practice on Transparency of AI-generated Content, published 10 June 2026, page updated 31 July 2026, and its questions and answers. View
  6. European Commission, opinion on the assessment of the code of practice, 9 July 2026. View
  7. European Commission, EU icons for labelling AI-generated content. View

FAQ

Can my chatbot keep a first name and a photo?

The regulation does not ban it as such, but the guidelines count a misleading human likeness among the insufficient signals, and among the factors that can affect whether the exchange is obvious. A first name with a clear statement, from the first message, that this is an AI remains possible. As we read it, a photo of a real person with no notice at all is exactly the situation the guidelines aim to rule out.

Do I have to rework images generated before 2 August 2026?

According to the Commission’s guidelines, content generated before 2 August 2026 does not need to be marked or labelled retroactively. The Commission does, however, encourage labelling older deepfakes that are still in circulation, without disproportionate effort. For a shop, that usually means dealing with the few most viewed images.

Should I sign the Commission’s code of practice?

It is not compulsory. The code is voluntary and open to both providers and deployers of generative systems. A signatory can rely on its measures to demonstrate compliance with marking and labelling. A non-signatory has to show by other means that its measures are adequate. For most shops, the more useful question is whether their providers have signed it.

Want to apply this to your own business?

Get in touch →

Further reading

Leave a comment

Your email address will not be published. Required fields are marked *

14 − 10 =