Europe Industry compliance

EU AI chat disclosure rules take effect

For teams running OTT support, in-app messaging, AI chat assistants, and account-help flows in Europe, this matters because telling users they are interacting with AI is now a legal compliance issue, not just a UX choice. On July 20, 2026, the European Commission published implementation guidelines for Article 50 of the AI Act. The transparency obligations started to apply on August 2, 2026, alongside supporting materials on labelling and machine-readable marking of AI-generated content.

Published:08/17/2026 Updated:08/17/2026

1. Regulatory focus

Article 50 of the EU AI Act does not simply say “disclose AI somewhere.” It separates obligations by use case: AI systems that directly engage in two-way interaction with people must inform users that they are dealing with AI, while systems generating or manipulating content must address machine-readable marking, detectability, and user-facing labelling. In its July 20, 2026 implementation guidelines, the Commission made clear that scope depends on concrete factors such as genuine bidirectional exchange, direct AI-to-person interaction, and whether the AI nature of the interaction is not already obvious to an average user. These obligations became applicable on August 2, 2026.

2. Business impact

For CPaaS providers, SaaS support teams, and cross-border digital platforms, the exposure is not limited to public website chat widgets. It extends to WhatsApp triage bots, in-app support assistants, ticket-routing copilots, login issue explainers, billing dispute flows, and other “semi-automated” conversation layers. If a company wraps AI responses under a human agent identity, or relies only on broad disclosure in privacy terms, that may fall short of Article 50. The risk increases further when AI-generated text is used to inform the public on matters such as public services, health, finance, consumer safety, or other public-interest topics. Providers outside the EU also need to pay attention: if the output is used in the EU, the obligations may still apply.

3. Operating recommendations

The practical move now is to treat AI transparency as a messaging-governance control, not a last-minute banner. Start by mapping every external conversation surface and classifying it: fully human, AI first response, AI-assisted human, or fully automated outbound flow. Then implement disclosure at the right points for in-scope use cases, including upfront notice, persistent in-conversation signalling where appropriate, handoff-to-human logic, and evidence logging. If your workflows also publish AI-generated text, summaries, or rich media, assess whether machine-readable marking and detection measures are needed. Where third-party models, bot platforms, or outsourced support vendors are involved, contracts should allocate responsibility for disclosure, labelling controls, audit logs, and change notifications.

Frequently Asked Questions

If our chat widget already says “virtual assistant,” do we still need extra disclosure?
Not always. The real test is whether an average user can clearly understand that the current responder is AI rather than a human support agent. If your interface still uses human avatars, agent names, or human-style presentation, add clear disclosure at entry and at key handoff points, and retain logs showing that the notice was displayed.
Can we skip AI disclosure if the bot can eventually hand off to a human agent?
No. Human escalation is not a substitute for disclosure. Article 50 focuses on whether the user is informed at the time of the interaction, not whether a human may join later. A stronger approach is to disclose AI handling from the first exchange, while making escalation conditions, expected wait times, and handoff paths visible and auditable.
We operate support systems outside the EU. Do these rules still matter if we serve EU users?
Yes. Location of incorporation or hosting is not the only factor. The Commission’s Q&A states that providers outside the EU can still be in scope where the AI system’s output is used in the EU. Cross-border teams should assess EU-facing entry points, language versions, numbering footprints, and routing patterns rather than relying only on company domicile.
This article is for informational purposes only and does not constitute legal advice.

Related products

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch