Is your website chatbot legal? The Aug-2026 disclosure checklist
Since 2 August 2026, anyone who interacts with an AI system must be told so — before or at the moment of interaction. That single sentence is Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689), and it applies to the chat widget sitting in the corner of most agency websites and most client sites you build.
What Article 50(1) says, in plain language
The legal text runs to a few lines; here is what it requires without the legalese:
- If a person interacts with AI, they must be informed. Not eventually, not in a privacy policy three clicks deep — the information must reach them when they interact with the system.
- The purpose is informed decision-making: a visitor who knows they are talking to a machine can choose how much to share, how much to trust, and whether to ask for a human.
- Where the AI produces artificial or manipulated image, audio, or video output, that output is disclosed too: if your bot speaks with a synthetic voice or presents as an avatar, its artificial nature must be made known (Art. 50(1), second subparagraph).
- One narrow exception exists: it applies to AI systems interacting with natural persons. A back-office tool summarizing tickets for your staff is a different question entirely — but a client-facing widget on your site is squarely covered.
- Both providers and deployers carry duties under Art. 50(1): the provider builds the disclosure capability in; the deployer — the agency running the bot on its own site or a client's site — must make sure the information actually reaches users.
- It has been live since 2 August 2026. This is not a 2027 deadline. If your widget lacks disclosure today, the gap exists now.
The 8-point self-check
Run this against every chat surface you operate or ship: your own site first, then each client deployment.
A human can be reached
Every chat entry point offers a clear route to escalate to a person — a button, an email address, or a phone line. Disclosure works both ways: people told they're talking to a machine will sometimes want the opposite.
The disclosure sits where the conversation happens
The notice appears in or immediately attached to the chat interface — inside the welcome message, the widget header, or directly beneath the input field. A line buried in your Terms page does not inform anyone "when" interaction happens.
The wording names the machine plainly
"You're chatting with an automated assistant" beats vague phrasing like "virtual experience." If a reasonable visitor could still assume they're typing to a human, the duty isn't met.
Timing is before or at first message
Ideally visible on open; acceptable as a clearly-worded first reply if the interface can't show a banner. What fails: disclosure only after the user has already shared their problem, budget, or contact details.
Synthetic voice or avatar? Disclosed separately
If the assistant talks (voice agent) or shows a generated face, Art. 50(1) also requires disclosing the artificial nature of that output itself — not just the text channel.
Client sites inherit the check
When you deploy a chatbot for a client, you are operating it under their brand but often configuring it yourself. Make the disclosure part of your launch checklist, and put it in writing on the project record.
New surfaces get checked before launch, not after
Any new chat touchpoint — support bot, quote wizard, AI search concierge — passes through the same eight checks before going public. Add it to your QA sheet.
You keep evidence
Screenshot the disclosure as deployed, note the date, and store it per site. If a market surveillance authority asks a deployer how users are informed, "we added a banner once" is weaker than a dated screenshot log.
Paste-ready disclosure lines
Adapt tone to the brand; keep the substance — an unambiguous statement that the responder is an AI system. These are starting points written for agency use, not legally reviewed copy.
Chat widget — short version (welcome bubble / header)
Chat widget — fuller version (first bot reply)
Footer link text (support / contact pages)
Voice agent script opener
Penalties: context, not panic
Honest framing first: there is no published record of enforcement sweeps against small agencies over chatbot disclosure as of this writing, and we won't invent scare statistics. The framework itself, from Regulation (EU) 2024/1689:
- Upper tier: up to €35M or 7% of global annual turnover for prohibited-practice violations (Art. 99(3)). Chatbot-disclosure failures don't sit here.
- Middle tier: up to €15M or 3% for breaches of most obligations, including the transparency duties (Art. 99(4)).
- Lower tier: up to €7.5M or 1% for supplying incorrect information (Art. 99(5)).
- SME cap: for SMEs and small mid-cap enterprises, each fine tier caps at the lower of the two amounts — the euro figure prevails over the turnover percentage (Art. 99, final subparagraph). For a typical agency, that means the euro amount, not a percentage of turnover, sets the ceiling.
- Proportionality runs through everything: authorities weigh the nature and gravity of the breach, plus intent and neglect. A good-faith operator who documented effort is in a different position than a willful one.
The practical read for an agency owner: the compliance cost here is trivially low — a disclosure line and an escalation route — while the downside of ignoring a live obligation compounds with every month and every client deployment.
Keep reading
- Every EU AI Act deadline agencies actually face — the full post-Omnibus deadline table.
- Labeling AI-generated images and video — what Art. 50(4) requires of publishers since August 2, platform by platform.
Want this checked across your whole site — not just the chatbot?
The free self-score covers disclosure, literacy, labeling, and governance in ten questions, and tells you which gaps matter before the December dates. Two minutes, no email wall.
Take the free AI-readiness self-score →
Need the full workup instead? Our AI Act Ready packet ships checklists, gap lists, and evidence templates within 72 hours.