When you don’t have to label your chatbot as AI

AI Act chatbot disclosure: when you don’t need a label

Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689) requires providers to design AI systems that interact directly with people so those people are told they are dealing with an AI — “unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.”

That phrase is not new drafting. It is the average consumer benchmark from EU consumer law, almost word for word, and it has been litigated at the Court of Justice since 1998. Which means the question “do we need a disclosure banner?” has an answer with thirty years of case law behind it — and it is not the answer the compliance-banner vendors are selling.

What Article 50(1) actually requires

Providers — not deployers — must ensure that AI systems intended to interact directly with natural persons are “designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system.” It is a design obligation, discharged at build time, and it sits with whoever puts the system on the market under their own name.

In practice the deployer inherits it. If you buy a chatbot and drop it on your checkout page, the provider owes the design duty, but you are the one whose customers see the result — and the exception turns on your circumstances and context of use, which the provider never saw. That gap is the reason contract terms on this matter more than most people assume.

The exposure is not theoretical: Article 99(4)(g) places breaches of Article 50 in the tier of up to €15,000,000, or 3% of total worldwide annual turnover for the preceding financial year if the offender is an undertaking, whichever is higher. Article 50 applies from 2 August 2026 and the Digital Omnibus did not defer it.

Systems in scope

White & Case’s EU AI Act Handbook reads the category as covering chatbots, voice assistants and robo-services — anything intended to interact directly with individuals. It explicitly does not include AI systems designed to interact exclusively with other AI systems or other non-human systems.

That exclusion is narrower than it sounds. An agent that calls your supplier’s API all day is out. An agent that calls your supplier’s switchboard and talks to a person is in, because the person on the other end is a natural person interacting directly with an AI system. The test is who is on the other end, not what your architecture diagram says.

The three exceptions, in order of usefulness

Article 50(1) can be switched off three ways. Only one of them is a live question for most businesses.

  • The “obvious” exception. No disclosure where it would be obvious to a reasonably well-informed, observant and circumspect person, taking into account the circumstances and the context of use. This is the one you will actually argue about.
  • Law enforcement. The obligation does not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties — unless the system is available for the public to report a criminal offence. White & Case gives the worked example: a chatbot on a law enforcement authority’s website. Public-facing crime-reporting bots get no exemption.
  • Out of scope entirely under Article 2. Chiefly individuals using AI systems in the course of a purely personal, non-professional activity. This is not an exception you can invoke as a business.

How far does “obvious” go?

The standard is contextual, not absolute — the Act says so, twice, with “taking into account the circumstances and the context of use.” So there is no such thing as a system that is obviously AI. There are only surfaces on which it is or isn’t obvious, and the same model can be on both sides of the line in the same company.

The reference person is where the argument gets decided, and the Act imported that person rather than inventing them. In Gut Springenheide (Case C-210/96), decided on 16 July 1998, the Court of Justice held that a national court assessing whether a description is misleading must take into account the presumed expectations of “an average consumer who is reasonably well-informed and reasonably observant and circumspect.” That formula became Recital 18 of the Unfair Commercial Practices Directive (2005/29/EC) and the default benchmark across EU consumer law. Article 50(1) reproduces it with one word dropped.

Three things follow, and none of them help a provider hoping for a bright line.

Nobody has defined it, deliberately. When the UCPD was negotiated, the definition of the average consumer was removed from the operative text — the European Parliament’s legislative record explains that a fixed definition was dropped precisely so the concept could keep evolving with the Court’s jurisprudence. The AI Act repeats the pattern: the formula appears in Article 50(1) and again in Recital 132, and is defined in neither. If you were waiting for the legislature to tell you what obvious means, it has told you it isn’t going to.

The reference person is not a rational maximiser. The Court has kept moving. In Compass Banca (Case C-646/22) it accepted that the average consumer’s assessment can be affected by cognitive bias — the benchmark is a notional typical consumer, not a perfectly rational market actor. A provider arguing “anyone would have realised” is arguing against a standard that has been explicitly loosened away from that assumption.

The reference person shifts when your audience does. Recital 132 says that in applying the obligation, account must be taken of the characteristics of people belonging to vulnerable groups due to their age or disability, insofar as the AI system is intended to interact with those groups too. This mirrors the UCPD, which makes specific provision for vulnerable consumers. Build a homework helper for teenagers and the person deciding what’s obvious is a teenager.

Apply that to two real surfaces. A support widget on your own site, opened by a user who clicked a button labelled “Chat”, staffed by a bot called AI Assistant, answering instantly at 3am: a decent argument that disclosure adds nothing a reasonably observant person doesn’t already have. An outbound call to a customer’s mobile in a synthetic voice: not obvious, ever. The recipient did not choose the channel, has no context, has one second of audio to work from, and the entire history of the average consumer test runs through cases about people being misled in exactly that posture.

White & Case’s own advice is to treat the exemption with caution, on the reasoning that a court or regulator may read the level of information a reasonably well-informed user is deemed to have more narrowly than a provider would like. One more reason for caution is on the calendar. The Commission is obliged under Article 96(1)(d) to develop guidelines on the practical implementation of Article 50, and its published FAQ confirms those guidelines will address AI interaction specifically, that a public consultation on the draft has closed, and that the final version will be published before the obligations start to apply. The guidelines can narrow the exception. They cannot widen it beyond the text.

What the Code of Practice does not cover

Worth knowing before you go looking: the Code of Practice on Transparency of AI-Generated Content is no help on this question. Article 50(7) directs the AI Office to facilitate codes of practice on the detection and labelling of artificially generated content — that is Article 50(2) and (4). When the Commission issued its opinion on 8 July 2026, it concluded the Code adequately covers Articles 50(2), (4) and (5). Article 50(1) is not on that list. There is no code to sign that demonstrates your chatbot disclosure is adequate.

Form and timing you can’t negotiate away

If the exception doesn’t apply, Article 50(5) governs how you tell people, and it is short enough to quote in full: the information “shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.”

Four consequences:

  • Clear and distinguishable. Distinguishable from what surrounds it. A line in the terms of service is not distinguishable; a greyed-out footer under the input box is a bad bet.
  • At the latest at first interaction. White & Case reads this as akin to the point-in-time notice requirements under the GDPR — the notice attaches to the moment, not to a document you have somewhere. You cannot disclose on turn three.
  • Accessibility requirements. Recital 132 adds that the information must be provided in a format accessible to persons with disabilities. A purely visual badge on a voice product fails this on its face.
  • Vulnerable users. This one is Recital 132, not Article 50(5) — worth knowing, because summaries routinely present it as an operative requirement. It shapes how the obligation and the exception are applied rather than adding a fifth element to the form rules.

Why the obligations stack

Article 50(6) says paragraphs 1 to 4 “shall not affect the requirements and obligations set out in Chapter III, and shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems.” Chapter III is the high-risk regime. So clearing Article 50(1) tells you nothing about Articles 13 and 26, and nothing about the GDPR notice you already owed.

The general-purpose AI overlap is real but comes from elsewhere — Article 50(2) applies to providers “of AI systems, including general-purpose AI systems”, and Chapter V imposes its own model-level duties. White & Case reads the whole set as applying cumulatively. A conversational assistant built on a general-purpose model, deployed in a high-risk context, can owe disclosure under 50(1), marking under 50(2), instructions for use under Article 13 and model documentation under Chapter V, all at once. They are not alternatives and satisfying one is not a defence to another.

Frequently asked questions

Does a bot name count as disclosure?

Calling it “AI Assistant” is evidence that the fact was obvious, not compliance with the disclosure duty. The two are different arguments: one says the exception applies so no notice was owed, the other says notice was given clearly and distinguishably at first interaction. If you are relying on the name, you are relying on the exception — write down why, in context, before a regulator asks.

Does the exception apply to voice?

Not to outbound voice, realistically. The recipient did not initiate the interaction, has no visual context and no prior expectation, and synthetic speech is now good enough that “reasonably observant” does not get you there. Inbound voice on a line the caller dialled knowing it is automated is a different and better argument.

Who is liable, the provider or the deployer?

Article 50(1) puts the design duty on the provider. But the exception depends on the circumstances and context of use, which the deployer controls — so a provider who ships without disclosure on the assumption that deployment will be obvious has made a bet on someone else’s product decisions. Allocate it in the contract: who decides whether the exception is relied on, and who evidences it.

What about an AI agent that calls a customer?

In scope of Article 50(1), and the exception almost certainly does not apply. See outbound voice above. This is the single clearest case in the whole provision.

Does this apply to internal-only tools?

Yes, if the tool interacts directly with natural persons — the Act does not distinguish between customers and employees here. The Article 2 carve-out covers individuals using AI in a purely personal, non-professional activity, which is the opposite of an internal work tool. Whether disclosure is obvious to a trained employee using a named internal assistant is a much easier argument than the customer-facing case, but it is still the argument you have to make.