New EU AI rules mean chatbots can no longer pretend to be human
Key Points
- EU AI Act transparency rules under Article 50 took effect on 2 August 2026
- Chatbots, voice assistants and AI agents must tell people they are not human
- Providers must watermark AI-generated audio, images, video and text and supply detection tools
- Deployers must label deepfakes and flag emotion recognition or biometric categorisation systems
- Fines reach €15 million or 3% of global annual turnover, whichever is higher
Businesses running chatbots in the EU must now tell people they are talking to a machine.
Article 50 of the EU AI Act took effect on 2 August, and sets four separate transparency obligations split between the companies that build AI systems and the companies that use them.
Law firm Travers Smith set out how those obligations land in a briefing on the new rules, covering who is caught, what each obligation demands and where the exceptions run out.
The Act calls the first group providers, meaning any entity that develops an AI system, or has one developed, and places it on the market under its own name or trade mark.
It calls the second group deployers, meaning any entity that uses an AI system under its own authority in a professional capacity.
Both roles carry the obligations regardless of where the business sits. Providers outside the EU fall within scope where they intend the outputs for use in the EU, and deployers fall within scope where they foresee that outputs will reach the EU, including by posting deepfake content on the open internet.
A horizontal requirement runs across all four obligations: companies must give the information clearly and distinguishably, at the latest at the point of first interaction or exposure.
Information buried in terms and conditions or hidden under layers of menus does not meet that standard.
The first obligation falls on providers of systems that interact directly with people, covering chatbots, voice assistants, AI companions, bots on social networks and agentic systems that contact individuals on a company’s behalf.
Those providers must make clear that the person is dealing with AI rather than a human, and must identify the person or entity the agent acts for.
When AI does not have to identify itself
The single exception applies where the AI element of the interaction is obvious, and the European Commission’s guidelines read that exception narrowly. The test asks whether the AI would be obvious to a reasonably well-informed, observant and circumspect person in the target audience.
The guidelines treat code assistance chatbots used only by professional developers as obvious, along with AI-enabled non-playable characters in a single-player video game where no other people can join.
They treat three cases as not obvious, all of which need disclosure:
- A robotic companion pet designed to mimic real human-pet interaction
- A chatbot embedded in an online helpdesk where users may read the output as human-written
- An immersive environment using realistic avatars, particularly where children or elderly users are involved
The obligation only bites where there is a direct, two-way exchange between the system and a person, so backend decision-support tools that simply hand a user an output sit outside it.
First interaction means each new individual who encounters the system rather than the first run of the system overall.
Deployments involving children, elderly users or sensitive areas such as health, legal advice, financial advice, insurance and complaints handling will need periodic contextual reminders on top of the initial notice.
Marking AI-generated content
The second obligation requires providers of systems that generate synthetic audio, images, video or text to mark the output in a machine-readable format and to supply a matching means of detection. Marking on its own does not satisfy the rule.
The marking sits in metadata, watermarks or other interoperable techniques, invisible to the reader but robust enough to survive routine edits.
The Code of Practice sets two layers as the current state of the art for most content: digitally signed metadata where the format supports it, and an imperceptible watermark inside the content itself.
Free-form text carries no metadata, so a single watermarking layer counts as enough, with carve-outs for short text.
Standard editing escapes the rule, covering grammar correction, spellchecking, translation, minor cropping and noise reduction. AI-generated summaries, face alterations, adding or removing objects from an image, and converting black-and-white footage to colour all require marking.
Real-time content that people consume immediately without recording or storing it, such as output inside a video game or virtual reality session, also escapes the rule where marking is not technically feasible and users learn of the AI origin in session.
The firm said many businesses assume purely industrial or B2B applications fall outside the marking rule, and the guidelines confirm the exception is far narrower than that.
It applies only where the output is strictly technical, only a limited pre-defined number of professionals inside the organisation will see it, and the company keeps safeguards against wider sharing.
Deepfakes, emotion recognition and fines
The third obligation requires deployers to tell people when an emotion recognition or biometric categorisation system is running, whether it works in real time or after the fact. A video game that records a player’s facial expressions must show a prominent notice before play begins, and a retail store using facial recognition to sort visitors by age group must post a visible notice at every entrance.
The fourth obligation covers deepfakes and AI-generated text on matters of public interest. Deployers must disclose that an image, audio clip or video is artificially generated or manipulated where it resembles existing people, objects, places, entities or events and would falsely appear authentic, whether or not they publish it.
The guidelines read “existing” broadly enough to cover photorealistic portraits of invented people. A video of someone resembling a politician giving a speech qualifies, as does an AI depiction of a celebrity in an advertisement and voice cloning of a podcast’s presenters. An AI-generated video of mice arguing over cheese in human language does not.
Artistic, creative, satirical and fictional works still need a label, though deployers may place it in credits or accompanying notes rather than over the content. Where a piece mixes informative and creative elements, the informative character wins, and the guidelines leave minimal room for reduced labelling in advertising.
AI-generated text published on matters of public interest needs a label unless a person has reviewed it editorially and a natural or legal person holds editorial responsibility. Any substantive AI intervention after editorial sign-off loses the exception.
The Commission finalised the guidelines on 20 July 2026, and although they bind nobody, the firm said the AI Office and national market surveillance authorities are expected to follow them closely. The Code of Practice offers the only EU-recognised route to demonstrating compliance with the marking and labelling obligations, and it covers neither interactive systems nor emotion recognition.
Signing the Code remains voluntary, and non-signatories will need to demonstrate compliance by other means and can expect closer regulatory scrutiny.
Article 50 also runs alongside existing law. GDPR transparency duties and data protection impact assessments apply next to the emotion recognition rule, the Digital Services Act adds separate labelling duties for very large online platforms, and a failure to disclose AI interaction can amount to a misleading practice under the Unfair Commercial Practices Directive.
Generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement. Code signatories relying on watermarking must put an interoperability solution for watermark detection in place by 2 February 2027.
Fines run to €15 million or 3% of global annual turnover, whichever is higher.