You run a chatbot on your website or publish AI-generated text and images – and you are wondering whether and how you now have to label it. From 2 August 2026, the transparency obligation under Art. 50 of the EU AI Act becomes binding. This article clarifies concretely what must appear on your site, where, and with what wording. The full legal overview – risk classes, deadlines, fines – is in the article on the AI Act obligations for SMEs .
As of 26 July 2026. This article is not legal advice. For a binding assessment of your website, consult a lawyer or your data protection officer.
Provider or deployer? Why it determines your obligations
The AI Act distinguishes between providers, who develop or place an AI system on the market, and deployers, who use it. If you use a purchased chatbot or an AI text tool on your website, you are, as a rule, a deployer. For deployers, the obligations under Art. 50 are manageable: you must establish transparency – that is, disclose that an AI is involved. The technically more demanding provider obligations (such as machine-readable marking at the source) lie with the maker of the system. This role question determines what you have to do yourself and what your tool provider supplies.
Labelling the chatbot: the right notice in the right place
Art. 50(1), as part of the transparency obligation , requires that users recognise, before interacting, that they are communicating with an AI and not a human – unless it is already obvious. A human-named, naturally phrasing service bot does not meet that obviousness exception under the Commission's interpretation. Placement is decisive: the notice belongs visibly at the start – as an opening bot message and as a static label on the chat window. A sentence hidden in the privacy policy is not enough, because the information must be given in good time and clearly.
Example wording for the chatbot greeting: "Note: you are chatting with an AI assistant, not a person. For personal matters, you can reach our team via the contact form."
AI text & images: what you must label – and what you need not
Precision pays here, because not every AI text needs labelling. Art. 50(4) requires the disclosure of AI-generated or manipulated content in two core cases: first, deepfakes – artificially created or altered image, audio and video content resembling real people, places or events – must always be marked as artificially created. Second, AI-generated text that informs the public on matters of public interest. Exempt is content that has undergone human editorial review with editorial responsibility. An AI-assisted but editorially reviewed product text therefore typically falls outside the obligation – an automatically published AI news text does not. AI labelling sums up what to do in each case.
Machine-readable marking – what affects deployers
Art. 50(2) additionally requires AI-generated content to be marked in a machine-readable way – for example via watermark or metadata. This obligation primarily concerns the provider of the generative system, not the deployer embedding it. A transition period also applies to machine-readable marking: generative AI already on the market before 2 August 2026 has until 2 December 2026. Important: this transition concerns only the machine-readable marking – not the visible chatbot notice under paragraph 1, which applies immediately from 2 August 2026.
And data protection? The GDPR seam at the chatbot
Labelling under the AI Act is only half of it. If your AI chatbot processes personal user input – often via an external, sometimes US-based service – GDPR obligations are added: a legal basis, a data processing agreement, a deletion concept. How to build a chatbot that meets both – GDPR-compliant and AI-Act compliant – is shown in the technical deep-dive article.
Implementation on the page: what goes where
For the typical SME website, Art. 50 reduces to a few clearly placed elements:
| Place on the page | What must be there | Example wording |
|---|---|---|
| Chat window (greeting) | Notice before the first interaction that it is an AI | "You are chatting with an AI assistant." |
| Chat window (static label) | Permanently visible label on the widget | "AI assistant" in the chat window header |
| AI-generated images/videos | Deepfake / synthetic marking | "Created with AI" as a visible image note |
| Privacy policy | Addition on the chatbot's data processing | Paragraph on provider, purpose, legal basis, deletion |
Website labelling from 2 Aug 2026 – place, obligation, example
In short
- As a deployer you must establish transparency from 2 Aug 2026; provider obligations lie with the tool maker.
- Chatbot notice visible before the interaction – not only in the privacy policy.
- Always label deepfakes; label AI texts only for matters of public interest and without editorial responsibility.
- Machine-readable marking (para. 2) primarily concerns the provider; transition for existing generative AI until 2 Dec 2026.
- Implementation is lean: a label on the chat window, marking of AI content, a privacy-policy addition.
