AIEU AI ActAcademy

Do I have to label my website chatbot as AI? Article 50 in practice

The Article 50 transparency obligation under the EU AI Act has applied since 2 August 2026 — with no transition period for deployers. What you have to label, who the December 2026 deadline actually binds, and who enforces it in Germany.

By Florian Obermeier · Marketing Operations Manager
Do I have to label my website chatbot as AI? Article 50 in practice

Yes — unless it is already obvious that the person is talking to a machine, your website chatbot has to identify itself as AI. That requirement sits in Article 50 of the AI Regulation, and it has applied since 2 August 2026. The obligation falls on your company, not on the provider of the language model behind it — with your own website chatbot it falls on you in the provider role, because you put the system into service under your own name.

What you’ll take away:

  • Chatbots and AI assistants must be identifiable as AI where this isn’t already obvious — in force since 2 August 2026.
  • AI-generated text, images, audio and video must be marked in a machine-readable format; deepfakes additionally need a disclosure visible to people.
  • There is no transition period for you as a deployer. The four-month period ending 2 December 2026 sits in Article 50(2) and binds the providers of systems that were already on the market before 2 August 2026.
  • Fines run up to 15 million euros or 3 percent of worldwide annual turnover; for small and medium-sized enterprises, the lower of the two applies.
  • In Germany, the Bundesnetzagentur has been the competent authority since 2 August 2026 — as market surveillance body, national contact point and complaints office.
  • The Digital Omnibus left Article 50 untouched. The relief applies to the high-risk obligations only.

Do I have to label my website chatbot as AI?

Yes, unless it is already obvious to the user. Article 50 of the AI Regulation requires that people can tell when they are interacting with an AI system rather than a human. The obligation sits with the company running the chatbot under its own name on its website, and it cannot be passed back to the vendor.

In practice this is a small intervention: a clear note in the greeting message or in the chat window title, worded so an average visitor understands it. Not buried in the privacy policy, but where the interaction starts. If you run a third-party chatbot, don’t assume the vendor has handled it — the responsibility still sits with you.

By when do I have to label AI-generated content?

Since 2 August 2026, and for you without a transition period. The Article 50 transparency obligations have applied since that date. If you put AI-generated content out today, you have to disclose it today.

The frequently cited deadline of 2 December 2026 concerns a different obligation. It sits in Article 50(2), covers the machine-readable marking of synthetic content in the output format, and is addressed to the providers of systems that were already on the market before 2 August 2026. A company waiting for December is waiting for a date that does not apply to it.

In practical terms: the fact that your image generator may only carry the marking in the file format from December onwards does nothing to change your own duty to visibly label an AI-generated image when it goes out.

What falls under the labelling requirement:

  • Synthetic content: AI-generated text, images, audio and video must be marked in a machine-readable format as artificially generated or manipulated.
  • Deepfakes: image, audio or video material resembling real people or events additionally needs a disclosure visible to humans.
  • Emotion recognition and biometric categorisation: affected people must be informed that the system is in use.
  • Chatbots and assistants: a notice that this is an AI system.

Not every internal use of AI is covered. If AI sorts a spreadsheet for you or improves a draft that a person then edits and takes responsibility for, that doesn’t create a labelling case under Article 50. It becomes relevant where content goes out to the public or where people interact with the system directly.

Am I a provider or a deployer under the AI Regulation?

Usually a deployer. A provider develops an AI system, or places it on the market or puts it into service under its own name; a deployer uses someone else’s system under its own responsibility. A mid-sized company using a language model in marketing or running a third-party chatbot is a deployer.

That distinction decides which paragraphs of Article 50 apply to you, and which deadlines:

  • Deployer duties sit in paragraphs 3 and 4: informing affected people about emotion recognition and biometric categorisation, and visible disclosure for deepfakes and for published text on matters of public interest. Both have applied since 2 August 2026, with no transition period.
  • Provider duties sit in paragraphs 1 and 2: designing a system so people can recognise the AI interaction, and marking outputs in a machine-readable format. The December 2026 deadline exists only there, and only for systems already on the market before 2 August 2026.

Your own website chatbot is a special case. If you put a third-party system on your own site as your own assistant, you put it into service under your own name and move into the provider role. Making clear that an AI is answering is then your job, not the vendor’s. So in neither role can you rely on the vendor: either the duty is yours directly, or you are the one who has to check that the tool you bought meets it.

Who enforces the AI Regulation in Germany?

The Bundesnetzagentur. Since 2 August 2026 it has been the central market surveillance authority for AI, the national contact point and the complaints office. The legal basis is the AI Market Surveillance and Implementation Act (KI-MIG), passed by the Bundestag on 11 June 2026 and approved by the Bundesrat on 10 July 2026.

Alongside it come a coordination and competence centre, AI regulatory sandboxes, and an AI service desk explicitly aimed at smaller companies. For you this has one practical consequence that tends to get lost in the headlines: there is now an address where competitors, customers and employees can file complaints. The risk shifts from an abstract regulatory audit to a concrete third-party report.

Wasn’t the AI Regulation watered down by the Digital Omnibus?

Partly — but not here. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July 2026. It amends more than 40 articles of the AI Regulation. Article 50 is not among them.

What was postponed are the high-risk obligations: standalone systems under Annex III now apply from 2 December 2027, product-embedded ones under Annex I from 2 August 2028. The high-risk classification was also narrowed — systems that merely assist, make workflows more efficient or automate processes are no longer automatically high-risk, provided their failure poses no genuine risk to health or safety. A new “small mid-cap” category with reduced documentation requirements was added as well.

Unchanged: the prohibited practices under Article 5, the transparency obligations under Article 50, the GPAI obligations under Article 53, and the sanctions regime. Anyone who read “all clear” into the Omnibus headlines missed the difference between postponed and switched on.

ObligationStatus since 27 July 2026Applies from
Prohibited practices (Art. 5)unchanged2 February 2025
AI literacy (Art. 4)softened to an obligation to take measures2 February 2025
Transparency / labelling (Art. 50)unchanged, subject to fines2 August 2026, no transition period for deployers (provider legacy systems under para. 2: 2 December 2026)
GPAI obligations (Art. 53)unchanged2 August 2025
High-risk Annex IIIpostponed and narrowed2 December 2027
High-risk Annex Ipostponed2 August 2028

What does the Digital Omnibus change about the AI training obligation?

Article 4 went from a guarantee obligation to an obligation to take measures. The new wording requires providers and deployers to “take measures to support the development of AI literacy among their staff”; the regulation explicitly clarifies that a particular level of knowledge for individual people does not have to be guaranteed.

The obligation has become softer, but it hasn’t disappeared — and it never carried a standalone fine in the first place. For deployers of high-risk AI, qualifying staff for human oversight remains binding. The full breakdown is in How to meet the EU AI Act training obligation in practice.

The interesting part is the shift behind it: the case for training now runs less through Article 4 and more through Article 50. Because only someone who recognises that they are producing AI content can label it.

Why is Article 50 mainly a people topic?

Because the real work isn’t in the technology, it’s with the people. The chatbot notice is a five-minute job. Labelling AI-generated content, by contrast, assumes that marketing, sales and customer service recognise in their daily work when a text, an image or a video needs labelling — and when it doesn’t.

That is role-specific competence, not an IT project. This is exactly what the PASSION4IT Academy is built for: role-specific learning paths, final tests and a certificate as documented proof, with no classroom dates. At 59 euros per user per year the proportions work too — small obligation, small product.

How do I approach this step by step?

Four steps, in this order:

  1. Build an inventory. Which AI systems are running in your company, who operates them, and where does content go out? Without that list, labelling is guesswork — and shadow AI via private accounts appears on no list at all.
  2. Check chatbots and assistants. Does every system identify itself as AI? That’s the quickest item to tick off.
  3. Map your output channels. Where does AI-generated text, imagery or video get produced for customers, applicants or the public? This is where the actual work sits, and it has been due since 2 August 2026.
  4. Qualify the people. Whoever produces content needs to know the rule. Everything else is after-the-fact control.

If you get stuck on step one because nobody can say which AI is actually running: that’s the norm, not the exception. The free AI readiness check on our AI consulting page is the entry point — it costs you a few minutes and gives you an initial baseline before you start thinking about consulting budgets.

Once the list exists and turns into a project, what decides the outcome is support all the way into operations, not the concept. What that means in practice is covered in IT consulting for the mid-market that supports implementation.

Frequently asked questions

Do I have to label my website chatbot as AI?

Yes, unless it is already obvious to the user. Article 50 of the AI Regulation requires that people can tell they are talking to an AI system rather than a human. The obligation falls on your company, including and especially when the chatbot is a third-party product embedded under your own name.

By when do I have to label AI-generated content?

Since 2 August 2026, with no transition period. The deadline of 2 December 2026 concerns the machine-readable marking under Article 50(2) and binds the providers of systems that were already on the market before 2 August 2026. For a mid-sized company using third-party AI tools, the date that matters is therefore 2 August 2026, not December.

Am I a provider or a deployer under the AI Regulation?

Usually a deployer: you use someone else’s AI system under your own responsibility. A provider develops a system or places it on the market or puts it into service under its own name — which can include you, for instance with a third-party chatbot answering under your name on your website. The role decides which paragraphs of Article 50 apply: paragraphs 3 and 4 bind the deployer, paragraphs 1 and 2 the provider.

How high are the fines for breaching Article 50?

Up to 15 million euros or 3 percent of worldwide annual turnover. For small and medium-sized enterprises, the lower of the two figures applies. Unlike Article 4, Article 50 genuinely does carry fines.

Who enforces the AI Regulation in Germany?

The Bundesnetzagentur, since 2 August 2026. It acts as central market surveillance authority, national contact point and complaints office, complemented by AI regulatory sandboxes and an AI service desk for smaller companies. The legal basis is the AI Market Surveillance and Implementation Act (KI-MIG).

What does the Digital Omnibus change about the AI training obligation?

It turned Article 4 from a guarantee obligation into an obligation to take measures: companies must support AI literacy but do not have to guarantee a specific level of knowledge. The obligation remains in place and stays binding for deployers of high-risk AI. Article 4 never carried a standalone fine.

Do I have to label AI used purely internally?

No, not under Article 50. If AI sorts a spreadsheet or improves a draft that a person then edits and takes responsibility for, that isn’t a labelling case. It becomes relevant where content goes out to the public or where people interact with the system directly.

We are not a law firm and don’t replace legal advice. We start where implementation stalls inside the business: which AI is running, which processes produce content that needs labelling, and how you bring the affected roles up to speed. First the honest maturity check, then the prioritised roadmap, then supported implementation.

Is consulting on an AI usage policy eligible for BAFA funding?

Yes, under the “Förderung von Unternehmensberatungen für KMU” programme. PASSION4IT is registered with BAFA (consultant number 222542), and consulting costs up to a 3,500 euro assessment base per engagement are subsidised. Important: the programme expires on 31 December 2026, and the application has to be approved before consulting begins.

Further resources

Want to know which AI is running in your company and who needs to understand the labelling rules? Book a conversation now.

Sources: Regulation (EU) 2026/1744 (Digital Omnibus Regulation on AI), Official Journal of 24 July 2026 · AI Regulation Art. 50(1) to (4) · European Commission guidelines on Article 50 of 20 July 2026 · Bundesnetzagentur, AI topic pages · BMDS press release on the KI-MIG · BAFA, Förderung von Unternehmensberatungen für KMU. As of 24 August 2026, corrected against the version of 4 August 2026: the transition period ending 2 December 2026 binds providers under Article 50(2), not deployers. This article is not legal advice.