Do I have to label my website chatbot as AI? Article 50 in practice
The Article 50 transparency obligation under the EU AI Act has applied since 2 August 2026. What you have to label, why 2 December 2026 is the deadline that matters, and who enforces it in Germany.
Yes — unless it is already obvious that the person is talking to a machine, your website chatbot has to identify itself as AI. That requirement sits in Article 50 of the AI Regulation, and it has applied since 2 August 2026. The obligation falls on the deployer, meaning your company — not the provider of the language model behind it.
What you’ll take away:
- Chatbots and AI assistants must be identifiable as AI where this isn’t already obvious — in force since 2 August 2026.
- AI-generated text, images, audio and video must be marked in a machine-readable format; deepfakes additionally need a disclosure visible to people.
- Systems already placed on the market before 2 August 2026 get a four-month transition period, ending on 2 December 2026.
- Fines run up to 15 million euros or 3 percent of worldwide annual turnover; for small and medium-sized enterprises, the lower of the two applies.
- In Germany, the Bundesnetzagentur has been the competent authority since 2 August 2026 — as market surveillance body, national contact point and complaints office.
- The Digital Omnibus left Article 50 untouched. The relief applies to the high-risk obligations only.
Do I have to label my website chatbot as AI?
Yes, unless it is already obvious to the user. Article 50 of the AI Regulation requires that people can tell when they are interacting with an AI system rather than a human. The obligation applies to the deployer of the system — the company running the chatbot on its website.
In practice this is a small intervention: a clear note in the greeting message or in the chat window title, worded so an average visitor understands it. Not buried in the privacy policy, but where the interaction starts. If you run a third-party chatbot, don’t assume the vendor has handled it — the responsibility still sits with you.
By when do I have to label AI-generated content?
For systems placed on the market after 2 August 2026, the obligation applies immediately. For systems already in use at that point, a four-month transition period applies — it expires on 2 December 2026. In practice that covers just about every chatbot and content tool that has been running for a while.
That makes the December date the one that actually matters for mid-sized companies. Anyone who discovered in August that their systems don’t label yet has until then — but no longer. The transition rule is in the regulation text; before larger rebuilds it’s worth checking the consolidated version, because it applies differently depending on the system type.
What falls under the labelling requirement:
- Synthetic content: AI-generated text, images, audio and video must be marked in a machine-readable format as artificially generated or manipulated.
- Deepfakes: image, audio or video material resembling real people or events additionally needs a disclosure visible to humans.
- Emotion recognition and biometric categorisation: affected people must be informed that the system is in use.
- Chatbots and assistants: a notice that this is an AI system.
Not every internal use of AI is covered. If AI sorts a spreadsheet for you or improves a draft that a person then edits and takes responsibility for, that doesn’t create a labelling case under Article 50. It becomes relevant where content goes out to the public or where people interact with the system directly.
Who enforces the AI Regulation in Germany?
The Bundesnetzagentur. Since 2 August 2026 it has been the central market surveillance authority for AI, the national contact point and the complaints office. The legal basis is the AI Market Surveillance and Implementation Act (KI-MIG), passed by the Bundestag on 11 June 2026 and approved by the Bundesrat on 10 July 2026.
Alongside it come a coordination and competence centre, AI regulatory sandboxes, and an AI service desk explicitly aimed at smaller companies. For you this has one practical consequence that tends to get lost in the headlines: there is now an address where competitors, customers and employees can file complaints. The risk shifts from an abstract regulatory audit to a concrete third-party report.
Wasn’t the AI Regulation watered down by the Digital Omnibus?
Partly — but not here. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July 2026. It amends more than 40 articles of the AI Regulation. Article 50 is not among them.
What was postponed are the high-risk obligations: standalone systems under Annex III now apply from 2 December 2027, product-embedded ones under Annex I from 2 August 2028. The high-risk classification was also narrowed — systems that merely assist, make workflows more efficient or automate processes are no longer automatically high-risk, provided their failure poses no genuine risk to health or safety. A new “small mid-cap” category with reduced documentation requirements was added as well.
Unchanged: the prohibited practices under Article 5, the transparency obligations under Article 50, the GPAI obligations under Article 53, and the sanctions regime. Anyone who read “all clear” into the Omnibus headlines missed the difference between postponed and switched on.
| Obligation | Status since 27 July 2026 | Applies from |
|---|---|---|
| Prohibited practices (Art. 5) | unchanged | 2 February 2025 |
| AI literacy (Art. 4) | softened to an obligation to take measures | 2 February 2025 |
| Transparency / labelling (Art. 50) | unchanged, subject to fines | 2 August 2026 (existing systems: 2 December 2026) |
| GPAI obligations (Art. 53) | unchanged | 2 August 2025 |
| High-risk Annex III | postponed and narrowed | 2 December 2027 |
| High-risk Annex I | postponed | 2 August 2028 |
What does the Digital Omnibus change about the AI training obligation?
Article 4 went from a guarantee obligation to an obligation to take measures. The new wording requires providers and deployers to “take measures to support the development of AI literacy among their staff”; the regulation explicitly clarifies that a particular level of knowledge for individual people does not have to be guaranteed.
The obligation has become softer, but it hasn’t disappeared — and it never carried a standalone fine in the first place. For deployers of high-risk AI, qualifying staff for human oversight remains binding. The full breakdown is in How to meet the EU AI Act training obligation in practice.
The interesting part is the shift behind it: the case for training now runs less through Article 4 and more through Article 50. Because only someone who recognises that they are producing AI content can label it.
Why is Article 50 mainly a people topic?
Because the real work isn’t in the technology, it’s with the people. The chatbot notice is a five-minute job. Labelling AI-generated content, by contrast, assumes that marketing, sales and customer service recognise in their daily work when a text, an image or a video needs labelling — and when it doesn’t.
That is role-specific competence, not an IT project. This is exactly what the PASSION4IT Academy is built for: role-specific learning paths, final tests and a certificate as documented proof, with no classroom dates. At 59 euros per user per year the proportions work too — small obligation, small product.
How do I approach this step by step?
Four steps, in this order:
- Build an inventory. Which AI systems are running in your company, who operates them, and where does content go out? Without that list, labelling is guesswork — and shadow AI via private accounts appears on no list at all.
- Check chatbots and assistants. Does every system identify itself as AI? That’s the quickest item to tick off.
- Map your output channels. Where does AI-generated text, imagery or video get produced for customers, applicants or the public? This is where the actual work sits before 2 December 2026.
- Qualify the people. Whoever produces content needs to know the rule. Everything else is after-the-fact control.
If you get stuck on step one because nobody can say which AI is actually running: that’s the norm, not the exception. The free AI readiness check on our AI consulting page is the entry point — it costs you a few minutes and gives you an initial baseline before you start thinking about consulting budgets.
Frequently asked questions
Do I have to label my website chatbot as AI?
Yes, unless it is already obvious to the user. Article 50 of the AI Regulation requires that people can tell they are talking to an AI system rather than a human. The obligation falls on the deployer — your company — even when the chatbot is a third-party product.
By when do I have to label AI-generated content?
For systems placed on the market after 2 August 2026, the obligation applies immediately. For systems that were already running before that date, the four-month transition period ends on 2 December 2026. For most mid-sized companies, the December date is the decisive one.
How high are the fines for breaching Article 50?
Up to 15 million euros or 3 percent of worldwide annual turnover. For small and medium-sized enterprises, the lower of the two figures applies. Unlike Article 4, Article 50 genuinely does carry fines.
Who enforces the AI Regulation in Germany?
The Bundesnetzagentur, since 2 August 2026. It acts as central market surveillance authority, national contact point and complaints office, complemented by AI regulatory sandboxes and an AI service desk for smaller companies. The legal basis is the AI Market Surveillance and Implementation Act (KI-MIG).
What does the Digital Omnibus change about the AI training obligation?
It turned Article 4 from a guarantee obligation into an obligation to take measures: companies must support AI literacy but do not have to guarantee a specific level of knowledge. The obligation remains in place and stays binding for deployers of high-risk AI. Article 4 never carried a standalone fine.
Do I have to label AI used purely internally?
No, not under Article 50. If AI sorts a spreadsheet or improves a draft that a person then edits and takes responsibility for, that isn’t a labelling case. It becomes relevant where content goes out to the public or where people interact with the system directly.
How is PASSION4IT different from legal advice on the AI Act?
We are not a law firm and don’t replace legal advice. We start where implementation stalls inside the business: which AI is running, which processes produce content that needs labelling, and how you bring the affected roles up to speed. First the honest maturity check, then the prioritised roadmap, then supported implementation.
Is consulting on an AI usage policy eligible for BAFA funding?
Yes, under the “Förderung von Unternehmensberatungen für KMU” programme. PASSION4IT is registered with BAFA (consultant number 222542), and consulting costs up to a 3,500 euro assessment base per engagement are subsidised. Important: the programme expires on 31 December 2026, and the application has to be approved before consulting begins.
Further resources
- The 2 August 2026 compliance trap: why the EU AI Act already affects your day-to-day business — the three baseline obligations at a glance, including the supply-chain duties under Art. 23 and 24.
- AI literacy mandatory training in the DACH region: proof for authorities — what credible proof of competence has to contain.
Want to know which AI is running in your company and who needs to understand the labelling rules? Book a conversation now.
Sources: Regulation (EU) 2026/1744 (Digital Omnibus Regulation on AI), Official Journal of 24 July 2026 · AI Regulation Art. 50 · Bundesnetzagentur, AI topic pages · BMDS press release on the KI-MIG · BAFA, Förderung von Unternehmensberatungen für KMU. As of 4 August 2026. This article is not legal advice.