EU AI Act · Article 50

In force

Article 50 has applied since 2 August 2026.

Does your chatbot
have to say it's
a chatbot?

Article 50 requires AI systems that talk to people to be built so the person knows it's an AI. The duty lands on whoever builtthe assistant — so if you made yours, or paid someone to, it's yours. If you licensed it, it's your vendor's. Paste your address: we'll show you what's actually running on your site and which side of that line it puts you on.

Free · no account · the report is public and shareable

Read this before you trust us

Three things we will never tell you

Compliance tools sell fear because fear converts. It also gets you a report your lawyer throws away. Here is exactly where our scan stops — written down before you paste anything.

That you're compliant

We read your server-rendered HTML. We don't execute JavaScript, so a widget injected by a tag manager can hide from us entirely — and we can't see what your assistant says at first interaction, which is the moment Article 50 actually cares about. “Not detected” means not detected. It never means compliant, and every report carries its own limitations.

That you're in breach

Article 50(1) binds the provider of an AI system — whoever built it, or had it built, and runs it under their own name. Buy a chatbot off the shelf and you're a deployer: the vendor carries that duty, and Article 50 asks nothing of you. Build it yourself on an API, or pay an agency for a bespoke one, and you are the provider. We can see the assistant. We can't see which of those you did, so we ask instead of accusing.

That your live chat is a problem

Article 50 applies to AI systems. A human answering your chat doesn't trigger it, so we report that as fine rather than counting it as a finding. Vendors that ship both a human inbox and an AI tier look identical from outside, so we say we can't tell instead of guessing. A scanner that flags every chat widget is selling fear.

How it works

Twenty seconds to a report you can forward to your lawyer

  1. 01

    You paste a URL

    No account, no card, no sales call. One input.

  2. 02

    We read the page

    We fetch your HTML and match it against 23 known assistant and chat vendors, each classed by whether it's an AI product, a widget with an optional AI tier, or human live chat. Then we look for disclosure wording.

  3. 03

    You get the questions

    A public, shareable report: what we found, what we couldn't see, which Article 50 paragraph each finding engages, and who is likely on the hook for it.

The law itself

Article 50, and who each paragraph actually binds

Most of Article 50 lands on whoever builds the AI system, not on you. Two paragraphs land on the business using it. Knowing which is which is the whole game.

Art. 50(1)

Binds the provider

AI systems that interact directly with people must be designed so the person knows they are dealing with an AI.

Binds the PROVIDER of the system — whoever developed it (or had it developed) and put it into service under their own name. If you EMBED a third-party assistant off the shelf, you are a deployer and this paragraph does not bind you: the vendor carries it. If you BUILT your assistant, or paid someone to build it for you, you are the provider and it does bind you. No duty where the AI nature is obvious to a reasonably well-informed, observant and circumspect person — though the Commission's final Guidelines (C(2026) 5054 final ¶45) say helpdesk chatbots do NOT meet that exception. Law-enforcement carve-out also applies.

Art. 50(2)

Binds the provider

Providers of generative AI must mark synthetic audio, image, video and text in a machine-readable way so it is detectable as AI-generated.

Binds the PROVIDER of the generative system, including general-purpose AI. Does not apply where the AI performs an assistive function for standard editing. Systems placed on the market before 2 August 2026 have until 2 December 2026 (Digital Omnibus grace period).

Art. 50(3)

Binds the deployer

Deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to them.

Binds the DEPLOYER, and carries GDPR obligations alongside. Narrow scope — most websites are unaffected.

Art. 50(4)

Binds the deployer

Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest.

Binds the DEPLOYER — this one lands squarely on ordinary businesses publishing AI-written content, and cannot be pushed onto a vendor. Artistic, creative or satirical works need only disclose in a manner that does not hamper enjoyment. Text that has undergone human review or editorial control, where a person holds editorial responsibility, is exempt.

Art. 50(5)

Binds both

The disclosure must be given clearly and distinguishably at the latest at the first interaction or exposure.

This is the paragraph a static scan cannot verify, and the one the deployer controls in practice. It is why our free report checks for the PRESENCE of disclosure language but never certifies timing. A statement buried in terms and conditions does not satisfy it — the information has to be perceivable in the interaction itself.

Art. 50(6)

Binds both

Article 50 does not displace other obligations — including Chapter III high-risk duties or other Union/national transparency law.

Clarificatory — creates no duty of its own. Relevant to us because it means an Art. 50 disclosure does not discharge GDPR or sectoral duties, and we must not imply that it does. It is also the hook for the point that a pure deployer's real exposure today is UCPD (passing a bot off as human is plausibly a misleading commercial practice) and GDPR — not Art. 50.

Art. 50(7)

Binds the provider

The AI Office facilitates codes of practice on detection and labelling of artificially generated content; the Commission may approve them by implementing act.

Art. 50 has SEVEN paragraphs, not six. The Code of Practice on Transparency of AI-Generated Content was published final on 10 June 2026 and the Commission's 8 July 2026 Opinion found it adequately covers Art. 50(2), (4) and (5) — NOT 50(1). There is no code for chatbot disclosure. Adherence is voluntary and is NOT a safe harbour: the Art. 50(7) implementing-act approval has not happened. Never tell a customer that signing the Code makes them compliant.

What the Digital Omnibus changed

Some of the AI Act just got delayed. Not this part.

The Digital Omnibus on AI pushed the high-risk obligations back to 2 December 2027and later. Those are real deadlines. They are not this one, and we won't point at them to make you move faster.

Article 50 was not deferred. It applies from 2 August 2026. One part of it does have a grace period — machine-readable marking of AI-generated content under 50(2), and only for systems already on the market before then, which have until 2 December 2026.

That's the entire urgency case, stated plainly. We'd rather you know the deadline you actually have than the one that sells better.

Every date on this page is read from our legal corpus, where each one carries its source and the date we last verified it against it.

Article 50 is in force. Find out where you stand.

The scan is free and takes about twenty seconds. If we find nothing, the report says we found nothing — and tells you what it couldn't see.

Need the notice hosted and re-checked every week? See pricing.

aiterms is not a law firm and this is not legal advice. We report what we observed on a page, name the Article 50 paragraphs it engages, and generate documents you can use. We do not certify compliance, and no scan can. If your exposure is material, the output of this tool is the beginning of a conversation with a lawyer, not a substitute for one.