Skip to content

Labelling AI: what chatbots, AI images and AI text have to disclose

Article 50 of the AI Act requires that people can tell when they're talking to an AI and when an image or text comes from one. The European Commission's guidelines now spell out who has to do what — and which notices fall short. An overview for businesses that use AI.

Attila Arndt
Attila Arndt

Triple A Digital, Cologne · · 9 min read

Who it's for
Anyone running a chatbot or AI agent, using AI images in advertising or in a shop, or publishing text written with AI.
What you'll be able to do
Know which of the four labelling duties applies to you, who in the company is responsible, and which notices the Commission considers insufficient.
As of
September 2026
TL;DR

Since 2 August 2026, people must be able to tell that they are talking to an AI or looking at something an AI produced. For most businesses that means the chatbot says at the start that it's an AI, and deceptively realistic AI images or videos carry a visible notice. A line in your terms and conditions won't do. Most advertising copy is not affected, and nor is text that a person has reviewed in substance and taken responsibility for.

What has applied since 2 August

Article 50 of the AI Act is the rule that affects almost every business using AI in front of customers. It has applied since 2 August 2026.1 Unlike the obligations for high-risk systems, which the amending Regulation (EU) 2026/1744 pushed back to 2 December 2027 (and, for AI in regulated products under Annex I, to 2 August 2028), it was not postponed — apart from one transitional period, covered below.2

The overall timetable is set out in the update at the top of the post on the AI inventory. This post is only about labelling.

Since 20 July 2026 there have been European Commission guidelines on the subject.3 They are not binding — as they say themselves, only the Court of Justice of the EU can give an authoritative interpretation.4 But they show how supervisors will read the rule, and they are full of examples. Most of what follows comes from there.

Applies since
2 Aug 20264
Article 50
Transition
2 Dec 20262
machine-readable marking only
Duties
44
in one article
Fines up to
€15m5
or 3% of turnover; for SMEs the lower figure

Four duties, two roles

Article 50 contains four duties aimed at two different parties: the provider, who develops an AI system or has it developed and places it on the market or puts it into service under its own name, and the deployer, who uses it under its own authority — unless purely for personal purposes.1

Who has to label what?
DutyParagraph 1: people are told they are interacting with an AI.
Who it applies toThe provider of the chatbot, voice assistant or agent.
DutyParagraph 2: AI-generated images, audio, video and text are marked in a machine-readable way.
Who it applies toThe provider of the generating system — usually whoever makes the image model, not you.
DutyParagraph 4, first subparagraph: deepfakes are disclosed as artificially generated.
Who it applies toThe deployer, meaning the business that uses the image or video.
DutyParagraph 4, second subparagraph: AI text on matters of public interest is disclosed.
Who it applies toThe deployer that publishes the text — unless a person has reviewed it.
Article 50(1) to (4) of Regulation (EU) 2024/1689. Paragraph 3 covers emotion recognition and biometric categorisation and is left aside here.

Your role depends on what you do, not on how big you are. The guidelines explicitly name as a provider a company that develops a chatbot in-house and puts it into service under its own name for its own use.4 Anyone who modifies an existing system, for example with new training data, and puts it into service under their own name also becomes the provider of the new system.4

By contrast, a company that simply commissions an advertising agency, without deciding whether or how the agency uses AI, is not a deployer under the guidelines.4

The chatbot: it has to say it's an AI

The duty in paragraph 1 is the one most often overlooked, precisely because it sounds so obvious. People interacting with an AI system must be told so — unless it is obvious from the circumstances to a reasonably well-informed, observant person.1

I wouldn't build on that exception. The guidelines say it "should be interpreted restrictively", and point out that general awareness that chatbots exist does not mean people recognise them in a conversation.4

The regulation doesn't prescribe what the notice looks like. The guidelines give examples: a chatbot that opens the conversation by saying it is based on AI; a voice assistant that says so at the start; an email from an AI agent with an AI label at the top.4 The notice has to come at the latest at the first interaction, be clearly recognisable and be accessible.1

What the Commission considers insufficient

The guidelines list notices that are not enough on their own:4

  • a notice only in the terms and conditions, in a URL or in the documentation
  • a machine-readable mark that the person doesn't perceive during the interaction
  • vague labels such as just "assistant", or a human-looking representation
  • a blanket line like "Services on this website use AI" on a site offering many services
  • a purely technical statement like "this system uses LLMs" that doesn't explain what it means for the user

A single, clearly visible notice before the first interaction is enough in most cases. In riskier contexts — the guidelines name financial, insurance, legal and health advice, as well as complaints handling, among others — repeated notices are likely to be needed.4 And if someone asks the chatbot whether it is a person, it has to tell the truth.4

The same applies to AI agents, with one addition. Agents that book, correspond or negotiate on someone's behalf should, according to the guidelines, disclose both that they are artificial and on whose behalf they are acting.4 More on agents in the post on four questions before an agent gets access.

A notice doesn't make a wrong answer right, by the way. That a business is liable for what its chatbot says was decided by the Higher Regional Court of Hamm in May — details in When your chatbot gets it wrong, you said it.

AI images and video: when an image becomes a deepfake

Under the regulation, a deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.1 Anyone using such content has to disclose that it was artificially generated.

The word suggests fake political speeches, but it covers product images too. The guidelines explicitly count machinery and consumer goods as "objects".4 And they give as an example of a deepfake an AI-generated image of a product in advertising or on packaging that can mislead as to the product's actual appearance, characteristics or use.4

The line doesn't run between real and artificial, but between harmless and misleading. The guidelines' examples show it:4

Deepfake or not? Examples from the guidelines
Not a deepfakeA real product, such as a car, against an AI-generated background, as long as the ad doesn't mislead about the product.
DeepfakeAn AI product image that makes the product look more appealing or higher quality than it is.
Not a deepfakeUsually: colour correction, extended backgrounds, arranging existing products or resizing in advertising.
DeepfakeA teleshopping-style video in which synthetic people demonstrate the product.
Not a deepfakeMice arguing about the best cheese in an advert for a cheese maker.
DeepfakeA realistic synthetic CEO congratulating staff on the year's results.
Summarised from section 6.1.1 of the guidelines. What matters is whether the content can mislead as to authenticity or truth — not whether it is photorealistic.

For evidently artistic, satirical or fictional works, a notice that doesn't spoil the work is enough.1 The EU has created a set of icons that deployers can use for labelling.6

AI text: usually not affected, with one exception

The text rule is narrower than many people think. Disclosure is only required for AI text published to inform the public on matters of public interest.1 The guidelines name topics such as politics, public administration, public health, environmental protection, consumer safety and economic developments that may be the subject of public debate.4

Explicitly outside the scope: AI-edited text in advertising and product descriptions, as long as it makes no claims about, for example, health, consumer safety or sustainability. Likewise internal texts on a corporate network and advice written for an individual client.4

And even within the scope, the duty falls away if two conditions are both met: a person has reviewed the text in substance, and someone holds editorial responsibility.1

The guidelines take "reviewed in substance" seriously. Fact-checking is the minimum; spell-checking, the mere existence of an editorial policy or a cursory sign-off don't count.4 And if you have the AI rework the text after sign-off, you lose the exception again.4

One example from the guidelines that concerns businesses: a sustainability report on a listed company's website that professionals, for instance from compliance, have reviewed falls under the exception.4 Without that review, the exception doesn't apply.

Machine-readable marking and the December deadline

Paragraph 2 requires AI output to be marked in a machine-readable format and detectable as artificially generated.1 That is the duty of the provider of the generating system. If you create images with an image model you've bought in, it usually isn't yours.

This is where the only transitional period applies. Providers whose systems were already on the market before 2 August 2026 have until 2 December 2026 to add the marking.2 The guidelines make clear that this only covers marking: a system that both generates content and talks to people has had to give the AI notice since 2 August.4

The deadline matters to you if you offer a generating system of your own — say, an image generator for customers. Then you are the provider, and 2 December is your deadline.

You don't have to label anything retroactively: content generated before 2 August 2026 doesn't need to be marked or labelled after the fact. Text on matters of public interest that was generated before but published after that date does.4

What happens if you don't

Breaches of Article 50 can be fined up to €15 million or up to 3% of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises, the lower of the two applies.5

In Germany, the Federal Network Agency has been the central point of contact and complaints body for the AI Act since 29 July 2026.7 According to the guidelines, anyone with grounds to suspect a breach can lodge a complaint.4

Anyone who signs a code of practice that the Commission has assessed as adequate can rely on its measures. There is such a code for labelling AI content; the Commission and the AI Board have confirmed it as an adequate voluntary tool.6

What I would do now

Most of the work isn't the implementation, it's knowing where to look. If you know where in the business an AI talks to people or produces images, can add the labelling where it is needed. If you don't, start with the AI inventory.

Checking your labelling
  • Every point listed where an AI talks to customers, applicants or suppliers — chatbot, phone, email agent
  • For each one, clarified whether you are the provider (own development, own name) or a provider supplies the labelling
  • A notice at the start of every conversation, not just in the terms or the privacy policy
  • AI product images checked for whether they show the product differently from how it is
  • For published text on public topics, decided who reviews it in substance and who signs off
  • Agreed with your agency or service provider who labels AI content they deliver
Get in touch

If you have a chatbot, an agent or an image workflow and aren't sure the notice is in the right place: tell me what it does and where it runs. I'll tell you what's missing according to the guidelines and how much work it is to fix. It is no substitute for legal advice.

Sources

  1. 1Regulation (EU) 2024/1689 (AI Act), Articles 3, 50 and 113 — EUR-Lex · retrieved 23 September 2026
  2. 2Regulation (EU) 2026/1744 (Digital Omnibus on AI), recital 38 and new Article 111(4) — EUR-Lex · retrieved 23 September 2026
  3. 3European Commission: Guidelines on transparency obligations for providers and deployers of AI systems (20 July 2026) · retrieved 23 September 2026
  4. 4European Commission: Guidelines on Article 50, C(2026) 5054 final, annex (PDF) · retrieved 23 September 2026
  5. 5Regulation (EU) 2024/1689, Article 99(4) and (6) — EUR-Lex · retrieved 23 September 2026
  6. 6European Commission: Code of Practice on Transparency of AI-generated Content · retrieved 23 September 2026
  7. 7Bundesnetzagentur: takes on central role in implementing the AI Act (29 July 2026, in German) · retrieved 23 September 2026
Questions

Answered in brief

Do I have to label every text I wrote with AI?

No. Article 50(4) only covers text published to inform the public on matters of public interest — and not even that if a person has reviewed its substance and someone holds editorial responsibility. The Commission's guidelines explicitly list advertising copy and product descriptions as outside the scope, as long as they make no claims about, for example, health, consumer safety or sustainability.

Am I a provider or a deployer if I put a chatbot built on someone else's language model on my website?

It depends on the case. The guidelines give as an example of a provider a company that develops a chatbot in-house and puts it into service under its own name for its own use. Anyone who modifies an existing system and puts it into service under their own name also becomes the provider of the new system. For labelling the chatbot, the provider's role is what counts.

Do I need to label old AI images after the fact?

According to the guidelines, no: content generated before 2 August 2026 doesn't need to be labelled retroactively. Text on matters of public interest that was generated before that date but is only published on or after it does need the label.

Related

What I do in this area


Keep reading

Attila Arndt

Attila Arndt · Triple A Digital, Cologne

Is there a process like this in your company?

Pick a time that suits you. In the intro call, we'll work out which process is worth tackling first — and whether I'm the right person for it.

Free intro call (opens in a new tab)

Or email me directly: hello@tripleadigital.de · I reply within 48 hours.