The European Commission began enforcing the AI Act's transparency requirements on 2 August 2026. Most coverage is written for AI teams. This is the part that lands on the people running conversational channels.

The obligation#

Providers of AI systems that interact directly with people must ensure those people are informed they are dealing with an AI rather than a human — unless it would be obvious to a reasonably observant, reasonably well-informed person.

The scope named in commentary on the rules is broad: chatbots, AI voice assistants, AI companions, bots on social networks, and agentic systems that autonomously contact individuals. An automated support agent on WhatsApp is squarely inside it.

Where an agent acts on someone's behalf, the identity of that person or entity is also covered.

Article 50 is narrower than most summaries of it, and the narrowness is the useful part. Reading it as "the EU regulates AI in customer service" produces a compliance programme far larger than the text requires.

The obligationNot the obligation
Who it bindsWhoever deploys the system in an interaction with a personWhoever built the model
What must happenThe person is informed they are interacting with an AI systemAny restriction on what the system may do
WhenClearly, and at the first interactionOn request, or in the terms of service
ExceptionWhere it is obvious to a reasonably informed personWhere you would prefer not to mention it
Consequence of silenceNon-compliance from 2 August 2026A ban on automated support
The whole obligation is disclosure. That is why it is cheap to comply with and expensive to be caught ignoring.

The presentation requirement is the operative part#

The obligation is not merely that the information exists somewhere. It must reach the person clearly and distinguishably, at the latest at the time of the first interaction, and meet applicable accessibility requirements.

Analysis of the rules is consistent about what fails this test: information buried in terms and conditions, or hidden behind layers of menus, does not satisfy it. If it can easily be overlooked, it does not count.

For a messaging channel that has practical consequences, because there is no interface chrome to put a persistent label in. The disclosure has to be in the message stream, and it has to be near the beginning.

It does not displace anything else#

The GDPR, the Digital Services Act, consumer protection law and accessibility legislation continue to apply in parallel and must be reconciled with the AI Act. Satisfying Article 50 does not discharge a GDPR obligation, and vice versa.

This is worth saying inside your organisation early, because the instinct is to assume the privacy notice already covers it.

Five obligations on one automated reply

  1. Lawful basis

    GDPR. Whether you may process this person's data at all. Untouched by Article 50.

  2. Consent to contact

    Per channel, per purpose. A separate question from data processing, and also untouched.

  3. Channel policy

    The platform's own rules on automation and on who may open a conversation.

  4. Article 50 disclosure

    The person must know they are talking to an AI system. New from 2 August 2026.

  5. Sector rules

    Finance, health, and services to children each add requirements this Act does not.

Article 50 sits in the middle of a stack. Satisfying it discharges exactly one layer, and the layers below it were already there.

What to actually change#

Add disclosure to the first automated message, in plain language, not as a footnote.

Re-disclose after a handover back to automation. If a human took over and then handed back, the person's mental model has changed.

Keep an always-available route to a person, and say so in the same breath. It makes the disclosure meaningful rather than merely present.

Record the disclosure as an event. Per contact, per channel, timestamped — the same shape as a consent record, and best stored in the same ledger. If asked to demonstrate compliance for a specific conversation eighteen months ago, that record is the answer.

Where the boundary is genuinely unclear#

Two areas where reasonable people will read this differently:

Templated automation. A rules-based auto-reply that does not use AI is arguably outside the definition. In practice most modern systems mix rule-based and model-based handling in one flow, which makes the line hard to hold and probably not worth defending.

Assistive drafting. A human agent using AI to draft a reply they then edit and send is a different case from an autonomous agent. The obligation is written around systems that interact directly with people; where a person remains in the loop and is the sender, the analysis differs.

Neither is settled enough to build a strategy on. The defensible default, and the one that costs almost nothing, is to disclose whenever automation is generating what the customer reads.

What to take away#

The obligation is disclosure, and only disclosure. One line, first interaction, in the conversation's language, with a real escalation path. Store it as a record beside consent and enforce it in the send path. It stacks on top of GDPR and channel policy rather than replacing either. Enforcement began 2 August 2026.

Sources

Every claim worth checking, with somewhere to check it.

  1. Safer and more transparent AIEuropean Commission · 2 August 2026
  2. Commission starts enforcing AI Act rules and new transparency requirements on 2 AugustEuropean Commission — Shaping Europe's digital future
  3. The AI Act's Transparency Obligations: Rules, Scope and TimelineStibbe
  4. Is it a bot? EU AI Act transparency rules take effect 2 August 2026Travers Smith