As of today, any chatbot, voice assistant, or AI tool serving users in the EU has a new, legally enforceable obligation: it has to tell people they are dealing with an AI system. Article 50 of the EU AI Act, the transparency provision covering direct human-AI interaction, synthetic content, emotion recognition, and deepfakes, is now in force. The obligation applies regardless of whether the underlying system is classified as high-risk, and it reaches beyond the EU itself: any business, including UK and US companies, serving EU users is in scope.
The penalty structure is what turns this from a compliance footnote into something a business actually has to act on. Non-compliance can draw fines of up to EUR 15 million or 3% of a company's total worldwide turnover for the preceding financial year, whichever is higher, with the same proportionality considerations for SMEs that run through the rest of the AI Act's enforcement regime.

Source: European Commission, Transparency obligations under Article 50 of the AI Act, captured August 2, 2026.
What Article 50 actually requires
Article 50 sits apart from the AI Act's better-known high-risk classification system. High-risk rules apply based on what a system does, hiring, credit scoring, biometric identification, and similar. Article 50's transparency duties apply based on a much simpler test: is a person interacting with, or being shown output from, an AI system without knowing it. That test catches a lot more software than most businesses assume.
Four categories of AI system carry a disclosure duty under Article 50. Providers of chatbots, AI agents, and similar interactive systems must ensure users are informed they are interacting with an AI system, unless that is already obvious from the context. Providers of systems that generate synthetic audio, image, video, or text content must mark that output in a machine-readable format so it can be detected as AI-generated. Deployers of emotion-recognition or biometric-categorization systems must inform the people exposed to them that the system is operating. And deployers of deepfake tools, AI-manipulated content that resembles a real person, place, or event, must clearly disclose that the content has been artificially generated or manipulated.
There is a narrow carve-out worth knowing about: a limited grace period through December 2, 2026 applies specifically to the machine-readable marking obligation on AI systems that were already on the market before today. The core disclosure obligations, telling a user they are talking to a chatbot, labeling a deepfake, flagging an emotion-recognition system, are not covered by that grace period and are enforceable starting today.
The penalty, and why it applies to non-EU businesses
Figure: Maximum Article 50 penalty as a share of global annual turnover, or EUR 15 million, whichever amount is higher, enforceable from August 2, 2026.
The "whichever is higher" structure means the fixed EUR 15 million figure is really a floor for smaller companies, and the 3% figure is what determines exposure for anyone with meaningful global revenue. A business with EUR 1 billion in annual turnover is not looking at a EUR 15 million cap, it is looking at up to EUR 30 million, because 3% of its turnover is the larger number. Enforcement sits mainly with national market surveillance authorities in each EU member state, with the EU's AI Office and the European Data Protection Supervisor holding narrower oversight roles for general-purpose AI providers and EU institutions respectively.
The extraterritorial reach is the detail that tends to catch non-EU companies off guard. Article 50 does not ask where a business is incorporated or headquartered. It asks whether people in the EU are interacting with the AI system. A UK-based SaaS company running a support chatbot for EU customers, or a US company offering an AI writing tool that EU users can access, falls inside the obligation the same way an EU-based company would. Serving EU traffic is the trigger, not EU incorporation.
What this means for your disclaimer
For most businesses, the practical fix is not a redesign of the AI system, it is making sure the disclosure obligation is actually documented and visible where users encounter the system. A chatbot needs a clear, upfront statement that the visitor is talking to an AI, not a human agent. A tool that generates images, video, or written content on a user's behalf needs disclosure language covering how that output was produced. If a business also markets AI-manipulated media or synthetic voice, that use needs its own explicit callout, since the deepfake disclosure duty is treated separately from general AI-interaction disclosure.
A generic terms of service page does not cover this. What Article 50 asks for is disclosure content that a user actually encounters at the point of interacting with the AI system, which is exactly what a dedicated disclaimer is built to carry. Our Disclaimer Generator includes AI-disclosure language built for this obligation, so a chatbot, AI writing tool, or synthetic-media feature can carry the upfront notice Article 50 now requires, rather than relying on buried terms nobody reads before they start typing.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.