Of all the obligations under the AI Act, the chatbot notice requirement is probably the most quoted and the most misattributed one. The version that circulates goes something like this: if you have a chatbot, you have to disclose that it's an AI. Anyone reading that finds it reasonable, because the practical conclusion is correct.
What doesn't add up is the subject.
What the paragraph says, and who it names
Article 50(1) of Regulation (EU) 2024/1689 opens like this: "Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system…"
Two things are settled in that sentence.
The subject is the provider. Whoever develops the system and places it on the market under its own name — not whoever procures it and puts it on their website.
And the way to comply is through design. "Designed and developed" isn't a decorative formula: it places the obligation at the moment the system is built. A company that deploys a third party's chatbot cannot comply with Article 50(1) even if it wants to, because it doesn't design or develop anything — it only configures what someone else built.
The paragraph also adds an exception that is rarely quoted: the obligation does not apply "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use." If the context makes it clear that a machine is on the other end, the duty falls away. There's also a second, narrower exception for systems authorised by law to detect, prevent, investigate or prosecute criminal offences, unless they are available for the public to report a criminal offence.
Why the confusion is so reasonable
Just reading the article's title is enough: "Transparency obligations for providers and deployers of certain AI systems."
The article covers both subjects. It splits duties between providers and deployers across different paragraphs, and whoever cites "Article 50" without a paragraph number is in fact citing an article that binds both — just not to the same thing.
That's where a task list comes from that many mid-sized companies take on without it being theirs to take on: implementing interaction notices, technically marking the system's outputs, ensuring watermark interoperability. None of that belongs to the deployer, and most couldn't do it even if they decided to try.
So what does fall to the deployer?
Other paragraphs of the same article fall to the deployer, and so does something that doesn't appear in it at all.
From the article: the duties Article 50 itself directs at deployers, which are distinct from the interaction notice and the technical marking. They deserve their own treatment and don't fit here without being oversimplified.
Outside the article, and this is what actually generates work in practice: checking that the provider meets its own obligations. Not as a legal obligation of result — Article 50(1) doesn't impose one — but as basic diligence for whoever puts someone else's system in front of its customers. If the chatbot you procured doesn't disclose that it's an AI, the non-compliance is the provider's, but you're the one your customer sees.
That check is one worth settling before signing, together with the other questions an AI provider should be able to answer in writing.
The other half of Article 50, which isn't yours either
Paragraph 2 follows the same logic and confirms the pattern: marking synthetic content is also the provider's obligation, in a machine-readable format, with its own narrow transitional arrangement.
It's useful to look at them together because it clears up the misconception at its root: the two most-quoted paragraphs of Article 50 — the notice and the marking — both belong to the provider. Whoever trims down a deploying company's task list usually finds that the two bulkiest items were never theirs to begin with.
How this differs from a date error
This series has been tracking a mechanism: statements that stop being accurate without the sentence itself changing — because the date's value changed, because it disappeared from the article, or because the statement lost its qualifier.
The attribution error belongs to a different family, and in one sense it's worse: it was never accurate. It didn't expire — it was wrong from birth. And it survives because its practical conclusion — the chatbot should disclose that it's an AI — is correct, so nobody has a reason to go back and check whose duty it actually was.
The notice isn't the hard part. The hard part is having built a compliance plan on obligations that were never yours, and discovering it when someone asks about the ones that were.
What to check
Three checks, and all three are about record-keeping, not development.
First: for every system that interacts with people, who is the provider. It's the data point that decides who owes what, and it's surprisingly common for it not to be recorded anywhere.
Second: whether the notice exists, and where it comes from. Whether the product ships with it, or someone on your team added it on their own. These are two different situations, and only one of them is stable across a provider update.
Third: whether the context makes it obvious that the other party is an AI. The paragraph's exception exists, and applying it or not is a judgement call — one worth recording with its date and who made it, because that's exactly what someone will ask about later.
None of the three requires advanced legal judgement. All three require the answer to be written down somewhere it will still be in two years, with the date of its last review next to it. That's what a shared folder doesn't give you: not because it can't hold the data, but because it doesn't record who put it there or when it stopped being true.
Content in accordance with Article 50 of Regulation (EU) 2024/1689. Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026) amends paragraph 7 of that article; paragraphs 1 and 2 are cited in their applicable wording.
This article is for informational purposes only and does not constitute legal advice.