In AI Act outreach content, there's a simplification repeated so often that almost no one questions it anymore: "if you have a chatbot, from 2 August you have to disclose that it's an AI." The idea captures the outcome the Regulation is after well enough — that no one should talk to a machine believing they're talking to a human. But it attributes the obligation to the wrong subject. And in compliance work, getting the subject wrong isn't a minor detail: it means taking on, in your documentation, obligations that aren't yours, while neglecting the ones that are.
What Article 50(1) actually says
Article 50(1) places the obligation on providers: those who develop and place the system on the market must design it so that people know they are interacting with an AI, unless this is obvious from the context. It's an obligation about product design, not about use. The notice "you're talking to a virtual assistant" has to come built in, because it's the manufacturer who is answerable for it existing.
Does that mean the company deploying the chatbot — the clinic using it for appointments, the distributor using it for support — can wash its hands of it? No. But its role is of a different nature: it's verification due diligence, not a design obligation. In practice, that comes down to three actions:
- Check that the notice is there before putting the system in front of customers. If the product you contracted doesn't disclose that it's an AI, that's the provider's problem — but you're the one with an interest in catching it, because it's your customer on the other end.
- Don't remove it or hide it. Configuring the widget to suppress the notice, or burying it where no one sees it, turns a product that got this right into a problematic deployment. Due diligence includes not breaking what the provider did well.
- Record the check. One line in the system's file — what was checked, when, with what result — turns an invisible action into evidence you can show.
Why the nuance matters
It may sound like a lawyer's fine distinction, but it has very concrete consequences for an SME.
First: your documents must reflect your actual role. If your policy or your compliance file says that you "comply with Article 50(1)", you're putting in writing a provider obligation that isn't yours. The day someone reviews that documentation, the imprecision works against you: it suggests you don't distinguish your position in the chain. The correct approach is to document your due diligence: "verified that the system discloses its nature; check carried out on [date]".
Second: the question you ask the provider changes. Instead of asking yourself "how do I comply with this?", the right question is "does the product I'm contracting comply with this?" It's a due diligence clause, not an internal project. And it's a question that filters providers: the one who answers precisely shows it; the one who doesn't know what you're talking about shows that too.
Third: the rest of Article 50 has its own division of roles. As we covered when reviewing the transparency obligations arriving on 2 August, Article 50 is a package with several sub-paragraphs, and not all of them point to the same subject. Deepfake labelling or the declaration of AI-generated text published on matters of public interest do reach whoever deploys and publishes. Lumping it all together — "Article 50 is my problem" or "Article 50 is the provider's problem" — is a sure way to get something wrong somewhere.
What this looks like in a real case
Take a dental clinic's appointment-booking chatbot. The software provider must deliver the widget with the virtual-assistant notice built in. The clinic, for its part: checks that the notice appears in the actual conversation (not just on the product's sales page), doesn't switch it off when customising the colours and text, and records the check in the system's file. Three actions, fifteen minutes, and the division of roles stays clean: each party answers for its own part, and the clinic can prove it.
That is, in miniature, the right way to read much of the AI Act as a deploying SME: not asking yourself "what huge obligations land on me?", but "what exactly is my role in this chain, and how do I leave evidence that I've met it?" Almost always, the answer is smaller and more concrete than the headline — and precisely for that reason, not doing it has no excuse.
This article is for informational purposes only and does not constitute legal advice.