28/07/26

Disclosure obligations for interactive AI?

AI & Transparency series – Part 2

In our first blog post in this AI & Transparency series, we introduced the general concepts, scope and timelines of the transparency rules under the AI Act. In this second instalment, we delve into the obligation set out in Article 50(1) AI Act for providers of AI systems that directly interact with natural persons.

The rationale behind this obligation lies in the risks of impersonation and deception. AI systems have become remarkably good at mimicking human conversation. When individuals do not realise they are speaking to a machine, they may place undue trust in its outputs or make decisions based on the false assumption that a human is on the other end. The concern extends beyond individual interactions: deceptive AI-driven content can distort public debate, undermine elections and erode societal trust more broadly. The transparency obligation is designed to close that gap, ensuring that people know when they are dealing with an AI system and can judge the interaction on its own terms.

Before we jump in, we should emphasize that the obligation of Article 50(1) AI Act only applies to the providers of these AI systems, and not the deployers. In practice, however, deployers may need to cooperate to ensure that the disclosure mechanisms embedded in the system function effectively in their deployment context. For more information, see the first blog post in this series.

A deceptively nuanced scope

Article 50(1) AI Act applies to AI systems intended to interact directly with natural persons. The brevity of this scope is deceptive: the provision requires more nuance than first meets the eye.

First, a "genuine" interaction is required, implying a conversational or responsive character. The interaction is typically text-based, but can also occur through auditory, visual or even physical means. Crucially, both sides of the exchange must be able to provide input: the AI system and the natural person. AI-powered recommender systems, spam filters and automated transcribers or translators are therefore excluded, given their one-directional nature. The interaction can take place in (near) real time (e.g. chatbots, hotlines) or not (e.g. via e-mail). Examples include AI-enabled voice assistants for customer support, chatbots for complaints management, AI hotlines for fraud reporting, AI companions and avatars, etc.

Second, the interaction must be direct, meaning that human-mediated interaction falls outside Article 50(1). If a human is in the loop and is being assisted by an AI system to suggest responses, the disclosure obligation under this article does not apply. However, this human involvement must be meaningful. This echoes the prohibition on automated individual decision-making under article 22 of the GDPR, which similarly does not apply where there is meaningful human intervention: the human intermediary cannot simply copy-paste the AI suggestion to circumvent the provision. In other words, the human in the loop must genuinely assess the AI-generated information and make their own decisions. While instructive, the analogy with art. 22 GDPR is not perfect. Article 22 GDPR concerns decisions solely based on automated processing: the focus is on who drives the outcome of a decision. Article 50(1) of the AI Act instead concerns the communicative directness of an interaction: the focus is on who is actually on the other end of the exchange. Where AI-generated and human input are blended – for instance, where a chatbot handles an opening query before a human agent takes over – the disclosure obligation remains applicable. As shown in the section on AI agents below, "direct" does not preclude that there may be multiple steps in the chain between the AI agent and the natural person.

Third, the interaction does not need to be longstanding. Even a single back-and-forth between bot and human qualifies. This means that AI bots on social media that automatically generate a response (other than through pre-determined, rule-based quick messages) following a message posted by a human are in scope.

Fourth, machine-to-machine (M2M) interaction is excluded, similar to how M2M services are excluded from the scope of telecom laws. The scope therefore excludes, for example, interaction between assembly robots in a closed industrial setting. However, if M2M communication is merely a link in a longer chain that ultimately leads to interaction between human and machine, the transparency obligation remains applicable.

AI agents

AI agents are not explicitly mentioned in the AI Act but should nevertheless be considered a type of AI system subject to its obligations. Article 50(1) of the AI Act applies to AI systems 'intended to interact directly with natural persons' – a design-purpose standard. For AI agents, however, the Guidelines extend this to systems that are capable of interacting with a natural person while carrying out its assigned functions, such as scheduling appointments, handling correspondence, conducting negotiations, entering into agreements and completing purchases. This 'capable' standard goes beyond the literal text of the AI Act: it reflects the Commission's view that autonomous agents may encounter human contact even when not primarily designed for it, and that the mere capability of such contact suffices to trigger the obligation. Providers of AI agents should therefore not limit their analysis to the agent's intended use case. They must consider every scenario in which the agent could foreseeably come into contact with a natural person.

The Commission even goes a step further: AI agents capable of interacting with other AI agents must also consider the scenario where those downstream agents can interact with humans. The transparency obligation therefore extends to indirect interaction with natural persons.

Where a provider is unable to predict with confidence at the design stage whether its agent will come into contact with a natural person, the system must be engineered at the level of its architecture, and through its operating instructions, to identify itself in every scenario where such contact is reasonably foreseeable. This includes situations where the individual on the other side is acting in a representative capacity for a legal entity. Disclosure is equally required towards the person directing the agent, at critical junctures such as authorisation requests, status updates and validation checkpoints, as well as at the outset of each new exchange.

When is "obvious" sufficiently obvious?

Article 50(1) provides a notable exception to the transparency obligation: if the fact that the person is interacting with an AI system is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and context of use, then the disclosure obligation does not apply. This benchmark is reminiscent of the 'average consumer' test under consumer or trademark law. Determining the average natural person for a given AI system involves two steps: (i) considering the intended and reasonably likely audience, and (ii) examining how reasonably well-informed, observant and circumspect an average member of that audience is. It is important to note that not only the target audience, but also the potential audience must be considered. While a highly specialised AI system used in life sciences will only be used by subject-matter experts, AI systems aimed at a wider audience (e.g. AI companions) must take into account a diverse composition, including persons with disabilities, elderly people and minors.

"Obviousness" is expected to become a contested concept under the AI Act. The Commission confirms the restrictive nature of this exception and highlights several potentially relevant factors: the anticipated nature of the interaction (i.e. its "look and feel") and the composition of the target and foreseeable audience (i.e. professional and specialised audience vs. general public). Notably, the Commission adds that providers should take into account the rapid advances in AI technology, which make it increasingly difficult to distinguish whether a person is interacting with AI or a human being. Providers of AI systems striving for realism, especially in immersive environments (AR/VR), will be less likely to benefit from this exception. This will be particularly relevant in gaming and artistic contexts.

It is also important to note that there is no exception under Article 50(1) for artistic, satirical or similar purposes, as opposed to the exception under Article 50(4) concerning deepfakes. The disclosure obligation therefore remains applicable unless the fact that one is interacting with AI is obvious.

Finally, article 50(1) AI Act provides for an additional exception for AI systems authorized by law for law enforcement purposes.

The information obligation in practice

Providers must design and develop their AI systems in such a way that natural persons are informed that they are interacting with an AI system. Much like the GDPR requires data protection by design, the AI Act now also requires transparency by design. The notification mechanism must be embedded in the system so that disclosure occurs during operation and at the latest at the time of the first interaction with the natural person.

Article 50(1) does not prescribe a specific disclosure format, leaving providers free to choose an appropriate technique, subject to two conditions: (i) the information must be clear and distinguishable at the latest at the time of first interaction, and (ii) the characteristics of natural persons belonging to vulnerable groups (minors, elderly, persons with disabilities) must be taken into account, to the extent that the AI system is intended or reasonably likely to interact with these categories. In practice, this means that disclosure cannot be buried in general terms and conditions, a URL or technical documentation. Equally, purely technical-level disclosures (e.g. machine-readable markings such as watermarks or metadata) are insufficient on their own. The Commission recommends a multimodal approach, combining textual, auditory and visual techniques to reinforce user understanding.

As to the content of the notification, neither the AI Act nor the Guidelines are overly prescriptive. The Commission states that the disclosure should be appropriate to the context, requiring proper and effective information while avoiding risks of deception or manipulation. Practical examples include a chatbot opening the conversation by stating it is based on AI technology, adding an AI label for visual interactions, and including a spoken disclosure at the beginning of an oral conversation with an AI system.

One way of looking at it, is that it is up to the provider to make it obvious that the person is interacting with AI. Of course, if it is already obvious by nature such as a clearly labelled chatbot interface, or a synthetic voice that no one could plausibly mistake for a human, the disclosure is not required. The more realistic and human-like a system is designed to appear, the less likely it is to qualify for this exception, and the more important timely, explicit disclosure becomes.

Looking ahead

Article 50(1) AI Act may read as a straightforward disclosure rule, but as this post illustrates, its application is anything but simple. Providers will need to make careful assessments of their systems' interaction capabilities, audience composition and disclosure design, all against the backdrop of rapidly evolving AI technology. With 2 August 2026 approaching, now is the time to audit existing AI systems, embed transparency mechanisms and prepare for the compliance demands ahead. In the next instalment of this series, we will turn to Article 50(2) and the marking and detection obligations for AI-generated synthetic content.

Other articles in this blog series

Authors:

  • Thibau Duquin, Associate, Brussels at Stibbe
  • Frederiek Fernhout, Senior Associate, Amsterdam at Stibbe
dotted_texture