Quick answer: Article 50 of the EU AI Act applies from August 2, 2026. A provider of a chatbot or other AI system that interacts directly with people must design it so users are informed that they are dealing with AI, unless that fact is genuinely obvious. For an ecommerce merchant using a third-party bot, the provider normally carries that specific design duty, while the merchant is usually the deployer. The practical response is still the same: map both roles, verify that the disclosure appears clearly at the start of the first interaction, keep it accessible, and do not market an automated sales or support agent as a human.
Updated: September 2, 2026
EU AI Act chatbot disclosure: key takeaways
- Article 50 transparency duties have applied since August 2, 2026.
- The direct-interaction disclosure duty is primarily a provider obligation.
- A merchant using an off-the-shelf chatbot is usually a deployer, but can become a provider if it develops the system or places it into service under its own name or trademark.
- The user should be informed no later than the start of the first interaction.
- The notice must be clear, distinguishable and accessible.
- The “obvious AI” exception is narrow and should not be a default compliance strategy.
- Providers of generative systems also have machine-readable marking duties for synthetic output.
- Deployers have separate duties for deepfakes, emotion recognition, biometric categorisation and certain public-interest text.
- A generic privacy-policy sentence is not a substitute for an in-context chatbot notice.
- Stores should preserve screenshots, vendor documentation, release notes and test records as evidence.
What changed on August 2, 2026?
The European Commission confirms that the AI Act’s Article 50 transparency obligations apply from August 2, 2026. The rules cover several different situations: AI systems that interact directly with people, machine-readable marking of synthetic content, emotion-recognition and biometric-categorisation systems, deepfakes, and certain AI-generated text on matters of public interest.
For ecommerce teams, the most immediate example is a customer-facing chatbot, AI sales associate, shopping assistant or support agent. Article 50(1) requires providers to design and develop these systems so the person is informed that the interaction is with AI, unless this is obvious to a reasonably well-informed, observant and circumspect person in the circumstances.
The Commission’s official Article 50 guidance stresses that people should know when they are interacting with AI and that the information should help them calibrate their trust. The official AI Act Service Desk text of Article 50 states that the notice must be provided clearly, distinguishably and accessibly no later than the first interaction or exposure.
This is not the whole AI Act
Article 50 is a transparency rule, not a universal certification for every AI feature. A product-recommendation model, fraud tool or demand forecast running entirely in the background may not trigger the direct-interaction disclosure rule because it does not itself communicate with a person. Other AI Act, consumer, privacy and platform rules can still apply. Treat the use case, role and data flow separately instead of adding one “AI compliant” badge to the entire store.
Is the store a provider or a deployer?
The role distinction prevents both overclaiming and under-compliance.
| Role | Practical meaning | Ecommerce example |
|---|---|---|
| Provider | Develops an AI system, or has it developed, and places it on the EU market or puts it into service under its own name or trademark. | A platform company sells its own branded AI shopping assistant. |
| Deployer | Uses an AI system under its authority in a professional activity. | A store installs a third-party support bot and configures its catalogue and policies. |
| Both or changed role | A business can take on provider responsibilities through its own development, branding or a sufficiently significant change to the system or its intended purpose. | A merchant commissions a white-label AI agent and launches it as the store’s own product. |
The Commission’s Article 50 questions and answers explains that employees and contractors acting under a company’s authority are not separate deployers; the business remains the deployer.
Why a deployer should still audit the chatbot notice
A merchant may not be the party that wrote the chatbot software, but it selects the tool, chooses its name and avatar, configures messages and places it in front of customers. A missing or misleading notice can create consumer confusion on the merchant’s storefront. Vendor responsibility is not a sensible reason to ignore what shoppers actually see.
If the widget calls itself “Emma from customer care,” uses a realistic human portrait and waits until a footer link to mention automation, the experience can imply a human conversation. The store should demand a compliant in-context notice and remove design choices that contradict it.
Which ecommerce tools are covered?
The Commission describes a directly interactive AI system as one designed for a genuine two-way exchange in which the AI itself communicates with a person. Examples in an online store can include:
- generative product-finder assistants;
- AI sales agents that compare products or build a basket;
- customer-support bots that draft answers from policies and order data;
- AI order-status agents that interpret questions rather than return a fixed lookup result;
- returns or troubleshooting assistants that adapt their answers;
- voice agents handling pre-sale or post-sale calls;
- avatars that demonstrate products or answer questions;
- AI negotiation or wholesale-qualification agents.
What may fall outside the direct-interaction rule?
A static FAQ, a conventional menu-based flow or a form that only collects information may not qualify as an AI system conducting a genuine two-way exchange. Background recommendation engines, stock forecasts and fraud checks also do not directly interact with people merely because their output changes the page. Classification should be based on how the tool works, not on whether the vendor places “AI” in its product name.
This distinction complements our guide to preparing a dropshipping store for AI shopping, which focuses on product visibility and machine-readable catalogue data rather than chatbot transparency.
What should the disclosure say and where should it appear?
Article 50 does not prescribe one universal sentence for every chatbot. It does require clear, distinguishable and accessible information at the latest when the first interaction begins.
A practical notice
A plain example is: “You are chatting with an AI assistant. It can help with products and store policies, but it may make mistakes. Ask for a human at any time.”
The first sentence handles identity. The second sets expectations and makes human escalation easy. Do not weaken the message with euphemisms such as “digital colleague,” “automated intelligence” or “smart concierge” if an ordinary shopper could still believe the agent is human.
Recommended placement
- in the chatbot header or opening message before the first generated answer;
- again after a long dormant session if the context is no longer clear;
- at the start of a voice interaction in an audible form;
- inside the mobile view, not only in desktop hover text;
- in a form that remains perceivable with screen readers and keyboard navigation;
- in the language used by the customer-facing conversation.
A privacy policy can provide detail about data use, retention and vendors, but it is not the right place for the only identity notice. The user should not have to open a legal document to discover that a live-looking support conversation is automated.
Do not rely casually on the obviousness exception
The Commission says the exception should be interpreted restrictively. An “AI” name or robot icon may help, but context matters: a human name, photograph, typing indicator or statement such as “one of our advisers is joining” can point the other way. An explicit sentence is normally cheaper and safer than debating whether every visitor should have understood the design.
AI-generated content, images and deepfakes
Chatbot identity is only one part of Article 50. Providers of systems generating synthetic audio, image, video or text must ensure output is marked in a machine-readable format and detectable as AI-generated or manipulated, subject to the stated technical limits and exceptions.
Deployers have a visible disclosure duty when they publish AI-generated or manipulated image, audio or video that constitutes a deepfake. A deepfake resembles an existing or plausibly existing person, object, place, entity or event and can falsely appear authentic. A wholly invented decorative background is not automatically a deepfake, while a fabricated “customer testimonial” video showing a real-looking person endorsing a product can create much greater risk.
Article 50 also addresses text published to inform the public on matters of public interest. The deployer disclosure does not apply where AI-generated text has undergone human review or editorial control and a person or organisation holds editorial responsibility. That exception does not turn inaccurate product copy into acceptable advertising. Claims about performance, safety, reviews and endorsements still need evidence. See our FTC fake-review guide for the separate US rules on testimonials and incentives.
Shopify and WooCommerce implementation checklist
1. Inventory every interactive surface
- storefront chat widgets;
- embedded product assistants;
- help-centre bots;
- messaging-channel automations;
- voice agents;
- post-purchase and returns assistants;
- AI features supplied by apps, plugins or agencies.
2. Record the legal and operational roles
For each tool, record the software provider, model provider, store entity using the tool, branding, who controls the instructions and whether the store has materially modified the system. Do not assume the app developer and model provider are the same company.
3. Test the first interaction
Open a private browsing window only as a normal user test performed by your own team. Check desktop and mobile, every supported language, guest and logged-in states, and the first message after consent settings load. The notice must not disappear behind a cookie banner or launcher icon.
4. Test accessibility
Use keyboard navigation, browser zoom and a screen reader. Confirm that the disclosure is announced in a logical order, has adequate contrast and does not rely only on colour or an icon. This aligns with the practical checkout and storefront work in our European Accessibility Act guide.
5. Make human handoff real
If the notice promises a human option, test it. Define staffed hours, expected response times and what happens when the bot cannot access the order or gives conflicting information.
6. Control conversation claims
Prevent the bot from inventing delivery guarantees, discounts, stock, return rights, safety claims or compatibility details. Use approved sources, uncertainty language and a clear escalation rule for policy or product-risk questions.
Questions to ask an AI vendor
- Which legal entity is the provider of the customer-facing AI system?
- How does the product satisfy Article 50(1) at the first interaction?
- Can the disclosure be removed, renamed or hidden by store configuration?
- Does the mobile or voice interface use a different disclosure?
- What accessibility testing has been performed?
- Which model providers and subprocessors are involved?
- Does the system generate image, audio, video or text content subject to machine-readable marking?
- How are model and interface changes announced?
- Can the merchant export configuration history and test logs?
- How does human handoff work when an answer is uncertain or sensitive?
- What happens if a customer asks whether the agent is human?
- Can the vendor provide written role and compliance documentation?
A generic “AI Act ready” badge is not enough. Ask for the exact feature, release, interface and responsibility covered by the claim.
Evidence, testing and change control
A working notice today can disappear after an app update, theme redesign or translation change. Build a small evidence file for each AI surface:
- dated screenshots of the first interaction on desktop and mobile;
- the exact disclosure copy in every language;
- keyboard and screen-reader test notes;
- vendor terms, technical documentation and compliance statements;
- the store’s provider/deployer role assessment;
- approved system instructions and prohibited claims;
- human-handoff test results;
- change dates, owners and rollback decisions.
Repeat the test after theme releases, app updates, model migrations, new languages and changes to consent tools. Treat the chatbot like a checkout component, not a one-time marketing installation.
A seven-day ecommerce AI transparency audit
Day 1: inventory
List every AI feature visible to shoppers or support users, including tools embedded by third parties.
Day 2: role map
Identify provider, deployer, model supplier, app developer and the entity responsible for customer communications.
Day 3: disclosure test
Record the first interaction across desktop, mobile, languages and logged-in states.
Day 4: accessibility and handoff
Test keyboard, screen-reader, zoom and human escalation.
Day 5: content controls
Challenge the bot with delivery, return, discount, compatibility and safety questions. Fix invented or unsupported answers.
Day 6: vendor evidence
Collect written documentation and resolve gaps about marking, updates and responsibility.
Day 7: governance
Assign an owner, retest schedule, incident route and approval process for every material change.
Frequently asked questions
Does every ecommerce chatbot need an AI notice?
The direct-interaction duty concerns AI systems. A static FAQ or simple menu flow may not qualify. If a system uses AI for a genuine two-way exchange, the provider must generally ensure the user is informed unless the AI nature is obvious.
Is the merchant always the provider?
No. A merchant using a third-party bot is normally a deployer. It can become a provider if it develops or has the system developed and places it on the market or puts it into service under its own name or trademark, or takes another action that changes its legal role.
Can the disclosure sit only in the privacy policy?
That is unlikely to meet the practical timing requirement. Article 50 says the information should be clear, distinguishable and accessible no later than the first interaction.
Is an “AI” label on the launcher enough?
It may help, but context and clarity matter. A direct sentence in the opening interface provides stronger evidence than relying only on an icon, product name or assumption.
Must the store label every AI-written product description?
Article 50 does not create a blanket visible label for every piece of commercial text. Provider marking duties and deployer duties for public-interest text are narrower. Misleading-advertising and consumer-protection rules still apply to the substance of product claims.
What about AI product images?
Providers can have machine-readable marking duties for synthetic images. A deployer has a visible Article 50 duty when the image constitutes a deepfake. Even when that definition is not met, a merchant should not use synthetic imagery that materially misrepresents the product.
Does a human-review statement remove the chatbot notice?
No. Human editorial review is relevant to a specific rule for public-interest text. It does not remove the separate requirement for providers of directly interactive AI systems to inform users that they are interacting with AI.
Who enforces Article 50?
National market-surveillance authorities, the AI Office for systems under its supervision and the European Data Protection Supervisor for EU institutions have enforcement roles described by the Commission.
Practical next step: Open your store on a phone as a first-time visitor and start the AI chat. Before reading the first generated answer, can you clearly tell that the agent is AI, understand what it can do and request a human? Save a dated screenshot. If any answer is no, fix the opening interaction before adding more automation.
Editorial disclaimer: Dropshipper Lab is an independent educational website and is not affiliated with or endorsed by the European Commission, the AI Office, Shopify, WooCommerce or any AI vendor. This article summarizes public EU guidance reviewed on September 2, 2026. It is general educational information, not legal advice. Classification, provider/deployer roles, exceptions, consumer law, privacy duties and national enforcement should be assessed for the exact system and deployment.
Disclosure: This article may contain affiliate links. If you make a purchase through one of these links, the author may earn a commission at no additional cost to you. This does not influence the content or our evaluation of the products and services discussed.

