Contents Machine disclosure

Encounters with AI

Machine disclosure

The judgement

As of 12 September 2026, a provider of a system designed to interact directly with people normally must make the machine interaction known. Article 50(1) places that duty on the provider unless the use of AI is obvious from the context. National market-surveillance authorities enforce it, with limited AI Office competence and the EDPS acting for EU institutions, from 2 August 2026. Article 50(5) requires the same provider, under enforcement by those authorities from that date, to make the disclosure clear, distinguishable, accessible and available no later than the first interaction.1

This diagram shows when that provider disclosure reaches a person and where the main exception applies.

flowchart TD
    A["Direct interaction with AI<br/>such as a chatbot, agent or avatar"] --> B{"Is AI involvement<br/>obvious in context?"}
    B -->|Yes| C["Article 50 disclosure<br/>is not required"]
    B -->|No| D["Provider tells the person<br/>they are interacting with AI"]
    D --> E["Disclosure by first interaction<br/>from 2 August 2026"]
    E --> F["National market-surveillance authority<br/>limited AI Office role<br/>EDPS for EU institutions"]
    A --> G{"Legally authorised<br/>criminal-law use?"}
    G -->|Yes, with safeguards| H["Disclosure exception may apply<br/>unless publicly available<br/>for reporting crime"]

Figure: Provider disclosure reaches the person by first interaction, subject to obviousness and the criminal-law exception.

Commission guidance lists chatbots, AI agents and avatars as examples, although the Regulation itself remains controlling.2 Article 2(1) also extends this provider duty to providers outside the EU when their system’s output is used in the EU. The competent national market-surveillance authority, the AI Office within its limited competence or the EDPS enforces it from 2 August 2026.1

This is a duty on the provider, not a general personal entitlement to demand that every use of software be revealed. Article 50(1) does not require notice that non-interactive, back-office software helped decide an application. If the direct-interaction duty appears to have been breached, Article 85 has allowed any person with grounds for suspicion to complain to the relevant market-surveillance authority since 2 August 2026. The authority uses its national procedures. No single EU-wide form or verified complete list of national portals was identified.1

If the system collects personal data, GDPR Articles 13 and 14 separately require the controller to explain matters such as its identity, purposes, legal basis and relevant automated decision-making. Data-protection authorities and courts have enforced those controller duties since 25 May 2018.3

The high-risk postponements to 2027 and 2028 do not postpone this machine-disclosure rule. It has already applied since August 2026.1

Boundary. This judgement covers direct interaction. It does not establish that a hidden scoring or recommendation system must be announced, and it does not remove the safeguarded exception for certain legally authorised criminal-law systems.

References

Quizzes
  1. A bank’s non-obvious chatbot starts a service conversation without saying it is AI. Which action addresses the missing disclosure through the AI Act route?

    • Complain to the relevant market-surveillance authority
    • Send a GDPR access request to the bank’s data controller
    • Use the bank’s own customer-service complaint process

    An AI Act disclosure concern goes to the relevant market-surveillance authority. GDPR requests address personal-data matters, while customer service is an organisational route.

  2. For a directly interactive AI system whose nature is not obvious, disclosure normally arrives by ____.

    • the first interaction
    • the final service decision
    • the regulator’s eventual response

    The provider’s disclosure must be available no later than the first interaction, rather than after a later decision or complaint.

  3. When an interactive AI system gathers personal data, its AI disclosure can coexist with separate GDPR information duties.

    • True
    • False

    The AI Act disclosure identifies the machine interaction, while the GDPR can require information about the controller, purposes and data processing.

Comments

No comments yet. Start the conversation.