If Your Chatbot Talks to Anyone in Europe, It Now Has to Confess
On August 2, with most of the tech industry watching other deadlines, a rule quietly took effect in the European Union that touches nearly every company with a customer-facing website: if your chatbot talks to a person, it now has to say it's a chatbot. Not eventually, not in the terms of service — at first interaction, for every new person who encounters it. The obligation is one of several transparency requirements under Article 50 of the EU's AI Act that the European Commission's AI Office and national regulators began enforcing this month, and it marks the moment Europe's sprawling AI law stopped being a compliance calendar and became a bill.
The requirements themselves read less like technology policy than like basic etiquette, codified. Interactive AI must identify itself unless the fact is obvious to a reasonably observant person — a carve-out that quietly turns product design into a legal question, since a bot that is obviously a bot needs no label. Synthetic images, audio and video must carry machine-readable marks so software can detect their origin. Deepfakes need visible labels. And if an AI system is analyzing someone's emotions or sorting them by biometric category, the person has to be told it's happening.
What makes this a business story rather than a European one is the reach. The Act applies to providers and deployers in any country when the output is used in the EU — and "used in the EU" is generous enough to cover a public website, an open podcast feed, or a YouTube upload. A Kansas City software firm with a support bot and European visitors is in scope. Europe has run this play before: GDPR, the sweeping data-privacy law it passed in 2018, technically only protected people in the EU, but because building one compliant product is cheaper than maintaining a European version and an everyone-else version, its rules became the default for websites worldwide. The AI Act will likely travel the same road — that is how a European regulation becomes, in practice, everyone's regulation. The cookie consent banner followed exactly this path, for better and, as anyone who has clicked through six of them before breakfast can attest, for worse.
The teeth are real. Violations of the transparency obligations carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher — a formula under which the penalty scales with the size of the company that ignores it. Readiness, meanwhile, is not: one industry survey found 78% of organizations in scope had not begun meaningful compliance work as the deadline arrived. That gap between obligation and preparation is where enforcement actions tend to be born, and regulators picking early examples rarely choose the companies that tried.
There is also a message in what Brussels chose not to delay. The transparency rules are only one piece of the AI Act — the law also imposes far heavier requirements on AI used for high-stakes decisions like hiring, credit scoring and medical care, obligating companies to run formal risk assessments and submit systems for review before deployment. Under industry pressure, the EU postponed that heavier tier to December 2027. The disclosure rules, though, kept their date. The audits can wait, in other words. The right to know you're talking to a machine cannot. For companies deciding where to spend a constrained compliance budget, that's about as clear a signal of regulatory priority as Europe ever sends.
The disclosure label itself costs almost nothing — a line of copy, an icon, an opening sentence. The interesting cost lands on businesses whose products were quietly worth more when the machine could pass as a person: the AI sales rep working leads, outbound service calls, companion apps sold on intimacy. That premium is now illegal to collect in Europe, and the price of trying is three points of global revenue. Honesty was always a virtue. As of August 2, it's also a compliance requirement.