EU AI Act Article 50 in customer service: does the disclosure duty apply to us?

Last updated:

When does the EU AI Act disclosure duty start to apply?

From 2 August 2026 the transparency duties of the EU AI Act take effect, set out in Article 50. They are the part of the rulebook that reaches many retailers in customer service first, because they do not hinge on a high-risk system. They hinge on an everyday question: does it have to be disclosed that AI is involved here? The duties apply to systems that communicate directly and on their own with people. The textbook case is a chatbot that answers without any human involvement and faces the customer as if it were a contact person. You can read the exact wording in EU AI Act, Art. 50.

This article places one thing in that picture: a draft reply that a human approves before it goes out. It is no substitute for reviewing your own case. If you want the wider context of self-hosting first, start with the guide to self-hosted AI customer service.

What exactly does Article 50 require, and of whom?

Article 50 bundles several transparency duties that are worth keeping apart, because they have different addressees.

Paragraph 1 obligates providers: AI systems intended for direct interaction with natural persons must be designed and developed so that the person concerned is told they are interacting with an AI system, unless that is already obvious. That is the chatbot rule. Paragraph 2 is a duty on providers of AI systems that generate synthetic content: such output has to be marked as artificially generated in a machine-readable form. Paragraph 4 covers AI-generated or AI-altered text that is published to inform the public on matters of public interest. For that text there is an exception where the content went through human review or editorial control and a person carries editorial responsibility.

Does a draft reply that a human approves fall under it?

The decisive difference is who speaks to the customer. With Corresa the AI drafts a reply, but it sends nothing. Every draft lands in a review view, a staff member reads it, edits it, and approves it. Only then does the email go out. The system does not interact on its own and does not interact directly with the customer. It hands a person a draft. Why that division of labor is the real point is covered in AI drafts, a human signs off.

Set the three paragraphs against this flow and none of them fits. The interaction duty in paragraph 1 presupposes a system that communicates directly with the person; here a human communicates by email. Paragraph 2 addresses providers of AI systems, not the retailer who puts a model to use. Paragraph 4 concerns published text on matters of public interest, not private correspondence with a single customer. By its wording, a draft reply that a human reviews and approves should not trigger the disclosure duty in Article 50.

The difference is not merely formal. The rule in paragraph 1 exists to stop someone believing they are talking to a human when a machine is answering. That confusion cannot arise with a draft reply, because a staff member owns the text before it leaves. The AI is an aid in the background, closer to a spell-checker or a text template, only more capable. Responsibility for the reply stays with the person.

Wasn't this duty postponed by the Digital Omnibus?

This question comes up often, because a lot was reported about postponed deadlines around the AI Act. The so-called Digital Omnibus package pushed back deadlines in the area of high-risk systems. On the position so far, the transparency duties in Article 50 were not among the postponed rules. They take effect on the scheduled date of 2 August 2026.

In practice that means: do not count on Article 50 having been swept away by a general postponement. For a draft-reply workflow it changes little either way, because that kind of flow does not fall under the duty in the first place. For anyone running a fully automated chatbot, though, the date matters, and the postponement of other deadlines is no help.

Should I disclose it voluntarily anyway?

Separate from that is the question of whether you want to disclose voluntarily that AI helps draft your replies. Article 50 does not require it for an email draft a human approves. Whether you mention it anyway, say on an information page or in your privacy notice, is a business decision and not a legal duty under this provision.

Some retailers choose deliberately to be open about the use, because it fits how they see themselves and it builds trust. Others see it as needless complication, since the reply comes from a human regardless. Both are defensible. What matters is not mixing the two levels: the data protection information about processing customer data is mandatory, a note about AI support in the wording is not, in this case.

What does this mean for my data protection in concrete terms?

That Article 50 does not apply does not mean there is nothing to do. A few points remain your responsibility, but they sit in data protection law, not in AI labeling.

You add the use of AI to your privacy policy: purpose, legal basis, the AI provider as processor, and the retention period. That is an information duty under Article 13 GDPR. With your AI provider you conclude a data processing agreement; with an EU provider one is usually in place, and there is no transfer to a third country. On top of that, Article 4 of the AI Act requires your team to have a sufficient level of competence in dealing with AI, which you cover with a short documented training session. For exactly these points Corresa ships templates, see below.

There is no automated individual decision of the kind Article 22 GDPR would govern, because at the end a human decides and approves. What matters for your data protection officer is an honest description of the data flow: the text of the inquiry does go to the language model. It runs through exactly one provider you hold a contract with, and control over the data stays layered with you, as the self-hosting guide describes.

What does Corresa ship for this?

So that your data protection officer does not start from scratch, we include a compliance pack at the outset. It contains a template for the privacy policy under Article 13 GDPR, a checklist for the data processing agreement with the AI provider, and a training sheet for AI competence under Article 4 of the AI Act.

These documents are meant as a template you adapt to your business and have your data protection officer review. They take the first draft off your hands, so the usual data protection questions are already answered. For the whole context, see the guide to self-hosted AI customer service.

This article is guidance, not legal advice. It describes how a draft reply that a human reviews sits under the wording of Article 50, and it cannot replace an assessment of your specific case. How your workflow, your data processing, and your documentation are to be judged is something you clear with your data protection officer and, in case of doubt, with a lawyer specializing in IT law.

Depending on the setup, further points can come into play, such as works council co-determination or the question of a data protection impact assessment. That cannot be settled conclusively from a distance. The good news holds: a workflow where a human approves every reply is a far simpler starting point for those conversations than a bot that talks to your customers on its own.