Skip to content

AI disclosure wording you can copy and paste

Article 50 of the EU AI Act has applied since 2 August 2026. It tells you that people must be informed — it does not hand you the sentence. Here is the sentence, for 10 surfaces and 8 languages, each mapped to the paragraph it answers to. No sign-up, no email, nothing hidden behind a form.

This is wording, not legal advice. These notices are drafting starting points written against the text of Article 50. They do not make anyone compliant on their own, and whether a duty applies to you depends on your system, your role — provider or deployer — and your facts. Article 50 binds different parties in different paragraphs; check which one you are before you paste. For anything consequential, ask a qualified lawyer in your jurisdiction.

Art. 50(1)provider duty

Website chatbot

A support or sales assistant embedded in a website or app.

When: Before or with the first message — Article 50(5) requires the information at the latest at the time of the first interaction. Put it in the opening message and keep it visible in the widget header, not behind a tooltip.

Short

You're chatting with an AI assistant, not a person.

Detailed

You're chatting with an AI assistant, not a person. It can make mistakes, so please check anything important. Ask for a human at any time and we'll pass you to a colleague.

Common mistake: Relying on "it's obvious it's a bot". The carve-out is judged from the perspective of a reasonably well-informed, observant and circumspect person — and an assistant that writes like a colleague is precisely the case the paragraph was written for. A robot avatar is not a disclosure.

Art. 50(1)+ Art. 50(2)provider duty

Voice agent / phone bot

An AI that answers or places calls and speaks to the caller.

When: In the first spoken turn, before any question is asked. A synthetic voice also produces synthetic audio, so Article 50(2) marking sits underneath the spoken notice.

Short

Hello — you're speaking with an automated AI assistant, not a person.

Detailed

Before we start: you're speaking with an automated AI assistant from [Company], not a person. It can make mistakes. Say "agent" at any point and I'll transfer you to a colleague.

Common mistake: Putting the notice at the end of the call, or only in the hold message the caller skipped. Article 50(5) sets the deadline at the first interaction — a disclosure after the caller has already given their details is late.

Art. 50(1)provider duty

WhatsApp / messaging bot

An automated responder on WhatsApp, Messenger, Telegram or SMS.

When: In the first message the person receives from the number, and again after any long gap where a human may have taken over and handed back.

Short

Replies from this number are written by an AI assistant, not a person.

Detailed

Heads-up: replies from this number come from an AI assistant, not a person. It can get things wrong. Reply HUMAN at any time and a colleague will take over the conversation.

Common mistake: Disclosing once at opt-in and never again. Messaging threads are long-lived and get handed between bot and human — the person needs to know which one they are talking to now.

Art. 50(1)+ Art. 50(2)provider duty

Email / inbox agent

An AI that drafts and sends replies from a shared or personal inbox.

When: In every message the agent sends autonomously. If a human reads and approves each message before it goes out, you are no longer in an unattended AI interaction — but say so honestly rather than quietly dropping the notice.

Short

This reply was written and sent by an AI assistant, not a person.

Detailed

This reply was written and sent automatically by an AI assistant on behalf of [Company] — no colleague has read it yet. It may contain errors. Reply to this email and a person will pick it up.

Common mistake: Signing an autonomous agent's mail with a real employee's name and photo. That is the opposite of the design duty in Article 50(1), and it turns a transparency gap into a credibility problem.

Art. 50(2)+ Art. 50(4)provider duty

AI-generated text

Articles, product copy, summaries or answers produced by a text model.

When: Marking is a provider duty at generation time. A separate, visible disclosure is a deployer duty under the second subparagraph of Article 50(4) when the text is published to inform the public on matters of public interest — unless it went through human review and a named person or organisation holds editorial responsibility.

Short

This text was generated with AI.

Detailed

This text was generated by an AI system and published by [Company]. [Optional, and only if true: it was reviewed by our editorial team, which holds responsibility for the published version.]

Common mistake: Treating the editorial-responsibility carve-out as automatic. It only applies where the AI output actually underwent human review or editorial control and a natural or legal person really does hold editorial responsibility — a rubber-stamp workflow with nobody named is not that.

Art. 50(2)provider duty

AI-generated image

Illustrations, product shots or stock-style images from an image model.

When: The machine-readable mark goes on at generation. A human-readable caption is not required by 50(2) unless the image is a deepfake — but it is the cheapest way to survive a platform that strips your metadata.

Short

AI-generated image.

Detailed

AI-generated image. This picture was created with an AI image generation system by [Company] and does not depict a real scene. It carries machine-readable provenance metadata identifying it as artificially generated.

Common mistake: Marking at upload instead of at generation, then losing the mark to a CDN resize. Test one real file through your full delivery path and read the manifest back at the other end — marking your own pipeline strips is marking you cannot demonstrate.

Art. 50(2)provider duty

AI-generated video or audio

Synthetic voice-over, generated music, or fully generated video.

When: Marked at generation. Where the output resembles real people or events, it is a deepfake and the visible disclosure under Article 50(4) applies on top.

Short

AI-generated audio — this voice is synthetic.

Detailed

This [audio/video] was generated by an AI system. The voice and imagery are synthetic, they do not record a real performance or event, and the file carries machine-readable provenance metadata.

Common mistake: Assuming a spoken disclaimer at the end covers it. Clips are cut and re-shared; the marking has to be in the file and, for deepfakes, the visible label has to survive the crop.

Art. 50(4)+ Art. 50(2)deployer duty

Deepfake

Image, audio or video resembling real people, places or events.

When: At the point of consumption, in or immediately adjacent to the frame — visible to the person looking at it, not only in metadata and not only in a caption field that disappears when the file is re-shared.

Short

AI-generated: this content was artificially created or manipulated.

Detailed

Artificially generated content. This [image/video/audio] was created or manipulated using AI. It depicts people, places or events that did not occur as shown, and is published by [Company] for [purpose].

Common mistake: Stretching the artistic/satirical accommodation. Evidently artistic, creative, satirical or fictional work may present the disclosure in a way that does not spoil the work — it does not remove the disclosure, and the Article 50(2) machine-readable marking stays underneath either way.

Art. 50(3)deployer duty

Emotion recognition

A system inferring emotional states from face, voice or behaviour.

When: Before the person is exposed — at the entrance, on the consent screen, or in the call preamble. Check Article 5 first: emotion recognition in the workplace and in education institutions has been prohibited outright since 2 February 2025, save for medical or safety reasons. No notice makes a prohibited use lawful.

Short

An AI system here estimates emotional state from [your voice / facial expression].

Detailed

Notice: [Company] operates an AI emotion recognition system in this [location/service]. It analyses [facial expression / tone of voice] to estimate emotional states for [purpose]. Personal data is processed by [controller] under [legal basis] — see [link to privacy notice]. You can [opt out / speak to staff] at [contact].

Common mistake: Writing the notice before checking Article 5. If the deployment is in a workplace or an education institution, the question is not how to word the disclosure — it is whether the system may run at all.

Art. 50(3)deployer duty

Biometric categorisation

A system sorting people into categories from biometric data.

When: Before exposure, alongside the GDPR information you already owe. Article 5 also bans categorisation that infers race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.

Short

This service uses AI to place people in categories based on biometric data.

Detailed

Notice: this [service/location] uses an AI biometric categorisation system operated by [Company]. It analyses [facial image / voice] to assign people to [categories] for [purpose]. Personal data is processed by [controller] under [legal basis] — see [link to privacy notice].

Common mistake: Burying it in the privacy policy. Article 50(5) wants the information clear and distinguishable at the latest at first exposure; a clause on page four of a policy nobody opened is neither.

The two notices in 8 languages

The AI Act does not tell you which language to disclose in — but informing someone “in a clear and distinguishable manner” is hard to argue in a language they do not read. These are the chatbot notice (Art. 50(1)) and the synthetic-content notice (Art. 50(2)/50(4)), kept plain and legally neutral so they do not promise more than the Regulation requires.

Deutsch

de
Chatbot — short

Sie chatten mit einem KI-Assistenten, nicht mit einem Menschen.

Chatbot — detailed

Hinweis: Sie chatten mit einem KI-Assistenten, nicht mit einem Menschen. Er kann Fehler machen — bitte prüfen Sie wichtige Angaben. Sie können jederzeit nach einem Mitarbeiter fragen.

AI-generated content

Dieser Inhalt wurde mit künstlicher Intelligenz erzeugt.

Français

fr
Chatbot — short

Vous discutez avec un assistant IA, et non avec une personne.

Chatbot — detailed

Information : vous discutez avec un assistant IA, et non avec une personne. Il peut commettre des erreurs — vérifiez les informations importantes. Vous pouvez demander un conseiller humain à tout moment.

AI-generated content

Ce contenu a été généré par une intelligence artificielle.

Español

es
Chatbot — short

Está hablando con un asistente de IA, no con una persona.

Chatbot — detailed

Aviso: está hablando con un asistente de inteligencia artificial, no con una persona. Puede cometer errores, así que compruebe la información importante. Puede pedir hablar con una persona en cualquier momento.

AI-generated content

Este contenido ha sido generado con inteligencia artificial.

Italiano

it
Chatbot — short

Stai parlando con un assistente IA, non con una persona.

Chatbot — detailed

Avviso: stai parlando con un assistente di intelligenza artificiale, non con una persona. Può commettere errori: verifica le informazioni importanti. Puoi chiedere di parlare con un operatore in qualsiasi momento.

AI-generated content

Questo contenuto è stato generato con l'intelligenza artificiale.

Nederlands

nl
Chatbot — short

U chat met een AI-assistent, niet met een persoon.

Chatbot — detailed

Let op: u chat met een AI-assistent, niet met een mens. De assistent kan fouten maken — controleer belangrijke informatie. U kunt op elk moment om een medewerker vragen.

AI-generated content

Deze inhoud is gegenereerd met kunstmatige intelligentie.

Polski

pl
Chatbot — short

Rozmawiasz z asystentem AI, a nie z człowiekiem.

Chatbot — detailed

Informacja: rozmawiasz z asystentem sztucznej inteligencji, a nie z człowiekiem. Może popełniać błędy — zweryfikuj ważne informacje. W każdej chwili możesz poprosić o kontakt z konsultantem.

AI-generated content

Ta treść została wygenerowana przez sztuczną inteligencję.

Türkçe

tr
Chatbot — short

Bir insanla değil, yapay zekâ asistanıyla konuşuyorsunuz.

Chatbot — detailed

Bilgilendirme: Bir insanla değil, yapay zekâ asistanıyla konuşuyorsunuz. Hata yapabilir; önemli bilgileri doğrulayın. Dilediğiniz anda bir müşteri temsilcisine bağlanmayı isteyebilirsiniz.

AI-generated content

Bu içerik yapay zekâ ile üretilmiştir.

العربية

arRTL
Chatbot — short

أنت تتحدث مع مساعد ذكاء اصطناعي، وليس مع شخص.

Chatbot — detailed

تنبيه: أنت تتحدث مع مساعد يعمل بالذكاء الاصطناعي، وليس مع شخص. قد يرتكب أخطاء، لذا يُرجى التحقق من المعلومات المهمة. يمكنك في أي وقت طلب التحدث إلى أحد الموظفين.

AI-generated content

أُنشئ هذا المحتوى بواسطة الذكاء الاصطناعي.

Embed a hosted transparency notice

The wording above goes in your interface. If you also want a persistent, linkable notice — the page an authority or a customer can be pointed at — Conformly serves a one-line script that renders a small chip linking to your public disclosure page. It is a supplement to the in-conversation notice under Article 50(1), not a substitute for it.

HTML

<script src="https://getconformly.com/embed/disclosure.js" data-conformly="your-slug" data-position="bottom-left" data-lang="en"></script>

  • data-position — bottom-left (default), bottom-right, or inline to place the chip where the tag sits.
  • data-lang — en, de, fr, es, it, nl, pl or tr. Unknown values fall back to English.
  • No cookies, no analytics. The script makes one JSON call back to Conformly to confirm the disclosure page is live.
  • All styles are inline, so host pages need no Content-Security-Policy change.
  • The chip links to a public notice page — it supplements an in-conversation disclosure, it does not replace one.

data-conformly is the slug of a published Conformly disclosure page. If no such page is live the script renders nothing at all — it never breaks the host page.

Questions people actually ask

Do I have to tell users they are talking to an AI?
Yes, in almost every real case. Article 50(1) of the EU AI Act requires providers to design AI systems that interact directly with people so those people are informed they are interacting with an AI system. The only carve-out is where that is obvious to a reasonably well-informed, observant and circumspect person, taking the context into account — which a conversational assistant that writes like a colleague is not. The obligation has applied since 2 August 2026.
What wording should I use for a chatbot disclosure?
Something plain, in the first message, that names the system as AI and offers a way to a human — for example: "You're chatting with an AI assistant, not a person. It can make mistakes, so please check anything important. Ask for a human at any time." The Act does not prescribe wording; it requires that the information be clear and distinguishable, and given at the latest at the time of the first interaction.
When exactly does the disclosure have to appear?
Article 50(5) sets the deadline: the information must be provided to the person concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. In practice that means the opening message of a chat, the first spoken turn of a call, or the notice at the entrance before an emotion recognition system processes anyone.
Does this apply to my company if we are not in the EU?
The AI Act applies where the AI system is placed on the market or put into service in the EU, or where its output is used in the EU — so a non-EU company with EU users is generally in scope. Where you are established does not decide it; where your users and your outputs are does.
Is a disclosure in the terms of service enough?
No. The duty is to inform the person concerned in a clear and distinguishable manner at first interaction. A clause inside terms nobody opened does not meet that, and neither does a tooltip the person has to hunt for. The notice belongs where the interaction starts.
Do I need a visible label on AI-generated content, or is metadata enough?
It depends on the paragraph. Article 50(2) asks providers for machine-readable marking of synthetic audio, image, video and text — metadata or watermarking, not a caption. Article 50(4) asks deployers for a disclosure a person can actually see, but only for deepfakes and for text published to inform the public on matters of public interest. Most generative products owe the marking; the visible label is narrower.
What happens if we get this wrong?
Breaches of Article 50 sit in the middle penalty tier of Article 99: up to €15 million or 3% of worldwide annual turnover, whichever is higher — and for SMEs, whichever is lower. Only the Article 5 prohibitions carry the €35M / 7% maximum.
Is this wording legal advice?
No. These are drafting starting points written against the text of Article 50, not advice on your situation. Whether a duty applies to you, and whether a given sentence discharges it, depends on your system, your role (provider or deployer) and your facts — and only a qualified lawyer in your jurisdiction can tell you that.

Wording is one step — knowing which duties you carry is the other

Which paragraph binds you is a question about your system, not about your sentence. The free Article 50 readiness checker walks the four triggers in two minutes and returns your duty list and the dates. If you also generate images or documents, the watermark & C2PA checker tells you whether your outputs actually carry the machine-readable marking Article 50(2) asks for — it runs in your browser and never uploads the file.

Want these notices as a document?

We'll email the full wording library — every surface, both variants, all eight languages — as a single file you can hand to legal or drop into your design system.

One email with the library. We do not sell or share your address, and one click unsubscribes.