EU AI Act, Article 50

Must you tell people they are talking to an AI?

Justas Butkus is a fractional AI officer based in Vilnius, Lithuania, who builds and operates production AI voice systems and advises companies deploying AI in customer-facing operations across the UK and EU. His applied work covers AI disclosure and cross-border outreach rules across EU member states, the UK and the US.

Short answer

Yes. Under Article 50 of the EU AI Act, providers must ensure that people are informed they are interacting with an AI system, unless it is obvious to a reasonably observant person. The obligation has applied since the Act entered into force and became enforceable on 2 August 2026. It applies to AI systems that call or chat with your customers.

What Article 50 actually requires

Article 50 is the transparency provision. In plain terms it does three things relevant to anyone running an AI system that talks to customers:

  • Disclosure of interaction. People must be informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed and observant person in the circumstances.
  • Labelling of synthetic content. Audio, image, video and text generated or manipulated by AI must be marked in a machine-readable way as artificially generated.
  • Deepfake disclosure. Content that convincingly resembles real people, places or events must be disclosed as artificially generated.

For a voice agent making or answering calls, the first is the one that bites. The exemption for the obvious is narrower than people assume: modern speech synthesis is precisely the case where it is no longer obvious.

The dates that matter

EU AI Act application timeline, relevant provisions
DateWhat applies
2 February 2025Prohibited practices, and Article 4 AI literacy obligations for providers and deployers
2 August 2025Baseline obligations for general-purpose AI model providers
2 August 2026The main compliance deadline. Article 50 transparency becomes enforceable and supervisory authorities gain full enforcement powers
2 December 2026Grace period ends for synthetic-content systems already on the market before August 2026
2 December 2027Standalone high-risk systems under Annex III
2 August 2028High-risk AI embedded in already-regulated products

Penalties for breaching the transparency obligations sit in the middle tier of the Act's sanctions regime, set out in Article 99: up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. The top tier, reserved for the prohibited practices in Article 5, runs to €35,000,000 or 7%.

Does the Act require you to appoint an AI officer?

No. This is worth stating plainly because it is widely misrepresented.

Unlike the GDPR, which mandates a Data Protection Officer in defined circumstances, the AI Act requires no specific role, no named title and no particular governance structure. Article 4 is outcome-based: you must ensure a sufficient level of AI literacy among staff operating these systems, proportionate to their role and context. There is no mandated curriculum, examination or certificate.

What the Act does create is accountability that has to land somewhere. Appointing a responsible person is the common way organisations demonstrate that, and it is what auditors, insurers and enterprise customers increasingly ask to see. That is a market practice responding to a real obligation, not a legal requirement, and anyone telling you otherwise is selling from fear.

What disclosure looks like on a real call

The provision is short. Implementing it without ruining the call is where the actual work is.

  • Say it early, and in the flow. Disclosure at the top of the call, in the natural greeting, rather than buried in a legal preamble nobody listens to.
  • Say it in the language being spoken. A disclosure in English on a call conducted in Lithuanian, German or Polish does not inform anyone.
  • Handle the direct question. If a caller asks whether they are speaking to a person, the system must answer honestly and immediately. This needs to be a hard rule, not a matter of the model's discretion.
  • Log it. Keep a record showing disclosure occurred on each call. When a regulator or a customer asks, the recording or transcript is the evidence.
  • Keep a route to a human. Not strictly required by Article 50, but it is the thing that turns a complaint into a resolved call.

Member states also layer their own telecoms and consent rules on top of this, and they differ considerably on calling hours, consent basis and caller identification. The Act is a floor, not the whole picture.

Who carries the obligation

Both the provider and the deployer have duties, and outsourcing does not transfer them. If you buy an AI calling system and point it at your customers, you are the deployer, and the obligation to inform those customers is yours regardless of who built it.

This matters commercially: procurement teams are now asking suppliers to evidence AI Act compliance, and enterprise customers and insurers are adding AI governance questions to diligence. The practical consequence for most mid-market companies is not a regulator knocking. It is losing a deal because they could not answer a questionnaire.

Frequently asked questions

Does the EU AI Act require disclosing that a caller is an AI?

Yes. Article 50 requires that people are informed they are interacting with an AI system unless it would be obvious to a reasonably observant person. For a synthetic voice on a phone call, that exemption is narrow, so disclosure is the safe and expected position.

When did Article 50 become enforceable?

2 August 2026, which is the Act's main compliance deadline and the point at which supervisory authorities gained full enforcement powers. Systems generating synthetic content that were already on the market before that date have until 2 December 2026.

What are the penalties for getting transparency wrong?

Breaches of the transparency obligations fall in the middle sanctions tier: up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. The most common practical cost, though, is failed procurement diligence rather than a fine.

Does the AI Act require us to appoint an AI officer?

No. It mandates no role, title or governance structure, unlike GDPR's Data Protection Officer. It does create accountability obligations that have to sit with someone, which is why many organisations name a responsible person, but that is practice rather than law.

Does this apply to us if we are outside the EU?

It can. The Act has extraterritorial reach: if your AI system is used in the EU, or its output affects people in the EU, the obligations can apply regardless of where your company is established.

We bought our AI calling system from a vendor. Is it their problem?

No. Providers and deployers each carry duties, and buying the system does not transfer yours. If you point an AI caller at your customers you are the deployer, and informing those customers is your obligation.

If AI is already talking to your customers

The disclosure question is usually the visible edge of a larger one: nobody is quite sure what AI is running, who approved it, or who answers for it. That is worth half an hour.