SiteProof AI Blog

EU AI Act Article 50 Compliance Checklist: 8 Steps for Websites (2026)

8 min read

EU AI Act Article 50 is the transparency chapter — and it's the only part of the regulation that became enforceable on August 2, 2026. If your website uses chatbots, AI-generated content, or emotion recognition, these obligations apply to you now.

This checklist covers every step required for full Article 50 compliance, with specific pass/fail criteria for each. Work through it in order — earlier steps are the highest priority.

What Article 50 Requires

Article 50 contains four distinct obligations. Each targets a different type of AI use:

ClauseRequirementApplies to
Art. 50(1)AI chatbots must disclose they are AI before or at the start of interactionAny website with a chatbot, AI assistant, or AI live chat
Art. 50(2)Synthetic media of real people (deepfakes) must be disclosedSites publishing AI-generated video/audio of real individuals
Art. 50(3)Emotion recognition and biometric categorization systems must notify usersSites using facial analysis, behavioral AI, or emotion detection
Art. 50(4)AI-generated content designed to appear authentic must be machine-labeledSites publishing AI-generated images, video, audio, or substantial AI text presented as human-written

Most websites are primarily affected by Art. 50(1) (chatbots) and Art. 50(4) (AI content labeling). Steps 1–4 below address these directly.

The 8-Step Checklist

1

Inventory every AI system on your website

List all AI-powered features: chat widgets, AI search, recommendation engines, AI content generation tools, analytics AI, and any third-party AI embeds. You cannot disclose what you haven't identified.

✓ PASS

You have a complete list of AI systems on your site with the tool name, vendor, and purpose for each.

✗ FAIL

You're unsure what AI tools are running on your site, or you know some but haven't documented them.

2

Add a disclosure to every chatbot and AI assistant

Every conversational AI widget must identify itself as AI to users. The disclosure must appear before or at the very start of the conversation — not in settings, not in terms of service.

✓ PASS

Every chat widget displays a persistent 'AI assistant' label or sends an opening message identifying itself as AI.

✗ FAIL

Your chat widget presents itself without AI identification, or the disclosure is only accessible if users look for it.

3

Label AI-generated images, audio, and video

Any AI-generated media that is designed to appear authentic requires both a visible label and machine-readable metadata (C2PA standard for images satisfies the technical requirement).

✓ PASS

AI-generated images have alt text or captions indicating they are AI-generated. AI audio/video has a visible disclosure.

✗ FAIL

AI-generated images are presented without any indication of their origin.

4

Add an AI section to your privacy policy

GDPR Articles 13–14 require disclosure of how AI systems process personal data. This is separate from but complementary to Article 50. Your privacy policy must name the AI tools, their purpose, legal basis, and any data transfers.

✓ PASS

Privacy policy has a dedicated section listing AI tools, what data they process, and the legal basis.

✗ FAIL

Privacy policy has no mention of AI systems, or only a generic 'third-party services' reference.

5

Check for emotion recognition or biometric AI

If your site uses any form of behavioral analysis, facial detection, or emotion recognition — even through third-party analytics tools — Article 50(3) requires notification to users before exposure.

✓ PASS

No emotion recognition or biometric AI in use. Or, if in use, users are notified via a clear banner or consent mechanism before exposure.

✗ FAIL

Behavioral or biometric AI is active without user notification.

6

Review third-party AI embeds

Third-party widgets (Intercom, Drift, Zendesk AI, etc.) do not relieve you of Article 50 compliance. As the website operator (deployer), you are responsible for ensuring disclosures are in place even for vendor-provided AI features.

✓ PASS

You have verified that all third-party AI chat tools display compliant disclosures, and you have evidence (screenshot or vendor documentation) of this.

✗ FAIL

You are relying on vendors to handle disclosure without verifying it yourself.

7

Publish an AI policy page

A dedicated public page documenting your AI use demonstrates good-faith compliance and is increasingly expected by regulators. It should cover: what AI systems you use, their purpose, what data they process, and how users can request human review of automated decisions.

✓ PASS

Your site has a public AI policy page linked from the footer. It was last updated within the last 6 months.

✗ FAIL

No AI policy page exists, or it exists but is outdated or not publicly linked.

8

Run an automated compliance scan

Manual review misses things — especially on multi-page websites. An automated scan checks every page for missing disclosures, AI elements without labels, and GDPR gaps that manual review typically overlooks.

✓ PASS

You have run an automated scan within the last 30 days and have addressed all high-priority findings.

✗ FAIL

No automated scan has been run, or findings from a previous scan remain unaddressed.

Most Common Compliance Mistakes

Based on common patterns in EU regulatory guidance and how similar regulations (GDPR) have been enforced, these are the most frequent Article 50 compliance gaps:

Disclosure in terms of service only

Article 50(1) requires disclosure 'at the start of' the interaction — not in a document users never read. Regulators consider ToS-only disclosure insufficient.

Treating the chatbot vendor as responsible

The deployer (you, the website operator) is responsible for ensuring disclosures are in place. Even if your vendor's documentation claims compliance, you need to verify it yourself.

No disclosure on mobile

Many sites add chatbot disclosures only on desktop. If your mobile experience suppresses or hides the disclosure, you have a separate violation on every mobile visit.

AI policy page not linked from footer

A policy page that exists but isn't linked from every page of your site is effectively invisible to regulators and users. It needs to be accessible from wherever users are.

Outdated privacy policy

Adding a new AI tool without updating your privacy policy creates a GDPR gap. Every new AI vendor that processes user data requires a privacy policy update.

How to Verify Your Compliance

After working through the checklist, verification is critical. Self-assessment has limits — you know your site too well to catch everything. There are three approaches, in order of thoroughness:

1. Manual review as a new visitor

Open your site in an incognito browser. Start a chat. Check that the AI disclosure appears. Read the privacy policy looking for AI mentions. Check your footer for the AI policy link. This catches obvious gaps but misses multi-page issues.

2. Automated compliance scan

An automated scanner checks every page on your site for missing disclosures, AI elements without labels, and GDPR gaps. This is the only way to catch issues on pages you don't regularly visit. SiteProof AI's free scan covers up to 10 pages with no signup required.

3. Legal review

For high-risk AI systems or complex privacy situations, engage a lawyer specializing in EU AI Act or GDPR compliance. Automated scanning and checklists identify technical gaps; legal review addresses interpretation questions and proportionality assessment.

For broader compliance beyond Article 50, see our GDPR AI compliance checklist and our guide to AI content disclosure requirements.

Run your Article 50 compliance check now.

SiteProof AI scans your website for Article 50 violations — missing chatbot disclosures, unlabeled AI content, privacy policy gaps — and tells you exactly what to fix, page by page.

Scan your site free →

Frequently Asked Questions

Is EU AI Act Article 50 already enforced?

Yes. Article 50 transparency obligations became enforceable on August 2, 2026. This is distinct from most EU AI Act provisions, which apply from August 2027. National market surveillance authorities in EU member states can investigate and fine non-compliant websites now.

Does Article 50 apply to websites outside the EU?

Yes. Article 2 gives the EU AI Act extraterritorial scope identical to GDPR. Any website accessible to EU users — regardless of where the company is based — must comply with Article 50 transparency requirements.

What are the fines for Article 50 violations?

Fines for Article 50 violations reach up to €15 million or 3% of global annual turnover, whichever is higher. For SMEs, national authorities may apply proportionality reductions. However, the per-violation structure means each non-compliant chatbot or piece of unlabeled content is a separate potential violation.

Does Article 50 apply to AI tools I use internally?

Article 50(1) specifically applies to AI systems that interact with natural persons — meaning user-facing tools. Internal employee tools are governed by different provisions. If your chatbot or AI system faces end users or website visitors, Article 50(1) applies.

Does my website need an AI policy page to comply with Article 50?

Article 50 does not explicitly require a standalone AI policy page. However, Article 13 transparency requirements (which apply to high-risk AI) and general good-faith compliance make a public AI policy page strongly recommended. Regulators reviewing complaints look for evidence of transparency effort.

Check Your Website Now — It's Free

Run a free EU AI Act compliance scan. No signup required.

Start Free Scan →