EU AI Act Article 50 is the transparency chapter — and it's the only part of the regulation that became enforceable on August 2, 2026. If your website uses chatbots, AI-generated content, or emotion recognition, these obligations apply to you now.
This checklist covers every step required for full Article 50 compliance, with specific pass/fail criteria for each. Work through it in order — earlier steps are the highest priority.
What Article 50 Requires
Article 50 contains four distinct obligations. Each targets a different type of AI use:
| Clause | Requirement | Applies to |
|---|---|---|
| Art. 50(1) | AI chatbots must disclose they are AI before or at the start of interaction | Any website with a chatbot, AI assistant, or AI live chat |
| Art. 50(2) | Synthetic media of real people (deepfakes) must be disclosed | Sites publishing AI-generated video/audio of real individuals |
| Art. 50(3) | Emotion recognition and biometric categorization systems must notify users | Sites using facial analysis, behavioral AI, or emotion detection |
| Art. 50(4) | AI-generated content designed to appear authentic must be machine-labeled | Sites publishing AI-generated images, video, audio, or substantial AI text presented as human-written |
Most websites are primarily affected by Art. 50(1) (chatbots) and Art. 50(4) (AI content labeling). Steps 1–4 below address these directly.
The 8-Step Checklist
Inventory every AI system on your website
List all AI-powered features: chat widgets, AI search, recommendation engines, AI content generation tools, analytics AI, and any third-party AI embeds. You cannot disclose what you haven't identified.
✓ PASS
You have a complete list of AI systems on your site with the tool name, vendor, and purpose for each.
✗ FAIL
You're unsure what AI tools are running on your site, or you know some but haven't documented them.
Add a disclosure to every chatbot and AI assistant
Every conversational AI widget must identify itself as AI to users. The disclosure must appear before or at the very start of the conversation — not in settings, not in terms of service.
✓ PASS
Every chat widget displays a persistent 'AI assistant' label or sends an opening message identifying itself as AI.
✗ FAIL
Your chat widget presents itself without AI identification, or the disclosure is only accessible if users look for it.
Label AI-generated images, audio, and video
Any AI-generated media that is designed to appear authentic requires both a visible label and machine-readable metadata (C2PA standard for images satisfies the technical requirement).
✓ PASS
AI-generated images have alt text or captions indicating they are AI-generated. AI audio/video has a visible disclosure.
✗ FAIL
AI-generated images are presented without any indication of their origin.
Add an AI section to your privacy policy
GDPR Articles 13–14 require disclosure of how AI systems process personal data. This is separate from but complementary to Article 50. Your privacy policy must name the AI tools, their purpose, legal basis, and any data transfers.
✓ PASS
Privacy policy has a dedicated section listing AI tools, what data they process, and the legal basis.
✗ FAIL
Privacy policy has no mention of AI systems, or only a generic 'third-party services' reference.
Check for emotion recognition or biometric AI
If your site uses any form of behavioral analysis, facial detection, or emotion recognition — even through third-party analytics tools — Article 50(3) requires notification to users before exposure.
✓ PASS
No emotion recognition or biometric AI in use. Or, if in use, users are notified via a clear banner or consent mechanism before exposure.
✗ FAIL
Behavioral or biometric AI is active without user notification.
Review third-party AI embeds
Third-party widgets (Intercom, Drift, Zendesk AI, etc.) do not relieve you of Article 50 compliance. As the website operator (deployer), you are responsible for ensuring disclosures are in place even for vendor-provided AI features.
✓ PASS
You have verified that all third-party AI chat tools display compliant disclosures, and you have evidence (screenshot or vendor documentation) of this.
✗ FAIL
You are relying on vendors to handle disclosure without verifying it yourself.
Publish an AI policy page
A dedicated public page documenting your AI use demonstrates good-faith compliance and is increasingly expected by regulators. It should cover: what AI systems you use, their purpose, what data they process, and how users can request human review of automated decisions.
✓ PASS
Your site has a public AI policy page linked from the footer. It was last updated within the last 6 months.
✗ FAIL
No AI policy page exists, or it exists but is outdated or not publicly linked.
Run an automated compliance scan
Manual review misses things — especially on multi-page websites. An automated scan checks every page for missing disclosures, AI elements without labels, and GDPR gaps that manual review typically overlooks.
✓ PASS
You have run an automated scan within the last 30 days and have addressed all high-priority findings.
✗ FAIL
No automated scan has been run, or findings from a previous scan remain unaddressed.
Most Common Compliance Mistakes
Based on common patterns in EU regulatory guidance and how similar regulations (GDPR) have been enforced, these are the most frequent Article 50 compliance gaps:
Disclosure in terms of service only
Article 50(1) requires disclosure 'at the start of' the interaction — not in a document users never read. Regulators consider ToS-only disclosure insufficient.
Treating the chatbot vendor as responsible
The deployer (you, the website operator) is responsible for ensuring disclosures are in place. Even if your vendor's documentation claims compliance, you need to verify it yourself.
No disclosure on mobile
Many sites add chatbot disclosures only on desktop. If your mobile experience suppresses or hides the disclosure, you have a separate violation on every mobile visit.
AI policy page not linked from footer
A policy page that exists but isn't linked from every page of your site is effectively invisible to regulators and users. It needs to be accessible from wherever users are.
Outdated privacy policy
Adding a new AI tool without updating your privacy policy creates a GDPR gap. Every new AI vendor that processes user data requires a privacy policy update.
How to Verify Your Compliance
After working through the checklist, verification is critical. Self-assessment has limits — you know your site too well to catch everything. There are three approaches, in order of thoroughness:
1. Manual review as a new visitor
Open your site in an incognito browser. Start a chat. Check that the AI disclosure appears. Read the privacy policy looking for AI mentions. Check your footer for the AI policy link. This catches obvious gaps but misses multi-page issues.
2. Automated compliance scan
An automated scanner checks every page on your site for missing disclosures, AI elements without labels, and GDPR gaps. This is the only way to catch issues on pages you don't regularly visit. SiteProof AI's free scan covers up to 10 pages with no signup required.
3. Legal review
For high-risk AI systems or complex privacy situations, engage a lawyer specializing in EU AI Act or GDPR compliance. Automated scanning and checklists identify technical gaps; legal review addresses interpretation questions and proportionality assessment.
For broader compliance beyond Article 50, see our GDPR AI compliance checklist and our guide to AI content disclosure requirements.
Run your Article 50 compliance check now.
SiteProof AI scans your website for Article 50 violations — missing chatbot disclosures, unlabeled AI content, privacy policy gaps — and tells you exactly what to fix, page by page.
Scan your site free →