Why Your Chatbot Vendor's EU AI Act Compliance Doesn't Cover Your Article 50 Disclosure Duty

If your chatbot vendor complies with the EU AI Act, is your disclosure duty covered on August 2?

Compliance protects you from the vendor. It doesn't protect you from the law.

The Situation

Article 50 of the EU AI Act enters into force on August 2, which requires any AI system built to interact directly with people be designed so a person knows they're talking to AI, and not told after the fact. Article 50 requires compliance to be designed into the system, and for the disclosure to land no later than the first exchange, in a form that's clear and distinguishable. Most external chatbots for sales and support, and internal chatbots for HR and IT, built on platforms like Salesforce Agentforce, Microsoft Copilot Studio, and Zendesk AI Agents, were deployed well before that standard was formalized.

The Exposure

Salesforce surveyed 6,500 service professionals for its 7th State of Service report, and respondents reported AI already resolves 30% of customer service cases today, rising to 50% by 2027, but that's one vendor's report on one use case, and chatbots have already spread well past customer service. Internally, many mid-market firms already use or plan to use a chatbot with AI for HR support, fielding routine benefits and policy questions, or IT, fielding technical support and enablement questions. All chatbot systems are in scope for Article 50 the moment you have EU-based employees or customers on the other side of it, regardless of where your company is headquartered. Violations carry a fine of up to €15 million or 3% of global annual turnover, whichever is higher.

The Judgment Call

Compliance teams reviewing a chatbot vendor contract generally assume Article 50 compliance is the vendor’s problem, since the vendor built the model and contracts typically include a boilerplate promise to comply with all applicable laws. However, that's a product liability instinct, which doesn't map cleanly onto the EU AI Act because it’s a statute that splits duties by role. Article 3 defines a "provider" as whoever develops the system or puts it into service under its own name or trademark. That means the vendor is not automatically the provider for your deployment - so you need to check. Article 50 also puts additional disclosure obligations on deployers for anything touching emotion recognition and deepfake content, obligations a vendor's compliance program doesn’t discharge no matter who built the model. The mistake isn't misidentifying the provider, it's never checking who the provider is.

  • Risk: Classifying your chatbots across customer-facing, HR, and IT systems is real work and with less than three weeks left before the August 2 deadline, you may have to divert additional resources or reprioritize current projects to get it done.

  • Benefit: Once you know which systems make you the provider, you can confirm disclosure compliance with Article 50 and avoid legal challenges.

This Week’s Action

  • What to do: Pull every chatbot in use, customer-facing and internal, and for each, note whether your company's name or trademark is what the end user actually sees.

  • Who to involve: General counsel or outside counsel, to confirm provider status legally under Article 3, plus the head of procurement for vendor-sourced systems, and the business unit leader owning the chatbot.

  • What outcome to achieve: A one-page inventory marking each bot as either provider or deployer status, with any Article 50 disclosure gap noted.

  • Time required: 45 minutes to pull the inventory, 30 minutes for counsel to confirm provider status on the unclear cases.

Artifact

Chatbot compliance decision tree

Question 1: Did your company either develop this system, or take a vendor's system and put it into service under its own name or trademark?
→ YES: You are the provider. Confirm the disclosure is designed into the system itself, not just referenced in a policy document.
→ NO, the vendor's name or trademark is what the end user sees: Continue to Question 2.

Question 2: Review the vendor's product documentation and public compliance statements. Do they identify the vendor as the provider responsible for the disclosure design on this system?
→ NO, or unclear: Treat your company as the provider by default and proceed to review with legal counsel.
→ YES: Document your basis for that conclusion and continue to Question 3.

Question 3: Does this system also use emotion recognition, biometric categorization, or generate deepfake content?
→ YES: Your company is a deployer under Article 50 for this feature, regardless of the answers above. Confirm those disclosure requirements are being met separately from the overall chatbot disclosure requirement.
→ NO: Document the conclusions from Questions 1 and 2, and the review date. This instance is covered.

When the stakes exceed your internal capacity:

  • AI Exposure Diagnostic: A 2-hour strategic evaluation for risk, compliance, and legal leaders to identify your highest-priority governance gaps and deliver a 90-day remediation roadmap.

  • 12-Week Governance Sprint: Translate regulatory requirements into audit-ready policies, control frameworks, and accountability structures.

  • Ongoing Advisory Retainer: Embedded judgment for policy updates, vendor assessments, and board prep as regulations and technology evolve.

Reply with "Diagnostic" or “Sprint” to schedule a conversation for next month.

Chris Cook writes Judgment Call weekly for compliance and risk officers navigating AI governance.

Former IBM Vice President and Deputy Chief Auditor. Published in the AI Journal, speaker at Yale.

Chris Cook

Managing Partner & Founder

Blackbox Zero

Forwarded this by a colleague? Subscribe to Judgment Call

Next
Next

AI Proxy Advisors Are Already Voting Against Management: What Your Board Needs to Test Now