Where should an AI chatbot disclosure appear?
Article 50(5) is the placement rule, and it is one sentence: the information must be provided "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure." That gives you a deadline and a quality bar, but no coordinates. This page turns it into coordinates — for chat widgets, voice, in-product AI features, AI agents that act on a user's behalf, and the surfaces teams most often get wrong.
The rule, unpacked into three tests#
When? At the latest at the first interaction. "Interaction" starts when the visitor engages with the AI system, not when they send their second message and not when they reach a confirmation screen. Anything the visitor has to do first — type, log in, fill a form, accept a banner — puts your disclosure on the wrong side of the deadline.
Where? In the surface where the interaction happens. The Commission's guidelines of 20 July 2026 spell out the floor: a mention in the terms and conditions, a bot name, or a robot icon alone is normally not enough. The disclosure travels with the interaction.
How clearly? "Clear and distinguishable" is a reader test, not an author test. The question is whether a reasonably well-informed person would come away knowing they are dealing with an AI system — not whether the words are technically present somewhere on the page.
Placement by surface#
Chat widget#
Three candidate positions, in descending order of safety:
- On the launcher, before the panel opens"Chat with our AI assistant" on the bubble discloses before first interaction. It is the only position that still works when the panel fails to open — which in our own sweep was the common case, not the exotic one.
- In the first bot messageThe workhorse position: "You're chatting with an AI assistant." Set it in the widget's greeting or welcome-message field, which renders in both desktop and mobile layouts.
- As a persistent header label"AI Assistant" in the title bar. Good as reinforcement, weak as the sole disclosure — whether it registers before the first exchange depends on one visitor's eye path, which is not a property you can evidence later.
Use 2 as your baseline and add 1 or 3. Never rely on 3 alone. Where the field lives differs per product; the per-widget guides name the exact setting for Intercom, Zendesk and 18 others.
Voice assistants and phone bots#
First exposure is the first few seconds of audio, so the disclosure belongs in the opening utterance, before the caller states their business: "Hello, you're speaking with an automated AI assistant." Two traps. A disclosure at the end of the call is not first exposure. And an IVR menu that hands off to an AI agent mid-call needs the disclosure at the handoff, because that is where the interaction with the AI system begins.
In-product AI features#
A "Summarise with AI" button, an AI-drafted reply, an AI search answer. First interaction is the moment the feature engages, and the label belongs on the control or on the output — "AI summary", "Drafted by AI" — not in a settings page or a release note. Where the feature runs automatically rather than on a click, the output carries the label.
AI agents acting on a user's behalf#
An agent that emails, books, or transacts with third parties interacts with people who never visited your site. The disclosure has to reach them, at their first interaction: in the message the agent sends, not in a policy on your domain that the recipient will never load.
AI-generated content on a page#
Different duty, different rule. Visible labels for deepfakes and public-interest AI text come from Article 50(4), and 50(5)'s "first exposure" means the label goes where consumption starts — on the image, at the start of playback, by the headline rather than after the body. That is its own subject: see the official EU icons and where each label goes and whether your AI-generated content needs a label.
Five placements that do not work#
- Terms and conditions, privacy policy, or an AI-use policy page
- Named in the guidelines as insufficient on their own. These documents have a real role — just not this one. See does a privacy policy count as AI chatbot disclosure?
- The cookie or consent banner
- Wrong surface, wrong moment, and typically dismissed before the chat is opened.
- After a pre-chat form
- Name and email first, disclosure second, means the visitor interacted before being told.
- Only in the widget chrome the mobile layout drops
- Compact layouts routinely hide header labels and pre-chat notices. The duty follows the visitor, and most EU visitors are on a phone.
- Only when asked
- A bot that admits to being AI on request has answered a question, not met a duty that attaches at first interaction. Test it anyway — a bot that denies it is a much worse problem than one that stays quiet.
Placement decides whether the duty is provable#
There is a second-order reason to prefer the earliest, most persistent position: everything about Article 50 enforcement is downstream of what someone can observe later.
A greeting line sits in the transcript. A launcher notice sits in the first screenshot anyone takes. A header label persists for the session. A one-time toast that fades after four seconds satisfies the timing test and leaves nothing behind — so a check run a week later, by you or by anyone else, finds no trace of it. Placements that persist are placements you can evidence, which matters because showing a disclosure was live on a given date is the half of Article 50 that no configuration screen answers.
A five-minute placement check#
- Open your site in a private window, as a first-time EU visitor, on desktop.
- Look at the launcher before clicking. Is anything disclosed there?
- Open the panel. Read the first message before typing. Is the AI nature stated?
- Repeat the whole thing on a real phone, not a resized desktop window.
- Ask the bot directly whether it is a person, and record the answer.
- Screenshot each step with the date visible.
That is the manual version of what our scanner does on every scan: it opens the widget the way a visitor would, reads the first message before anyone types, checks the mobile layout separately, and seals what it saw. The free homepage scan returns those findings with the captures attached, no signup.
Common questions
What does "at the latest at the time of the first interaction" mean in practice?
The disclosure must be present when the visitor engages with the AI system — not after they send a message, not on a confirmation screen. Anything the visitor has to do first, such as typing or logging in, puts the notice on the wrong side of the deadline. So does completing a pre-chat form. Disclosing earlier, on the launcher before the panel opens, is always safe.
Is a disclosure in the chat window's header enough?
It is good reinforcement but weak on its own. Whether a header label registers before the first exchange depends on one visitor's eye path, and that is not something you can evidence after the fact. Use the first bot message as your baseline placement and keep the header label as well.
Where does the disclosure go for a voice assistant or phone bot?
In the opening utterance, before the caller states their business: "Hello, you're speaking with an automated AI assistant." First exposure is the first few seconds of audio. A disclosure at the end of the call is not first exposure, and where an IVR menu hands off to an AI agent mid-call, the disclosure belongs at the handoff.
Does the disclosure need to persist for the whole conversation?
Article 50(5) sets a timing requirement, not a persistence requirement, so a disclosure delivered at first interaction meets the rule. Persistence still matters for a practical reason: a notice that fades after four seconds leaves nothing in the transcript, so a check run later — by you or by anyone else — finds no trace of it. Placements that persist are placements you can evidence.
Do we need a separate disclosure for the mobile layout?
Not a separate disclosure, but a separate check. Compact layouts routinely drop header labels and pre-chat notices that the desktop layout keeps, and the duty follows the visitor. Setting the disclosure in the widget's greeting or welcome-message field is the most reliable approach, because that field renders in both layouts.
Sources and further reading
- Article 50 — Transparency obligations (EU AI Act)
- Commission guidelines on transparency obligations, 20 July 2026
Last updated September 2026. Informational only, not legal advice: this page describes what the text of the EU AI Act says and what an external check can observe, not whether any particular site complies. Corrections welcome at hello@disclosureproof.com.