EU AI Act · Article 50 in force · marking deadline 2 December 2026
EU AI Act · Article 50(5) · common mistake

Does a privacy policy count as AI chatbot disclosure?

Short answer: noArt. 50(5) placement ruleWhat policy pages are for

Short answer: no. A privacy policy does not satisfy the Article 50(1) chatbot disclosure. Neither do your terms of service, your cookie banner, or a dedicated AI-use policy page. The European Commission's guidelines of 20 July 2026 say so about as directly as guidelines say anything: a mention in the terms and conditions is normally not enough.

The longer answer is worth reading, because the reasoning tells you what those documents are good for — and there is a real role for an AI policy page, just not this one.

On this page Why the policy page fails the testThe GDPR habit that causes thisWhat each document actually doesThe AI policy page is worth having anyway"But we disclosed it somewhere" — the pattern behind the questionWhat to do this week Common questions

Why the policy page fails the test#

Article 50(5) requires the information to reach people "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure." Measure a privacy policy against that sentence and it fails on all three counts.

Timing. The visitor opens the chat and types. They have interacted. Whether a document elsewhere on the domain describes the chatbot is not something that happened before or at the first interaction — it is something that was available, which is a different claim.

Surface. The duty attaches to the interaction. A policy page is a separate document reached by a separate navigation, usually from a footer link. Nothing about opening a chat window puts a visitor in front of it.

Clarity. Even where a policy does mention the chatbot, it is typically one clause inside a data-processing document written for a different audience and a different regulation. "Clear and distinguishable" is a test about what a reader comes away knowing.

This is not a drafting problem you can solve with better policy copy. A perfectly drafted sentence in the right document is still in the wrong place at the wrong time.

The GDPR habit that causes this#

The instinct is well-trained and, under a different regulation, correct. GDPR transparency — Articles 13 and 14 — is genuinely satisfied by a privacy notice: you tell people what you do with their data, in a document, and you make it accessible. A decade of doing that correctly builds a reflex that "disclosed" means "written down somewhere authoritative and linked."

Article 50 is built on the opposite premise. It regulates a moment in the conversation, and a document cannot stand in for one. The obligation is that a specific person, at a specific instant, is not misled about what they are talking to. A document cannot discharge a duty that attaches to an instant, which is why the same team that handles GDPR flawlessly can be exposed here.

Worth noting the two regulations stack rather than substitute: your chatbot almost certainly still needs its GDPR notice, and that notice still does not do Article 50's job.

What each document actually does#

DocumentSatisfies Art. 50(1)?What it is genuinely for
Privacy policyNoGDPR Art. 13/14 transparency about processing. Keep it, and keep the chatbot in it.
Terms of serviceNoContract terms. Named in the Commission's guidelines as insufficient for this.
Cookie / consent bannerNoConsent for storage and tracking. Wrong surface and wrong moment — usually dismissed before the chat is opened.
AI-use / editorial policy pageNo, but usefulYour public account of where AI is used and who is responsible. Real evidentiary value; not a substitute for the in-conversation disclosure.
First bot messageYesThe surface the duty is written for.
Launcher / pre-chat noticeYes, and earlierDiscloses before the interaction rather than at it.

The AI policy page is worth having anyway#

Do not read this as "policy pages are pointless." An AI-use page — what AI you use, where, under whose editorial responsibility — is worth publishing for reasons that have nothing to do with Article 50(1):

So publish it. Just do not spend the disclosure budget there and skip the greeting line.

"But we disclosed it somewhere" — the pattern behind the question#

Most people who ask this question have already done real work. There is a paragraph in the privacy policy, a line in the terms, perhaps a note in an internal compliance register. The question is whether that adds up.

It does not, because Article 50 is unusually easy to check from outside and unusually document-blind. An authority — or a competitor drafting a complaint, which in practice is how many of these start — opens your site, clicks the chat bubble, and reads. Your policy is a different page. Whatever is in the chat window is the whole of what they see, and that is the entire evidentiary basis on which the first question gets asked.

The fix is nearly always small: one sentence in the greeting field you already have. What takes longer is discovering that the sentence is missing, or that it says "virtual assistant" — which describes where the assistant works, not what it is. Those near-miss wordings are the most common finding we have measured: on the first-interaction surfaces our 2026 sweep could read, 47% carried wording an automated check could not resolve either way, against 11% with a clear disclosure. Fifteen worked examples, sorted clear / weak / risky.

What to do this week#

The free homepage scan does the visitor's-eye version of that check and seals what it found — including whether an AI policy page exists — into a dated record.

See what a visitor actually sees. One free scan opens your chat the way a first-time visitor would, reads the first message, and records whether an AI-use policy page exists too — sealed into a dated record. Run the free scan →

Common questions

Does mentioning the chatbot in our privacy policy satisfy Article 50?

No. Article 50(5) requires the information to reach people clearly and distinguishably at the latest at the time of the first interaction, and a policy page fails on timing, surface and clarity. The Commission's guidelines of 20 July 2026 state directly that a mention in the terms and conditions is normally not enough. This is not a drafting problem — a perfectly worded sentence in the wrong document at the wrong moment still does not discharge the duty.

We satisfy GDPR transparency with a privacy notice. Why is this different?

GDPR Articles 13 and 14 are document duties: you tell people what you do with their data, in an accessible notice. Article 50 regulates a moment instead — that a specific person, at a specific instant, is not misled about what they are talking to. A document cannot discharge a duty that attaches to an instant. Both obligations stack: your chatbot still needs its GDPR notice, and that notice still does not do Article 50's job.

Is an AI-use policy page worth publishing at all?

Yes, just not as your Article 50(1) disclosure. It supports the Article 50(4) carve-out, which turns on human review and a named natural or legal person holding editorial responsibility, and it is useful corroboration if a complaint arrives. Our scanner looks for one alongside the visible checks, because its presence signals a considered position rather than an accident.

What about putting the disclosure in the cookie or consent banner?

Wrong surface and wrong moment. Consent banners are for storage and tracking, they are typically dismissed before the chat is ever opened, and in practice they often cover the corner of the screen where the chat launcher sits. The disclosure belongs in the conversation.

Where should the disclosure go instead?

In the first bot message, set in your widget's greeting or welcome-message field, which renders in both desktop and mobile layouts. Adding a notice on the launcher itself discloses even earlier, before the panel opens, which is the safest side of the line.

Sources and further reading

Last updated September 2026. Informational only, not legal advice: this page describes what the text of the EU AI Act says and what an external check can observe, not whether any particular site complies. Corrections welcome at hello@disclosureproof.com.