Does a privacy policy count as AI chatbot disclosure?
Short answer: no. A privacy policy does not satisfy the Article 50(1) chatbot disclosure. Neither do your terms of service, your cookie banner, or a dedicated AI-use policy page. The European Commission's guidelines of 20 July 2026 say so about as directly as guidelines say anything: a mention in the terms and conditions is normally not enough.
The longer answer is worth reading, because the reasoning tells you what those documents are good for — and there is a real role for an AI policy page, just not this one.
Why the policy page fails the test#
Article 50(5) requires the information to reach people "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure." Measure a privacy policy against that sentence and it fails on all three counts.
Timing. The visitor opens the chat and types. They have interacted. Whether a document elsewhere on the domain describes the chatbot is not something that happened before or at the first interaction — it is something that was available, which is a different claim.
Surface. The duty attaches to the interaction. A policy page is a separate document reached by a separate navigation, usually from a footer link. Nothing about opening a chat window puts a visitor in front of it.
Clarity. Even where a policy does mention the chatbot, it is typically one clause inside a data-processing document written for a different audience and a different regulation. "Clear and distinguishable" is a test about what a reader comes away knowing.
This is not a drafting problem you can solve with better policy copy. A perfectly drafted sentence in the right document is still in the wrong place at the wrong time.
The GDPR habit that causes this#
The instinct is well-trained and, under a different regulation, correct. GDPR transparency — Articles 13 and 14 — is genuinely satisfied by a privacy notice: you tell people what you do with their data, in a document, and you make it accessible. A decade of doing that correctly builds a reflex that "disclosed" means "written down somewhere authoritative and linked."
Article 50 is built on the opposite premise. It regulates a moment in the conversation, and a document cannot stand in for one. The obligation is that a specific person, at a specific instant, is not misled about what they are talking to. A document cannot discharge a duty that attaches to an instant, which is why the same team that handles GDPR flawlessly can be exposed here.
Worth noting the two regulations stack rather than substitute: your chatbot almost certainly still needs its GDPR notice, and that notice still does not do Article 50's job.
What each document actually does#
| Document | Satisfies Art. 50(1)? | What it is genuinely for |
|---|---|---|
| Privacy policy | No | GDPR Art. 13/14 transparency about processing. Keep it, and keep the chatbot in it. |
| Terms of service | No | Contract terms. Named in the Commission's guidelines as insufficient for this. |
| Cookie / consent banner | No | Consent for storage and tracking. Wrong surface and wrong moment — usually dismissed before the chat is opened. |
| AI-use / editorial policy page | No, but useful | Your public account of where AI is used and who is responsible. Real evidentiary value; not a substitute for the in-conversation disclosure. |
| First bot message | Yes | The surface the duty is written for. |
| Launcher / pre-chat notice | Yes, and earlier | Discloses before the interaction rather than at it. |
The AI policy page is worth having anyway#
Do not read this as "policy pages are pointless." An AI-use page — what AI you use, where, under whose editorial responsibility — is worth publishing for reasons that have nothing to do with Article 50(1):
- Article 50(4)'s carve-out turns on editorial responsibility. AI-generated text published to inform the public on matters of public interest must be disclosed unless it has undergone human review and a natural or legal person holds editorial responsibility. A published page naming who holds it is the kind of thing that makes that carve-out arguable. See whether AI-written articles need a label.
- It is corroboration when a complaint arrives. It does not prove the chat window said anything, but it shows a considered position rather than an accident.
- Our scanner looks for one, alongside the visible checks, because its presence is a meaningful signal about how deliberately a site handles this.
So publish it. Just do not spend the disclosure budget there and skip the greeting line.
"But we disclosed it somewhere" — the pattern behind the question#
Most people who ask this question have already done real work. There is a paragraph in the privacy policy, a line in the terms, perhaps a note in an internal compliance register. The question is whether that adds up.
It does not, because Article 50 is unusually easy to check from outside and unusually document-blind. An authority — or a competitor drafting a complaint, which in practice is how many of these start — opens your site, clicks the chat bubble, and reads. Your policy is a different page. Whatever is in the chat window is the whole of what they see, and that is the entire evidentiary basis on which the first question gets asked.
The fix is nearly always small: one sentence in the greeting field you already have. What takes longer is discovering that the sentence is missing, or that it says "virtual assistant" — which describes where the assistant works, not what it is. Those near-miss wordings are the most common finding we have measured: on the first-interaction surfaces our 2026 sweep could read, 47% carried wording an automated check could not resolve either way, against 11% with a clear disclosure. Fifteen worked examples, sorted clear / weak / risky.
What to do this week#
- Add the disclosure to the first bot message. One sentence, in the widget's greeting field.
- Leave the privacy policy alone — it is doing its own job — but check the chatbot is described in it for GDPR purposes.
- Keep the AI policy page if you have one; publish one if you do not.
- Check the live site rather than the settings screen, on desktop and mobile separately.
- Keep a dated record of what the chat window showed, because the configuration screen is not evidence of what a visitor saw.
The free homepage scan does the visitor's-eye version of that check and seals what it found — including whether an AI policy page exists — into a dated record.
Common questions
Does mentioning the chatbot in our privacy policy satisfy Article 50?
No. Article 50(5) requires the information to reach people clearly and distinguishably at the latest at the time of the first interaction, and a policy page fails on timing, surface and clarity. The Commission's guidelines of 20 July 2026 state directly that a mention in the terms and conditions is normally not enough. This is not a drafting problem — a perfectly worded sentence in the wrong document at the wrong moment still does not discharge the duty.
We satisfy GDPR transparency with a privacy notice. Why is this different?
GDPR Articles 13 and 14 are document duties: you tell people what you do with their data, in an accessible notice. Article 50 regulates a moment instead — that a specific person, at a specific instant, is not misled about what they are talking to. A document cannot discharge a duty that attaches to an instant. Both obligations stack: your chatbot still needs its GDPR notice, and that notice still does not do Article 50's job.
Is an AI-use policy page worth publishing at all?
Yes, just not as your Article 50(1) disclosure. It supports the Article 50(4) carve-out, which turns on human review and a named natural or legal person holding editorial responsibility, and it is useful corroboration if a complaint arrives. Our scanner looks for one alongside the visible checks, because its presence signals a considered position rather than an accident.
What about putting the disclosure in the cookie or consent banner?
Wrong surface and wrong moment. Consent banners are for storage and tracking, they are typically dismissed before the chat is ever opened, and in practice they often cover the corner of the screen where the chat launcher sits. The disclosure belongs in the conversation.
Where should the disclosure go instead?
In the first bot message, set in your widget's greeting or welcome-message field, which renders in both desktop and mobile layouts. Adding a notice on the launcher itself discloses even earlier, before the panel opens, which is the safest side of the line.
Sources and further reading
- Article 50 — Transparency obligations (EU AI Act)
- Commission guidelines on transparency obligations, 20 July 2026
Last updated September 2026. Informational only, not legal advice: this page describes what the text of the EU AI Act says and what an external check can observe, not whether any particular site complies. Corrections welcome at hello@disclosureproof.com.