AI Guide

Limited-Risk AI System (EU AI Act): Article 50 transparency duties for chatbots and deepfakes

A limited-risk AI system is an artificial intelligence system that the EU AI Act does not classify as high-risk or prohibited, but that still triggers transparency obligations under Article 50 because it interacts with people or generates synthetic content, such as chatbots, emotion recognition tools, and deepfake generators. Unlike high-risk classification, limited-risk status requires disclosure rather than conformity assessment, and it applied from August 2, 2026 regardless of company size. Learn below what qualifies as limited-risk, which Article 50 duties follow, and how it differs from the EU AI Act's other risk tiers.

Key Facts
  • Article 50 of the EU AI Act imposes transparency duties, not conformity assessment, on limited-risk AI systems such as chatbots, emotion recognition tools, and deepfake generators.
  • These transparency obligations became applicable on August 2, 2026, independent of a system's risk tier, so even an otherwise minimal-risk chatbot must disclose that it is AI.
  • Providers of generative AI systems must mark text, image, audio, and video output in a machine-readable format so it can be detected as artificially generated.
  • Article 50 breaches can draw fines of up to 15 million euros or 3 percent of global annual turnover, whichever is higher.
  • Bitkom's February 2026 study found 93 percent of German companies view the EU AI Act as a driver of additional compliance workload, even though most limited-risk duties require only a clear disclosure, not a full risk-management system.

Definition: Limited-Risk AI System (EU AI Act)

A limited-risk AI system under the EU AI Act is an artificial intelligence system outside the prohibited and high-risk tiers that still interacts with people or generates synthetic content, triggering Article 50 transparency duties rather than conformity assessment.

Core characteristics of limited-risk AI systems

Article 50 covers four situations, not a fixed use-case list, so one chatbot can trigger several duties at once. Every duty is disclosure, not pre-market approval.

  • Systems for direct interaction with natural persons: chatbots, voice assistants
  • Emotion recognition and biometric categorization systems
  • Generative AI producing synthetic text, image, audio, or video
  • Deepfake generators and AI-generated public-interest text

Limited-Risk AI System vs. High-Risk AI System

A high-risk AI system must clear conformity assessment first, since its use case carries significant potential harm. A limited-risk system carries no such presumption; it only has to disclose that a person is dealing with AI. A chatbot can be limited-risk alone, yet join a high-risk workflow once it feeds a hiring decision.

Importance of limited-risk classification in enterprise AI

Limited-risk duties reach far more everyday tools than high-risk rules do, since almost every customer-facing chatbot falls under Article 50. Gartner projects that by 2026, half of customer service organizations will have deployed generative AI virtual assistants.

Methods and procedures for limited-risk AI systems

Meeting Article 50 duties follows the interaction or content type a system produces.

Transparency-by-design for human-AI interaction

Article 50(1) requires providers to design systems so a person is informed they are interacting with AI, unless this is already obvious from context.

  • Add a visible AI disclosure at the start of a conversation
  • Avoid interface design that could pass a system off as human
  • Document any reliance on the “obvious” exception

AI-generated content marking (Article 50(2))

Providers of generative AI systems must mark synthetic output in a machine-readable format that allows detection as artificially generated, using metadata or watermarking.

Deepfake and public-interest content disclosure (Article 50(4))

Deployers who publish deepfake media, or AI-generated text on public-interest matters, must disclose it as artificially generated at first exposure, clearly and without buried fine print.

Important KPIs for limited-risk AI systems

Tracking Article 50 readiness needs indicators separate from high-risk compliance metrics.

Disclosure coverage

  • Chatbot disclosure rate: share of conversational tools with a visible AI notice
  • Content marking rate: share of synthetic output with provenance metadata
  • Deepfake disclosure rate: share of synthetic media labeled at first exposure
  • Channel coverage: share of touchpoints reviewed for Article 50 gaps

Strategic risk exposure

Boards increasingly track Article 50 exposure separately from high-risk counts, since disclosure gaps are easier to spot than classification errors. Bitkom’s February 2026 study found 93 percent of German companies see the AI Act as a driver of extra compliance workload.

Quality of disclosure

A notice that technically exists but is easy to miss, such as text buried in a settings menu, does not satisfy Article 50’s “clear and distinguishable” standard.

Risk factors and controls for limited-risk AI systems

Limited-risk status still carries specific, ongoing compliance risks despite its lighter obligations.

Treating limited-risk as no-risk

The most common error is assuming “limited-risk” means “no action needed,” since Article 50 applies regardless of risk tier or company size.

  • Inventory every customer-facing or content-generating AI tool
  • Assign a named owner for Article 50 disclosure across marketing and service
  • Re-check disclosure design whenever a tool changes provider

Inconsistent disclosure across channels

A chatbot might carry a clear AI notice on the website but not in a WhatsApp or voice channel added later, leaving a gap even where the original rollout was compliant.

Marking and watermarking technical gaps

Many generative AI tools used by Mittelstand marketing teams do not yet embed machine-readable provenance metadata by default, leaving the AI provider’s marking duty unmet even where a human-facing disclosure exists.

Practical example

A 130-employee online furniture retailer in Lower Saxony ran a website chatbot and generated AI product photography for seasonal campaigns. Before August 2026, neither carried an AI disclosure or provenance metadata. Working with its e-commerce agency, the retailer added a visible AI-assistant notice, switched to an image tool with built-in marking, and logged both changes for its data protection officer.

  • Visible AI disclosure banner at the start of every chatbot conversation
  • Machine-readable provenance metadata in AI-generated product images
  • Quarterly channel review covering website, app, and social media
  • Article 50 compliance log shared with the retailer’s legal advisor

Current developments and effects

Three developments are shaping how companies handle Article 50 now that its deadline has passed.

Enforcement attention shifts to disclosure gaps

With the Digital Omnibus postponing most Annex III high-risk duties to December 2027, supervisory authorities have more capacity for early Article 50 enforcement.

  • Consumer protection bodies are testing chatbots for missing disclosures
  • Journalists increasingly flag unlabeled deepfakes and AI-generated news
  • Regulators favor visible fixes like banners over lengthy investigations

EU Code of Practice on AI-generated content

The European Commission has advanced a voluntary Code of Practice on transparency of AI-generated content, giving providers a reference set of marking techniques it treats as acceptable Article 50(2) evidence.

Vendor disclosure clauses in procurement

Enterprise buyers increasingly ask AI vendors to confirm in writing which Article 50 duties their product already meets, moving disclosure design earlier into vendor selection.

Conclusion

Limited-risk classification touches the most AI tools an enterprise actually uses day to day, even though its obligations are lighter than high-risk compliance. Article 50’s disclosure duties are simple to describe but easy to miss across every channel a tool reaches, which is where regulators are looking first. Mittelstand companies that inventory their customer-facing AI tools now, rather than assuming limited-risk means no risk, avoid enforcement exposure and the cost of a customer discovering undisclosed AI on their own. Treating Article 50 as a standing design requirement, not a launch checkbox, keeps a deployment trustworthy as new tools are added.

Frequently Asked Questions

What makes an AI system “limited-risk” under the EU AI Act?

A system is limited-risk if it misses the prohibited or high-risk criteria but still interacts directly with people or generates synthetic content. It triggers Article 50 transparency duties instead of conformity assessment.

Does a small company with a simple website chatbot really need to comply with Article 50?

Yes. Article 50 applies regardless of company size, so a small retailer’s chatbot carries the same disclosure duty as a large enterprise’s, though the obligation itself is just a clear AI notice.

How is Article 50 different from the Digital Omnibus deadline extension for high-risk systems?

The Digital Omnibus postponed Annex III high-risk duties to December 2, 2027, but Article 50 obligations were unaffected and applied from August 2, 2026 as scheduled. A company can be current on high-risk timelines and still breach Article 50 if its chatbots remain undisclosed.

What does Article 50 compliance cost for a Mittelstand company?

For a handful of customer-facing tools, adding disclosure banners and switching to a content tool with built-in marking typically takes days, not months. The bigger cost driver is discovering late that a tool lacks marking support.

Do we need our own IT team to handle Article 50 disclosures?

No. Most of the work is interface copy and vendor configuration, so marketing and compliance staff can typically handle it with light IT support. Companies like Superkind that build AI agents on top of existing systems design the disclosure in from the start.

How does limited-risk status interact with GDPR when a chatbot processes personal data?

Article 50 governs whether people are told they are talking to AI, while GDPR governs how any personal data that chatbot collects is processed. A chatbot handling customer data typically needs both, addressed in the same rollout review.

Further Resources

EU AI Act: The Omnibus Reprieve - What the Postponed High-Risk Deadline Really Changes for the Mittelstand
AI Compliance

EU AI Act: The Omnibus Reprieve - What the Postponed High-Risk Deadline Really Changes for the Mittelstand

The Digital Omnibus pushed Annex III high-risk obligations to December 2027, but Article 50 transparency, deployer duties, and AI literacy still apply now. What the Mittelstand must keep doing despite the reprieve, and why a deferred deadline is a trap if you stop preparing.

The Best AI Voice Agents for Inbound Customer Calls: An Honest 2026 Buyer Comparison
AI in Customer Support

The Best AI Voice Agents for Inbound Customer Calls: An Honest 2026 Buyer Comparison

An honest 2026 comparison of the AI voice-agent platforms for inbound customer calls - Retell AI, Vapi, PolyAI, Parloa, Synthflow, NICE Cognigy, Bland AI and Salesforce Agentforce Voice, plus generic assistants as a baseline - across latency, conversational robustness on the phone, CRM and telephony integration, deployment model and pricing reality. Every platform answers and routes calls, but none keeps how your company actually resolves a call - the answers, exceptions and escalation rules - nor owns the last mile across your real systems. The durable win is a Company Brain that keeps your call-handling knowledge when the support lead leaves, plus an AI employee that runs the routine calls end to end. Includes the EU AI Act Article 50 transparency line and the DSGVO/call-recording realities most comparisons skip.

DPIA for AI Agents: How the German Mittelstand Implements GDPR Article 35 for Agent Rollouts in 2026
AI Compliance

DPIA for AI Agents: How the German Mittelstand Implements GDPR Article 35 for Agent Rollouts in 2026

Practical guide for German SMEs on running a DPIA for AI agents. WP248 nine-criteria test, DSK Orientierungshilfen, DPIA vs. FRIA (EU AI Act Art. 27), 7-step process, RAG-specific risks, costs and timelines.

Building better software Contact us together