Definition: Limited-Risk AI System (EU AI Act)
A limited-risk AI system under the EU AI Act is an artificial intelligence system outside the prohibited and high-risk tiers that still interacts with people or generates synthetic content, triggering Article 50 transparency duties rather than conformity assessment.
Core characteristics of limited-risk AI systems
Article 50 covers four situations, not a fixed use-case list, so one chatbot can trigger several duties at once. Every duty is disclosure, not pre-market approval.
- Systems for direct interaction with natural persons: chatbots, voice assistants
- Emotion recognition and biometric categorization systems
- Generative AI producing synthetic text, image, audio, or video
- Deepfake generators and AI-generated public-interest text
Limited-Risk AI System vs. High-Risk AI System
A high-risk AI system must clear conformity assessment first, since its use case carries significant potential harm. A limited-risk system carries no such presumption; it only has to disclose that a person is dealing with AI. A chatbot can be limited-risk alone, yet join a high-risk workflow once it feeds a hiring decision.
Importance of limited-risk classification in enterprise AI
Limited-risk duties reach far more everyday tools than high-risk rules do, since almost every customer-facing chatbot falls under Article 50. Gartner projects that by 2026, half of customer service organizations will have deployed generative AI virtual assistants.
Methods and procedures for limited-risk AI systems
Meeting Article 50 duties follows the interaction or content type a system produces.
Transparency-by-design for human-AI interaction
Article 50(1) requires providers to design systems so a person is informed they are interacting with AI, unless this is already obvious from context.
- Add a visible AI disclosure at the start of a conversation
- Avoid interface design that could pass a system off as human
- Document any reliance on the “obvious” exception
AI-generated content marking (Article 50(2))
Providers of generative AI systems must mark synthetic output in a machine-readable format that allows detection as artificially generated, using metadata or watermarking.
Deepfake and public-interest content disclosure (Article 50(4))
Deployers who publish deepfake media, or AI-generated text on public-interest matters, must disclose it as artificially generated at first exposure, clearly and without buried fine print.
Important KPIs for limited-risk AI systems
Tracking Article 50 readiness needs indicators separate from high-risk compliance metrics.
Disclosure coverage
- Chatbot disclosure rate: share of conversational tools with a visible AI notice
- Content marking rate: share of synthetic output with provenance metadata
- Deepfake disclosure rate: share of synthetic media labeled at first exposure
- Channel coverage: share of touchpoints reviewed for Article 50 gaps
Strategic risk exposure
Boards increasingly track Article 50 exposure separately from high-risk counts, since disclosure gaps are easier to spot than classification errors. Bitkom’s February 2026 study found 93 percent of German companies see the AI Act as a driver of extra compliance workload.
Quality of disclosure
A notice that technically exists but is easy to miss, such as text buried in a settings menu, does not satisfy Article 50’s “clear and distinguishable” standard.
Risk factors and controls for limited-risk AI systems
Limited-risk status still carries specific, ongoing compliance risks despite its lighter obligations.
Treating limited-risk as no-risk
The most common error is assuming “limited-risk” means “no action needed,” since Article 50 applies regardless of risk tier or company size.
- Inventory every customer-facing or content-generating AI tool
- Assign a named owner for Article 50 disclosure across marketing and service
- Re-check disclosure design whenever a tool changes provider
Inconsistent disclosure across channels
A chatbot might carry a clear AI notice on the website but not in a WhatsApp or voice channel added later, leaving a gap even where the original rollout was compliant.
Marking and watermarking technical gaps
Many generative AI tools used by Mittelstand marketing teams do not yet embed machine-readable provenance metadata by default, leaving the AI provider’s marking duty unmet even where a human-facing disclosure exists.
Practical example
A 130-employee online furniture retailer in Lower Saxony ran a website chatbot and generated AI product photography for seasonal campaigns. Before August 2026, neither carried an AI disclosure or provenance metadata. Working with its e-commerce agency, the retailer added a visible AI-assistant notice, switched to an image tool with built-in marking, and logged both changes for its data protection officer.
- Visible AI disclosure banner at the start of every chatbot conversation
- Machine-readable provenance metadata in AI-generated product images
- Quarterly channel review covering website, app, and social media
- Article 50 compliance log shared with the retailer’s legal advisor
Current developments and effects
Three developments are shaping how companies handle Article 50 now that its deadline has passed.
Enforcement attention shifts to disclosure gaps
With the Digital Omnibus postponing most Annex III high-risk duties to December 2027, supervisory authorities have more capacity for early Article 50 enforcement.
- Consumer protection bodies are testing chatbots for missing disclosures
- Journalists increasingly flag unlabeled deepfakes and AI-generated news
- Regulators favor visible fixes like banners over lengthy investigations
EU Code of Practice on AI-generated content
The European Commission has advanced a voluntary Code of Practice on transparency of AI-generated content, giving providers a reference set of marking techniques it treats as acceptable Article 50(2) evidence.
Vendor disclosure clauses in procurement
Enterprise buyers increasingly ask AI vendors to confirm in writing which Article 50 duties their product already meets, moving disclosure design earlier into vendor selection.
Conclusion
Limited-risk classification touches the most AI tools an enterprise actually uses day to day, even though its obligations are lighter than high-risk compliance. Article 50’s disclosure duties are simple to describe but easy to miss across every channel a tool reaches, which is where regulators are looking first. Mittelstand companies that inventory their customer-facing AI tools now, rather than assuming limited-risk means no risk, avoid enforcement exposure and the cost of a customer discovering undisclosed AI on their own. Treating Article 50 as a standing design requirement, not a launch checkbox, keeps a deployment trustworthy as new tools are added.
Frequently Asked Questions
What makes an AI system “limited-risk” under the EU AI Act?
A system is limited-risk if it misses the prohibited or high-risk criteria but still interacts directly with people or generates synthetic content. It triggers Article 50 transparency duties instead of conformity assessment.
Does a small company with a simple website chatbot really need to comply with Article 50?
Yes. Article 50 applies regardless of company size, so a small retailer’s chatbot carries the same disclosure duty as a large enterprise’s, though the obligation itself is just a clear AI notice.
How is Article 50 different from the Digital Omnibus deadline extension for high-risk systems?
The Digital Omnibus postponed Annex III high-risk duties to December 2, 2027, but Article 50 obligations were unaffected and applied from August 2, 2026 as scheduled. A company can be current on high-risk timelines and still breach Article 50 if its chatbots remain undisclosed.
What does Article 50 compliance cost for a Mittelstand company?
For a handful of customer-facing tools, adding disclosure banners and switching to a content tool with built-in marking typically takes days, not months. The bigger cost driver is discovering late that a tool lacks marking support.
Do we need our own IT team to handle Article 50 disclosures?
No. Most of the work is interface copy and vendor configuration, so marketing and compliance staff can typically handle it with light IT support. Companies like Superkind that build AI agents on top of existing systems design the disclosure in from the start.
How does limited-risk status interact with GDPR when a chatbot processes personal data?
Article 50 governs whether people are told they are talking to AI, while GDPR governs how any personal data that chatbot collects is processed. A chatbot handling customer data typically needs both, addressed in the same rollout review.