Chatbots, AI assistants and deepfakes: when must AI be disclosed?
Part 3 of a three-part series on the European guidelines on AI transparency

Since 2 August 2026, the transparency obligations under the AI Act apply. In Part 1 of this series, we discussed when the use of AI must be disclosed. Part 2 focused specifically on AI-generated texts and the role of human review and editorial responsibility. In this third and final part, we focus on chatbots, AI assistants and deepfakes.
Does your organisation use a chatbot for customer contact? Or AI to create or edit images, audio or video? The same rules do not automatically apply. For a chatbot, the key issue is whether a person knows that they are interacting directly with AI. For a deepfake, it must instead be disclosed that certain content has been artificially generated or manipulated.
In this article
Do you use a chatbot or AI assistant? This is what your users need to know
Do you always need to disclose that someone is interacting with AI?
Do you use AI for images, audio or video? When is it a deepfake?
Do different rules apply to artistic, creative, satirical or fictional works?
One AI application may trigger several obligations for your organisation
Do you use a chatbot or AI assistant? This is what your users need to know
Article 50(1) of the AI Act applies to providers of AI systems intended to interact directly with natural persons. They must design and develop their systems so that persons are informed that they are interacting with an AI system, unless this is obvious from the circumstances and context.
According to the guidelines, four cumulative criteria apply:
the system qualifies as an AI system;
it is designed for a genuine two-way exchange with persons, rather than merely collecting data or providing automated responses;
the interaction is direct: the AI system itself communicates with the person and not through a human intermediary;
the interaction takes place with natural persons, such as consumers, professionals or other users.
AI systems that operate solely in the background, communicate machine-to-machine or have no direct contact with persons fall outside this specific obligation.
Do you always need to disclose that someone is interacting with AI?
No. A separate disclosure is not required where it is obvious to the user that they are interacting with an AI system. The Commission stresses, however, that this exception should be interpreted restrictively. The assessment is made from the perspective of an average person who is reasonably well-informed, observant and circumspect. Organisations should therefore not assume too readily that a user will automatically understand that their conversation partner is AI.
In practice, a simple statement can avoid ambiguity: “You are chatting with our AI assistant.” Users must be informed from the beginning of the first interaction. The information must be clearly distinguishable and comply with applicable accessibility requirements.
Does the obligation rest with you or with your AI supplier?
That depends on your role. The direct-interaction obligation under Article 50(1) of the AI Act rests with the provider of the AI system. An organisation using an existing AI solution supplied by a third party does not automatically become the provider merely because it uses that solution.
Other parts of Article 50 may instead impose obligations on the deployer: the organisation using an AI system under its authority. For deepfakes, for example, the deployer is responsible for the disclosure. It is therefore important for your organisation not only to identify which AI applications it uses, but also which legal role it performs for each application.
Do you use AI for images, audio or video? When is it a deepfake?
Not all AI-generated content is a deepfake. The AI Act defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
According to the guidelines, three cumulative criteria must be met:
Resemblance: there is a high level of similarity between the content and the simulated subject.
Existing or plausible: the simulated person, object, place, entity or event exists, can plausibly exist or could plausibly have existed in reality.
False appearance of authenticity or truthfulness: the content may potentially deceive or mislead a person as to its authenticity or truthfulness.
For example, an AI-generated video may convincingly show an existing director saying something they never said, or an AI-generated audio recording may strongly resemble the voice of an existing person. A clearly fictional AI-generated image, by contrast, is not automatically a deepfake merely because AI was used to create it.
Context matters
According to the Commission, the assessment may take into account:
the degree of resemblance;
the substantive message conveyed by the content;
the intended and reasonably foreseeable context of use;
the composition and expectations of the intended and reasonably foreseeable audience.
If the audience does not expect the content to be authentic or truthful in the relevant context, this may be relevant to whether the deepfake criteria are met. The Commission refers in this context to background scenes, special effects and technical pre- and post-production in ordinary film production.
What should you do if content is a deepfake?
Where content qualifies as a deepfake, the deployer must disclose that it has been artificially generated or manipulated. The disclosure must be made no later than when a natural person is first exposed to the content. It must be clear and distinguishable, understandable and perceptible to natural persons. The recipient should not have to use special technical tools or take separate steps to access the disclosure. A technical marker embedded in the content alone is therefore not sufficient.
Do different rules apply to artistic, creative, satirical or fictional works?
There is no complete exemption. Where a deepfake forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligation continues to apply. However, the obligation is limited to disclosure of the existence of the generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
The form of disclosure may therefore differ in this context. Whether the content qualifies as a deepfake in the first place still depends on the criteria described above, including the context and the expectations of the audience.
One AI application may trigger several obligations for your organisation
A single AI system may fall under several transparency obligations in Article 50 of the AI Act. Consider an AI assistant that communicates directly with users and also generates synthetic images during the interaction. Depending on the system's functionality and the way the output is used, several obligations may apply alongside one another:
Article 50(1) AI Act: the provider must ensure that natural persons are informed that they are interacting directly with an AI system, unless this is already obvious.
Article 50(2) AI Act: providers of AI systems that generate synthetic audio, image, video or text must ensure that AI-generated or manipulated output is marked in a machine-readable format and technically detectable as artificially generated or manipulated.
Article 50(4) AI Act: where a deployer uses AI-generated or manipulated image, audio or video material as a deepfake, natural persons must be informed that the content has been artificially generated or manipulated.
The distinction between paragraphs 2 and 4 is important. Paragraph 2 concerns the technical detectability of AI content and is directed at the provider. Paragraph 4 concerns transparency towards the person exposed to a deepfake and is directed at the deployer. A machine-readable marker under paragraph 2 is therefore not sufficient on its own to satisfy the disclosure obligation for deepfakes under paragraph 4.
What can your organisation do now?
Does your organisation use chatbots, AI assistants or AI to generate or edit text, images, audio or video? It is advisable to identify specifically where Article 50 of the AI Act affects your organisation. Start, for example, with the following steps:
Map where persons interact directly with AI.
Check what users see or hear from the beginning of the interaction.
Determine your role for each application: provider, deployer or potentially both.
Identify where AI generates or manipulates text, images, audio or video.
For images, audio and video, assess whether the content may qualify as a deepfake, taking account of resemblance, authenticity, context of use and audience expectations.
Check how any required disclosure is provided.
Document who is responsible internally for assessment and follow-up.
An employee using an AI system under the instructions and control of their employer is not thereby treated as a separate deployer. The legal person may retain that role. The same may apply where contractors or freelancers act on behalf of and under the responsibility and control of the organisation.
Can you still wait before implementing the requirements?
In principle, no. Article 50 of the AI Act has applied since 2 August 2026. From that date, providers and deployers must comply with the applicable transparency obligations.
A limited transitional arrangement applies only to certain AI systems placed on the market before 2 August 2026 and only to the marking and detectability obligation under Article 50(2). For those systems, that obligation applies from 2 December 2026. That transition does not apply to the obligation to inform persons who interact directly with AI.
What is the risk of non-compliance?
Infringements of Article 50 of the AI Act may result in fines of up to €15 million or 3% of worldwide annual turnover. Adjusted rules apply to the maximum fine for SMEs.
In the Netherlands, the supervisory framework for the AI Act is still being finalised. The proposal provides for several existing supervisory authorities, with coordinating roles for the Dutch Data Protection Authority (AP) and the Radiocommunications Agency Netherlands (RDI). This does not change the obligations themselves: Article 50 of the AI Act has applied since 2 August 2026.
Conclusion: transparency for chatbots and deepfakes
The AI Act does not require every use of AI to carry a general warning label. For your organisation, the analysis should therefore not start with: “Do we use AI?” but with: “Where do we use AI, what does the system do, what output does it produce, how is that output used and what role do we have?”
For chatbots and AI assistants, the key issue is whether natural persons interact directly with AI and are informed of this from the outset. For deepfakes, the question is whether AI-generated or manipulated image, audio or video content may falsely appear authentic or truthful — and whether the required disclosure is actually perceptible to the recipient.
This also brings the three-part series to a close: the use of AI itself does not determine which transparency obligation applies. The specific application, output, use of that output and the role of your organisation are decisive.
Earlier in this series
What do the AI transparency obligations mean for your business?
DUFINCO helps organisations determine which AI transparency obligations apply to their applications and which role they fulfil. We translate these obligations into workable processes, clear information for users and clearly assigned internal responsibilities.
Would you like to know what the AI transparency obligations mean for your business? Contact us at info@dufinco.nl or call +31 (0)6 512 47 217.


