EU AI Act's transparency rules are here - here's what you need to know for your AI tools
Is your internal AI knowledge base in scope for the EU AI Act? What Article 50 requires, who actually owes the disclosure, and the real SME fine ceiling.

EU AI Act's - Article 50 Overview
Disclaimer: This article is for general information only and does not constitute legal advice. If you need advice on how the new rules apply to your situation, speak to a qualified solicitor.
Through July, almost everything published about the EU AI Act's transparency rules described the same thing: a support bot on a public website, greeting customers. That's one use case, but there's many use cases for AI and it's not always clear where the new legislation applies and doesn't. We choose to apply broadly, not only for our customers benefit but also to ensure we're not inadvertently hitting an EU tripwire.
As we own and operate infrastructure that allows companies to build their own AI knowledge bases it was important we figured out how best to apply it to our situation and we decided to do a write up to help anyone else looking for these answers.
What Article 50 actually requires of an internal AI knowledge base
Article 50 covers four different situations, and they get muddled together constantly. Marking synthetic audio, image and video output. Telling people when emotion recognition or biometric categorisation is being used on them. Labelling deep fakes and AI-generated text published to inform the public. And, first in the list, the one that matters if your team types questions into a chatbot: a system that interacts directly with people has to tell those people they're dealing with an AI system.
That obligation applies from 2 August 2026, per the Commission's own FAQ [1]. The Commission adopted detailed guidelines on the transparency obligations on 20 July 2026, which is where most of the practical detail lives [2]. The guidelines are non-binding — they say so themselves, noting that authoritative interpretation "may ultimately only be given by the Court of Justice of the European Union" [2]. They're still the best available read on how enforcement will think.
Two details did more work for us than anything else. The obligation sits on providers, not on the companies deploying the system — more on that below. And it reaches outside the EU: providers established in a third country are subject to it where the output of their system is used in the Union [2]. Not incidental or unforeseeable use, but staff in Dublin or Berlin asking your handbook assistant about parental leave is neither incidental nor unforeseeable.
So a UK company with EU employees or EU customers is inside the frame.
“Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.”
European Commission, AI Act Service Desk
Article 50, Regulation (EU) 2024/1689
"Internal" is not a scope limit
Article 50(1) says "natural persons". Your employees are natural persons. The guidelines are explicit that those persons "may be professional deployers, other users… or other persons using the system on their behalf", and the only things carved out are closed physical environments like industrial machinery, backend machine-to-machine calls whose output never reaches a person, and virtual environments with no human contact [2]. There is no public, consumer or customer-facing carve-out anywhere in it. Your access controls decide who gets in. They don't decide whether the rule applies.
Here's the part the fear-based posts skipped, and it cuts against the point we've just made. Among its examples of "obviousness", the Commission lists an internal employee-facing assistant for properly trained, AI-literate staff using it for internal organisational purposes — HR, legal, procurement, compliance, IT support [2]. So there is a route by which a handbook assistant needs no disclosure.
We wouldn't lean on it. The same guidelines say the exception "should be interpreted restrictively" and should be limited to cases where "there is almost no doubt left about the nature of the interaction" [2]. It turns on facts about your staff and their training, which means it's an argument you'd have to make rather than a box you tick. Also worth knowing: disclosure buried in terms and conditions doesn't satisfy the duty, and generic wording like "assistant" is listed as insufficient on its own [2]. The cheap version of compliance is the one that doesn't work.
“The exception should be interpreted restrictively given that it deprives natural persons from the protection and the right to be informed with clear and distinguishable disclosures that they are interacting with AI systems. The general awareness of consumers and other natural persons that AI systems (including chatbots and agents) exist does not imply that they recognise them in interactions.”
European Commission
Guidelines on transparency obligations for providers and deployers of AI systems, para 45 (2026)
Who actually owes the disclosure — the provider/deployer split
A provider is whoever develops an AI system, or has it developed, and places it on the market or puts it into service under their own name or trademark [2]. Deployers — the companies using someone else's system — are pulled into Article 50(3) and (4), the emotion-recognition and deep-fake duties. They are not listed as bearing 50(1) [2]. The chatbot disclosure duty follows the build, not the usage.
Three scenarios, and you'll recognise yours immediately.
You bought a tool off the shelf. Your vendor built it, placed it on the market under their name, and owes the disclosure. Your job is to check they've done it and keep a record that you checked. That's it. If your assistant runs at a URL your vendor hosts, this is you.
You built it yourself on a raw model API. You wired up a model behind your own interface, over your own documents, for your own staff. The guidelines address this case directly: a company that develops an interactive AI system in-house and puts it into service under its own name is a provider [2]. You owe the disclosure. Nobody upstream discharges it for you, and "we only used an API" is not a defence.
You white-labelled it under your own brand and domain. Genuinely unsettled. The guidelines cover modification-plus-rebrand: take an existing generative system, modify it — new training data, for instance — put it into service under your own name, and you become a provider of the new system, without prejudice to the original provider's responsibility [2]. What they don't address is pure rebranding with no modification, which is exactly what a custom domain and your own logo amount to. Read your contract. If it's silent on who owns Article 50 disclosure, ask, and get the answer in writing.
If your vendor is the provider, the useful thing to hold is evidence: who owes the disclosure, what security accreditation sits behind the system, and whether your documents are ever used to train models. Ours are documented rather than described.
ISO 27001In Stark Chat, the AI disclosure is a fixed element of the interface. It appears before the first message, and theming can't remove it — you can change colours, logos and copy elsewhere, not that. That mirrors what the guidelines recommend: a single prominent notification before the first interaction is likely to suffice in most instances, delivered as a banner or first-turn greeting [2].
The risk of getting it wrong
It's relatively simple to get right - but if you do inadvertently miss something, the fine isn't nearly as damning as made out.
Article 99(4)(g) sets fines for Article 50 breaches at up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher [3]. That's the number every alert we read quoted. Cooley: "Noncompliance can trigger fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher" [4]. Accurate, and incomplete.
Two paragraphs down, Article 99(6) inverts it: "In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower" [3]. Lower, not higher. None of the law-firm alerts we sampled in the SERP mentioned it [4].
The arithmetic on a real company. Turnover £5m, 40 staff. 3% of £5m is £150,000. €15m is the higher figure, so under Article 99(6) it drops out. Your exposure ceiling is around £150,000, and that's a ceiling, not a tariff — the Commission adds that fines must take account of SMEs' "economic viability" [2]. Medium-sized means under 250 staff with turnover of €50m or less, or a balance sheet of €43m or less, so most readers of this qualify.
£150,000 is still real money. It is not the existential number that's been circulating.
“Provider and deployers that do not comply with the applicable transparency obligations laid down in Article 50 AI Act may be fined up to EUR 15 000 000 or, if the offender is an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher... In the case of small and medium-sized enterprises (SMEs), including start-ups, each fine shall be up to the above percentages or amount, whichever is lower. The fines shall be effective, proportionate and dissuasive and take into account the interests of SMEs and small mid-cap enterprises (SMCs), including start-ups, and their economic viability.”
European Commission
Guidelines on transparency obligations for providers and deployers of AI systems, para 152 (2026)
The five checks we ran on our own EU AI Act internal AI knowledge base position
It's short because it's the list we actually used, not a maturity framework.
One: write down every conversational AI in the business. The knowledge base, the recruitment screener, the thing someone in marketing signed up for in March. Count it if a human types into it.
Two: open each one and look at the first screen. Is there a plain statement that this is an AI system, before the first message? Not in the footer, not in the terms.
Three: email each vendor. Two questions — do you consider yourself the provider under Article 50(1), and how do you handle the Article 50(2) marking duty? Keep the replies.
Four: record who signs off AI in your organisation. One named person. Most companies can't answer this quickly, which is a problem you can fix this week.
Five: note, per system, whether any EU staff or EU customers touch the output. That's what pulls a UK deployment into scope.
None of that needs counsel. The white-label question does, and it's the only one we'd send to a lawyer.
Every Stark Chat knowledge base ships with the AI disclosure fixed in the interface, before the first message, on every plan. Worth seeing on screen rather than taking on trust.
See the demoSources
[1] European Commission, FAQ — Transparency obligations under Article 50 of the AI Act, 2026 — https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
[2] European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, 2026 — https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
[3] European Commission, AI Act Service Desk — Article 99 (Penalties), Regulation (EU) 2024/1689 — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99
[4] Cooley, EU AI Act: Transparency Obligations Take Effect 2 August 2026 — https://www.cooley.com/news/insight/2026/2026-08-03-eu-ai-act-transparency-obligations-take-effect-2-august-2026
[5] European Commission, AI Act Service Desk — Article 50, Regulation (EU) 2024/1689 — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
Stark Chat - Bespoke AI knowledge bases
Connect your sources, brand it, set who gets access, and publish — a bespoke AI knowledge base your team can use in ten minutes. No code, no dev.
