News

The customer does not know whether a human is replying: what the company must disclose

  • 23. September 2026

1. ABSTRACT

A customer on a website often does not know whether a human is replying. The company, for its part, does not know which text, voice or image it must label as the product of artificial intelligence and which it need not. That duty has applied since 2 August 2026 under Article 50 of Regulation (EU) 2024/1689 of the European Parliament and of the Council on artificial intelligence (the “AI Act”). Regulation (EU) 2026/1744, in force since 27 July 2026 (the “Omnibus”), did not postpone it. The Omnibus moved other rules, in particular the duties for high-risk systems.

Most Slovak overviews stop at the sentence that a chatbot must be disclosed and a deepfake labelled. That is a sound start and a weak ending. On 20 July 2026 the European Commission issued Guidelines C(2026) 5054 final on Article 50 (the “Guidelines”). They are not a statute. They are the reading by which supervisory authorities will assess the duty. And on 17 September 2026 the National Council of the Slovak Republic sent to second reading a bill on state administration in the field of artificial intelligence and European data regulation. The Digital Integrity Authority will not be created under that bill. The bill is not yet law.

This text does not deal with what an employee must not paste into ChatGPT. We addressed that on 18 August 2026 in ChatGPT at work. An internal tool for trained staff and a chatbot offered to customers are two different legal situations. The Guidelines separate them by examples as well.

The article covers five points that overviews usually fold into one: (A) who is the provider and who merely deploys the system, (B) when the “it is obvious anyway” exception fails, (C) when a text on a matter of public interest need not be labelled, and what defeats that exception, (D) what consumer law already requires, even though the Slovak authority for the AI Act has not yet been set up, and (E) what does not yet follow from the September bill.

2. THE RULES AND THEIR WEIGHT

When we advise a client, we do not sort material into “what is being written about AI”. We sort it by what binds us.

(A) Binding, and already applicable: Regulation (EU) 2024/1689, in particular Article 3 (definitions), Article 50 (transparency), Article 99 (fines) and Article 113 (temporal application). The Regulation applies directly. A Slovak statute is not needed for the duty to arise.

(B) Binding, and it changes the timetable: Regulation (EU) 2026/1744. Chapter III duties for stand-alone high-risk systems (Annex III, for example recruitment or credit scoring) will apply from 2 December 2027. For systems embedded in regulated products, from 2 August 2028. The transitional period until 2 December 2026 concerns only machine-readable marking under Article 50(2) for generative systems placed on the market before 2 August 2026. The duty to disclose a direct interaction with a human being is not postponed beyond 2 August 2026. Point 153 of the Guidelines says so.

(C) This is an interpretative rule, not a binding instrument: Commission Guidelines C(2026) 5054 final of 20 July 2026. The Court of Justice may adjust or change such an interpretative rule. Until it does, the Guidelines are the reference text for a uniform application of Article 50 in the Union. The Code of Practice on marking content created by artificial intelligence, published on 10 June 2026, is voluntary. A firm that does not sign it does not lose the duty. It loses only the simpler way of demonstrating compliance (points 146 to 148 of the Guidelines).

(D) Not yet law: the Slovak bill after the second reading of 17 September 2026. It regulates authorities, inspection and the sanction procedure. It does not repeat the duties in the Regulation, and it does not yet enforce them either.

3. THE PROVIDER IS NOT WHOEVER HOLDS THE OPENAI INVOICE

Article 3(3) of the AI Act defines the provider as the person who developed the system, or had it developed, and places it on the Union market or puts it into service under its own name or trademark, whether for payment or free of charge. The deployer is the person who uses the system in a professional activity, other than personal non-professional use.

That split cannot, in contract practice, be replaced by the sentence “the model supplier takes care of the watermark”.

Under Article 50(1) the provider must design the system so that a person knows they are communicating with a machine, unless that is obvious. Under Article 50(2) it must ensure that the outputs of a generative system carry a machine-readable mark. If a Slovak software firm takes someone else’s model, builds a chatbot on it and sells the chatbot to clients under its own brand, that firm is the provider. The laboratory that trained the model is not.

A company that merely switches such a chatbot on its own website and lets it answer customers is the deployer. A machine-readable mark in the file does not discharge its duty under Article 50(4). That duty requires a label a person can perceive. Point 8 of the Guidelines adds that one system may at the same time create a duty for the provider and a duty for the deployer. Where an image is produced in a conversation with a person, paragraphs 1 and 2 may both apply, and if the output is a deepfake or a text on a matter of public interest, paragraph 4 as well.

In a mandate where the client buys a chatbot and at the same time uses it to serve its own customers, both positions meet in one contract. Without a written split, the risk stays with the name under which the system is used outwardly. We recommend recording three things separately in the contract: who is the provider under Article 3(3), who holds editorial responsibility for publication, and who pays the fine if the label is missing. A fine under Article 99 may reach EUR 15,000,000 or, if the offender is an undertaking, 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher. For small and medium-sized enterprises, including start-ups, point 152 of the Guidelines applies the lower of the two amounts. The Omnibus extends part of the relief intended for small and medium-sized enterprises to small mid-cap enterprises as well. The level of the rate does not, by itself, mean that a Slovak authority was in a position to impose it in September 2026. We return to that in section 7.

4. THE “IT IS OBVIOUS” EXCEPTION DOES NOT APPLY TO A WEBSITE CHAT

Article 50(1) does not require a notice if the artificial nature of the interaction is obvious to a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. Points 42 to 45 of the Guidelines say that this test is to be interpreted narrowly. A general awareness that chatbots exist does not mean that a person recognises one in a particular conversation. For systems that write and reply in a human way, the exception should remain for cases in which an average person in the target audience is left with almost no doubt.

The Commission itself states in the Guidelines what does not meet the exception: a chatbot embedded in an online platform or in a customer-support tool, where the user receives replies that may be perceived as human. A website chat given a first name and a photograph of a face, without a sentence saying that it is a machine, is exactly that case. The exception cannot be built on it.

The Commission takes a different example out of the exception. An internal assistant for properly trained employees, who know that they are using an artificial-intelligence system for HR, legal, procurement or IT work, may be obvious. The same applies to a code-review tool intended only for professional developers. The August article on ChatGPT at work concerns that internal use and data protection. A customer chat on a website is the other column. A conclusion from one cannot be carried over to the other.

If the general public can reach the system, including children, older people or persons with a lower level of knowledge of artificial intelligence, and the interaction is not obvious to them, the exception cannot be relied on under point 45 of the Guidelines. An e-shop that opens the chat to every visitor will generally fail that condition.

A sentence in the terms and conditions is not enough either. Point 142 of the Guidelines treats information as indistinct if it sits only in a manual, in a deep layer of a menu, or in terms that people do not ordinarily read. Article 50(5) requires a clear and distinguishable notice at the latest at the first interaction. Under point 143, once at the start of the session is enough. It need not be repeated with every sentence. It must be placed where a person will see it before the first reply, and in the language in which the service is provided. If the audience includes children, the notice should be appropriate to their age.

5. WHEN A TEXT ON A MATTER OF PUBLIC INTEREST NEED NOT BE LABELLED

Article 50(4), second subparagraph, requires the deployer to label text generated or manipulated by artificial intelligence if it was published in order to inform the public on matters of public interest. The duty falls away only if two conditions are met together: the text has undergone human review or editorial control, and a natural or legal person holds editorial responsibility for the publication.

Points 134 and 135 of the Guidelines say what that review is not. It is not a spell-check, the existence of an editorial policy on paper, or an automated review. The minimum is a substantive check of accuracy by a person who has professional judgement on the subject and who can approve, change or reject the text on the merits. Under point 138, the identity and contact details of the person or function that holds editorial responsibility should be publicly and easily findable, for example in the information on the website.

Point 136 adds a rule that Slovak overviews omit. If, after that approval, the system again substantively edits, supplements or reformulates the text, the exception falls. The result is again treated as text generated or manipulated by artificial intelligence. In an editorial process it is therefore not enough that “a lawyer looked at it” and the model is then left to make a shorter version for the website. A further pass through the model calls for a fresh substantive approval.

In points 131 and 138 the Commission also draws the scope. Among texts on a matter of public interest that must be labelled if the exception does not apply, it places, for example, a summary of a municipal council decision on a newspaper website, parts of an article on the effect of diets on a particular disease, investor information in a report of a listed company published on its website, and a warning by a meteorological institute on a social network. Outside the scope it places a fantasy novel, an advertisement and a product description, unless they contain a claim about health, consumer safety or sustainability, a chatbot answer intended only for the person who asked, internal communication, and advice by a consultant to a single client on compliance with the rules.

For a company newsletter the practical cut is this. An ordinary product description does not need a label under Article 50(4). A report for investors, a sustainability claim, or a text on how a new statute changes the duties of the public, does, unless it has gone through the review described in points 134 to 138. Legal news of a law firm, substantively approved by an attorney, with the firm taking the editorial responsibility stated on the website, may use the exception. A text that the model rewrites again after that approval may not.

A timing detail in point 154 of the Guidelines should also be kept apart from slogans. Outputs created and published before 2 August 2026 are not labelled after the event. A text created before that day, but published on or after 2 August 2026, must be labelled if it falls under Article 50(4). The date of publication decides, not the date on which the model generated the text.

6. RETOUCHING A PRODUCT PHOTOGRAPH IS NOT A DEEPFAKE

Under the AI Act, a deepfake is an image, audio or video generated or manipulated by artificial intelligence which resembles existing persons, objects, places, entities or events and would appear to a person to be authentic or truthful. The deployer must label it. For an evidently artistic, creative, satirical or fictional work, it is enough to disclose the existence of such content in a manner that does not hamper the enjoyment of the work.

Point 116 of the Guidelines narrows what e-shops heard as a blanket duty to label every “realistic” graphic. An alteration of insignificant substantive or technical elements, which does not change the judgement of authenticity, does not make a deepfake. The Commission expressly mentions lighting adjustment, colour correction, noise removal, cosmetic finishing, and the replacement or extension of the background of existing content for an aesthetic purpose, including product advertising. By contrast, the voice or face of a particular person, which nobody recorded or filmed in that way, must be labelled. A machine-readable mark inserted by the provider of the tool does not replace a visible label.

7. THERE IS NO SLOVAK AUTHORITY YET. THE DUTY, AND OTHER STATUTES, ALREADY APPLY

Member States were to designate market-surveillance authorities within a deadline tied to August 2025. As at 23 September 2026 Slovakia has no statute under which a fine under Article 99 could be imposed. The missing authority postpones enforcement of the fine under the AI Act. It does not postpone Article 50.

Article 50(6) states expressly that transparency under that article is without prejudice to other duties under Union or national law. Point 50 of the Guidelines applies this to Directive 2005/29/EC on unfair commercial practices and to Directive 2011/83/EU on consumer rights. If a service is driven by artificial intelligence, that feature may be a main characteristic which must be told to the consumer before the consumer is bound by a contract. That information duty applies even where the interaction would be obvious under Article 50(1). In Slovakia these directives apply through the consumer-protection rules. An unfair practice in which a machine presents itself as a particular employee is therefore already a matter for consumer supervision. It is not a matter waiting for a Slovak artificial-intelligence statute to enter into force.

Information duties under Regulation (EU) 2016/679 stand apart. Point 52 of the Guidelines says that Article 50(1) has a different aim and does not replace the duties towards the data subject. The sentence “you are writing to a machine” does not satisfy the notice under Article 13 of the General Data Protection Regulation if the chatbot collects personal data. And the reverse is also true: a link to a privacy notice in the website footer does not satisfy Article 50.

8. WHAT PARLIAMENT MOVED ON 17 SEPTEMBER, AND WHAT DOES NOT YET APPLY

On 17 September 2026 the National Council of the Slovak Republic sent to second reading a bill on state administration in the field of artificial intelligence and European data regulation. According to the text reported by the News Agency of the Slovak Republic, and according to an earlier announcement by the sponsoring ministry of 13 August 2026, the Digital Integrity Authority that had originally been considered will not be created. The general market-surveillance authority and the single contact point is to be the Ministry of Investments, Regional Development and Informatisation of the Slovak Republic. In selected areas, competence is also to lie with the National Security Authority, the Office for Personal Data Protection of the Slovak Republic, the Inspection Service Office and the Ministry of Justice of the Slovak Republic. The ministry is to establish a regulatory sandbox for testing systems. Penalties for breaches of the artificial-intelligence rules are to be determined under the AI Act. For serious breaches of the data rules, the bill provides for a fine of up to EUR 10,000,000 or up to 4% of worldwide turnover. That is a different rate and a different instrument. It is not to be mixed with EUR 15,000,000 or 3% under Article 99.

The bill envisages entry into force on 1 January 2027. The text may still change in the second reading. Until the statute is published in the Collection of Laws, a company can neither hide behind it nor treat it as the address to which a complaint belongs. The practical conclusion for a client is narrower: through the end of 2026, do not wait for a fine from the ministry, and do not wait with the notice on the website until the ministry has hired its staff. The notice under Article 50 has been due since 2 August 2026. Machine-readable marking for a generative system placed on the market earlier must be added by the provider by 2 December 2026.

9. WHAT THIS MEANS IN PRACTICE

Before a company changes the notice on its website, it must know how it uses the system. Only then does the wording of the warning make sense.

(A) Write down which systems the company sells or offers under its own name, and which it only uses on its own website. If a chatbot runs on someone else’s model but the customer sees your brand, you have the provider’s duties. For a tool that was already on the market before 2 August 2026, machine-readable marking of outputs must be added by 2 December 2026.

(B) For a chat aimed at customers, put the sentence at the very start of the conversation, where it can be seen. Hiding it in the terms and conditions is not enough. If the chat introduces itself with a person’s name and photograph and that sentence is missing, it cannot be said that everyone can see it is a machine. The exception for trained employees does not apply to a chat open to anyone from the public.

(C) A text on law, sustainability, health or for investors must either be labelled visibly, or be checked on the merits before publication by a person who understands the subject. State on the website who is responsible for the text. If, after that check, the model rewrites the text once more, the earlier check no longer holds and the text must be labelled.

(D) Adjusting colour or light on a product photograph need not be labelled. What must be labelled is sound or an image that pretends to be a particular person, or an event that did not happen.

(E) In the contract with an agency or with the chatbot supplier, write who labels the content, who is responsible for the published text, and who pays the fine if the label is missing. The fact that someone else prepares the campaign does not release the company from the duty. If the company uses the system and has control over it, the duty stays with the company.

10. CONCLUSION

The duty to say that a machine is involved, and to label specified content, already applies. A postponement does not cover it. Slovakia does not yet have an authority that could impose a fine under Article 99 for a breach. Firms draw two wrong conclusions from that. Some wait for the ministry and leave the chatbot on the website to introduce itself by a first name. Others label every leaflet, because they read that everything made by artificial intelligence must be labelled.

The Commission Guidelines of 20 July 2026 draw the line differently. A chat for customers must be identified as a machine at the start. An internal tool used only by trained employees who know that fact generally does not need this notice. An ordinary product description is not labelled under Article 50(4). An investor notice, a sustainability claim and legal information addressed to the public must be labelled. That duty falls away only when, before publication, a person who understands the subject checks the text on the merits, and a named person stated on the website is responsible for the publication.

ULC Čarnogurský assesses whether, for a particular deployment, the client is the provider or the deployer, prepares the wording of the notice, an editorial rule for texts on matters of public interest, and a contractual split of responsibility with the supplier of the system or with the agency.

The author is JUDr. Mag. Ján Čarnogurský, MBA, managing partner of the firm, entered in the list of attorneys of the Slovak Bar Association. This text does not replace an assessment of a particular system, contract or campaign.

SOURCES

(A) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Articles 3, 50, 99 and 113.

(B) Regulation (EU) 2026/1744, in force since 27 July 2026.

(C) Commission Notice, Guidelines on the transparency obligations of providers and deployers of certain AI systems under Article 50 of the AI Act, C(2026) 5054 final, 20 July 2026, in particular points 8, 42 to 45, 50, 52, 116, 131 to 138, 142, 143, 146 to 148, 152 to 154.

(D) Code of Practice on the transparency of content created by artificial intelligence, published on 10 June 2026, read with Article 50(7) of Regulation (EU) 2024/1689.

(E) Bill on state administration in the field of artificial intelligence and European data regulation, second reading in the National Council of the Slovak Republic on 17 September 2026. It has not been published in the Collection of Laws. The sponsoring ministry’s earlier announcement that the Digital Integrity Authority would be dropped is dated 13 August 2026.

A customer, seen from the side, looks at a laptop and does not know whether a human is replying: an android head claims to be a superb human
Contact form

Your rights, our expertise.
Contact us!

Enter your email address.
Enter your phone number.
Write us a message.
Consent to the processing of personal data.

Message is being sent...