Money · Operator memo

Does Article 50 apply to my WhatsApp or SMS chatbot?

Yes if the bot replies to people. The Commission FAQ lists chatbots, AI agents, and avatars as systems that interact directly with people. A WhatsApp, SMS, RCS, iMessage, or Telegram bot that answers a customer with generated text is in. The channel is just the pipe. The four criteria look at the exchange, not the app logo.

A one-way OTP or shipping blast is usually out of Article 50(1). The FAQ’s second criterion is a genuine two-way exchange, not merely collecting data or giving automated responses. “Your code is 482911” or “Your order shipped” with no talk-back usually fails that test. You may still have Article 50(2) marks on any generated text those blasts do write.

Get the $29 Article 50 Ship Checklist Buy a Money Brief $149

Not legal advice. Related: Email support agents · Voice / phone · Free notice tool

The four FAQ criteria, applied to messaging

The Article 50 FAQ (last update 24 July 2026) lists four cumulative criteria for the interaction-notice duty. All four have to hold:

  1. The system is an AI system.
  2. It is designed for a genuine two-way exchange with people, not merely collecting data or providing automated responses.
  3. The interaction is direct: the AI itself communicates with the person, not through a human intermediary.
  4. The person is a natural person (consumer, professional, or other user).

A WhatsApp Business number that answers “where is my order?” and keeps the thread going usually clears all four. A Twilio template that only fires an OTP, and never replies to a person, usually fails criterion (2) and the FAQ’s background carve-out.

What you shipped on the number

What you shipped Art. 50(1) notice? Why
WhatsApp / SMS / RCS / iMessage / Telegram bot replies to a customer with generated text Yes Direct two-way AI-to-person interaction. FAQ examples include chatbots and AI agents.
Flow that asks a question (“1 for tracking, 2 for returns”) and the AI answers Yes The person started a two-way exchange. The bot is talking, not a human intermediary.
Bot with a human first name and a staff photo as the WhatsApp avatar Yes, and treat “obvious” as out FAQ: identify a reasonably well-informed, observant person. A number dressed as a colleague is the opposite of obvious. Read the exception restrictively.
One-way blast: OTP, shipping, appointment reminder. No talk-back Usually no under Art. 50(1) FAQ: not a genuine two-way exchange; automated responses / background / no direct contact.
AI drafts the WhatsApp reply; a human agent hits send Usually no under Art. 50(1) FAQ: not direct when it goes through a human intermediary.
US company, EU customers on the number Still in if the other criteria hold FAQ: third-country providers are in if the output of the system is used in the EU.

Where Article 50(1) applies, people must be informed from the start of the first interaction, in a clear and distinguishable way, including accessibility. On WhatsApp or SMS that is the first bot message in that conversation (or persistent chrome on the thread), not a later “About” line, a website privacy policy, or a WhatsApp Business profile bio.

Other Article 50 duties that still bite one-way blasts

Article 50(2): providers of systems that generate synthetic text must mark that text in a machine-readable format so it can be detected as AI-generated. Bot replies are synthetic text. A limited grace period exists only for systems already on the market before 2 August 2026: those marks are due 2 December 2026. The in-thread notice is a different duty and had no extra delay.

Article 50(3): if the bot does emotion recognition or biometric categorisation on messages or voice notes (sentiment, “who is angry”), deployers must inform the people exposed. That duty is independent of the chatbot notice.

Article 50(4) public-interest text: deployers must label AI-generated text that is published to inform the public on matters of public interest, unless it had real human review or editorial control. A private customer thread is not that. A broadcast about a public-health recall or a political campaign might be.

WhatsApp Business terms, carrier rules, and GDPR (including ePrivacy / cookie-style consent for marketing SMS) are separate from Article 50. This page does not cover them.

What is live this week

Article 50 applies from 2 August 2026. The 31 July 2026 Commission press says chatbots and other interactive AI systems have to tell users they are dealing with AI, not a human. The Digital Omnibus moved high-risk dates, not Article 50.

National market surveillance authorities enforce most Article 50 cases. Fines can reach €15 million or 3% of worldwide turnover, with proportionality language for SMEs.

Do this in seven days

  1. Inventory every messaging surface: WhatsApp Business API, SMS/RCS short code, iMessage, Telegram, Instagram DMs if they share the same bot.
  2. If the AI replies to a person, ship a first-interaction notice in that conversation. Commission-style example used on this desk: “You are interacting with an AI system.”
  3. If it only sends one-way OTP or shipping texts, document why Article 50(1) is out (automated responses / no two-way exchange). Do not skip Article 50(2) marks on any generated text.
  4. Do not treat a human first name, a staff photo, or “everyone knows this is a bot” as obvious. The FAQ says read that exception restrictively.
  5. Do not put the only notice in the WhatsApp About field or a website privacy policy. The FAQ wants the start of the first interaction, clear and distinguishable.
  6. Open a 2 December marking ticket for pre-2 August products. If you run sentiment on inbound messages, add the Article 50(3) exposure notice.

Buy the checklist

The $29 Article 50 Ship Checklist is the print-and-tick page: inventory, notice line, deepfake labels, 2 December mark. The $149 Money Brief is the sourced memo if your stack mixes a one-way blast, a reply bot, and EU numbers on the same account and legal wants the FAQ criteria applied line by line.

Free notice-copy tool · Omnibus did not delay Article 50

Sources

Fetched 29 August 2026 (PT). No invented quotes.

  1. European Commission, “Transparency obligations under Article 50 of the AI Act,” FAQ, last update 24 July 2026 (chatbots, AI agents, and avatars as direct-interaction examples; four Art. 50(1) criteria including two-way exchange vs collecting data / automated responses; background and no-direct-contact carve-out; obviousness exception read restrictively; third-country providers in if output is used in the EU; Art. 50(2) machine-readable marks for synthetic text; Art. 50(3) emotion recognition; Art. 50(4) public-interest text; applies from 2 August 2026; 2 December grace only for Art. 50(2) marks; fines up to €15m / 3%). digital-strategy.ec.europa.eu
  2. European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, C(2026) 5054 final, 20 July 2026 (examples include chatbots/conversational agents and AI bots on social networks and media; first-turn greetings and persistent labels). ai-act-service-desk.ec.europa.eu
  3. European Commission, “Commission starts enforcing AI Act rules and new transparency requirements on 2 August,” press release, 31 July 2026 (chatbots and other interactive AI). digital-strategy.ec.europa.eu
  4. European Commission, AI Act policy page, last update 3 August 2026. digital-strategy.ec.europa.eu