Research

Most of them had written the disclosure. Almost none had put it where the conversation is.

Published 5 September 2026

Since 2 August 2026 a rule has applied across the European Union to very nearly every customer chatbot on the continent. Article 50 of the EU AI Act says that when a person interacts with an AI system, they have to be told — clearly, and at the latest at the first interaction.

It is a short rule, and an unusually concrete one. It does not ask for a policy, a process or an annual report. It asks for a sentence, in a particular place, at a particular moment. Which means you can go and look for it.

So we did. Between 8 August and 1 September 2026 we tried to open the customer chatbots of fifty-four organisations in Portugal, Italy, Spain and France — banks, airlines, supermarkets, railways, insurers, postal operators, energy companies and government portals — and wrote down what each one told a first-time visitor before they typed a word.

We expected to find organisations that do not say their assistant is an AI. That is not really what we found.

Most organisations with a working assistant had written a disclosure. Several had written a very good one. The commonest problem, by a wide margin, was not silence — it was placement. The sentence exists, and it is somewhere other than the conversation.

What we were looking for

One thing only: what a first-time visitor is told, inside the conversation, before they type anything. Not what the website says elsewhere, not what the terms of use say, and not what the assistant will admit if you ask it directly — because none of those is the moment the rule is about.

Two things follow from that, and they shape everything below.

The first is that a great many assistants cannot be reached at all. Of the fifty-four organisations we tried, we got a conversation out of twenty-nine. The other twenty-five either advertise an assistant that will not open, put a wall in front of it, or have no chat in the first place.

The second is that this is not a compliance audit and could not be one. Article 50 places its duty on the provider of the AI system — broadly, whoever built it and put it on the market under their own name — and from outside a website you cannot tell who that is. There is also an exemption for cases where it is obvious anyway that you are dealing with a machine; the European Commission says that exemption should be read narrowly, but it has never been tested in court. So what follows is a record of what visitors were shown, and when. Nothing more than that.

And it should be said at the outset that this is a small, chosen sample. Fifty-four organisations is not many, they were picked rather than sampled at random, and what follows is what we saw in four countries over three and a half weeks. It is a snapshot, not a picture of the European web.

Nine times, the right words were in the wrong place

Across the four countries, nine organisations had an accurate description of their AI assistant sitting somewhere a person in the middle of a conversation would never see it. Some of those assistants we could talk to and some we could not; the disclosure was in the wrong place either way.

In one case the terms of use state plainly that the assistant is automated and that its answers are generated by an artificial intelligence system. The chat itself introduces the assistant by name and says nothing at all. In another, the disclosure sits in the privacy note beneath the window rather than in the window. In a third it is in a banner further up the page, whilst the greeting inside the widget mentions only a “virtual assistant”. Elsewhere it lives on a promotional page describing a chat that cannot be started, or in an answer to a question about what powers the assistant — a question you would have to think to ask.

None of these organisations is hiding anything. Every one of them has an employee who sat down and wrote an accurate account of the technology. The words then went to the marketing page, the terms, the help centre or the privacy notice — and the conversation went somewhere else.

The European Commission’s guidance on Article 50, adopted on 20 July 2026, gives disclosure buried in terms and conditions as an example of what does not work, and says the “obvious” exemption should be read restrictively because it deprives people of transparency. What our fieldwork adds is that this is not an edge case. It was the single most common thing we saw.

It also means the fix is unusually cheap. These organisations do not need persuading to disclose. They have already written the sentence. It needs moving.

Not one launcher bubble said anything

Most assistants announce themselves with a small bubble that appears unprompted in the corner of the page. We checked every one of them for what it says before you click. Across four countries, every sector, and every organisation we reached, not one disclosed anything.

They say hello. They ask whether you need help. They introduce a first name. They do not say what you are about to talk to.

That matters more than it sounds, because the bubble is the only thing a great many visitors ever see. It arrives without being asked for, it is designed to be read at a glance, and most people close it. For a rule that asks for the notice at the latest at the first interaction, a system whose opening move is an undisclosed greeting — with the disclosure waiting behind a click — is at least an open question. It is a question the entire industry has answered the same way.

Most of them, you cannot reach at all

Fifty-four organisations attempted; twenty-nine conversations reached. The other twenty-five divide into three groups, and the split is itself a finding.

  • Some advertise an assistant that will not start — a button that does nothing, a page whose own instructions point at a control that is not there, a promise of help at any hour above a link that goes nowhere. We re-checked several of these three weeks later, on a weekday afternoon: unchanged, with the advertising still in place.
  • Some put a wall in front of it: an email address, a first name and surname, a membership number, or a full login before a single word is exchanged.
  • And a good many simply have no chat. Postal operators, railways, energy retailers, national government portals.

The walls are worth pausing on. In every case where an assistant sits behind a form, that form asks for personal details and explains, prominently and before you can proceed, what will be done with them. The data-protection notice is always there. The notice about who or what you are about to talk to never is.

The contrast is not really an accident of design so much as of age. The GDPR has applied since May 2018, and in eight years its requirements have worked their way into the fabric of every form on the internet, including that one — it is simply what a form looks like now. Article 50 has applied since August. It has not got there yet, and this is roughly what the early years of a transparency rule look like from the outside.

France was the extreme case: seven organisations attempted, one conversation reached. That is not a judgement on France — the one assistant we did reach there writes the plainest disclosure in the whole study.

“Virtual assistant” is doing a lot of work

Sorting what people actually write, three groups appear rather than two.

Some name the technology. They say artificial intelligence, in the conversation, before or at the first message.

Some state plainly that you are talking to a machine without naming the technology. “I am the chatbot of…”, “welcome to the service robot”. Nobody hears either of those as a person, and the Regulation prescribes no particular form of words, so the absence of the letters A and I is not itself a shortcoming.

And a great many use a phrase that describes both software and a job that people do. “Virtual assistant” and “digital assistant” are not false. They are simply ambiguous — a virtual assistant is also an occupation, and a remote human being answering messages is a perfectly ordinary arrangement. Measured against the Commission’s test of how an average person, reasonably well-informed and observant, would understand it, that is the difference that matters. It is also a difference of one word.

Two of the assistants in this group are represented not by a cartoon robot but by a photorealistic photograph of a woman. Whatever the words say, the picture is making an argument of its own.

What good looks like

Four organisations are worth naming, and they are good in different ways. They are named because there is nothing here for them to answer.

The most readable: Orange, France.

“Je suis une IA, pensez à vérifier mes réponses. Comment puis-je vous aider ?”
“I am an AI, remember to check my answers. How can I help you?” — the first line of the first message, with no gate, no login and no launcher to find: the assistant is simply there, already open, on the help page.

Nine words name the technology and attach the one caveat that matters. For a notice that has to work at the very start of a conversation, brevity is not a lesser virtue.

The most precise: the Agencia Tributaria, Spain.

“Se apoya en sistemas de Inteligencia Artificial para un mejor entendimiento y clasificación de las preguntas. No obstante, las respuestas proporcionadas han sido redactadas por personal cualificado.”
“It relies on Artificial Intelligence systems to better understand and classify questions. That said, the answers provided have been written by qualified staff.”

The Spanish tax authority is the only organisation in the study that separates what the machine does from what a person did. It is a more informative statement than “this is an AI”, and it tells you where the tool sits on the line between sorting your question and writing the answer.

The most complete: Aeroporti di Roma, Italy.

“Le risposte sono generate automaticamente senza interazione con un operatore umano.”
“The answers are generated automatically without any interaction with a human operator.” — shown, along with the reference to generative AI, before the greeting.

It answers the question a visitor is actually asking, which is not “is this an AI” but “am I talking to a person”. Almost nobody else does.

The most humble: gov.pt and the Portal das Finanças, Portugal.

“…assistente virtual baseado em inteligência artificial (IA). Este sistema não é um ser humano e pode cometer erros.”
“…a virtual assistant based on artificial intelligence (AI). This system is not a human being and can make mistakes.”

Two Portuguese government portals, running near-identical wording from what is evidently a shared template: name the technology, deny the humanity, admit the fallibility, and route anything serious to a person. It is the most copyable thing we found.

Three others deserve a mention. Caixa Geral de Depósitos puts its AI statement above the greeting rather than inside it. Eni Plenitude puts it in the panel you pass through to start. And the Comunidad de Madrid is the only organisation in the study that offers a genuine refusal — accept or decline — where everyone else treats carrying on as consent.

If you run a chatbot, three things follow

  • Look at your launcher bubble. It is probably the only thing most of your visitors read, and it probably says nothing.
  • Find out where your disclosure actually lives. If it is in your terms, your privacy notice, a page banner or a help article, it is not where the conversation is.
  • Check whether the notice is even yours. On one site the only mention of AI came from the chat software’s own default system message, in a language the rest of the page was not written in. If the sentence arrived with the widget rather than from you, you do not control it — and it may not be in your customers’ language.

How this was done

Fifty-four organisations across Portugal, Italy, Spain and France, between 8 August and 1 September 2026, on a desktop browser, from a connection in the relevant country. Twenty-nine first interactions reached. Anything ambiguous was re-checked by hand; where a widget did not open, that is recorded as “did not open for us”, never as broken.

Assistants on WhatsApp and on telephone lines sit outside a survey of websites, and at least two of the organisations here have one. Mobile versions, screen-reader text and what happens after the first message were not tested. Some websites refuse automated connections altogether.

One finding is a method problem worth reporting. A large retailer’s Italian page served us a chat that greeted us in Portuguese; the same address, on an Italian connection, served the Italian version. These widgets are routed by where the visitor appears to be rather than by the language of the page — and a disclosure delivered in a language the reader is not reading is not much of a disclosure to them.

What this is not a picture of

The candidate lists were built from trade coverage, vendor case studies and press reports. Those sources favour large, well-known organisations that publicise their assistants, and they report launches enthusiastically whilst never reporting withdrawals. So this survey describes big, visible brands in four countries, one month into a new rule.

It says nothing at all about small businesses. A shop or a practice running an off-the-shelf widget bought from a supplier is entirely untested here, and might look very different in either direction. Twenty-three of the twenty-seven member states were not looked at. Twenty-nine conversations is far too few to carry a percentage, which is why we have deliberately not calculated one.

And each observation is a single visitor, arriving by one route, at one moment. A different entry point into the same widget might well produce different wording, and we have not tested that. Where something changed between two visits we have said so; where we only looked once, that is all we claim.

Why the organisations are not named. We did not contact any of them for a response before publishing. Without a right of reply, naming an organisation in connection with a shortcoming is not fair — and it is least fair to the smallest, who have the least capacity to answer. So every observation that could be read as critical is described without a name, and where a direct quotation would identify the organisation it has been paraphrased. The organisations named above are named only for things they did well, where there is nothing to answer.

The legal position, stated once

Article 50(1) of the EU AI Act has applied since 2 August 2026. It requires that people interacting with an AI system are informed of that, clearly and distinguishably, at the latest at the first interaction, unless it is obvious to a reasonably well-informed, observant and circumspect person. The duty binds the provider — whoever developed the system and put it on the market under their own name. From outside a website it is not possible to tell who the provider of any given assistant is, so nothing here is a statement about whether anybody has met or missed a legal obligation. The Regulation prescribes no particular form of words. The “obvious” exemption exists, is untested in case law, and several of the organisations we looked at would have a real argument under it. This page reports what a visitor was shown, and when.

Not sure where you stand? The free checker tells you in two minutes which duties apply to you — no signup, no tracking cookies, and your answers never leave your browser.

Run the free 2-minute check →
Not legal advice. Disclosed. is an information and template tool, not a law firm. The EU AI Act’s official text, the European Commission’s Article 50 Guidelines and the Code of Practice on Transparency of AI-generated Content are the authoritative sources. Nothing here creates a solicitor–client relationship, and it can’t account for your specific circumstances. For decisions with real consequences, consult a qualified adviser in your jurisdiction.

Want to know when this changes?

The rules are new and still moving. Leave an address and you will hear from a person, rarely, about the things you tick — and nothing else. The checker and every guide stay free and open either way.

No account, no password, and nothing on this site is behind it. Leave at any time by replying to any email. What happens to your address: the privacy notice.