8 min read

EU AI Act Article 50: Swiss Chatbot Compliance Duties

Disclosure duties for chatbots, deepfakes, and synthetic media are now enforceable across the EU market — and Swiss companies serving EU users have no carve-out, transition period, or "high-risk" threshold to hide behind.

Since August 2, 2026, Article 50 of the EU AI Act has been in force, imposing transparency obligations on providers and deployers of chatbots, conversational agents, emotion-recognition systems, and any tool that generates or manipulates synthetic text, image, audio, or video. Unlike the Act's headline "high-risk system" provisions, these duties apply regardless of risk classification: a customer-support chatbot, a marketing deepfake generator, and a biometric categorisation tool are all in scope purely because of what they do, not how dangerous a regulator judges them to be. Swiss companies with no EU legal entity are not exempt — the Act's extraterritorial reach captures any organisation offering AI systems to users located in the EU, which covers the substantial share of Swiss fintech, e-commerce, and SaaS businesses selling across the border. The compliance clock is no longer theoretical: national market surveillance authorities can now act on non-compliance, with fines reaching €15 million or 3% of global annual turnover, whichever is higher.

What Article 50 actually requires

The obligations split into four distinct duties. First, chatbots and conversational AI must clearly inform users, at the start of the interaction, that they are communicating with an AI system — a requirement that applies even when the AI nature might seem self-evident, with only narrow carve-outs such as certain law-enforcement contexts. Second, any AI-generated or AI-manipulated content — text, image, audio, or video — must be marked as synthetic, both visibly to a human viewer and, critically, in a machine-readable format that supports automated detection. Third, deepfakes specifically must be labelled as "artificially generated or manipulated" regardless of intent to deceive, a standard that captures satirical or clearly fictional content alongside malicious impersonation. Fourth, AI-generated text published on matters of public interest requires disclosure unless it has undergone substantive human editorial review with clear accountability attached — a provision aimed squarely at AI-assisted journalism and public communications.

Generative AI systems already on the market before the August 2 deadline receive a narrow reprieve: machine-readable watermarking specifically has a grace period running to December 2, 2026, while the visible-disclosure duties for chatbots and deepfakes apply immediately with no equivalent grace period. Organisations that read "grace period" as covering the whole Article are exposed to enforcement action on the disclosure obligations that are already live.

The Swiss compliance gap: nDSG overlap and enforcement reality

Swiss organisations already navigating nDSG fairness and transparency obligations will find meaningful overlap here, but not equivalence. The nDSG's transparency principle concerns how personal data is processed; Article 50 concerns whether a system's AI nature and synthetic outputs are disclosed, a distinct duty that applies even where no personal data changes hands — a purely text-generation chatbot with no data-protection footprint is still squarely inside Article 50's scope. Swiss legal and compliance teams treating this purely as a data-protection adjacent issue risk missing an entirely separate enforcement track, one with its own fine ceiling and its own market-surveillance authority structure across each EU member state where the company has users.

The burden-of-proof structure compounds the risk: under Article 50, the obligation is on the provider or deployer to demonstrate compliance if challenged, not on a regulator to prove a violation occurred. A Swiss company that has not documented its disclosure mechanisms, watermarking implementation, and editorial-oversight processes for AI-assisted public content has no evidentiary basis to contest an enforcement action, regardless of whether its actual practice was compliant.

Practical marking mechanisms and their limits

The European Commission has published a voluntary set of recommended icons and disclosure templates, but voluntary means exactly that — Swiss organisations can satisfy the legal standard through alternative implementations provided they meet the same visibility and machine-readability bar. In practice this means a genuine engineering decision, not a legal afterthought: machine-readable marking typically requires embedding metadata (such as C2PA-style content provenance signals) directly into generated media files, which must survive common transformations like re-encoding, cropping, or social-media re-upload to remain useful for downstream detection. Swiss marketing, communications, and product teams deploying generative AI tools need to validate that their chosen watermarking approach actually survives the distribution channels their content passes through, rather than assuming a one-time technical implementation satisfies an ongoing obligation.

◆ Key Takeaway

Article 50's chatbot and deepfake disclosure duties are already enforceable, with no risk-tier exemption and no meaningful grace period beyond machine-readable watermarking. Swiss companies serving EU users need documented, provable compliance now — the burden of proof sits with the provider, not the regulator.

  • Inventory every chatbot, conversational agent, and generative-AI tool that reaches EU users, regardless of whether it is classified as high-risk elsewhere in the AI Act.
  • Implement clear, front-loaded AI-disclosure notices at the start of every chatbot interaction, not buried in terms of service or a dismissible popup.
  • Apply visible synthetic-content labels to all AI-generated or AI-manipulated media, and validate that machine-readable markers survive your actual distribution channels.
  • Establish a documented human-editorial-review process for any AI-generated text published on matters of public interest, with named accountability.
  • Prioritise machine-readable watermarking retrofits for pre-August-2026 generative systems ahead of the December 2, 2026 deadline.
  • Maintain compliance documentation proactively — disclosure mechanisms, watermarking evidence, editorial-oversight records — since the burden of proof falls on the provider under enforcement.
  • Coordinate legal review between nDSG transparency counsel and AI Act compliance leads, since the two obligations overlap but are not interchangeable.

Article 50 is the first EU AI Act provision most Swiss organisations will actually encounter in production, precisely because it applies without regard to risk classification. The companies treating it as a documentation exercise now, before an enforcement inquiry forces the issue, will be the ones able to demonstrate compliance rather than scramble to reconstruct it after the fact.