
Aug 27, 2026
Must You Tell Customers They're Talking to an AI?
Yes, if your assistant serves anyone in the EU, and since 2 August 2026 that yes has been a legal obligation rather than a courtesy. Step outside that scope and the answer grows more interesting: neither Saudi PDPL nor Meta's own rules oblige you to announce that a bot is answering. Because a German entity operates us, this was never a hypothetical on our side.
What the law actually says
Three distinct rulebooks get tangled up in this conversation, and each of them asks for something different. Only one of them is even about disclosure.
The EU AI Act, Article 50
Entry into force came on 1 August 2024; Article 50 became applicable on 2 August 2026. The obligation is stated briefly. Providers must ensure that natural persons are informed that they are interacting with an AI system, except where a reasonably well-informed person would find that obvious from the circumstances and the context. Certain law enforcement uses are carved out, and that carve-out will not reach your shop.
Another part of Article 50 deals with marking synthetic audio, image, video and text. For that piece, systems already on the market before 2 August 2026 were given until 2 December 2026. Where an assistant answers support questions, the first obligation is the one that bites.
Saudi PDPL
This is a data protection statute, not an AI disclosure statute, and treating the two as the same thing is the mistake we see most often. What it governs is how personal data gets collected, used and transferred: lawful basis, purpose, notice, and the rights of the person whose data it is. Nowhere does it contain an equivalent of Article 50 ordering you to announce that a machine is replying.
For a Gulf business, what matters is its reach. PDPL applies to processing the personal data of individuals inside the Kingdom, processing carried out by an entity outside it included. A Saudi merchant running a German-hosted assistant therefore sits inside PDPL's scope, and so do we. The duties attach to how the conversation is handled afterwards, not to whether you admit who wrote the reply. Those duties are walked through in the PDPL compliance guide.
What Meta's own policies require
Here is where people get surprised. Nowhere does the WhatsApp Business Messaging Policy oblige you to reveal that a bot is answering. Its demands run differently: an accurate business profile carrying real contact details, no impersonation of another business and no misleading people about what your business is, and when automation runs inside the 24 hour window, prompt, clear and direct escalation paths, with in-chat transfer to a human agent listed first among the acceptable routes.
Set those side by side and Meta's position hangs together: whether the customer knows a machine is typing barely registers with it, while the customer's ability to reach a person registers enormously. Compared with the AI Act, that is a different priority, and arguably a more practical one.
What the AI Act does not require
No legal disclaimer is demanded, no consent checkbox, no wall of text standing between a visitor and a question about opening hours. Repeating the disclosure in every message is not required either. Nor must the assistant withhold help until the customer acknowledges something. And where disclosure would be obvious anyway you are excused from it, which is a genuine exemption rather than a loophole: a widget labelled as an AI assistant, placed under a heading that says AI assistant, has already told the person what they are talking to.
Informing people is what the obligation asks. One sentence discharges it.
When you must disclose, and when you needn't
In substance, the duty attaches whenever anyone you serve is located in the EU. The trigger is not a European company on your side but European humans on the other end of the conversation. A Gulf hotel whose European guests message about a booking stands exactly where a European business stands, and most tourism, travel and export businesses across the region are in that position without ever having thought about it.
On the strict text of these three rulebooks, no disclosure is needed if your customers are only Saudi or Gulf and your escalation path to a human genuinely works. That is the honest reading of the rules. It also falls short of what we would recommend, but recommendation is a separate question, and we will reach it.
Disclosure that doesn't cost you the conversation
What people worry about is that admitting a bot is on the other end will get the chat closed. What actually gets chats closed, in our experience, is the customer finding out late, after typing out a long problem in good faith. Here are three patterns, ordered from least costly upward.
One line in the first message
Put one clause into the greeting, ahead of everything else. Not a paragraph, not a disclaimer, not grey text in brackets down at the bottom. Something along these lines: you are chatting with our automated assistant, and a colleague can take over any time you ask. That single sentence meets the obligation while setting an expectation that eases the rest of the exchange, because the customer now knows to write plainly rather than chat.
A name that isn't a person's name
The problem starts with the decision to call the assistant Sara, a decision usually taken in search of warmth, not to deceive. Still, a human first name operates as an implicit claim, and the customer feels handled once that claim proves false. Take the name from the business or the function instead. Meta's prohibition on misleading people about the nature of your business points the same direction.
A handover the customer can see
This is the strongest pattern, and also our default. A human taking over is announced inside the thread. When no answer is available, the assistant says so and puts a person on offer instead of manufacturing something plausible. At every moment the customer knows which of the two is on the other end, and nobody has to spend a thought on compliance.
How we read it, and what we did
Operating out of Germany ruled out two options for us: treating Article 50 as somebody else's problem, or waiting to see how enforcement would shape up. As we read it, the obligation is light, the exemption for obvious cases is genuine, and building to the strict interpretation costs next to nothing, so doing less had no case in its favour.
In practice that reading condensed into one default: handover to a human, done visibly. Our assistant says so when it reaches the edge of what your knowledge base covers, and offers a person rather than improvising, with the transfer shown inside the conversation. That one behaviour answers the AI Act's concern, that people know what they are talking to, and Meta's concern that people can reach a human, and it happens to be the behaviour customers prefer regardless of either rulebook. AI chatbot against human support sets out the trade-offs between automated and human answering.
And for the reason given above, no default persona ships from us carrying a human first name.
This is how we read it, not legal advice
What appears here is our own reading of published rules, checked against the primary sources on 6 September 2026, with links included so you can check them too. A software company is what we are; your lawyers we are not. The AI Act especially is young enough that enforcement practice will mould the meaning of these words in ways nobody can cite yet. Where the answer carries weight for your business, and for anyone serving EU customers it probably does, take advice from someone qualified to give it, and hand them the links above rather than this page.