Your Agentforce Bot Now Has to Say It's a Bot: EU AI Act Article 50

What changed for customer-facing agents on August 2, 2026?
Article 50 of the EU AI Act became enforceable on August 2, 2026. Any AI system that interacts with a person now has to tell that person they are dealing with AI, unless it is already obvious. It applies to agents already in production, regardless of when you shipped them, and national regulators can fine violations starting now.
This is not a future roadmap item you can park in a backlog. The transparency and information obligations are live and enforceable by national competent authorities across the EU. If you run an Agentforce agent that talks to people in the EU, the disclosure requirement attached to it on August 2, whether or not anyone told your client.
Does this hit my Agentforce deployment?
If your agent serves anyone in the EU, yes. Article 50 covers chatbots, in-app messaging, Agentforce Voice, and WhatsApp or SMS bots. It ignores high-risk classification and it ignores your go-live date. A bot you launched in 2024 for EU customers is in scope exactly like one you ship tomorrow.
Four scenarios sit inside Article 50. The one that touches almost every Agentforce build is the first: systems that interact directly with people must disclose they are AI. The other three cover machine-marking AI-generated content, disclosing deepfakes and AI-written public-interest text, and informing people exposed to emotion-recognition or biometric-categorization systems. Most CRM agent work lands on scenario one, and any Data 360 flow that generates public-facing copy or media pulls you into scenario two.
Where do I add the "you are talking to AI" disclosure?
Put the disclosure at the first point of contact in every channel: the agent's welcome message, the voice greeting before the caller starts talking, and the opening line of any SMS or WhatsApp thread. The rule is that the user knows before they interact, not after. One clear sentence is enough.
Concrete placement in Agentforce:
- Web and in-app messaging: set the agent's welcome/greeting message so the first thing rendered is the disclosure. Example copy: "Hi, I'm an AI assistant for Acme. I can help with orders, returns, and account questions. Ask me anything."
- Agentforce Voice: the IVR greeting has to carry it out loud, before the caller states their request. "You're speaking with Acme's AI assistant. How can I help?" The disclosure has to be audible, not buried in a privacy notice nobody hears.
- WhatsApp and SMS bots: the first outbound message in a new thread includes it, because there is no visual chrome telling the user this is automated.
"Unless it is obvious" is a real carve-out, but do not lean on it. A chat widget labeled "Live Chat" is not obviously an AI. If a reasonable EU user could think they reached a human, you owe the disclosure. Treat the exemption as narrow and write the line anyway; one sentence is cheaper than arguing about obviousness with a regulator.
Am I the provider or the deployer, and why does it matter?
Article 50 splits duties between providers and deployers, and the split changes who owns what. The provider builds or supplies the AI system; the deployer runs it under its own authority. Your Salesforce customer is usually the deployer. Salesforce and the model vendor sit on the provider side. Confirm this in the contract before you assume who is liable.
The distinction matters because scenario one (design the system so users are informed) leans on the provider, while deepfake and public-text disclosure duties (scenarios three and four) attach to the deployer. In practice, the operational disclosure copy in the greeting is something the deployer configures and is responsible for showing, even when the platform gives them the field to do it. When scoping an engagement, write down explicitly which party owns each of the four obligations. Fitting that mapping into an existing large org, on top of legacy agents nobody has audited since launch, is the kind of pre-go-live scoping I get pulled into, and it is faster to do before enforcement than after a complaint.
What about AI-generated content and the December 2 deadline?
Scenario two has its own clock. Providers of generative systems must machine-mark AI-generated or manipulated audio, image, video, and text in a detectable, interoperable format. For generative systems already on the market, there is a transitional runway: compliance is required by December 2, 2026, not August 2.
If your Agentforce or Data 360 build produces public-facing content, drafts published to a website, generated images, synthesized voice, that marking requirement is on the roadmap now with a hard date. Inventory every place an agent produces publishable text or media. The greeting disclosure is a config change you can ship this week; detectable synthetic-content marking is a technical dependency you want to raise with the client and the platform team while there is still runway.
What does getting this wrong cost?
Article 50 violations carry fines up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. That is the correct tier for transparency duties. Do not quote the 7% / EUR 35 million figure to your client for this: that higher tier applies to prohibited AI practices, not to transparency obligations.
Getting the number right matters for the business case. The 3% tier is still large enough to justify the work, and inflating it to 7% costs you credibility the first time the client's legal team checks the article. State the accurate exposure and let the size speak for itself.
A scoping checklist you can run this week
Run this against any Agentforce deployment touching EU users. Each item is a config change or an inventory task, not a rebuild.
- List every customer-facing agent and channel (web, in-app, Voice, WhatsApp, SMS) that reaches EU users.
- Add or verify an explicit AI disclosure in each channel's first point of contact, including the voice greeting.
- Map each of the four Article 50 scenarios to provider or deployer, and record who owns it in writing.
- Inventory every place an agent generates publishable text or media, and flag synthetic-content marking as a December 2 dependency.
- Put the accurate penalty tier (EUR 15M or 3% of turnover) in the risk section, not the prohibited-practices number.
The greeting change is a one-line edit. The value is doing it deliberately across every channel before someone files a complaint, instead of discovering the gap during an audit.
