AI transparency
Article 50 of the EU AI Act requires that a person interacting with an AI system is told so, unless it would already be obvious. The obligation applied from 2 August 2026. This page states how ChatWidget meets it, and goes further than the law requires, because a business that puts an assistant in front of its customers should be able to explain every answer it gives.
Disclosure
Every chat carries the line “You're chatting with an AI assistant” in its header, before the first reply. Merchants can reword it and translate it, but they cannot remove it: a blank value falls back to the default text. When a person from the merchant's team takes over, the line changes to say so.
Who bears the obligation
Both of us, in different respects. We are the provider: we place the system on the market and are responsible for it being capable of compliant operation, and for its default behaviour. Our customer is the deployer: they decide where it runs, what it is told to do, and how it is described to their own users. A provider cannot discharge a deployer's obligations, and we do not claim to.
Where a deployer's own use goes beyond the assistant as supplied, for example instructing it to present itself as a named human employee, that use is theirs to assess, and our acceptable use policy prohibits it.
How disclosure works in the product
- Disclosure is on by default in every workspace. It is not an option a customer must find and enable.
- It is shown before the first assistant message, in the panel itself, not in a tooltip, a footer or a hover state.
- The wording is editable so it can be translated and matched to a deployer's register, and the field cannot be emptied to remove the notice. A blank value falls back to the default text rather than rendering nothing.
- There is no setting, documented or otherwise, that removes the disclosure. This is enforced server-side, in the configuration merge, rather than left to the widget to honour, a client-side check would be removable by anyone editing the page.
Other Article 50 duties, and where we stand
| Duty | Applies | Position |
|---|---|---|
| Art. 50(1), inform natural persons they are interacting with an AI system | Yes | Met as described above. |
| Art. 50(2), mark synthetic audio, image, video or text in a machine-readable format | Not currently | The assistant generates conversational replies in a chat surface, not published synthetic media. We do not generate images, audio or video. If that changes, marking obligations will be assessed before release. |
| Art. 50(3), emotion recognition or biometric categorisation | No | The product performs neither. We do not infer emotion, and we do not process biometric data. |
| Art. 50(4), deep fakes, and text published to inform the public on matters of public interest | No | Out of scope for a customer-support assistant on a commercial website. |
| Art. 50(5), information given clearly, at the first interaction, accessibly | Yes | The notice is text in the panel, reachable by screen reader and keyboard, and not dependent on colour or hover. |
Risk classification
We assess the product as a limited-risk system subject to the transparency obligations of Article 50, and not as a high-risk system under Article 6 and Annex III. That assessment rests on the use the product is sold for: answering questions about a customer's own published content and performing commerce actions on their store. It does not extend to a deployer who configures it for a purpose in Annex III, for instance to influence access to employment, education, credit or essential services. A deployer intending any such use should not rely on our classification and should carry out their own.
Which models answer
Answers are written by language models accessed through OpenRouter. Merchants choose between the models listed in their settings; the default is named there.
We do not train models on a merchant's content or on their visitors' conversations, and the model provider is engaged on terms that prohibit it from doing so.
What the assistant will not do
It will not recommend a product that is not in the merchant's catalogue. It will not quote a price it has not read from the store. It will not ask for a password or a card number in the chat. When nothing in the merchant's content answers a question, it says so and offers a person.
How an answer can be explained
Every answer is stored with the passages it considered, the score of each, and the ones it was not allowed to use. The merchant can open that record beside any conversation, in the trace panel. Visitors see “Sourced from this store” under answers built from the merchant's own content.
Human oversight
A person can always take a conversation over. Shoppers can ask for one at any point, and operators can take over any chat from the console; while they do, the assistant stays silent. Every answer the assistant did give remains open to review afterwards, with its trace, and any answer a shopper marked as unhelpful arrives in the merchant's review queue with the shopper's own comment.
The assistant is built to decline rather than guess, and to hand a conversation to a person when it lacks grounds to answer. A deployer choosing to run without anyone monitoring that queue is making a decision about oversight, and should record it in their own assessment.
Keeping this page honest
This page describes the product as it is today. When something here changes, such as a new model or a change to how disclosure works, the change is dated on the changelog before it is reflected here, so there is always a record of when it happened.
What we ask of merchants
Keep the disclosure in a language your visitors read. Review your review queue, where questions the assistant could not answer collect. If your sector has its own disclosure rules, treat ours as the floor rather than the ceiling.
Do not instruct the assistant to deny being an AI, or to adopt the identity of a specific real person.
Contact
Questions about this position, or a request for our written assessment, go to our contact form. Related: the privacy policy, the sub-processor list and the security page, which states plainly what we have not certified.