Here is the question landing in inboxes across Hong Kong this month: if a customer messages your shop at midnight and an AI answers, are you legally required to tell them it is not a person?
The short answer is that it depends where your customer sits, and for a growing number of Hong Kong businesses the answer is now yes. A major transparency deadline arrives on 2 August 2026. This guide explains what AI disclosure means, who it applies to, what changes on that date, and how to disclose without losing the customer.
What Is AI Disclosure?
AI disclosure means telling a person, clearly and up front, that they are interacting with an AI system rather than a human, or that a piece of content was generated by AI. It is a transparency duty, not a restriction on using AI. You may still automate the conversation. You simply may not let the customer believe a person is on the other end.
Three things disclosure usually covers
--- Conversations. A chatbot, voice agent or AI avatar that talks directly with a person must identify itself as AI.
--- Synthetic content. Images, audio, video or text produced or materially altered by AI should be marked as such.
--- Deepfakes. Content that realistically depicts a real person, place or event but is fabricated must be labelled.
Notice what is absent from that list: your internal use of AI. Drafting your own quotations with AI, summarising your own meetings, or cleaning up your own spreadsheets creates no disclosure duty to anyone. Disclosure attaches to the moment AI faces a customer.
Do You Legally Have to Tell Customers They Are Talking to AI?
If any of your customers are in the European Union, yes. Article 50 of the EU AI Act requires that any AI system designed for direct interaction with a real person must inform that person they are dealing with AI. The obligation sits with both the company that built the system and the company that deploys it, which means the shop owner, not only the software vendor.
The rule is specific about timing and clarity. According to the text published by artificialintelligenceact.eu, the notification must be given at the latest at the time of the first interaction or exposure, and it must be delivered in a clear and distinguishable manner that meets accessibility requirements.
In practice that rules out three popular shortcuts. Burying the fact in a terms-of-service page does not count. Revealing it only after the customer asks does not count. A grey four-point footnote under the chat window does not count.
There is one sensible carve-out. Where it is obvious to a reasonable person that they are dealing with a machine, the notice is not required. A ticket kiosk does not need to announce itself. A friendly chat window named after a human being does.
Hong Kong has no equivalent statutory disclosure rule today. What it has instead is a privacy regulator paying close attention, which the next sections cover.
What Exactly Changes on 2 August 2026?
On 2 August 2026 the EU AI Act's transparency obligations become enforceable. Chatbot disclosure, synthetic content marking and deepfake labelling all switch on, and the Commission gains the power to fine providers of general-purpose AI models. Penalties for transparency breaches reach 15 million euros or 3% of worldwide annual turnover, whichever is higher.
Just as important is what does not change on that date, because a lot of alarming commentary has blurred the two.
Enforceable from 2 August 2026
--- Article 50 transparency: chatbot disclosure, AI content marking, deepfake labelling.
--- Fining powers over providers of general-purpose AI models.
--- A newly added prohibition in Article 5 covering AI-generated non-consensual intimate imagery.
Pushed back, not enforced yet
--- Standalone high-risk systems listed in Annex III now have until 2 December 2027.
--- AI embedded in regulated products under Annex I has until 2 August 2028.
That deferral came from the Digital Omnibus on AI, signed on 8 July 2026, the first set of amendments to the Act since its adoption in 2024. So 2 August 2026 is an enforcement date for transparency, not a cliff edge for every AI obligation in the law. For a small business, the practical scope is narrow and manageable: label the robot, label the fake.
This article is general information, not legal advice. A firm with meaningful European revenue should have its own counsel confirm scope.
Does This Apply to a Hong Kong Business?
It applies if your AI output reaches people in the EU, regardless of where your company is registered. A Hong Kong trading firm whose website chatbot serves German wholesalers is in scope. A Sheung Wan noodle shop whose WhatsApp bot answers Hong Kong regulars is not.
Three Hong Kong situations that commonly fall inside the perimeter:
--- Export and trading. A Kwun Tong electronics exporter runs an AI agent that quotes lead times to European buyers.
--- Cross-border e-commerce. A local skincare brand ships to France and uses an AI assistant on its storefront.
--- Tourism and hospitality. A boutique hotel in Wan Chai handles European booking enquiries with an AI voice agent.
Domestically, the pressure comes from a different direction. The Privacy Commissioner for Personal Data completed a round of AI compliance checks covering 60 Hong Kong organisations, with findings published in May 2026. Of the 57 organisations using AI, 24 (roughly 42%) collected or used personal data through those systems. The same body of work found that 55% of the SMEs surveyed had no Personal Data Privacy Management Programme at all.
The PCPD has published a Model Personal Data Protection Framework and a plain-language leaflet titled "10 TIPS for Users of AI Chatbots". Neither carries the force of a disclosure statute. Both signal what a regulator would expect to see if it came knocking.
There is also a commercial reason to care that has nothing to do with law. A customer who discovers mid-complaint that "Amy" was never a person tends to escalate rather than settle.
How Do You Disclose AI Without Scaring Customers Away?
The fear is that a disclosure line kills the conversation. Evidence points the other way: customers accept AI readily when it is fast and honest, and react badly to concealment discovered later. The trick is to pair the disclosure with a promise of speed and an obvious route to a human.
A disclosure line that works
Weak: "This service may use automated technology."
Better: "Hi, I'm an AI assistant for Wing Tai Trading. I can check stock, prices and delivery dates in seconds. Type HUMAN any time and a colleague will take over."
The second version does three jobs in two sentences. It discloses, it states the benefit, and it hands the customer an exit. Nothing about it reads as a legal notice.
Five practical placements
--- Chat widget. First message in the thread, before any customer input.
--- WhatsApp or messaging. Opening line of the automated reply, not in the profile bio.
--- Voice agent. First spoken sentence, before collecting any information.
--- Email autoresponder. One line in the signature block confirming the draft was AI-assisted.
--- AI-generated marketing images. A visible caption or on-image mark.
Two further habits help. Give the AI a name that does not impersonate a human, and log which conversations the AI handled so you can answer questions about a specific exchange months later.
Common Misconceptions About AI Disclosure
Most of the anxiety around this topic comes from four beliefs that do not survive contact with the actual rules. Clearing them up usually shrinks the job from a project to an afternoon.
"Disclosure means I cannot use AI for customer service." It means the opposite. The law assumes you will automate and asks only that you say so. Nothing in Article 50 limits what the AI may handle.
"My software vendor handles compliance for me." Article 50 places duties on providers and deployers separately. The vendor must build the capability. You must switch it on and word it properly.
"We are too small to be noticed." Size is not the test. Reach is. A two-person exporter with German customers sits inside the same perimeter as a listed company, and the PCPD's own findings show small firms are the least prepared, with 55% lacking any privacy management programme.
"A line in our terms and conditions covers it." The requirement is disclosure at the point of first interaction, in a clear and distinguishable manner. A hyperlink at the bottom of a page is neither.
Frequently Asked Questions
Do I need to disclose AI if a human reviews every reply before it sends?
If a person reviews and approves each message, the customer is receiving human-approved communication and the direct-interaction trigger is weaker. Once the AI replies without a human in the loop, disclose.
Does this cover AI-generated social media posts?
Synthetic content marking applies to AI-generated or materially altered images, audio, video and text published to the public. A fully AI-generated product photo should be marked. Light AI editing of a photo you shot yourself generally is not the target of the rule.
What is the penalty if we get it wrong?
Transparency breaches under the EU AI Act carry penalties of up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. Regulators typically begin with information requests rather than immediate fines.
Is there a Hong Kong law requiring AI disclosure?
Not as a standalone statutory duty today. The Personal Data (Privacy) Ordinance governs how you handle personal data collected through AI, and the PCPD has issued guidance frameworks, but Hong Kong has no direct equivalent of Article 50 at present.
How long does it take to become compliant?
For a single chatbot on one website, changing the opening message and adding a human handover path is usually a same-day change. The longer work is inventorying every customer-facing AI touchpoint you already run.
The Takeaway
AI disclosure is one of the cheapest compliance items a small business will meet this decade. It costs a sentence. The expensive version is the one where a customer finds out on their own.
Three actions worth taking before 2 August 2026:
--- List every place AI already speaks to your customers, including the chatbot you installed and forgot.
--- Rewrite each opening line to disclose, state the benefit, and offer a human.
--- Check whether any of those conversations reach people in the EU.
Nobody starts an AI project hoping to read regulation. That is precisely why guidance matters more than tooling in the early stages. We understand AI. UD stands with you.
Reviewed by the UD AI team, Hong Kong. Published 30 July 2026.
Not Sure Where AI Already Touches Your Customers?
Most owners underestimate how many customer-facing AI touchpoints their business already has. A short readiness check maps them, flags the gaps, and tells you what to fix first. We will walk you through it step by step, from the first audit to a live setup you can stand behind.