
Your Voice Bot Has Had to Say "I'm an AI" Since August. By 2 December, Its Voice Needs a Hidden Label Too.
On 5 October OpenAI said it would start adding an invisible watermark to ChatGPT and Codex text for users in the EU "over the coming weeks". Developers anywhere can switch it on through the API for "select models". It is off by default. The trigger is Article 50 of the EU AI Act, the transparency rules that became enforceable on 2 August 2026.
For contact centres the bigger part of Article 50 is elsewhere. Three of its duties apply to an AI voice agent on a customer call, and a fourth rule, in force since February 2025, covers emotion analytics. Only one of the four got a grace period, and it ends in eight weeks.
Four rules, one phone call
Rule | Who carries it | What it means on a call | Applies from | Maximum fine |
|---|---|---|---|---|
Art. 50(1) Tell people they are interacting with an AI system, unless it is obvious from the circumstances | Provider of the system (built into its design) | The caller has to know it's a bot, "at the latest at the time of the first interaction" | 2 Aug 2026 | €15M or 3% of worldwide turnover |
Art. 50(2) Mark synthetic audio, image, video and text "in a machine-readable format" so it is "detectable as artificially generated" | Provider of the generative system (TTS engine, speech model, LLM) | The bot's synthetic voice carries a detectable mark | 2 Aug 2026 for new systems; 2 Dec 2026 for systems on the market before 2 Aug | €15M or 3% |
Art. 50(3) Inform people exposed to emotion recognition | Deployer (the business running it) | If you infer a caller's emotions from their voice, tell them, no later than first exposure | 2 Aug 2026 | €15M or 3% |
Art. 5(1)(f) No emotion recognition on people at work | Everyone | Inferring your agents' emotions from their voice is banned | 2 Feb 2025 | €35M or 7% |
Sources: AI Act Articles 3, 5, 50 and 99; Digital Omnibus on AI (in force 27 July 2026); Commission guidelines on prohibited practices. Fines are "whichever is higher".
Two points from that table get missed.
The grace period covers marking only. The Digital Omnibus on AI entered into force on 27 July. It gave generative systems already on the market before 2 August until 2 December 2026 to meet the Article 50(2) marking requirement. It did not delay the duty to tell people they are talking to an AI, or the emotion-recognition notice. Both have applied since 2 August. As Goodwin's August alert put it, the marking extension is "one narrow exception" to immediate compliance.
Disclosure has to come first. Article 50(5) says the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure". On a phone call, that means the greeting. It can't be a line in the privacy policy or a mention at the transfer to a human.
The marking problem: OpenAI's own numbers
Marking is the hard part, and OpenAI's announcement is unusually candid about why. Its text watermark, called textGrain, nudges word choices. The figures below are OpenAI's own evaluation results:
- At a 1% false-positive target, the detector found the mark in "about 80% of 200-token passages, compared with about 95% of 400-token passages".
- Replacing 10% of words with synonyms cut detection "from approximately 92% to 66%". Replacing 25% cut it "to 17%".
- Maths answers scored "substantially lower", because there are fewer ways to phrase them.
- Detector access is "initially limited to approved researchers and expert organizations".
So text marking weakens with short outputs and light editing, which is exactly what a support chat produces. OpenAI's announcement covers text only. It says nothing about audio, voice models or its Realtime API.
Audio has its own tools. Google says files from its Gemini 3.8 Flash TTS models "embed imperceptible SynthID audio watermarks and cryptographic C2PA provenance metadata directly into the exported waveform". The same release names "customer-facing conversational agents" as a target use. Neither Google's release nor OpenAI's gives detection rates for audio after it has gone through a phone network. That is the number a contact centre would need, and no vendor we checked publishes it.
The pressure for a working mark is growing. Cloning a voice is getting easier: ElevenLabs' v4 can clone one from "just 10 seconds of audio", while Google's TTS asks for a 30-second reference plus "an explicit verbal consent track spoken by the original voice owner". Two vendors, announced four days apart, with very different approaches to consent.
Disclosure is the cheap part, and customers expect it
Article 50(1) costs a contact centre one sentence. Customers already want that sentence. In MaxContact's 2026 survey of UK consumers, "Nearly 9 in 10 (88%) consumers say it's important for companies to clearly disclose when AI is being used". The same survey found that "Over one in five discovered — after the fact — that part of their experience was automated without them knowing."
The UK sits outside the AI Act, but customers there and regulators in the EU are asking for the same thing: disclosure at the start of the call.
The emotion-analytics line most teams haven't drawn
This is where voice analytics teams should read closely. The AI Act defines an emotion recognition system as one that infers "emotions or intentions of natural persons on the basis of their biometric data". Voice qualifies: biometric data includes "behavioural characteristics".
The European Commission's guidelines on prohibited practices draw the line using the contact centre itself as the example:
- "The use of webcams and voice recognition systems by a call centre to track their employees' emotions, such as anger, is prohibited."
- "The use of voice recognition systems by a call centre to track their customers' emotions, such as anger or impatience, is not prohibited by Article 5, provided that they do not track the employees' emotions at the same time."
In practice:
- Customer-side voice emotion analytics is allowed, but since 2 August callers must be told about it no later than first exposure (Art. 50(3)), and GDPR applies.
- Agent-side voice emotion analytics is banned, and has been since February 2025. A stereo recording that scores both channels for "frustration" crosses the line on the agent side.
- Text is treated differently. Legal commentary on the guidelines reads the definition as excluding systems that analyse written text rather than biometric data. Sentiment scored from a transcript sits in a different category from tone scored from the waveform. Check your own case with counsel.
The same question is live in the US. Walmart and Lowe's face Illinois class actions under the state's biometric privacy law, BIPA, over customer-service phone systems. The Walmart complaint alleges the AI "measures the physical and behavioral identifiers of a person's voice, such as pitch, cadence, tone, and frequency spectrums". These are allegations only, but they target the same thing the EU rules do: what your stack does with the sound of a caller's voice.
A checklist for the next eight weeks
- Script the disclosure. Make "you're speaking with an automated assistant" part of the greeting on every AI-handled line, in every language you serve. This has been required since 2 August.
- Ask your TTS and speech-model vendors two questions. Which marking method do they use (for example SynthID, C2PA, or their own)? And is their system covered by the 2 December grace period, or did it launch after 2 August?
- Map every emotion signal in your analytics. Note whether each one comes from audio or text, and whether it scores the customer, the agent, or both. Switch off agent-side voice emotion scoring.
- Add the Art. 50(3) notice wherever caller-side voice emotion analysis runs. The greeting can carry it.
- Keep the evidence: the scripts, vendor confirmations and analytics configuration. Regulators audit what you can show.
Where Aura stands
We build voice AI and conversation analytics, so these questions apply to us too. Our position: say it's an AI in the first sentence, analyse the customer's experience rather than the agent's emotional state, and be able to explain in plain language what is measured on a call. In the EU, Article 50 now makes that the law.
This article is for information only and is not legal advice. Check your specific deployment against the AI Act text, the Commission's guidelines and your own counsel.
Sources
- OpenAI, "Our approach to EU text provenance rules", 5 Oct 2026 — https://openai.com/index/eu-text-provenance/
- TechCrunch, "OpenAI will start watermarking ChatGPT's text in the EU", 5 Oct 2026 — https://techcrunch.com/2026/10/05/openai-will-start-watermarking-chatgpts-text-in-the-eu/
- EU AI Act, Article 50 (transparency obligations) — https://artificialintelligenceact.eu/article/50/
- EU AI Act, Article 3 (definitions: biometric data, emotion recognition system) — https://artificialintelligenceact.eu/article/3/
- EU AI Act, Article 99 (penalties) — https://artificialintelligenceact.eu/article/99/
- Goodwin, "Not Delayed, Not Deferred: EU AI Act Transparency Obligations Are Now in Force", 3 Aug 2026 — https://www.goodwinlaw.com/en/insights/publications/2026/08/alerts-technology-dpc-eu-ai-act-transparency-obligations-now-in-force
- Usercentrics, "EU AI Act Deal: Digital Omnibus Now in Force" — https://usercentrics.com/knowledge-hub/eu-ai-act-high-risk-delay-article-50-transparency-consent/
- AI Act Explorer, "A Practical Guide to Article 50", 14 May 2026 — https://artificialintelligenceact.eu/transparency-rules-article-50/
- Bird & Bird on the Commission's guidelines on prohibited AI practices — https://www.twobirds.com/en/insights/2025/global/new-eu-ai-act-guidelines-what-are-the-implications-for-businesses
- Wolters Kluwer, "The Prohibition of AI Emotion Recognition Technologies in the Workplace under the AI Act" — https://legalblogs.wolterskluwer.com/global-workplace-law-and-policy/the-prohibition-of-ai-emotion-recognition-technologies-in-the-workplace-under-the-ai-act/
- AI News, Google Gemini 3.8 Flash TTS, 24 Sep 2026 — https://www.artificialintelligence-news.com/news/google-gemini-3-8-flash-tts-voice-models/
- TechCrunch, ElevenLabs v4, 28 Sep 2026 — https://techcrunch.com/2026/09/28/elevenlabs-new-v4-speech-model-supports-more-expression-control-and-90-languages/
- MaxContact, "The Trust Gap: Voice of the UK Consumer 2026" — https://www.maxcontact.com/downloads/voice-of-the-uk-consumer-2026
- CX Today, "Voice AI Lawsuits Put Contact Centers on BIPA Watch", 4 Oct 2026 — https://cxtoday.com/voice-ai-lawsuits-put-contact-centers-on-bipa-watch
- Biometric Update, Walmart voiceprint complaint, Aug 2026 — https://www.biometricupdate.com/202608/walmart-sued-over-alleged-voiceprint-collection-from-customer-calls