AI Act Article 50 is live: your AI disclosures have to be accessible too
Article 50 of the AI Act applies from August 2, 2026. Those who operate chatbots, generate synthetic content, or publish deepfakes must inform individuals. Paragraph 5 adds a condition missing from almost all compliance checklists: the notice itself must comply with applicable accessibility requirements.
.jpg)
Introduction
This Privacy Notice aims to clearly and transparently explain which personal data we collect when you visit our website, why we collect it, how we use it, and what Your rights are.
We process your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. We are committed to ensuring that all processing activities are carried out in accordance with the principles of lawfulness, fairness, transparency, data minimization, integrity, and confidentiality.
Specifically, in this notice you will find information about:
-
which data we collect about you and for what purposes;
-
the legal bases on which we process such data;
-
who we may share your data with;
-
how long we retain your data;
-
your rights and how to exercise them.
While we sometimes need Your data for example, to respond to your requests or improve our website), we do so with respect, care and only when truly necessary.
Our Privacy Promises
-
We deeply value your privacy, and for this reason, we guarantee that:
-
We treat your data as if it were our own.
-
We use your data only for the purposes outlined in this notice.
-
We retain your data only for as long as strictly necessary.
-
We do not share your data with third parties without a valid legal basis or your explicit consent.
1. Who Processes Your Personal Data
The Data Controller — that is, the entity that determines the purposes and means of the processing of Your personal data — is AccessiWay S.a.S., with registered office at 7 Rue du Général Henrion Bertier, 92200 Neuilly-sur-Sein registered with the Nanterre Trade and Companies Register under number 914 022 595.
AccessiWay is part of the team.blue group and, in certain cases, acts as joint controller together with team.blue NV, with registered office at Skaldenstraat 121, 9042 Ghent, Belgium. In this context, Your personal data may be shared within the group for statistical, administrative, operational, and service improvement purposes.
AccessiWay and team.blue have defined their respective roles and responsibilities under a joint controllership agreement pursuant to Article 26 of the GDPR, ensuring full compliance with data protection regulations.
For more information regarding joint controllership or to exercise Your rights, you may contact AccessiWay via email at the following email addresses:
📧 legal.fr@accessiway.com or info@accessiway.com.
2. Who This Privacy Notice Applies To
This notice applies to:
-
users who browse the website www.accessiway.com,
-
individuals who contact us through the form available on the website or via email;
-
users who interact with tools we have implemented (e.g. widgets, cookies);
-
individuals who, through the website or other channels, access external platforms or third-party entities through which they may submit a job application (e.g. recruiting portals or employment agencies).
-
In such cases, the privacy notices of the third parties involved — independent from AccessiWay — also apply.
3. What Data We Process
To manage your interaction with our website, we may process the following categories of personal data:
-
Identification and contact details such as name, surname, company, job title, email address, and phone number.
-
These data may be partially processed through our customer relationship management (CRM) system.
-
Data relating to your interaction with our services such as information collected via the website or through Hubspot, such as communication history, preferences, requests, and commercial or technical notes.
-
Technical data such as IP address, device type, operating system, browser, access times, and other data automatically recorded by our systems or servers.
-
Browsing data and preferences such as collected via cookies or similar technologies, in accordance with the choices expressed through the cookie consent banner.
-
Application data such as personal information included in your CV or other documents submitted through third-party platforms (e.g. professional experience, education, contact details).
-
These data are processed by AccessiWay only after being transmitted by the third party, which remains autonomous in the initial processing.
4. Purposes and Legal Basis of Processing
We process Your personal data in compliance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. Your data may be processed for the following purposes:
-
Technical operation of the website
We process technical data, using technical cookies and similar tools, to allow You to access the site, view it correctly, and ensure it functions properly (e.g. browsing, content loading, storing preferences).
📌Legal basis: this processing is necessary to provide a service requested by the user, pursuant to Article 6(1)(b) of the GDPR. Your consent is not required for these cookies.
-
Handling contact or support requests
When you send us a request — via the contact form or by email — we process your data to respond and provide the information requested.
📌 Legal basis: this processing is necessary to take steps at your request prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.
-
Compliance with legal obligations
In certain cases, we may need to process your data to comply with legal obligations, such as tax, accounting, or IT security requirements.
📌 Legal basis: this processing is based on compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR.
-
Statistical analysis and website improvement
We use analytical tools (e.g. analytical cookies) to collect aggregated data in order to understand how the website is used and to improve its content and functionality.
📌 Legal basis: we process this data only with your freely given and specific consent, pursuant to Article 6(1)(a) of the GDPR.
-
Marketing and Profiling
If you authorize us to do so, we may use your data to send you promotional communications or provide personalized content (e.g. through profiling cookies).
📌 Legal basis: this processing is carried out only with your explicit consent, pursuant to Article 6(1)(a) of the GDPR. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
-
Management of job applications through third parties
We may receive job applications via third-party platforms (e.g. job portals) or through recruitment agencies. In such cases, we process the submitted data to assess your suitability for the proposed role.
📌 Legal basis: this processing is necessary to take steps at your request prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.
Note: the privacy policies of the third-party platforms or agencies involved also apply, independently of AccessiWay.
5. Cookies and Tracking Tools
This website uses a cookie management system provided by iubenda, which allows you to:
-
view a full and transparent list of the cookies in use;
-
modify or withdraw your consent at any time;
-
access the complete Cookie Policy, integrated in the cookie widget.
You can manage your preferences by clicking on the cookie widget icon located at the bottom left corner of every page on the site.
Technical cookies are necessary and therefore enabled by default. Other non-essential cookies (analytical, profiling) are only enabled with your consent.
For more information, please refer to the full Cookie Policy accessible from the cookie widget.
6. Use of accessWidget
This website integrates accessWidget, an automated accessibility tool developed by accessiBe Ltd. and distributed by AccessiWay. The widget allows users to personalize their browsing experience based on their needs.
When the user activates the widget, their IP address is technically transmitted, but:
-
it is not stored, tracked, or associated with identifiable individuals;
-
it is anonymized via a proxy located in the European Union;
-
it is not used for profiling or marketing purposes.
📌 Legal basis: provision of a service requested by the user (Article 6(1)(b) of the GDPR).
7. Data Security
We adopt appropriate technical and organizational measures to ensure the security, integrity, and confidentiality of the personal data we process. These measures are designed to prevent unauthorized access, loss, disclosure, or alteration of your data. In particular, we implement:
-
secure connections via HTTPS (SSL/TLS);
-
authentication systems and access control;
-
access limitation and internal access tracking mechanisms;
-
regular audits and verification procedures;
-
continuous updates to systems and security measures according to the level of risk.
8. Data Retention
Your personal data is stored only for the time strictly necessary to achieve the purposes for which it was collected. Specifically:
-
Contact data: up to 10 years if relevant for contractual or legal purposes;
-
Technical and browsing data: according to what is outlined in the Cookie Policy;
-
Marketing data: until consent is withdrawn.
9. Your Rights (Data Subject Rights)
As a data subject, you may exercise the rights provided under Articles 15–22 of the GDPR at any time. In particular, you have the right to:
-
Obtain confirmation as to whether or not your personal data is being processed and access such data (right of access);
-
Request the rectification of inaccurate personal data or the completion of incomplete data (right to rectification);
-
Request the erasure of your data, if the conditions set out in the GDPR are met (right to erasure);
-
Obtain restriction of processing where applicable (right to restriction);
-
Object to the processing of your data, in whole or in part, under certain circumstances (right to object);
-
Receive your data in a structured, commonly used, and machine-readable format, and, where technically feasible, have it transmitted directly to another controller (right to data portability);
-
Withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
📧 You can exercise Your rights at any time by contacting us at: legal.fr@accessiway.com.
🔗 If you are located in France and believe that the processing of your personal data violates applicable law, you have the right to lodge a complaint with the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés – CNIL) via the website: www.cnil.fr.
*If you have difficulty accessing our form, please feel free to contact us. Send an e-mail to info@accessiway.com
In short: On 2 August 2026, the transparency obligations in Article 50 of the AI Act started to apply across the European Union. If your product talks to people, generates content, or publishes AI-modified media, you now owe those people a disclosure that reaches everyone, including people with disabilities.
In this article
What Article 50 of the AI Act requires from 2 August 2026
The deadline the Digital Omnibus didn't move
Why paragraph 5 is the part accessibility teams should read
What an accessible AI disclosure looks like in practice
Where AI transparency and the EAA already overlap
Frequently asked questions about AI Act Article 50 and accessibility
What Article 50 of the AI Act requires from 2 August 2026
Article 50 of the AI Act is the transparency section of Regulation (EU) 2024/1689, and it requires providers and deployers of certain AI systems to tell people when they're dealing with AI.
Four obligations landed on 2 August 2026:
Interactive systems. Providers make sure people know they're interacting with an AI system, unless that's obvious from the context.
Synthetic content. Providers of generative systems mark audio, image, video, and text outputs in a machine-readable format, so the content is detectable as artificially generated.
Emotion recognition and biometric categorization. Deployers inform the people exposed to the system that it's running.
Deepfakes and public-interest text. Deployers disclose that content was artificially generated or manipulated. For evidently artistic, satirical, or fictional work the disclosure is scaled down rather than dropped, and the exception for editorially reviewed publications covers AI-generated text only, not deepfakes.
The split matters commercially. A bank or insurer running a licensed chatbot is a deployer, and those duties don't travel back to the vendor. Non-compliance carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
The deadline the Digital Omnibus didn't move
Article 50 came through the reform round intact. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and postponed the high-risk obligations in Annex III to 2 December 2027, with product-embedded AI under Annex I moving to 2 August 2028. The transparency obligations stayed where they were.
One narrow concession survived: generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement, and content published before that date needs no retroactive labeling. The rules everyone assumed had been postponed were the high-risk ones, and the disclosure your chatbot owes its users was never on that list.
Why paragraph 5 is the part accessibility teams should read
Paragraph 5 governs how the disclosure reaches people, not only what it says. The information has to be provided "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure," and it "shall conform to the applicable accessibility requirements."
In its guidelines on the transparency obligations, published in July 2026, the European Commission reads "clear" as noticeable and easy to understand, and "distinguishable" as easy to identify as separate from other information. A notice parked in the terms of service or two menu layers deep doesn't meet that bar.
Add the accessibility clause on top, and a label, banner, badge, or voice notice that a screen reader skips, that fails contrast, or that a keyboard user can't reach stops being a compliant disclosure.
What an accessible AI disclosure looks like in practice
The Code of Practice on Transparency of AI-generated Content, finalized on 10 June 2026 and signed by roughly 190 organizations by late July 2026, publishes a set of EU icons for labeling AI-generated content. Using those icons is optional. The labeling duty isn't, and icons are where accessibility problems usually start. Four checks cover most of the ground.
Step 1: Give every visual label a text alternative
An icon with no accessible name is invisible to assistive technology. Each AI label needs a programmatic name, which is WCAG Success Criterion 1.1.1 doing the job it was written for.
Step 2: Don't let color or position carry the message
If the only thing separating AI-generated content from human content is a tint or a corner placement, the disclosure fails Success Criterion 1.4.1. Pair every visual cue with text.
Step 3: Make the disclosure reachable, readable, and persistent
Badges and "more info" layers need keyboard access (Success Criterion 2.1.1) and contrast of at least 4.5:1 for body text (Success Criterion 1.4.3). Toast notifications that vanish after three seconds are a frequent failure, because a screen reader may never announce them.
Step 4: Give audio and video disclosures a text equivalent
A spoken "you're talking to a virtual assistant" doesn't reach a person who is deaf or hard of hearing. Add captions or an on-screen equivalent, and give text disclosures an audible route in voice interfaces.
In Accessiway's audit work across four European markets, the components that fail most often are the same ones companies are now reaching for to satisfy Article 50: icon-only controls, low-contrast badges, and disappearing notifications.
Where AI transparency and the EAA already overlap
For most consumer-facing companies, the "applicable accessibility requirements" in paragraph 5 aren't new requirements. They're the ones already in force under the European Accessibility Act (EAA), Directive (EU) 2019/882, whose technical baseline runs through EN 301 549 v3.2.1 to WCAG 2.1 level AA. Article 50 extended the reach of the accessibility standard your organization is already accountable for.
AI disclosure joins the list of surfaces where two regimes meet, alongside GDPR consent and EAA compliance and the accessibility questions agentic browsing in Lighthouse opened up earlier this year.
Frequently asked questions about AI Act Article 50 and accessibility
Does Article 50 apply if we only use a third-party AI chatbot?
Yes. Running a purchased or licensed system under your own authority makes you a deployer, and deployers carry the deepfake and public-interest text disclosures in their own right.
What counts as the "applicable accessibility requirements" for an AI disclosure?
The European Accessibility Act, implemented through EN 301 549 and WCAG 2.1 level AA. Public sector bodies reach the same technical standard through the Web Accessibility Directive.
Who enforces the accessibility part of Article 50?
Two authorities have an interest. National market surveillance authorities designated under the AI Act are the primary enforcers of Article 50, and the bodies already supervising EAA compliance cover the accessibility of the same interface. A disclosure that fails WCAG can surface in either channel.
Article 50 is a good moment to look at your AI disclosures the way your users encounter them. Start with a free scan on our accessibility compliance platform, and our audit and remediation team can tell you which of those components a screen reader, a keyboard, or a magnifier actually reaches.
Content generated with the support of artificial intelligence and subject to human oversight and review.

Editorial Board
New Accessiway research published on Global Accessibility Awareness Day finds 64% of UK smartphone users struggle with digital services on their phones
News

Editorial Board
The ruling against Carrefour shows that digital accessibility can no longer stay confined to an isolated technical team. It involves the legal department, the product department, and the executive team.
News

Author
An accessible color palette preserves visual identity and ensures that text, states, and components stay readable for everyone who uses them, including people with visual disabilities.
Digital Accessibility