Articolo 50 AI Act: avvisi sull'IA accessibili dal 2026
Dal 2 agosto 2026 si applica l'articolo 50 dell'AI Act. Chi gestisce chatbot, genera contenuti sintetici o pubblica deepfake deve informare le persone. Il paragrafo 5 aggiunge la condizione che manca in quasi tutte le checklist di compliance: l'avviso stesso deve essere conforme ai requisiti di accessibilità applicabili.
.jpg)
Introduction
This Privacy Notice aims to clearly and transparently explain which personal data we collect when you visit our website, why we collect it, how we use it, and what Your rights are.
We process your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. We are committed to ensuring that all processing activities are carried out in accordance with the principles of lawfulness, fairness, transparency, data minimization, integrity, and confidentiality.
Specifically, in this notice you will find information about:
-
which data we collect about you and for what purposes;
-
the legal bases on which we process such data;
-
who we may share your data with;
-
how long we retain your data;
-
your rights and how to exercise them.
While we sometimes need Your data for example, to respond to your requests or improve our website), we do so with respect, care and only when truly necessary.
Our Privacy Promises
-
We deeply value your privacy, and for this reason, we guarantee that:
-
We treat your data as if it were our own.
-
We use your data only for the purposes outlined in this notice.
-
We retain your data only for as long as strictly necessary.
-
We do not share your data with third parties without a valid legal basis or your explicit consent.
1. Who Processes Your Personal Data
The Data Controller — that is, the entity that determines the purposes and means of the processing of Your personal data — is AccessiWay S.a.S., with registered office at 7 Rue du Général Henrion Bertier, 92200 Neuilly-sur-Sein registered with the Nanterre Trade and Companies Register under number 914 022 595.
AccessiWay is part of the team.blue group and, in certain cases, acts as joint controller together with team.blue NV, with registered office at Skaldenstraat 121, 9042 Ghent, Belgium. In this context, Your personal data may be shared within the group for statistical, administrative, operational, and service improvement purposes.
AccessiWay and team.blue have defined their respective roles and responsibilities under a joint controllership agreement pursuant to Article 26 of the GDPR, ensuring full compliance with data protection regulations.
For more information regarding joint controllership or to exercise Your rights, you may contact AccessiWay via email at the following email addresses:
📧 legal.fr@accessiway.com or info@accessiway.com.
2. Who This Privacy Notice Applies To
This notice applies to:
-
users who browse the website www.accessiway.com,
-
individuals who contact us through the form available on the website or via email;
-
users who interact with tools we have implemented (e.g. widgets, cookies);
-
individuals who, through the website or other channels, access external platforms or third-party entities through which they may submit a job application (e.g. recruiting portals or employment agencies).
-
In such cases, the privacy notices of the third parties involved — independent from AccessiWay — also apply.
3. What Data We Process
To manage your interaction with our website, we may process the following categories of personal data:
-
Identification and contact details such as name, surname, company, job title, email address, and phone number.
-
These data may be partially processed through our customer relationship management (CRM) system.
-
Data relating to your interaction with our services such as information collected via the website or through Hubspot, such as communication history, preferences, requests, and commercial or technical notes.
-
Technical data such as IP address, device type, operating system, browser, access times, and other data automatically recorded by our systems or servers.
-
Browsing data and preferences such as collected via cookies or similar technologies, in accordance with the choices expressed through the cookie consent banner.
-
Application data such as personal information included in your CV or other documents submitted through third-party platforms (e.g. professional experience, education, contact details).
-
These data are processed by AccessiWay only after being transmitted by the third party, which remains autonomous in the initial processing.
4. Purposes and Legal Basis of Processing
We process Your personal data in compliance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. Your data may be processed for the following purposes:
-
Technical operation of the website
We process technical data, using technical cookies and similar tools, to allow You to access the site, view it correctly, and ensure it functions properly (e.g. browsing, content loading, storing preferences).
📌Legal basis: this processing is necessary to provide a service requested by the user, pursuant to Article 6(1)(b) of the GDPR. Your consent is not required for these cookies.
-
Handling contact or support requests
When you send us a request — via the contact form or by email — we process your data to respond and provide the information requested.
📌 Legal basis: this processing is necessary to take steps at your request prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.
-
Compliance with legal obligations
In certain cases, we may need to process your data to comply with legal obligations, such as tax, accounting, or IT security requirements.
📌 Legal basis: this processing is based on compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR.
-
Statistical analysis and website improvement
We use analytical tools (e.g. analytical cookies) to collect aggregated data in order to understand how the website is used and to improve its content and functionality.
📌 Legal basis: we process this data only with your freely given and specific consent, pursuant to Article 6(1)(a) of the GDPR.
-
Marketing and Profiling
If you authorize us to do so, we may use your data to send you promotional communications or provide personalized content (e.g. through profiling cookies).
📌 Legal basis: this processing is carried out only with your explicit consent, pursuant to Article 6(1)(a) of the GDPR. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
-
Management of job applications through third parties
We may receive job applications via third-party platforms (e.g. job portals) or through recruitment agencies. In such cases, we process the submitted data to assess your suitability for the proposed role.
📌 Legal basis: this processing is necessary to take steps at your request prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.
Note: the privacy policies of the third-party platforms or agencies involved also apply, independently of AccessiWay.
5. Cookies and Tracking Tools
This website uses a cookie management system provided by iubenda, which allows you to:
-
view a full and transparent list of the cookies in use;
-
modify or withdraw your consent at any time;
-
access the complete Cookie Policy, integrated in the cookie widget.
You can manage your preferences by clicking on the cookie widget icon located at the bottom left corner of every page on the site.
Technical cookies are necessary and therefore enabled by default. Other non-essential cookies (analytical, profiling) are only enabled with your consent.
For more information, please refer to the full Cookie Policy accessible from the cookie widget.
6. Use of accessWidget
This website integrates accessWidget, an automated accessibility tool developed by accessiBe Ltd. and distributed by AccessiWay. The widget allows users to personalize their browsing experience based on their needs.
When the user activates the widget, their IP address is technically transmitted, but:
-
it is not stored, tracked, or associated with identifiable individuals;
-
it is anonymized via a proxy located in the European Union;
-
it is not used for profiling or marketing purposes.
📌 Legal basis: provision of a service requested by the user (Article 6(1)(b) of the GDPR).
7. Data Security
We adopt appropriate technical and organizational measures to ensure the security, integrity, and confidentiality of the personal data we process. These measures are designed to prevent unauthorized access, loss, disclosure, or alteration of your data. In particular, we implement:
-
secure connections via HTTPS (SSL/TLS);
-
authentication systems and access control;
-
access limitation and internal access tracking mechanisms;
-
regular audits and verification procedures;
-
continuous updates to systems and security measures according to the level of risk.
8. Data Retention
Your personal data is stored only for the time strictly necessary to achieve the purposes for which it was collected. Specifically:
-
Contact data: up to 10 years if relevant for contractual or legal purposes;
-
Technical and browsing data: according to what is outlined in the Cookie Policy;
-
Marketing data: until consent is withdrawn.
9. Your Rights (Data Subject Rights)
As a data subject, you may exercise the rights provided under Articles 15–22 of the GDPR at any time. In particular, you have the right to:
-
Obtain confirmation as to whether or not your personal data is being processed and access such data (right of access);
-
Request the rectification of inaccurate personal data or the completion of incomplete data (right to rectification);
-
Request the erasure of your data, if the conditions set out in the GDPR are met (right to erasure);
-
Obtain restriction of processing where applicable (right to restriction);
-
Object to the processing of your data, in whole or in part, under certain circumstances (right to object);
-
Receive your data in a structured, commonly used, and machine-readable format, and, where technically feasible, have it transmitted directly to another controller (right to data portability);
-
Withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
📧 You can exercise Your rights at any time by contacting us at: legal.fr@accessiway.com.
🔗 If you are located in France and believe that the processing of your personal data violates applicable law, you have the right to lodge a complaint with the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés – CNIL) via the website: www.cnil.fr.
*If you have difficulty accessing our form, please feel free to contact us. Send an e-mail to info@accessiway.com
Il 2 agosto 2026 gli obblighi di trasparenza dell'articolo 50 dell'AI Act sono diventati applicabili in tutta l'Unione europea. Se il tuo prodotto dialoga con il pubblico, genera contenuti o pubblica media modificati dall'IA, adesso hai l'obbligo di dichiararlo, e di farlo in modo che l'avviso raggiunga tutte le persone, comprese quelle con disabilità.
In questo articolo
Cosa richiede l'articolo 50 dell'AI Act dal 2 agosto 2026
L'articolo 50 dell'AI Act è la sezione sulla trasparenza del Regolamento (UE) 2024/1689 e obbliga fornitori e deployer di determinati sistemi di IA a dichiarare quando entra in gioco l'intelligenza artificiale.
Quattro obblighi sono scattati il 2 agosto 2026:
Sistemi interattivi. I fornitori garantiscono che le persone sappiano di interagire con un sistema di IA, a meno che non sia già evidente dal contesto.
Contenuti sintetici. I fornitori di sistemi generativi marcano gli output audio, immagine, video o testuali in un formato leggibile meccanicamente, così che siano rilevabili come generati artificialmente.
Riconoscimento delle emozioni e categorizzazione biometrica. I deployer informano le persone esposte al sistema che è in funzione.
Deepfake e testi di interesse pubblico. I deployer dichiarano che il contenuto è stato generato o manipolato artificialmente. Per le opere manifestamente artistiche, creative, satiriche o di fantasia la dichiarazione si adatta all'opera senza ostacolarne la fruizione, ma non viene meno, e l'eccezione per i contenuti sottoposti a revisione editoriale vale solo per i testi generati dall'IA.
La distinzione dei ruoli ha conseguenze concrete. Una banca o una compagnia assicurativa che usa un chatbot in licenza è deployer: gli obblighi del paragrafo 1 restano al fornitore, quelli dei paragrafi 3 e 4 sono suoi. Le violazioni possono comportare sanzioni fino a 15 milioni di euro o al 3% del fatturato annuo mondiale, se superiore.
La scadenza che il Digital Omnibus non ha rinviato
L'articolo 50 è uscito intatto dalla revisione dell'AI Act. Il Regolamento Digital Omnibus sull'IA, Regolamento (UE) 2026/1744 dell'8 luglio 2026, è entrato in vigore il 27 luglio 2026 e ha spostato gli obblighi per i sistemi di IA ad alto rischio dell'Allegato III al 2 dicembre 2027 e quelli per l'IA integrata nei prodotti dell'Allegato I al 2 agosto 2028. Gli obblighi di trasparenza sono rimasti dove erano.
È rimasta una sola agevolazione, molto circoscritta: i sistemi generativi già sul mercato prima del 2 agosto 2026 hanno tempo fino al 2 dicembre 2026 per la marcatura in formato leggibile meccanicamente, e i contenuti pubblicati prima di quella data non vanno etichettati a posteriori.
Perché il paragrafo 5 riguarda direttamente l'accessibilità
Il paragrafo 5 disciplina come l'avviso arriva alle persone, non solo cosa dice. Le informazioni sono fornite «in maniera chiara e distinguibile al più tardi al momento della prima interazione o esposizione» e «devono essere conformi ai requisiti di accessibilità applicabili».
Negli orientamenti sugli obblighi di trasparenza pubblicati a luglio 2026, la Commissione europea interpreta «chiara» come percepibile e facile da capire, e «distinguibile» come facilmente identificabile rispetto alle altre informazioni. Un avviso nascosto nelle condizioni d'uso o due livelli di menu più in basso non soddisfa questo requisito.
A questo si aggiunge la clausola sull'accessibilità: un'etichetta, un banner, un badge o un avviso vocale non è conforme se uno screen reader lo salta, se non raggiunge il rapporto di contrasto minimo o se non si arriva a leggerlo da tastiera.
Come si presenta un avviso sull'IA accessibile
Il Codice di buone pratiche sulla trasparenza dei contenuti generati dall'IA, pubblicato il 10 giugno 2026 e firmato da circa 190 organizzazioni entro fine luglio 2026, mette a disposizione una serie di icone europee per etichettarli. Usare quelle icone è facoltativo, l'obbligo di etichettatura no. Ed è proprio dalle icone che partono i problemi di accessibilità. Quattro passaggi coprono l'essenziale.
Primo passaggio: dare un'alternativa testuale a ogni etichetta visiva
Un'icona senza nome accessibile è invisibile alle tecnologie assistive. Ogni etichetta ha bisogno di un nome accessibile determinato programmaticamente, ed è esattamente ciò che chiede il criterio di successo 1.1.1 delle WCAG, a cui si aggiunge il criterio 4.1.2 per gli elementi interattivi. La logica è la stessa del testo alternativo sulle immagini.
Secondo passaggio: non affidare il messaggio solo al colore o alla posizione
Se i contenuti generati dall'IA si distinguono da quelli creati dalle persone solo per una sfumatura di colore, l'avviso non supera il criterio 1.4.1. Se l'avviso si affida soltanto alla posizione, per esempio un angolo dello schermo, la relazione con il contenuto non è espressa nel codice ed entra in gioco il criterio 1.3.1. Abbina sempre un testo al segnale visivo.
Terzo passaggio: rendere l'avviso raggiungibile, leggibile e persistente
Badge e pannelli informativi espandibili hanno bisogno di accesso da tastiera (criterio 2.1.1) e di un rapporto di contrasto di almeno 4,5:1 per il testo corrente (criterio 1.4.3). Le notifiche toast che scompaiono dopo tre secondi sono un errore frequente, perché uno screen reader potrebbe non annunciarle mai.
Quarto passaggio: dare un equivalente testuale agli avvisi audio e video
Un avviso vocale come «stai parlando con un assistente virtuale» non arriva alle persone sorde o con problemi di udito. Aggiungi sottotitoli o un equivalente a schermo, e assicurati che nelle interfacce vocali gli avvisi testuali vengano anche pronunciati.
Negli audit di Accessiway in quattro mercati europei i componenti che più spesso non superano la verifica sono proprio quelli che le aziende stanno usando adesso per l'articolo 50: pulsanti con la sola icona, badge con contrasto insufficiente e notifiche che spariscono troppo presto.
Dove si incontrano trasparenza dell'IA, EAA e Legge Stanca
Per la maggior parte delle aziende che vendono al pubblico, i «requisiti di accessibilità applicabili» del paragrafo 5 non sono requisiti nuovi. Sono quelli già in vigore dal 28 giugno 2025: in Italia il Decreto Legislativo 82/2022, che recepisce l'Atto europeo sull'accessibilità (direttiva (UE) 2019/882), con riferimento tecnico di fatto alla norma EN 301 549 e alle WCAG 2.1 livello AA. L'articolo 50 estende quello standard a un nuovo elemento dell'interfaccia: l'avviso stesso.
C'è poi un secondo binario che in Italia si dimentica spesso. La Legge Stanca non riguarda solo la Pubblica Amministrazione: dall'articolo 3, comma 1-bis si applica anche ai soggetti privati che offrono servizi al pubblico con un fatturato medio superiore a 500 milioni di euro nell'ultimo triennio, soglia valutata a livello di gruppo. Vigila AgID, le sanzioni arrivano fino al 5% del fatturato e il riferimento tecnico sono le Linee Guida AgID 38/2026. Sulla stessa interfaccia si applicano adesso due normative in parallelo, un tema già visto quando la navigazione agentica è arrivata in Lighthouse.
Domande frequenti sull'articolo 50 dell'AI Act e l'accessibilità
L'articolo 50 vale anche se usiamo solo un chatbot di terze parti?
Sì, ma non per tutti gli obblighi allo stesso modo. Per il chatbot in sé la dichiarazione del paragrafo 1 è del fornitore, e diventa tua se lo distribuisci con il tuo marchio. Come deployer rispondi in prima persona quando generi deepfake, pubblichi testi di interesse pubblico o usi il riconoscimento delle emozioni: l'avviso che compare sulla tua interfaccia è tuo, accessibilità compresa.
Quali sono i «requisiti di accessibilità applicabili» per un avviso sull'IA?
Il Decreto Legislativo 82/2022, che recepisce l'EAA, con riferimento tecnico alla norma EN 301 549 e alle WCAG 2.1 livello AA. La Pubblica Amministrazione e i grandi soggetti privati raggiungono lo stesso livello con la Legge Stanca e le Linee Guida AgID.
Chi controlla la parte sull'accessibilità dell'articolo 50?
In Italia la vigilanza del mercato per i sistemi di IA è in capo all'ACN, l'Agenzia per la cybersicurezza nazionale, mentre AgID è l'autorità di notifica e, su un binario distinto, vigila sull'accessibilità digitale. Un avviso che non supera le WCAG può quindi essere contestato da entrambi i fronti.
Vale la pena verificare i tuoi avvisi sull'IA dal punto di vista di chi usa il tuo prodotto. Parti da una scansione gratuita sulla nostra piattaforma per la conformità all'accessibilità, e con un audit di accessibilità il nostro team ti dice quali di quei componenti raggiungono davvero le persone che usano screen reader, ingranditore di schermo o soltanto la tastiera.
.jpg)
Paolo Berro
Per molte persone con disabilità non si tratta di funzioni semplicemente innovative, ma di strumenti che possono aumentare l'autonomia, facilitare l'accesso alle informazioni e favorire la partecipazione al lavoro e alla vita sociale.
Accessibilita Digitale

Redazione
Un video accessibile permette a chiunque di seguirlo, indipendentemente dal tipo di disabilità. Questo significa avere sottotitoli e trascrizioni accurati, un'audiodescrizione chiara e un contrasto sufficiente tra testo e sfondo.
Accessibilita Digitale

Author
Tra l'ingresso in azienda e l'accesso ai ruoli decisionali delle persone con disabilità continua a esistere uno spazio difficile da attraversare.
Inclusione E Csr