On August 2, 2026, the transparency obligations of the EU AI Act — Article 50 — become enforceable. If your website talks to visitors through a chatbot, publishes AI-generated content, or uses synthetic media, this is the rule that says your users have the right to know. This guide explains what Article 50 actually requires, who it covers, and the practical steps a small business can take this week — in plain language, without the scare tactics.
This article is educational content, not legal advice. For decisions that depend on your specific systems and jurisdiction, consult a qualified lawyer.
The 60-second version
- The EU AI Act entered into force on August 1, 2024, with staged deadlines. AI-literacy duties (Article 4) have applied since February 2, 2025. The transparency rules in Article 50 apply from August 2, 2026.
- If people interact with your AI system (a chatbot, a voice agent), they must be informed they're dealing with AI — unless it's already obvious to a reasonable person.
- AI-generated and AI-manipulated content (including deepfakes) must be disclosed and, for providers, marked in machine-readable form.
- These duties attach to what your systems do, not to how big your company is. There is no small-business exemption from disclosure.
- Transparency violations can draw fines up to €15 million or 3% of worldwide turnover — the bigger €35M/7% ceiling people quote belongs to the prohibited-practices category, not this one. Precision matters; so does not panicking.
What Article 50 actually says
Article 50 sits in the AI Act's chapter on transparency obligations for certain AI systems. Four duties matter to a typical small business:
1. Tell people when they're talking to AI
Providers must ensure that AI systems intended to interact directly with people — chatbots, support agents, voice assistants — are designed so that the people concerned are informed they are interacting with an AI system. The exception: when that fact is already obvious "from the point of view of a natural person who is reasonably well-informed, observant and circumspect."
In practice, don't lean on the exception. A support widget that answers fluently at 3 a.m. under a human-sounding name is not self-evidently a machine to every visitor. A one-line label — "You're chatting with our AI assistant" — is cheap, honest, and removes the ambiguity entirely.
2. Mark AI-generated content in machine-readable form
Providers of generative systems must ensure outputs (text, audio, images, video) are marked in a machine-readable format as artificially generated or manipulated — think watermarking and provenance metadata. If you build on top of a major model provider, much of this happens upstream, but the duty to not strip or defeat those markings lands on you.
3. Disclose deepfakes and synthetic media
Deployers of systems that generate or manipulate images, audio, or video that resembles real people, places, or events must disclose that the content is artificially generated or manipulated. For a small business, this covers things like AI-generated spokesperson videos or synthetic product photography presented as real.
4. Disclose AI text published to inform the public
If AI-generated text is published "with the purpose of informing the public on matters of public interest," the deployer must disclose the AI's role unless a human took editorial responsibility. If your content marketing runs on an AI pipeline straight to publish, this one deserves your attention.
"Does this really apply to my five-person company?"
The honest answer: if EU users interact with your AI features, yes. Three points people get wrong:
- Size doesn't exempt you. The AI Act contains proportionality gestures toward SMEs (documentation simplifications, regulatory sandboxes), but Article 50's disclosure duties apply by function, not headcount.
- Location doesn't automatically exempt you. Like the GDPR before it, the Act reaches providers and deployers outside the EU when the system's output is used in the EU. A US company with EU website visitors talking to its chatbot is in scope.
- "I just embedded a chat widget" doesn't exempt you. If your site runs Intercom, Crisp, Tidio, or any of the dozens of AI-enabled chat platforms, you are the one presenting that AI to your users. The disclosure your visitors see — or don't see — is on your pages.
What enforcement looks like (without the fear-mongering)
National market-surveillance authorities enforce these rules, and the fine ceiling for transparency violations is €15M or 3% of worldwide turnover — whichever is higher. Will a regulator's first move on August 3 be to fine a bakery's website? Almost certainly not. Enforcement historically starts with the egregious and the large.
But that's not the real risk calculus for a small business. The real exposure is asymmetry: the fix (a disclosure line, a labeled widget, a marked image) costs minutes; the tail risk — a complaint from a competitor or a user, a distributor requiring compliance attestations, an enterprise customer's procurement checklist — costs deals and legal hours. Cheap insurance, expensive neglect.
A practical checklist for this week
- Inventory your AI touchpoints. Chat widgets (check what your website actually loads — many teams forget a widget installed two years ago), AI-written pages, synthetic images or voice, recommendation or scoring features EU users can reach.
- Label conversational AI. Put the disclosure where the interaction starts: widget header, first message, or both.
- Check your content pipeline. If AI drafts and humans edit and take responsibility, document that. If AI publishes unreviewed, add disclosure.
- Keep provenance markings intact. Don't strip metadata or watermarks from generated media; keep originals.
- Write the one-pager. A short internal note — what AI you use, where, what's disclosed — doubles as your Article 4 AI literacy artifact and your answer when a customer asks.
- Re-check quarterly. Widgets get added, campaigns ship, vendors change models. Transparency drifts unless someone looks.
Where an automated check fits — and where it stops
Steps 1 and 2 are exactly the kind of work a machine should do for you. An automated readiness scan can load your site the way a visitor's browser does, detect which chat platforms actually execute on your pages, check whether an AI disclosure is present, and hand you a prioritized fix list. That turns an afternoon of manual auditing into seconds.
What an automated scan cannot do is make a legal judgment about your edge cases — whether your specific use qualifies for an exception, how your sector's rules interact with the Act, whether your human editorial process meets the responsibility bar. Any tool that promises "instant compliance" is overpromising; treat the scan as your honest first look and your ongoing monitor, not a certificate.
The bigger picture: transparency as a trust asset
It's easy to file Article 50 under regulatory burden. The more useful frame: the EU just made honesty about AI a legal baseline, and businesses that get ahead of it convert a compliance chore into a trust signal. "You're chatting with our AI assistant — a human is one click away" reads as confidence, not weakness. The companies that resent disclosure are usually the ones whose AI experience can't survive it.
Deadlines like August 2 are simply forcing functions. The businesses that treat user trust as a feature — labeled AI, honest claims, accessible pages — compound quietly while everyone else waits for the first enforcement headlines.