PPilotMain

EU AI Act Article 50 Is Now in Force: What Small Businesses Must Disclose

By Raya Meresa · PilotMain LLC9 min read

Since August 2, 2026, the transparency obligations of the EU AI Act — Article 50 — are enforceable law. If your website talks to visitors through a chatbot, publishes AI-generated content, or uses synthetic media, this is the rule that says your users have the right to know — and the grace period is over. This guide explains what Article 50 actually requires, who it covers, and the practical steps a small business can take this week — in plain language, without the scare tactics.

This article is educational content, not legal advice. For decisions that depend on your specific systems and jurisdiction, consult a qualified lawyer.

The 60-second version

  • The EU AI Act entered into force on August 1, 2024, with staged deadlines. AI-literacy duties (Article 4) have applied since February 2, 2025. The transparency rules in Article 50 have been enforceable since August 2, 2026 — they apply today.
  • If people interact with your AI system (a chatbot, a voice agent), they must be informed they're dealing with AI — unless it's already obvious to a reasonable person.
  • AI-generated and AI-manipulated content (including deepfakes) must be disclosed and, for providers, marked in machine-readable form.
  • These duties attach to what your systems do, not to how big your company is. There is no small-business exemption from disclosure.
  • Transparency violations can draw fines up to €15 million or 3% of worldwide turnover — the bigger €35M/7% ceiling people quote belongs to the prohibited-practices category, not this one. Precision matters; so does not panicking.

What changed since August 2

Three developments landed around the enforcement date that change how you should read the rest of this guide.

  • The Commission published its final Article 50 guidelines on July 20, 2026. They are the authoritative reading of terms the text leaves open — what counts as "obvious" AI interaction, how the deepfake and public-interest-text disclosures work in practice. If you built your policy from the bare Article text before that date, it is worth a re-read.
  • There is exactly one transition, and it expires December 2, 2026. Providers of generative AI systems already placed on the market before August 2, 2026 have until then to meet the Article 50(2) machine-readable marking duty. That is the only grace period — it does not cover the chatbot disclosure in 50(1), and it does not apply to anything launched on or after August 2.
  • A Code of Practice on Transparency of AI-Generated Content now exists — assessed as adequate by the Commission on July 8 and the AI Board on July 9, 2026, with roughly 190 signatories. It is voluntary. Signing it can give a partial presumption of conformity, not a safe harbour, and it is aimed at organizations generating content at scale rather than at a small business with a support widget.

The short version: no, the deadline was not delayed, and the thing being widely described online as a "grace period until December" is a narrow marking transition for pre-existing generative systems.

What Article 50 actually says

Article 50 sits in the AI Act's chapter on transparency obligations for certain AI systems. Four duties matter to a typical small business:

1. Tell people when they're talking to AI

Providers must ensure that AI systems intended to interact directly with people — chatbots, support agents, voice assistants — are designed so that the people concerned are informed they are interacting with an AI system. The exception: when that fact is already obvious "from the point of view of a natural person who is reasonably well-informed, observant and circumspect."

In practice, don't lean on the exception. A support widget that answers fluently at 3 a.m. under a human-sounding name is not self-evidently a machine to every visitor. A one-line label — "You're chatting with our AI assistant" — is cheap, honest, and removes the ambiguity entirely.

2. Mark AI-generated content in machine-readable form

Providers of generative systems must ensure outputs (text, audio, images, video) are marked in a machine-readable format as artificially generated or manipulated — think watermarking and provenance metadata. If you build on top of a major model provider, much of this happens upstream, but the duty to not strip or defeat those markings lands on you.

3. Disclose deepfakes and synthetic media

Deployers of systems that generate or manipulate images, audio, or video that resembles real people, places, or events must disclose that the content is artificially generated or manipulated. For a small business, this covers things like AI-generated spokesperson videos or synthetic product photography presented as real.

4. Disclose AI text published to inform the public

If AI-generated text is published "with the purpose of informing the public on matters of public interest," the deployer must disclose the AI's role unless a human took editorial responsibility. If your content marketing runs on an AI pipeline straight to publish, this one deserves your attention.

"Does this really apply to my five-person company?"

The honest answer: if EU users interact with your AI features, yes. Three points people get wrong:

  • Size doesn't exempt you. The AI Act contains proportionality gestures toward SMEs (documentation simplifications, regulatory sandboxes), but Article 50's disclosure duties apply by function, not headcount.
  • Location doesn't automatically exempt you. Like the GDPR before it, the Act reaches providers and deployers outside the EU when the system's output is used in the EU. A US company with EU website visitors talking to its chatbot is in scope.
  • "I just embedded a chat widget" doesn't exempt you. If your site runs Intercom, Crisp, Tidio, or any of the dozens of AI-enabled chat platforms, you are the one presenting that AI to your users. The disclosure your visitors see — or don't see — is on your pages.

What has changed since August 2

The deadline passed without fireworks — no wave of day-one fines, no headline enforcement sweep. That is exactly how these regimes start, and it is not the same as nothing having changed:

  • The duties are live. Before August 2, an unlabeled chatbot was a to-do item. Now it is a violation in progress. Every day without disclosure is a day of non-compliance on the record.
  • The complaint channel is open. Users, competitors, and advocacy groups can now report non-compliant sites to national market-surveillance authorities. Small businesses rarely get swept — they get reported.
  • Procurement checklists are updating. Enterprise customers and distributors are beginning to ask for AI Act attestations the way they ask for GDPR ones. "Are your AI touchpoints disclosed?" is becoming a deal-flow question, not a legal-department question.
  • Late compliance still beats none. If you are reading this after the deadline with an unlabeled widget, the right move is unchanged: fix it now and document when you did. Authorities weigh remediation; a dated fix is a far better story than an ongoing gap.

What enforcement looks like (without the fear-mongering)

National market-surveillance authorities enforce these rules, and the fine ceiling for transparency violations is €15M or 3% of worldwide turnover — whichever is higher. Was the regulators' first move after the deadline to fine a bakery's website? Of course not. Enforcement historically starts with the egregious and the large.

But that's not the real risk calculus for a small business. The real exposure is asymmetry: the fix (a disclosure line, a labeled widget, a marked image) costs minutes; the tail risk — a complaint from a competitor or a user, a distributor requiring compliance attestations, an enterprise customer's procurement checklist — costs deals and legal hours. Cheap insurance, expensive neglect.

A practical checklist for this week

  1. Inventory your AI touchpoints. Chat widgets (check what your website actually loads — many teams forget a widget installed two years ago), AI-written pages, synthetic images or voice, recommendation or scoring features EU users can reach.
  2. Label conversational AI. Put the disclosure where the interaction starts: widget header, first message, or both.
  3. Check your content pipeline. If AI drafts and humans edit and take responsibility, document that. If AI publishes unreviewed, add disclosure.
  4. Keep provenance markings intact. Don't strip metadata or watermarks from generated media; keep originals.
  5. Write the one-pager. A short internal note — what AI you use, where, what's disclosed — doubles as your Article 4 AI literacy artifact and your answer when a customer asks.
  6. Re-check quarterly. Widgets get added, campaigns ship, vendors change models. Transparency drifts unless someone looks.

Where an automated check fits — and where it stops

Steps 1 and 2 are exactly the kind of work a machine should do for you. An automated readiness scan can load your site the way a visitor's browser does, detect which chat platforms actually execute on your pages, check whether an AI disclosure is present, and hand you a prioritized fix list. That turns an afternoon of manual auditing into seconds.

What an automated scan cannot do is make a legal judgment about your edge cases — whether your specific use qualifies for an exception, how your sector's rules interact with the Act, whether your human editorial process meets the responsibility bar. Any tool that promises "instant compliance" is overpromising; treat the scan as your honest first look and your ongoing monitor, not a certificate.

The bigger picture: transparency as a trust asset

It's easy to file Article 50 under regulatory burden. The more useful frame: the EU just made honesty about AI a legal baseline, and businesses that get ahead of it convert a compliance chore into a trust signal. "You're chatting with our AI assistant — a human is one click away" reads as confidence, not weakness. The companies that resent disclosure are usually the ones whose AI experience can't survive it.

Deadlines like August 2 were simply forcing functions — and this one has now passed. The businesses that treat user trust as a feature — labeled AI, honest claims, accessible pages — compound quietly while everyone else waits for the first enforcement headlines.

Frequently asked questions

Does the EU AI Act apply to small businesses?
Yes. The transparency obligations in Article 50 apply based on what your systems do (chatbots, AI-generated content, synthetic media), not on company size. The Act includes some proportionality measures for SMEs, but there is no small-business exemption from the disclosure duties themselves.
When did Article 50 become enforceable?
August 2, 2026 — the rules are in force now. The AI Act entered into force on August 1, 2024 with staged application: prohibited-practice rules and AI-literacy duties (Article 4) applied from February 2, 2025, and the transparency obligations in Article 50 have applied since August 2, 2026.
Do I have to tell visitors my chatbot is AI?
In most cases, yes. Article 50(1) requires that people interacting with an AI system are informed they are interacting with AI, unless that is already obvious to a reasonably well-informed person. A support widget that answers in natural language at 3 a.m. is not automatically 'obvious' — a clear label is the safe, low-cost fix.
What are the penalties for violating Article 50?
Non-compliance with the Act's transparency obligations can draw administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. The often-quoted €35M / 7% ceiling applies to prohibited practices — a different, more severe category.
Does this apply to businesses outside the EU?
It can. Like the GDPR, the AI Act has extraterritorial reach: if your website serves users located in the EU with an AI chatbot or AI-generated content, the transparency duties can apply to you even if your company is registered elsewhere.
Is an automated scan enough to make me compliant?
No — and be wary of any tool that claims otherwise. An automated readiness check can tell you what is detectable on your site (chat widgets, missing disclosures, unlabeled AI content) and give you a prioritized fix list. Full compliance is a legal judgment that depends on your specific systems; for edge cases, talk to a lawyer.

TrueConform's AI Act Scan loads your site in a real browser, detects chat widgets across 18+ platforms, and checks the Article 50 disclosure points — with a shareable report in 6 languages and copy-paste fix snippets. One site free, forever.

Run a free TrueConform AI Act Scan

More from PilotMain: TrueConform (web accessibility scanning), PursuitCue (federal bid-fit screening for cleaning companies), and the full product family.