PPilotOS

EU AI Act Enforcement Has Started: What Happens If Your Website Isn't Compliant?

By Raya Meresa · PilotMain LLC8 min read

The EU AI Act's transparency rules stopped being a future deadline on August 2, 2026. If your website runs an undisclosed AI chatbot or publishes unlabeled AI content to EU visitors, you are no longer "preparing for compliance" — you are out of compliance. This article walks through what enforcement actually looks like in practice: who can come after you, how the process works, what fines are realistic, and what to do if you're reading this late.

This article is educational content, not legal advice. For decisions that depend on your specific systems and jurisdiction, consult a qualified lawyer.

Who actually enforces the AI Act against a small business?

Not "Brussels." Day-to-day enforcement of the transparency obligations belongs to national market-surveillance authorities — each EU member state designates its own, the same way GDPR enforcement runs through national data-protection authorities. The European Commission's AI Office concentrates on general-purpose AI model providers; your website's chatbot disclosure is a national-authority matter.

That structure has two practical consequences. First, enforcement intensity will vary by country — some authorities staffed up early, others are still building capacity. Second, your exposure follows your users: a US or UK company whose site serves visitors in France, Ireland, or Germany can hear from the authority where those users are, not where the company is registered.

How a case actually starts: complaints, not sweeps

Regulators do not crawl the internet fining small websites alphabetically. Realistically, a transparency case against a smaller business starts one of four ways:

  • A user complaint. Anyone who realizes mid-chat that the "support agent" was a bot can report it. The complaint is free to file and lands on you as a documented case.
  • A competitor report. The quiet weapon of every compliance regime. If a rival discloses their AI and you don't, reporting you is cheap and legal.
  • A customer's procurement process. Not enforcement in the legal sense, but the same effect: enterprise buyers are adding AI Act attestations next to their GDPR questionnaires. A missing answer costs you the deal without any regulator involved.
  • Spillover from another investigation. An authority examining your sector, your platform vendor, or a data-protection issue finds the unlabeled AI touchpoints while it's looking.

The pattern to internalize: small businesses rarely get swept; they get reported. Your risk is not abstract regulator attention — it's one annoyed user, one sharp-elbowed competitor, one procurement checklist.

The realistic penalty math

The number that circulates — €35 million or 7% of worldwide turnover — is the ceiling for prohibited practices: social scoring, banned biometric systems, the category of things you should never be doing at all. Transparency violations sit in a different band: up to €15 million or 3% of worldwide annual turnover, whichever is higher. And the Act instructs authorities to consider proportionality — including the size of the provider — when setting fines; SMEs can face the lower of those two amounts rather than the higher.

Does that mean a five-person company gets a €15M invoice for an unlabeled chat widget? No — first actions in regimes like this historically involve warnings, orders to remedy, and deadlines before headline fines, and they start with egregious, large-scale cases. But "the fine probably won't be maximal" is a strange comfort when the fix costs a line of text. The rational move is not to price the fine — it's to make the violation not exist.

The compliance asymmetry, one more time

Here is the whole economic argument in three lines. The cost of compliance for a typical small-business website: labeling your chat widget, disclosing AI-generated content, keeping provenance metadata intact — minutes to hours of work, near-zero ongoing cost. The cost of non-compliance: an open-ended tail that includes regulator correspondence, legal hours, procurement failures, and the reputational cost of being the business that hid its bot. Asymmetries like that have only one rational answer.

Reading this late? Do these four things this week

  1. Find out what your site actually exposes. Not what you remember installing — what executes on your pages today. Chat widgets accumulate; marketing pages ship with AI copy nobody flagged. An automated scan of your live site is the fastest honest answer.
  2. Label conversational AI now. "You're chatting with our AI assistant" at the start of the interaction. This single line addresses the most visible, most reportable gap.
  3. Disclose AI-generated content where it informs the public, and keep watermarks and provenance metadata intact on generated media. If a human takes real editorial responsibility for AI-drafted text, document that process.
  4. Date your fixes. Keep a simple record of what you changed and when. If a question ever comes, "we identified the gap and remediated on this date" is a categorically better position than an ongoing violation — authorities weigh remediation.

What "being ready" looks like from here

Compliance is not a certificate you frame once. Widgets get added, campaigns ship, vendors swap models under you. The businesses that stay clean treat AI transparency like uptime: something monitored, not remembered. A quarterly re-check of your AI touchpoints — or an automated monitor that does it for you — turns the AI Act from a recurring scare into a solved background process.

And the framing that serves you best hasn't changed since before the deadline: disclosure done well reads as confidence. "You're talking to our AI — a human is one click away" tells EU visitors you run your technology honestly. The rule is now mandatory; the trust it builds is still a competitive advantage most of your market hasn't claimed.

Frequently asked questions

Who enforces the EU AI Act's transparency rules?
National market-surveillance authorities in each EU member state handle transparency obligations like Article 50 — similar to how GDPR runs through national data-protection authorities. The European Commission's AI Office focuses on general-purpose AI model providers, not individual websites.
How would a regulator even find my small business?
Usually they don't — someone reports you. Realistic triggers are a user complaint, a competitor report, an enterprise customer's procurement questionnaire, or spillover from another investigation. Small businesses rarely get swept; they get reported.
What is the realistic fine for a transparency violation?
The ceiling is €15 million or 3% of worldwide annual turnover — not the €35M/7% figure often quoted, which applies to prohibited practices. The Act also directs authorities to weigh proportionality, and first actions in comparable regimes have historically been warnings and remediation orders rather than maximal fines.
I missed the August 2 deadline. What should I do?
Fix the gaps now and date your fixes. Label conversational AI, disclose AI-generated content, keep provenance markings intact, and keep a simple record of what you changed and when. Documented remediation is a categorically better position than an ongoing violation.
Can I be fined if my company isn't in the EU?
The Act has extraterritorial reach: if EU users interact with your AI chatbot or consume your AI-generated content, the transparency duties can apply regardless of where your company is registered. Cross-border collection is harder in practice, but procurement and platform pressure reach you either way.

TrueConform's AI Act Scan loads your site in a real browser, detects chat widgets across 18+ platforms, and checks the Article 50 disclosure points — with a shareable report in 6 languages and copy-paste fix snippets. One site free, forever.

Run a free TrueConform AI Act Scan

More from PilotMain: TrueConform (web accessibility scanning), PursuitCue (federal bid-fit screening for cleaning companies), and the full product family.