The EU AI Act's transparency rules stopped being a future deadline on August 2, 2026. If your website runs an undisclosed AI chatbot or publishes unlabeled AI content to EU visitors, you are no longer "preparing for compliance" — you are out of compliance. This article walks through what enforcement actually looks like in practice: who can come after you, how the process works, what fines are realistic, and what to do if you're reading this late.
This article is educational content, not legal advice. For decisions that depend on your specific systems and jurisdiction, consult a qualified lawyer.
Who actually enforces the AI Act against a small business?
Not "Brussels." Day-to-day enforcement of the transparency obligations belongs to national market-surveillance authorities — each EU member state designates its own, the same way GDPR enforcement runs through national data-protection authorities. The European Commission's AI Office concentrates on general-purpose AI model providers; your website's chatbot disclosure is a national-authority matter.
That structure has two practical consequences. First, enforcement intensity will vary by country — some authorities staffed up early, others are still building capacity. Second, your exposure follows your users: a US or UK company whose site serves visitors in France, Ireland, or Germany can hear from the authority where those users are, not where the company is registered.
How a case actually starts: complaints, not sweeps
Regulators do not crawl the internet fining small websites alphabetically. Realistically, a transparency case against a smaller business starts one of four ways:
- A user complaint. Anyone who realizes mid-chat that the "support agent" was a bot can report it. The complaint is free to file and lands on you as a documented case.
- A competitor report. The quiet weapon of every compliance regime. If a rival discloses their AI and you don't, reporting you is cheap and legal.
- A customer's procurement process. Not enforcement in the legal sense, but the same effect: enterprise buyers are adding AI Act attestations next to their GDPR questionnaires. A missing answer costs you the deal without any regulator involved.
- Spillover from another investigation. An authority examining your sector, your platform vendor, or a data-protection issue finds the unlabeled AI touchpoints while it's looking.
The pattern to internalize: small businesses rarely get swept; they get reported. Your risk is not abstract regulator attention — it's one annoyed user, one sharp-elbowed competitor, one procurement checklist.
The realistic penalty math
The number that circulates — €35 million or 7% of worldwide turnover — is the ceiling for prohibited practices: social scoring, banned biometric systems, the category of things you should never be doing at all. Transparency violations sit in a different band: up to €15 million or 3% of worldwide annual turnover, whichever is higher. And the Act instructs authorities to consider proportionality — including the size of the provider — when setting fines; SMEs can face the lower of those two amounts rather than the higher.
Does that mean a five-person company gets a €15M invoice for an unlabeled chat widget? No — first actions in regimes like this historically involve warnings, orders to remedy, and deadlines before headline fines, and they start with egregious, large-scale cases. But "the fine probably won't be maximal" is a strange comfort when the fix costs a line of text. The rational move is not to price the fine — it's to make the violation not exist.
The compliance asymmetry, one more time
Here is the whole economic argument in three lines. The cost of compliance for a typical small-business website: labeling your chat widget, disclosing AI-generated content, keeping provenance metadata intact — minutes to hours of work, near-zero ongoing cost. The cost of non-compliance: an open-ended tail that includes regulator correspondence, legal hours, procurement failures, and the reputational cost of being the business that hid its bot. Asymmetries like that have only one rational answer.
Reading this late? Do these four things this week
- Find out what your site actually exposes. Not what you remember installing — what executes on your pages today. Chat widgets accumulate; marketing pages ship with AI copy nobody flagged. An automated scan of your live site is the fastest honest answer.
- Label conversational AI now. "You're chatting with our AI assistant" at the start of the interaction. This single line addresses the most visible, most reportable gap.
- Disclose AI-generated content where it informs the public, and keep watermarks and provenance metadata intact on generated media. If a human takes real editorial responsibility for AI-drafted text, document that process.
- Date your fixes. Keep a simple record of what you changed and when. If a question ever comes, "we identified the gap and remediated on this date" is a categorically better position than an ongoing violation — authorities weigh remediation.
What "being ready" looks like from here
Compliance is not a certificate you frame once. Widgets get added, campaigns ship, vendors swap models under you. The businesses that stay clean treat AI transparency like uptime: something monitored, not remembered. A quarterly re-check of your AI touchpoints — or an automated monitor that does it for you — turns the AI Act from a recurring scare into a solved background process.
And the framing that serves you best hasn't changed since before the deadline: disclosure done well reads as confidence. "You're talking to our AI — a human is one click away" tells EU visitors you run your technology honestly. The rule is now mandatory; the trust it builds is still a competitive advantage most of your market hasn't claimed.