# The EU AI Act's August 2 Deadline Probably Applies to Your Chatbot

The EU AI Act's Article 50 transparency rules start August 2, 2026, and they reach small businesses outside the EU. Here's what a chatbot, AI images, or AI-written copy actually require.

Published: 2026-07-23
Updated: 2026-07-23
Author: Oshane Spencer
Category: AI-Powered Operations
Tags: EU AI Act, AI compliance, AI transparency, small business, generative AI
Canonical: https://ariostech.ca/ai-insights-hub/eu-ai-act-article-50-transparency-smb

---


On July 20, 2026, the European Commission adopted its final guidelines on Article 50 of the EU AI Act ([European Commission](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems)). The practical version for a small business: if you run an AI chatbot, publish AI-written articles, or post AI-generated images that reach people in the EU, you pick up new disclosure duties on August 2, 2026.

Most owners I talk to file "EU AI Act" under problems for companies with a legal department. That instinct is wrong here, and the gap between what people assume and what the rule actually says is exactly where the risk lives. So let me walk through what changed, whether it reaches you, and the short list of what you would actually have to do.

## What exactly changed on July 20?

The rule itself already existed. What arrived on July 20 was the Commission's final guidance on how Article 50 works in practice, plus a Q&A and a Code of Practice for AI-generated content ([European Commission](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems)). The obligations become enforceable on August 2, 2026.

Article 50 is the transparency layer of the AI Act. It does not ban anything. It says that in a handful of situations where a person could be misled about whether they are dealing with AI, someone has to say so plainly ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/transparency-rules-article-50/)).

That "someone" is the part worth slowing down on, because the rule splits the work between the company that builds the AI tool and the company that uses it. You are almost always the second one.

## Does the EU AI Act really reach a business outside the EU?

Yes, and this is the part that catches people. Article 2 of the AI Act applies to providers and deployers located in a third country when the output of the AI system is used in the Union ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/article/2/)). Your head office being in Calgary or Denver does not put you outside it.

Think about how ordinary this is. A chatbot on your site answers a visitor in Berlin. An AI-drafted article you published gets read in Dublin. The output is being used in the EU, so the rule is in scope regardless of where you sit. This is the same territorial logic the GDPR taught everyone a few years ago, applied to AI ([William Fry](https://www.williamfry.com/knowledge/a-practical-guide-to-the-extraterritorial-reach-of-the-ai-act/)).

If you have no EU users at all and can be confident that stays true, this genuinely does not touch you. For most businesses selling online, that is a hard thing to promise.

## What are your actual obligations as a small business?

Short version: as a deployer, you owe disclosures, not engineering. There are three places the rule can land on a small business, and each one comes down to telling people the truth about AI in language they can see. If you want the plain-English backstory on what "generative" even means here, we wrote a [primer on generative AI](/ai-insights-hub/what-is-generative-ai) that keeps this readable.

### Do you run a chatbot on your website?

Then Article 50(1) applies. You have to inform users they are interacting with an AI, clearly and at the latest when the interaction starts ([Greenberg Traurig](https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act)). A first message that says the assistant is automated, or a visible indicator by the chat window, does the job.

What does not do the job: a line buried in your terms and conditions, metadata a human never sees, or a vague label like "assistant" ([Greenberg Traurig](https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act)). The one exception is when it is already obvious to a reasonable person that they are talking to a machine, and the guidelines apply that exception narrowly. The honest read is to just say it.

One wrinkle worth knowing: the guidelines get stricter when children or other vulnerable users are part of the audience ([Greenberg Traurig](https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act)). If your site serves families or patients, be especially plain that the bot is automated.

### Do you post AI-generated images or video of realistic people?

Then you are in deepfake territory under Article 50(4), and the definition is broader than "malicious fake." It covers realistic synthetic images, audio, or video, and intent to deceive is not required ([Greenberg Traurig](https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act)). An AI-generated ad with a lifelike person who does not exist counts.

The deployer has to disclose that the content is artificial. Clearly fantastical material, dragons and physics that cannot happen, falls outside the definition, and genuinely artistic or satirical work gets a lighter touch rather than a full pass ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/transparency-rules-article-50/)). For a normal marketing image, a visible label is the safe move.

Picture a local clinic running an ad with an AI-generated patient who looks completely real. That image needs a label, even though nobody set out to fool anyone, because the test is whether it looks authentic, not whether you meant to deceive.

### Do you publish AI-written articles to inform the public?

This is the one people over-worry. The text duty under Article 50(4) applies to AI-generated text published to inform the public on matters of public interest, read broadly to include health, consumer, economic, and political topics ([Greenberg Traurig](https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act)). But there is a real exemption, and it is a workflow you probably want anyway.

If a named person or organization with genuine editorial authority substantively reviews the piece before it publishes, no label is required. A spell-check does not qualify, and a token sign-off does not either ([Greenberg Traurig](https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act)). This is just a human [approval gate before publishing](/ai-insights-hub/ai-agent-approval-gates-for-smb), which is the same discipline we tell clients to run on any AI-drafted output for quality reasons.

## Whose job is the watermarking, really?

Not yours, in almost every case. The headlines on this story focus on machine-readable marking, the requirement that synthetic output carry a hidden signal detection tools can read. Under Article 50(2), that duty falls on the provider of the generative AI system, the tool, not on the small business using it ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/transparency-rules-article-50/)).

Providers whose systems were already on the market before August 2 even get extra time, until December 2, 2026, to bring that marking into conformity ([Sidley](https://datamatters.sidley.com/2026/06/24/eu-ai-act-transparency-obligations-preparing-for-compliance-by-2-august-2026/)). So the piece of this rule that sounds the most technical and expensive is the one you are least likely to own. That is the part I would push back on if someone tried to sell you a watermarking product to "get compliant." Read your obligations before you buy anything, which is a good rule for AI generally and a theme in [how to start with AI when you have no team](/ai-insights-hub/how-to-start-with-ai-no-team).

## What happens if you ignore it?

Article 50 breaches sit in a real penalty tier: up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities from August 2 ([Sidley](https://datamatters.sidley.com/2026/06/24/eu-ai-act-transparency-obligations-preparing-for-compliance-by-2-august-2026/)). Regulators are told to weigh proportionality and company size, so a five-person shop is not treated like a large platform.

Enforcement runs through each member state's own authority rather than one central EU office, and regimes like this tend to move on complaints in practice. The trigger is often a customer or a competitor noticing, not a proactive sweep, which is a reason to close the obvious gaps rather than bet on staying invisible.

I would not read that as permission to skip it. The exposure is dated and the cost of compliance is close to zero, so the math is lopsided. Following the Commission's Code of Practice is also offered as a way to show good faith if a question ever comes up ([European Commission](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content)).

## So what does this mean for your business?

It means a short audit, not a project. The real cost of Article 50 for a small deployer is an afternoon, and the real risk of ignoring it is a fine tier you do not want to test. Walk your own AI surface and close the three gaps.

Check three things. First, does your site chatbot say it is an AI up front? If not, add a first-message notice. Second, do any live ads or posts use realistic AI-generated people? Label them. Third, is a named human actually reviewing your AI-assisted articles before they publish? If yes, you are covered on text and you should make that reviewer visible; if no, add the review or add the label.

That is the whole job for most small businesses. This is the kind of low-drama governance that belongs in your normal operating model, not a separate compliance binder, and it is one line item in a broader [AI operations blueprint](/ai-insights-hub/the-ai-operations-blueprint). If you are also leaning on AI for [marketing copy at small-business scale](/ai-insights-hub/chatgpt-for-small-business-program), the same human-review habit keeps you both compliant and better read.

If you want a second set of eyes on where AI actually touches your customers, that is exactly what a free AI Opportunity Call is for. We will map your AI surface and tell you plainly which of these three, if any, applies to you.

## FAQs

### Does the EU AI Act apply to my business if I am not based in the EU?

Yes, it can. Article 2 of the AI Act extends to providers and deployers located outside the EU when the output of their AI system is used in the Union. So a Calgary shop whose website chatbot answers a customer in Berlin, or whose AI-written article is read in Dublin, is in scope. Where your company is headquartered does not decide it. Whether EU users touch the output does.

### What do I have to disclose if I use an AI chatbot on my website?

Under Article 50(1), you have to tell people they are talking to an AI, clearly and up front, at the latest when the conversation starts. In practice that means a plain notice a visitor actually sees, such as a first message that says the assistant is automated, or a visible indicator by the chat window. Burying it in your terms and conditions or calling the bot an "assistant" does not count. The only carve-out is when it is already obvious to an average person that they are dealing with a machine.

### Do I have to label AI-written blog posts and marketing copy?

Only in narrower cases than most people assume. The text disclosure duty applies to AI-generated text published to inform the public on matters of public interest, which the guidelines read broadly (health, consumer, economic, political, and similar topics). But there is an exemption: if a named person or organization with real editorial authority substantively reviews the content before it goes out, you do not have to label it. A quick spell-check does not qualify. Genuine human review does.

### Whose job is the machine-readable watermarking, mine or my AI vendor's?

Your vendor's. The Article 50(2) duty to mark synthetic output in a machine-readable format so it is detectable as AI-generated falls on the provider of the generative AI system, meaning the tool you use, not the small business deploying it. Providers of systems already on the market before August 2 have until December 2, 2026 to bring that marking into conformity. As a deployer, your duties are the disclosures, not the watermarking engineering.

### What are the penalties if a small business ignores Article 50?

Transparency breaches sit in the same penalty tier as several other AI Act violations: up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities. Regulators are directed to weigh proportionality and the size of the business, so a small company is not treated like a large platform, but the exposure is real and it is dated. The point is that the fix is far cheaper than the risk.

### When do the Article 50 rules actually start?

The transparency obligations apply from August 2, 2026. The European Commission adopted its final guidelines on July 20, 2026, which is what turned the general rule into practical detail. The one moving piece is the machine-readable marking duty for generative AI systems already on the market, where providers have until December 2, 2026. Everything a small deployer has to do, the disclosures, is live on August 2.
