On August 2, two weeks from the date of this post, the EU AI Act's transparency obligations go live. If your business uses AI in any customer-facing capacity and any of your customers or users are based in the EU, some part of this reaches you. Which part depends on your role.
Most of the coverage has focused on large tech companies and high-risk AI systems. The high-risk rules were postponed to December 2027 for standalone systems, and to August 2028 for AI built into products already covered by EU product safety law. What was not postponed is Article 50, the transparency chapter, and that is the one affecting the broadest range of ordinary businesses right now.
What Article 50 Requires
It covers four situations, and which of them lands on you depends on your role. The Act separates providers, who develop an AI system and put it on the market under their own name, from deployers, who use one in the course of their business. Most small businesses are deployers.
Two of the four sit with providers. A system that interacts directly with people has to be built so users are told they are dealing with AI from the first interaction, unless that is already obvious. A generative system has to mark its output in a machine-readable format so it can be detected as artificially generated. If you are using someone else's chatbot or image generator, those are their obligations rather than yours. If you had a chatbot built for you and put it into service under your own name, you may be its provider.
Two sit with deployers, which is where most small businesses will find themselves. Deepfakes and synthetic depictions of real people have to be clearly labeled to anyone who sees them. AI-generated text published to inform the public on a matter of public interest has to be labeled, unless it went through real human review or editorial control. Spell-checking does not count.
You do not need to be a tech company for this to apply. A retail business running a customer service chatbot is in scope. A marketing team generating social content with AI is in scope. A consultancy using an AI assistant to draft client communications may be in scope, depending on how that output reaches the client.
Content creators can be in scope. If you run AI-generated ad creative to EU audiences on Instagram or YouTube, you are the deployer of that system. What matters is whether the creative is a deepfake, meaning it resembles a real person, place or event closely enough to look authentic. Where it is, you have to label it visibly to the people who see it, and the Commission has said directly that relying on the machine-readable mark the generator embedded does not satisfy that duty. Ordinary AI-assisted creative that is neither a deepfake nor public-interest text carries no deployer labeling obligation under Article 50. Both platforms have disclosure tools and using them is sensible, but they are not what discharges the obligation.
You also do not need to be based in the EU. The Act reaches providers and deployers outside the EU when an AI system's output is used by people in the EU. If your website has European visitors, or your client list includes European companies, that question is worth a closer look.
What It Does Not Mean
It does not mean you need to stop using AI. The obligations are disclosure and labeling requirements, not prohibitions. Breaches of Article 50 carry fines of up to 15 million euros or 3% of total worldwide turnover. For small and medium enterprises the Act applies whichever of those two is lower, and the Commission has said proportionality is taken into account. The message here is that transparency about AI use has moved from best practice to legal expectation. Very few small businesses are about to be fined.
One important detail. Providers of systems already on the market before August 2 have until December 2, 2026 to meet the machine-readable marking requirement, and content generated before August 2 does not have to be labeled retroactively. Everything else in Article 50 applies from August 2 with no transition period.
Three Things Worth Doing Now
First, list every AI system your business uses that touches customers or produces customer-facing output. That includes chatbots, auto-reply sequences, content generation tools, and image generators.
Second, for any system where customers interact with AI directly, add a disclosure at the point of first contact. "You are chatting with an AI assistant" at the start of a session is the right shape. If you are the provider of that chatbot, it is what Article 50(1) asks for. If you are a deployer using someone else's, it is not required of you, and it is still worth doing.
Third, for AI-generated content going to EU customers, check whether the platform you use supports machine-readable marking. Most major platforms are building this in ahead of the deadline. If yours does not, that is a conversation to have with the vendor.
This is not a crisis. It is a disclosure requirement. Most of what it asks for is straightforward. The businesses that will have a problem are the ones that ignore it entirely and get caught using AI in ways their customers never knew about.
If you are already being transparent about how you use AI, August 2 changes very little for you. If you are not, it is worth a few hours to get there.
Sources
- Article 50's application date of August 2, 2026, the four situations it covers, and the split of duties between providers and deployers: European Commission, Transparency obligations under Article 50 of the AI Act. The same page carries the grace period to December 2, 2026 for machine-readable marking on systems already placed on the market, the point that content generated before August 2 needs no retroactive labeling, and the fine ceiling of 15 million euros or 3% of worldwide turnover with proportionality for SMEs.
- The deepfake definition, the three cumulative criteria it turns on, and the statement that a deployer cannot rely on the provider's machine-readable mark to discharge its own disclosure duty come from the Commission's Guidelines on Transparency of AI-Generated Content, summarized on the FAQ page above. Named rather than linked, since the guidelines are long and the FAQ states the specific points used here.
- The deferral of high-risk obligations to December 2, 2027 for standalone Annex III systems and August 2, 2028 for AI embedded in products under Annex I is Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on July 24, 2026 and in force from July 27. This post was published on July 19, when the deferral had been agreed and adopted but had not yet entered into force.
- An earlier version of this post described the chatbot disclosure and the machine-readable marking requirement as obligations on the reader's own business. Both sit with providers under Article 50(1) and 50(2). A small business using a chatbot or image generator built by someone else is a deployer and carries neither. The section now separates the four situations by role, which is the distinction the Act actually draws.
- AI Act timelines have moved repeatedly, including twice between this post being drafted and being corrected. Dates here reflect the position in August 2026 and are worth rechecking against the Commission's own pages before acting on them.
A note on images across this site. Illustrations and workflow diagrams are made with AI, from prompts we write and refine, and we edit most of them afterwards. Screenshots taken in n8n are not, since they show workflows we built in the tool.