Skip to main content

Your Chatbot Is Now Breaking EU Law Unless It Introduces Itself: A Small Business Guide to the AI Act's Transparency Rules

Published 9 min readMike ThriftMike Thrift
Your Chatbot Is Now Breaking EU Law Unless It Introduces Itself: A Small Business Guide to the AI Act's Transparency Rules
On this page

If your website has a support chatbot, an AI receptionist answering calls, or product pages illustrated with AI-generated images — and any of your customers are in the EU — you picked up new legal obligations on August 2, 2026. That is the day Article 50 of the EU AI Act became enforceable, and it does not care that your company is small, American, or has never heard of Brussels rulemaking. If your AI output reaches people in the EU, the transparency rules reach you.

The good news: for most small businesses, compliance is a disclosure audit you can finish in an afternoon, not a six-figure consulting engagement. This guide walks through what the rules require, who they apply to, and the practical steps to get compliant.

What Article 50 Actually Requires

Article 50 of Regulation (EU) 2024/1689 sets out four transparency obligations aimed at different actors along the AI value chain. You do not need to memorize the legal numbering, but you do need to figure out which bucket you fall into — because the obligations can apply cumulatively, and getting one right does not excuse the others.

1. If people interact with your AI, it must say so

Providers of interactive AI systems — chatbots, voice assistants, AI agents, AI-powered search or support interfaces — must design their systems so users are informed they are dealing with a machine, not a human. The European Commission's guidelines, adopted July 20, 2026, read this obligation broadly: it explicitly covers agentic AI that carries out tasks autonomously, whether the AI talks to the person who gave the instruction or to third parties it encounters along the way.

What counts as sufficient disclosure is strict. A line buried in your terms and conditions does not count. Metadata or watermarks alone do not count, because users do not notice them at the point of interaction. Vague labels like "assistant" or technical jargon like "this system uses LLMs" fall short too. The Commission recommends a combination of plain-language notices, audio cues where relevant, and persistent visual indicators — disclosure that is visible before and during the interaction, not discoverable afterward.

2. If you build AI that generates content, outputs must be machine-marked

Providers of AI systems that generate or manipulate synthetic audio, image, video, or text must implement machine-readable marking so outputs are detectable as AI-generated. This duty sits with the company that builds or supplies the model or tool — for most small businesses using off-the-shelf AI products, this is your vendor's problem, not yours. Note the timing: under the AI Omnibus proposal, this particular marking obligation for systems already on the market is expected to shift to December 2, 2026, while every other Article 50 duty applies from August 2.

3. If you use emotion recognition or biometric categorization, exposed people must be told

Deployers of emotion recognition and biometric categorization systems must inform the individuals exposed to them. Few small businesses run these systems directly, but if your hiring tool, proctoring software, or customer-analytics product does, the duty to inform the people being scanned sits with you as the deployer.

4. If you publish deepfakes or AI-written public-interest text, you must label it

This is the obligation most likely to surprise a small business. Anyone who deploys a deepfake — or publishes AI-generated or AI-edited text to inform the public on matters of public interest — must disclose the artificial origin of the content.

Two features of this rule deserve emphasis. First, the deepfake test does not depend on your intent to deceive. Posting a realistic AI-generated testimonial video or a synthetic product-demo persona triggers the labeling duty even if you meant no deception at all. Second, "matters of public interest" is defined broadly: health, consumer protection, the environment, fundamental rights, and economic, political, scientific, or cultural developments of societal relevance. A clinic publishing AI-drafted patient-education articles or a financial newsletter leaning on AI-written market commentary is squarely in scope.

The Exemptions Are Narrower Than You Think

Two exceptions get cited a lot, and both are easy to misread.

The "obvious AI" exception. For interactive systems, no disclosure is needed when it is obvious to a reasonably well-informed, observant person that they are interacting with AI. Do not stretch this: the Commission's standard is calibrated to the average member of your target audience, and a polished support bot with a human name and avatar will not pass. When in doubt, disclose.

The human-review exception for published text. AI-generated public-interest text escapes labeling only if a person with relevant expertise genuinely reviewed it for substance — spell-checking or a cursory sign-off is not enough — and an identifiable person or organization bears clearly attributable editorial responsibility, with name and contact details publicly accessible and real authority to approve, amend, or reject the content. Both conditions must hold simultaneously. A founder skim-reading AI-drafted health tips before hitting publish does not qualify unless they have the expertise and the public accountability to match.

Artistic, satirical, and fictional content gets a reduced disclosure duty rather than a full exemption: the label must go only far enough to avoid impairing the work, but it must still exist.

The Part Non-EU Businesses Miss: This Applies to You

Like the GDPR before it, the AI Act has extraterritorial reach. If your chatbot converses with users in the EU, your marketing site serves AI-generated content to EU visitors, or your SaaS product's AI features are used by EU customers, you are in scope regardless of where your company is incorporated. Enforcement began August 2, 2026, with the EU's AI Office and national market-surveillance authorities now actively policing the rules, and a Code of Practice on marking and labeling AI-generated content — already signed by more than 180 organizations — sets the practical benchmark authorities will measure you against.

Penalties run to 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher. For SMEs and startups the fine is capped at the lower of those two figures, which still means up to 3 percent of your global revenue — a painful number for a business running on thin margins. And the AI Act is not the only regime in play: consumer-protection law, platform rules, and personality and IP rights can each impose their own labeling requirements on top.

A Practical Compliance Checklist

Work through these steps in order. For a typical small business with one chatbot and some AI-assisted marketing, this is a few hours of work.

Step 1: Inventory every user-facing AI touchpoint

List each place AI meets a human or produces visible content: support chatbots, voice agents, AI receptionists, AI-generated images or videos on your site and social channels, AI-drafted blog posts or newsletters, and any hiring, proctoring, or analytics tools with emotion or biometric features. Include third-party tools — using a vendor's AI does not move your deployer duties to the vendor.

Step 2: Add pre-interaction disclosure to every conversational interface

Each chatbot, voice assistant, and agent needs a clear, plain-language statement that the user is interacting with AI, shown before or at the start of the conversation and reinforced with a persistent indicator. "Hi, I'm Ava, an AI assistant" at the top of the chat window is the shape of compliance; a footnote in your terms of service is the shape of a violation. Audit your EU-facing locales specifically — a disclosure that exists only in English on a multilingual site is a gap.

Step 3: Label synthetic media and AI-written public content

Realistic AI-generated images, videos, and audio that depict people, places, objects, or events that could exist — including fictitious-but-natural-looking people — should carry a visible disclosure of their artificial origin. The same goes for AI-generated text published on matters of public interest, unless you genuinely satisfy both prongs of the human-review exception. Build the label into your content templates and publishing checklist so it cannot be forgotten on a busy week.

Step 4: Check your vendors' marking, and document everything

Ask your AI vendors how they meet the machine-readable marking duty, and keep their answers on file — non-signatories of the Code of Practice can still comply through alternative means, but they should expect heavier evidentiary burdens and more frequent questions from authorities. Keep a simple compliance record: your AI inventory, screenshots of each disclosure, your editorial-review workflow for published content, and vendor attestations. If a market-surveillance authority ever asks, this file is your defense.

Step 5: Fold AI transparency into your regular compliance rhythm

Treat these disclosures like tax filings: recurring, dated, and documented. Re-audit whenever you add an AI feature, switch vendors, or launch in a new locale, and diary the December 2, 2026 date for the machine-marking transitional relief to confirm your providers have complied.

Bookkeeping for Compliance: Track the Costs You Are Incurring Anyway

Every step above generates costs — vendor upgrades, developer time for disclosure UI, legal review, staff training — and those costs belong in your books as clearly as any other compliance spend. Create a dedicated expense category for AI compliance rather than scattering the charges across software subscriptions and professional fees. If your accountant ever needs to capitalize implementation costs, defend a deduction, or benchmark what regulation costs your business, a clean ledger beats a forensic reconstruction. Tracking these expenses separately also helps at tax time, when advisory fees and software costs often fall under different deduction rules.

Simplify Your Financial Management

As you work through new obligations like AI transparency disclosures, maintaining clear financial records of the compliance costs is essential. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article

Source: https://beancount.io/blog/2026/09/17/eu-ai-act-article-50-transparency-rules-chatbot-disclosure-deepfake-labeling-guide

Published: September 17, 2026