The AI Act applies from 2 August. What to do with your website, content and chatbot
From 2 August 2026 the transparency layer in Article 50 of the AI Act applies. For most small and mid-sized companies it comes down to three things: the chatbot on your website has to identify itself as AI, realistic images and voices from generative models need labelling, and text that went through your editorial control stays outside the obligation. The heavy rules for high-risk systems were pushed back to 2 December 2027.
29 July 2026 · Bartek Liszkowski
If you write your company blog with the help of AI, do you have to label it from August?
This is the question I get more often than any other right now. The answer is: most likely no, but there are three situations that call for action, and one of them touches practically every company with a chatbot on its website.
On 2 August 2026 the next layer of the EU AI Act starts to apply. Instead of summarising the regulation, I read it with one question in mind: what does the owner of a small or mid-sized company actually have to do when there is a website, content goes out regularly and AI runs in the background of daily work.
An honest disclaimer first: I am not a lawyer. I am a developer who puts AI into business systems and had to read all of this to know what to build. For an unusual situation or a high-stakes one, talk to a solicitor.
First, a sense of scale: what arrives now is light
Plenty of fear has grown around the AI Act, so let us start with proportions. The obligations that begin on 2 August come down to transparency: tell people when they are talking to a machine and when they are looking at content a machine produced. Certification, audits and quality management systems sit on a completely different shelf, they belong to high-risk systems.
Those heavier duties, meaning AI in recruitment, employee evaluation, credit scoring or education, were meant to arrive at the same time, but they were pushed back. Regulation (EU) 2026/1744, the so-called digital omnibus, published on 24 July and in force since 27 July 2026, moved them from 2 August 2026 to 2 December 2027. AI built into regulated products (medical devices, toys, aviation) has until 2 August 2028.
So if your system has a module that scores job candidates or rates employees, sixteen months remain for the adjustment. That time is worth spending on calm preparation.
Article 50 itself was left in place. The only relief covers the technical side for providers of tools: machine-readable marking of content (Article 50(2)) applies to systems already on the market before 2 August 2026 only from 2 December 2026. For a company that uses AI, the duties start on 2 August.
AI Act · calendar of obligations
What starts to apply, and when
As at 29 July 2026, after the changes introduced by Regulation (EU) 2026/1744.
-
Already applies
2 February 2025
Prohibited AI practices and the duty to support AI literacy in the organisation (Article 4).
-
Already applies
2 August 2025
Obligations for providers of general-purpose AI models (GPAI).
-
Next deadline
2 August 2026
Transparency (Article 50): the chatbot identifies itself as AI, synthetic content is marked, deepfakes are disclosed. Market surveillance begins.
-
Postponed
2 December 2027
High-risk systems under Annex III: recruitment, employee evaluation, scoring, education. Previously: August 2026.
-
Postponed
2 August 2028
AI in regulated products under Annex I: medical devices, toys, aviation. Previously: August 2027.
National supervision: the regulation applies EU-wide, while each member state designates its own market surveillance authority, for instance the Bundesnetzagentur in Germany and KRiBSI in Poland. Every member state also has to run at least one AI regulatory sandbox, free of charge for small and mid-sized companies. Penalties for breaching the transparency duties: up to 15 million euros or 3% of worldwide turnover.
Question one: do I have to label text on my website
This is the heart of it, and this is where the wrong answer comes up most often.
The provision (Article 50(4) of the AI Act) requires disclosure of AI-generated text only when it is published to inform the public on matters of public interest. That wording aims at journalism and commentary, at a portal flooding readers with automatically generated news items. A write-up of a production system rollout, a guide for customers or a service description sit outside that scope.
Even if someone tried to stretch the interpretation, the provision carries a second exemption, and that one matters most to companies. The obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
You read the text before publishing. You correct it. You decide what goes on the site. You publish under your own brand and carry the responsibility. That is editorial control, a legally relevant act with real weight. The exemption works.
One caveat: the European Commission reads this exemption narrowly. What counts is a substantive review by a person who knows the subject, plus clearly assigned editorial responsibility. A spellcheck or a quick nod through falls short.
Conclusion: a company blog, a newsletter, a service description or a project write-up where AI drafted the first version and you read it, corrected it and approved it require no labelling.
Question two: what about images
Here it gets more serious, because the editorial control exemption covers text alone. Images, video and audio stay outside it. The fact that you looked at a graphic and approved it changes nothing.
On top of that, the definition of a deepfake reaches further than many assume. The letter of the provision (Article 3(60)) speaks of content resembling existing persons, objects, places or events that would falsely appear authentic. The Commission's guidelines stretch that criterion to anything that exists or could plausibly exist in reality. A realistic photo of a person who never existed therefore falls inside the definition. An AI-generated product shot in an advert, a synthetic voiceover in a video, a heavily reworked photograph: all of it calls for disclosure.
What stays outside is openly fantastical material that could not exist in reality, along with small technical corrections such as colour balance or sharpness.
It also helps to know what the provision leaves alone: a chart from a spreadsheet, a diagram, a slide, an infographic built from typography and shapes. That is the deterministic output of a tool, even where AI helped with the layout. The line runs at a generative model producing a realistic image. Both graphics in this article are exactly that case: built from typography, colour and shapes, so the labelling duty passes them by.
Question three: the chatbot on your website
This is the one duty of the three that comes without exemptions, which is why it matters most.
If a chatbot, a voicebot or an assistant handling customers runs on your website, from 2 August it has to identify itself as AI. Clearly, visibly, at the latest at the moment of the first interaction. A mention in the terms of service or the privacy policy falls short. It also makes no difference that a human reads the conversations afterwards.
There is exactly one narrow exception: where contact with AI is obvious to a reasonably well-informed person. The Commission reads it narrowly, so relying on it is a poor bet. Adding „AI assistant” to the header of the chat window settles the matter in five minutes.
The decision table
One page to walk through, and the topic is off your desk.
AI Act · Article 50 from 2 August 2026
What needs labelling and what does not
A decision table for a company that publishes content and uses AI in daily work.
No labelling needed
the obligation does not apply
- A blog article written with the help of AIprovided a person reads it, corrects it and carries editorial responsibility
- A newsletter drafted by AI and edited before sendingthe same ground: editorial control
- Service description, offer, project write-upthis is not informing the public on matters of public interest
- Chart, diagram, infographic, slidethe deterministic output of a tool rather than generative content
- Correcting colour, crop or sharpness of a photoa small technical edit
Labelling required
the obligation applies directly
- A chatbot or voicebot handling customerswithout exception, at the first interaction; the terms of service fall short
- A realistic image or photo from a generative modelthe editorial control exemption covers text alone
- Synthetic voiceover, AI voice, video with an avataraudio and image come without the editorial exemption
- Content published automatically, without human reviewno editorial control closes the route to the exemption
- Deepfake, including the likeness of a person who does not existrealism decides: could it plausibly exist in reality
Informational material, not legal advice. Legal position as at 29 July 2026.
What almost everyone forgets: AI literacy
There is one more duty, in force since February 2025, that most companies have never heard of. Article 4 of the AI Act asks providers and deployers to look after the AI literacy of the people who work with AI on their behalf. The digital omnibus softened the wording: today it is a duty to take appropriate measures supporting that literacy, an obligation of effort rather than a hard result.
In a small company this is a modest project. In practice a single page does the job: which AI tools we use, what they may be used for, what must never be pasted into them (personal data, customer data, trade secrets), who checks the output before it is published or sent to a client. An hour of work, and in an audit, a tender or a conversation with a larger partner it makes a very good impression.
Who enforces this, and where
The AI Act applies directly across the EU, while supervision sits with the member states. Each of them designates its own market surveillance authority, and the names differ. In Germany the general authority is the Bundesnetzagentur, under the implementing act in force since 29 July 2026. In Poland the new Commission for the Development and Security of Artificial Intelligence (KRiBSI) takes that role, with the act signed on 24 July 2026 and the body due to start around November 2026. If you operate in several markets, it pays to check the authority for each of them.
There is one element worth knowing wherever you are: regulatory sandboxes. Every member state has to run at least one AI sandbox, a supervised environment for testing solutions before they reach the market, and small and mid-sized companies get priority access free of charge. If you are building something unusual and the classification is unclear, that is a real path forward.
Penalties for breaching the transparency duties reach 15 million euros or 3% of worldwide annual turnover, whichever is higher. For small and mid-sized companies the lower of the two amounts applies, so the sanction stays proportionate to size. Still, the fact that supervision has teeth is worth noting.
What I would do this week
Three things, each of them a single day of work. First: check whether any bot or assistant runs on your website, and if so add a visible note that it is AI. Second: go through the graphics on your site and in your marketing materials to see whether any of them are realistic images from a generative model, and label those. Third: write down the one-page rules for using AI in your company and pass them to the team.
And one thing the law leaves out that is still worth considering: a note at the foot of an article saying the text was produced with the support of AI tools and that a named person carries responsibility for its substance. Legally unnecessary. Yet at a time when clients increasingly ask whether a human wrote this, openness pays off.
Finally: the same applies to systems you have built
If you put AI inside your own system, in a CRM, an ERP or a document flow, the same principles translate into architecture. The simplest route to compliance is building so that AI proposes while the decision stays with a person: analysis in read-only mode, a visible confidence threshold, a human approving the write, and an audit trail of who decided what and when. A system like that meets the spirit of the regulation along the way.
That is exactly how I recently built automatic order entry into a client's production system. The AI reads emails and technical drawings and prepares proposals, while the record appears only after a person clicks.
Running AI inside your system and unsure which side of the line you are on? Write to me and we will go through it together.
Legal position as at 29 July 2026. This article is informational and does not constitute legal advice.
Common questions about labelling AI
Does a blog article written with AI need a label?
Does a chatbot on a website have to say it is AI?
Do AI images and photos need labelling?
When do the rules for high-risk systems start to apply?
How large is the penalty for missing labels?
Book 30 minutes or write a message
The first call is a calm conversation to get to know each other. I check whether I can help at all. No slides, no sales pressure. If I see it is a poor fit, I say so directly.
Prefer to write?
Briefly describe what you need - I reply within one business day. Often sooner.
Phone +48 601 789 966 - you can call, I pick up myself.