EU AI Act: what applies to your business since 2 August 2026

TL;DR
- Since 2 August 2026, the transparency obligations in Article 50 of the EU AI Act apply.
- In plain terms: a system that talks to a person or produces content has to say so. That covers chatbots, generated text and images, and deepfakes.
- This is not just for AI vendors. Any company that deploys such a system is covered, including a small business running a chatbot on its website.
- Penalties reach €15 million or 3% of global annual turnover, and up to €35 million or 7% for the most serious breaches.
The EU AI Act stopped being a distant deadline: part of it became enforceable on 2 August 2026. Many companies assume it does not concern them because they do not build AI. That is a misreading. The text also targets the businesses that simply use these tools in front of their customers, and it reaches beyond Europe: if your product or your content is available to people in the EU, it applies to you. Here is what is in force, for whom, and what you should already have in place.
What changed on 2 August 2026?
On that date, the transparency obligations set out in Article 50 of the EU AI Act became applicable. They cover three situations that almost every business now runs into.
- A system that interacts with a person must make clear that the person is talking to a machine. That covers customer service chatbots and booking assistants.
- Content generated or modified by AI must be identifiable as such, whether text, image, audio or video.
- Content imitating a real person, a deepfake, must be explicitly disclosed.
Why this is the broadest duty in the text
The other parts of the regulation target specific, often industrial systems. Transparency targets the most ordinary use of generative AI, the one everybody already makes. That is what makes it structural for a small business.
Who exactly is covered?
The regulation separates the provider, who puts a system on the market, from the deployer, who uses it in their own activity. The most common mistake is assuming only the first has duties.
| Your situation | Covered? | What falls on you |
|---|---|---|
| You run a chatbot on your website | Yes | Clearly disclose that the visitor is talking to an AI |
| You publish AI-generated visuals | Yes | Make the artificial origin identifiable |
| Your reps draft emails with AI | Depends on use | A text reviewed and owned by a human is not the same as automated distribution |
| You use AI internally only | Transparency not triggered | But staff training is still expected |
| You ship software with AI inside | Yes, as a provider | Heavier duties, including informing your deployers |
A point that is often misdated: the duty to build AI literacy in your teams did not start in August 2026. It has applied since February 2025. If it has never been addressed, it is overdue, not upcoming.
What should you have in place?
Label your conversational agents
A visible notice in the chatbot’s first message, not a line buried in the terms of service. The wording has to be understandable by an ordinary user without effort.
Mark your generated content
A readable notice on AI-produced visuals and text that you publish. Machine-readable watermarking helps, but on its own it does nothing for the human reader.
Inventory your AI usage
List the AI tools actually used across the business, including the ones that arrived through the side door in individual teams. You cannot bring into compliance what you do not know you have.
Train your people
The AI literacy duty falls on those using the tools. Documented awareness sessions, with a written record, beat an oral practice.
Write an internal policy
What may be pasted into an assistant, what never may, and who signs off on what. This is the document that turns intent into evidence of diligence.
The document that makes the difference
A dated, distributed and acknowledged AI usage policy is what separates a company that thought about the question from one that simply absorbed whatever tools appeared. It fits on one page, and it earns its keep internally as much as with a regulator.
What does non-compliance cost?
Breaches of the transparency duties can be fined up to €15 million or 3% of global annual turnover, whichever is higher. For the most serious infringements in the regulation, the ceiling rises to €35 million or 7%.
Those ceilings are clearly aimed at large operators, and no small business will wake up to a fine of that size. Its realistic exposure lies elsewhere: a formal notice, a rushed remediation, and above all a reputational hit if a customer discovers they were talking to a machine without being told.
What comes next?
The calendar has moved. The obligations covering high-risk systems under Annex III, which include recruitment, credit scoring and education, have been pushed back to December 2027. That is breathing room, not a cancellation: companies using AI to screen job applications gain a year to prepare, not a reason to do nothing.
Where should you start this week?
If you are starting from zero, three actions cover most of the immediate exposure, and none of them needs a lawyer.
- Open your own website and see whether a chatbot answers. If one does, check that it states its nature in the first message.
- Review the last three months of publishing and find the AI-generated visuals that carry no disclosure.
- Ask your teams which AI tools they actually use. The list is almost always longer than the one IT holds.
The rest, full inventory, written policy, recorded training, follows from there. But those three steps are enough to clear the most visible form of non-compliance, the kind a customer or a competitor can spot from the outside.
Choosing your AI tools?
Our comparison ranks the AI software and assistants of 2026, including what they do with your data.
What to do next
To choose your tools with the full picture, see our best AI software 2026 comparison, or our explainer on what an AI agent is.
Frequently asked questions
Does the EU AI Act apply to my business if I do not build AI?
Very probably yes. The regulation separates the provider, who places a system on the market, from the deployer, who uses it in their activity. A company running a chatbot on its website or publishing AI-generated visuals is a deployer, and the Article 50 transparency duties have applied to it since 2 August 2026.
Does it apply to companies outside the EU?
Yes, where the output is used in the European Union. A business established elsewhere that serves EU customers through an AI chatbot, or publishes AI-generated content that reaches people in the EU, falls within scope. Location of the company is not the test, reach into the EU market is.
What exactly does Article 50 require?
Three things. A system that interacts with a person must tell them they are dealing with an artificial intelligence. Content generated or modified by AI must be identifiable as such, whether text, image, audio or video. And content imitating a real person, a deepfake, must be explicitly disclosed.
What are the penalties?
For a breach of the transparency duties, up to €15 million or 3% of global annual turnover, whichever is higher. For the most serious infringements of the regulation, the ceiling reaches €35 million or 7% of global turnover.
Are the high-risk rules in force?
Not yet. The obligations covering high-risk systems under Annex III, which include recruitment, credit and education, have been postponed to December 2027. Companies using AI to screen candidates therefore have additional time to prepare, though the AI literacy duty has applied since February 2025 regardless.