On 2 August 2026 the transparency rules in Article 50 of the EU AI Act start to apply, and they are aimed at products, not at model labs. If your app talks to people through a chatbot, generates images or audio, or publishes AI-written text about matters of public interest, you have a disclosure obligation and roughly a week to ship it. The obligations are small: a sentence at the start of a conversation, a machine-readable mark on generated media, a visible label on a deepfake, and a record of who reviewed your published text. The Commission's own FAQ, dated 24 July 2026, is more forgiving than the coverage suggests, and one exemption in particular takes most content publishers out of scope entirely. Here is how to work out which of the four applies to you.
First question: are you the provider or the deployer?
The Act splits duties between the party that puts the system on the market (the provider) and the party that uses it in a professional context (the deployer). Most small companies are deployers of someone else's model and providers of their own product at the same time, which is why the roles confuse people. Four setups, sorted:
- You built a support chatbot on top of a hosted model API and put it on your site. You are the provider of that AI system as placed on your market. The direct-interaction disclosure is yours to make, not your model vendor's.
- You use a text-to-image tool to make product shots. The tool's maker is the provider and owes the machine-readable marking. You are the deployer, and your duty attaches only if the output is a deepfake in the Act's sense.
- You publish AI-drafted articles on your company blog. Deployer, and the public-interest text rule is the one to read, along with the editorial-review exemption below.
- You resell a white-labelled AI assistant under your own brand. Putting your name on it generally puts you in the provider seat. Get this one checked rather than assumed.
The four duties, and what each one actually requires
1. Tell people they are talking to a machine. Article 50 requires providers of systems intended to interact directly with people to inform them, "unless this is obvious from the point of view of a natural person who is reasonably well-informed." The Commission FAQ says this covers chatbots, AI agents and avatars designed for a "genuine two-way exchange," and the notice must come "from the start of the first interaction in a clear and distinguishable manner." In practice: one line in the opening message, not a link to a policy page. The "obvious" carve-out is judged against an average, reasonably informed person, so do not lean on it for an assistant with a human first name and a photograph.
2. Mark generated media in machine-readable form. Providers of systems producing synthetic audio, image, video or text must mark outputs "in a machine-readable format and detectable as artificially generated or manipulated," using solutions that are effective, reliable, robust and interoperable as far as technically feasible. No specific standard is named. The Commission's Code of Practice on transparency of AI-generated content, final on 10 June 2026, deliberately declines to mandate one. If you generate media through a third-party tool, this duty sits with them; your job is to stop stripping their metadata, which most image pipelines do by default on resize and re-encode.
3. Label deepfakes visibly. Deployers must disclose on first exposure, "in a clear and distinguishable manner," using visible or audible labels understandable without technical tools. The FAQ sets three cumulative conditions for content to count: it resembles existing people or things, it appears authentic, and it is capable of deceiving someone about its truthfulness. Artistic, satirical or fictional works need only appropriate disclosure that does not impair enjoyment of the work. A synthetic presenter in an ad reading a script is caught. A stylised illustration is not.
4. Disclose AI-generated public-interest text, unless a human owns it. This is the duty most publishers assume will bite them, and it is the one with the widest exemption.
The exemption worth reading twice
Text published to inform the public on matters of public interest does not require an AI label where it has undergone human review or editorial control. The FAQ defines both terms rather than leaving them to argument. Review means "deliberate examination by one or more natural persons possessing relevant knowledge." Editorial control means someone holds the authority to "approve, alter or reject" the content substantively. It states explicitly that spell-checking alone does not qualify.
Read as an operating instruction, that is a staffing and record-keeping requirement rather than a labelling one. A named person with subject knowledge must actually be able to reject a piece, and you should be able to show who that was for any given article. If your process is a model drafting and a person skimming for typos, you are outside the exemption and the label is owed. This mirrors the test Google applies for a different purpose in its scaled content abuse policy, where the question is also whether a knowledgeable human added something rather than whether a machine was involved.
What the fines actually cap out at for a small company
Article 99 puts Article 50 breaches in the middle tier: up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher. That is where the alarming headline number comes from, and for a large company it is the right one to quote. For a small one it is not, because Article 99 also states that for SMEs and start-ups each fine is capped at the percentage or the amount, whichever is lower.
Run our arithmetic on a company turning over 2 million euro a year. The general rule would take the higher of 15 million euro and 3% of turnover, which is 15 million euro. The SME rule takes the lower, which is 3% of 2 million euro, or 60,000 euro. Same breach, a difference of more than two orders of magnitude, decided entirely by a clause most summaries skip. Sixty thousand euro is still a bad quarter, and the Commission notes proportionality is considered for SMEs and small mid-cap companies, so treat that figure as a ceiling rather than a forecast.
Ship these four things before 2 August
- A first-message line in every conversational surface. Something on the order of "You are chatting with an automated assistant." In the first message, in the same language as the interface, not behind a tooltip.
- A metadata check on your image and audio pipeline. Generate one asset, run it through your full publishing path, and inspect the file at the far end. If the provenance metadata your generator wrote is gone by the time it reaches your CDN, fix the step that strips it.
- A visible label rule for synthetic people. Write down which of your outputs meet the three deepfake conditions, and where the label goes on each format. Ads, product videos and social clips need different placements.
- A reviewer record for published text. One field in your CMS naming the human who approved each piece, plus a note of the knowledge that qualifies them. This is the artefact that operationalises the exemption, and it costs nothing until you need it.
Two limits to keep in view. The Code of Practice is voluntary, and signing gives you the ability to rely on its measures to demonstrate compliance rather than arguing adequacy to a market surveillance authority yourself. And the AI Act is one of several rulebooks now reaching into ordinary product decisions from outside your company; the useful habit is not tracking each one but knowing which of your features would need rebuilding if a rule landed, which is the point of a dependency audit. Start with the chatbot line. It is a sentence, and it is the duty most likely to be missed by a team that never thought of itself as an AI provider.
Discussion
Sign in with Google or just a name. No email link, no password to remember.