The AI Disclosure Rules That Started on 2 August 2026

Two dials showing different times, one lit and one dark, representing two AI Act deadlines that moved apart

If your business uses a chatbot, publishes AI-written content, or serves customers in the EU, one set of AI Act rules started applying on 2 August 2026. Those are the Article 50 transparency obligations, and they were not delayed. The rules that were delayed — the heavy high-risk compliance regime — mostly never applied to small businesses anyway.

That distinction is the whole story, and most coverage lost it. In July 2026 the EU passed a reform package that pushed several AI Act deadlines into 2027 and 2028. Headlines compressed that into “the AI Act has been delayed.” For a five-person business running a support chatbot, the part that matters was untouched.

Key takeaways

  • Article 50 transparency applied from 2 August 2026. It was deliberately left out of the delay package.
  • High-risk obligations moved to 2 December 2027 (stand-alone systems) and 2 August 2028 (systems embedded in regulated products).
  • Most small businesses are deployers, not providers — and the chatbot-disclosure duty sits mainly with the provider who built the tool.
  • Your real duties are narrower than the headlines suggest: deepfake labelling, emotion-recognition notice, and content published to inform the public.
  • It applies by where your users are, not where you are. A US business with EU customers is in scope.

What Actually Changed in July 2026?

The EU published Regulation (EU) 2026/1744, the Digital Omnibus on AI, in the Official Journal on 24 July 2026. It entered into force three days later, on 27 July. It amends the original AI Act — Regulation (EU) 2024/1689 — rather than replacing it.

The reform postponed the compliance-heavy obligations and left the transparency layer alone. Here is the full set of moved dates.

Obligation Original date New date
High-risk AI, stand-alone (Annex III) 2 Aug 2026 2 Dec 2027
High-risk AI in regulated products (Annex I) 2 Aug 2027 2 Aug 2028
Systems used by public authorities 2 Aug 2026 2 Aug 2030
National regulatory sandboxes operational 2 Aug 2026 2 Aug 2027
Machine-readable marking, Art. 50(2), for systems already on the market 2 Aug 2026 2 Dec 2026
Article 50 transparency, everything else 2 Aug 2026 Unchanged — 2 Aug 2026
Dates as set out in Regulation (EU) 2026/1744 and confirmed in the published analyses listed in Sources. The last row is the one that affects small businesses.

The one-line version: the rules with the audits, the documentation and the conformity assessments moved. The rule that says “tell people it’s AI” did not.

Does This Apply to a Business Outside the EU?

Yes, if your AI system’s output reaches people in the EU. The AI Act follows the same extraterritorial logic as GDPR — scope is set by where the users are, not where the company is incorporated. A Texas consultancy whose website chatbot answers a customer in Dublin is in scope for that interaction.

This catches more small businesses than people expect. You do not need an EU entity, EU staff, or EU billing. A public-facing website with EU visitors is enough to raise the question.

What it does not do is create a registration requirement or a filing. There’s no portal to sign up to. Article 50 is a set of disclosure duties that live in your product and your content, not in a submission to a regulator.

Are You a Provider or a Deployer?

Almost every small business is a deployer: someone who uses an AI system under their own responsibility without having built it. If you licence a chatbot, run it on your site and never touch its model, you are the deployer and the vendor is the provider. That single classification decides most of your obligations.

The distinction matters because Article 50 splits its four duties unevenly between the two roles, and the two that fall hardest on deployers are not the ones that get written about.

Article 50 duty Whose duty Does it hit a typical small business?
50(1) — tell users they’re talking to an AI Provider Rarely. Your vendor builds this in. Verify it is switched on.
50(2) — machine-readable marking of AI output Provider No. This is a duty on the model vendor, not on you.
50(3) — notice for emotion recognition or biometric categorisation Deployer Only if you run such a system. Uncommon, but check any “sentiment” feature.
50(4) — disclose deepfakes and AI content published to inform the public Deployer Yes. This is the one that catches AI-assisted publishing.
Using a third-party model does not by itself make you a provider. Modify or rebrand one substantially and the analysis changes.

One caveat worth stating plainly: roles are per system, not per company. You can be a deployer of your chatbot and a provider of a tool you built and sold on. Most small businesses will be deployers across the board.

What About AI-Written Blog Posts and Social Content?

Article 50(4) covers AI-generated or manipulated text published to inform the public on matters of public interest. That’s a narrower category than “anything AI helped write.” A product description or a marketing email is not a matter of public interest. Reporting, current affairs commentary, and public-health or election-adjacent content are.

The same paragraph also covers deepfakes — synthetic image, audio or video resembling real people, places or events. If you generate a spokesperson’s face or clone a voice for an ad, that requires disclosure regardless of subject matter.

There’s an exemption people miss: where AI output has been through meaningful human review and someone holds editorial responsibility for it, the public-interest text obligation is not intended to bite in the same way. That is a genuine safe harbour for the ordinary case of drafting with AI and editing properly. It is not a licence to publish unreviewed output and claim editorial oversight after the fact.

What Happens If You Ignore It?

Article 50 breaches sit in the AI Act’s middle penalty band — up to €15 million or 3% of worldwide annual turnover, whichever is higher. In practice, a first enforcement wave against a five-person business at that ceiling is not a realistic expectation. Regulators start with scale and harm.

The realistic risk for a small business is duller and more likely: a complaint, a national authority asking questions, and the cost of answering them. Add the commercial risk that an enterprise customer’s procurement questionnaire asks how you comply and you have no answer.

Enforcement is also not instant. Member states had to designate national authorities and build capacity, and the sandbox deadline slipping to 2027 tells you how ready that machinery is. Treat the next year as the window to get tidy, not as a reason to do nothing.

What Should You Actually Do This Month?

For most small businesses this is a 30-minute pass, not a project. The work is inventory and a few lines of copy — closer to writing a privacy notice than to a compliance programme.

Step What you’re checking Time
1. List every AI touchpoint Chatbot, phone agent, email autoresponder, AI in your CRM or helpdesk 10 min
2. Open your chatbot as a customer Does the first message say it’s an AI? If not, switch the setting on 5 min
3. Check for emotion or sentiment features Anything scoring caller mood or facial expression triggers 50(3) 5 min
4. Check synthetic media in ads Generated faces or cloned voices need a visible disclosure 5 min
5. Write down who reviews AI-drafted content One line naming the human editor is your evidence of oversight 5 min
A deployer’s pass. If you build and sell an AI product, you have a longer list and should take advice.

Two of those steps are worth doing regardless of the law. Knowing every AI touchpoint in your business is the same inventory that stops you paying for tools twice — the problem we work through in AI tool sprawl. And naming a human reviewer for AI-drafted content is basic quality control.

If you run a support bot, the disclosure question overlaps with a design question we cover in AI agents for customer service: bots that announce themselves and escalate cleanly perform better on satisfaction than bots that pretend to be people and get caught.

Frequently Asked Questions

Was the EU AI Act delayed?

Partly. Regulation (EU) 2026/1744 postponed high-risk obligations to 2 December 2027 and 2 August 2028. The Article 50 transparency obligations were deliberately left in place and applied from 2 August 2026.

Do I have to label AI-written blog posts?

Only if the text is published to inform the public on a matter of public interest. Ordinary marketing copy, product descriptions and newsletters are outside that category. Content that has genuine human editorial review and an accountable editor is treated differently again.

Does the EU AI Act apply to US businesses?

Yes, where the output of your AI system reaches people in the EU. Like GDPR, scope follows the users rather than the company’s location. No EU entity or EU staff is required for the rules to be engaged.

Am I a provider or a deployer of AI?

If you use a third-party AI tool without building or substantially modifying it, you are a deployer. Buying, configuring and running a vendor’s chatbot does not make you a provider. Roles are assessed per system, so you can hold both.

What are the fines for breaking Article 50?

Up to €15 million or 3% of worldwide annual turnover, whichever is higher. That ceiling is aimed at serious cases at scale; the practical risk for a small business is a complaint and the cost of responding to it.

Do I need to register my chatbot anywhere?

No. Article 50 creates disclosure duties, not a registration or filing requirement. There is no portal for deployers to sign up to and nothing to submit.

The Bottom Line

The reporting got this backwards. The reform that made headlines postponed the obligations least likely to touch a small business, and left standing the one that touches nearly all of them.

The good news is how small the actual duty is. Say it’s a bot. Label synthetic media. Don’t run emotion detection on people without telling them. Keep a human accountable for what you publish. Four sentences, and most businesses already satisfy three of them by accident.

Do the 30-minute pass this month while it’s cheap and voluntary. Then get back to the work that pays — starting with picking tools that earn their place, or the wider payback question in our case studies and ROI hub.

Want one practical automation you can set up in 15 minutes, twice a month? Join the free newsletter.

Sources

All sources retrieved 11 August 2026. This is a plain-English summary for small business owners, not legal advice. Article 50 has exceptions and definitions this post simplifies; if you build or sell AI systems, or operate in a regulated sector, take qualified advice on your specific position.