Back to blog
7 min read

The AI Transparency Rules Are Now Live. Here Is Your Checklist.

EU AI Act Article 50 is in force since 2 August 2026. A practical checklist for small businesses using AI chatbots, AI-written content or AI images.

The AI Transparency Rules Are Now Live. Here Is Your Checklist.

The chat widget on your website answered a customer at 09:14 last Saturday morning. If it never mentioned that it was an AI, that reply — however helpful — was the first one your business sent under a law it may be breaking. On 2 August, the transparency chapter of the EU AI Act, Article 50, became enforceable across the EU, with fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, according to analysis by law firm Kingsley Napley. The good news: for most small businesses, compliance is a week of tidy-up work, not a legal project. Here is the checklist, written two days after the rules went live.

What actually changed on 2 August

Article 50 does four things, and legal summaries from Morgan Lewis and Kingsley Napley agree on the shape. People must be told when they are interacting with an AI system, such as a chatbot. AI systems that generate audio, images, video or text must mark their output in a machine-readable way so it can be detected as artificial. Anyone deploying emotion-recognition or biometric-categorisation systems must inform the people exposed to them. And deepfakes, plus AI-generated text published to inform the public, must be visibly disclosed. National authorities now supervise all of this. If you followed the AI Act news earlier this year, note the contrast: the Digital Omnibus pushed the Act's high-risk obligations back to December 2027 — as we covered in June — but the transparency rules kept their date. This is the part of the law that actually applies to you now.

First, work out which hat you wear

The Act splits duties between "providers" — those who build or offer AI systems — and "deployers" — those who use them. A small business is almost always a deployer: you didn't build the chatbot, you subscribed to it. That matters, because the heaviest technical duty — machine-readable marking of AI output — sits with the model providers, and roughly 190 organisations signed a voluntary Code of Practice on transparency of AI-generated content in July. Your duties are the visible ones: disclosure and labelling. So start with a fifteen-minute inventory. Write down every place AI touches a customer or the public: the website chat, the phone assistant, AI-written newsletters and blog posts, AI-generated product photos or social videos. Each item on that list gets one of the checks below.

Your chatbot must say it is a chatbot

The rule, per the Act's implementation guidance, is that people must be informed they are talking to an AI at the latest at the first interaction, in a clear and distinguishable way. There is an exemption when it is "obvious" to a reasonably informed person — but lawyers consistently advise not to lean on it, because what is obvious to you is not obvious to a seventy-year-old customer at 11 PM.

Do this now. Rename the widget from "Sofia" to "Sofia — AI assistant" or similar, and have its first message say plainly that it is automated and how to reach a human. Vague wording, small grey print or a disclaimer that flashes once do not meet the standard, according to guidance summarised on the AI Act portal artificialintelligenceact.eu. If your chatbot answers the phone or WhatsApp, the same applies there — a spoken "you're speaking with our AI assistant" at the start of the call. Then screenshot the disclosure and file it; being able to show compliance is half the value.

Label what AI made — text, images, video

Marketing images and video. Content that shows real people, places or events in a way that didn't happen — the Act's definition of a deepfake territory — must be clearly disclosed as AI-generated or manipulated. A visible caption such as "image generated with AI" does the job. Purely illustrative AI images (an abstract banner, a generated background) sit lower on the risk ladder, but a label costs you nothing and builds trust while the standardised EU mark — a proposed "AI/KI/IA" label is in development — takes shape.

Blog posts and newsletters. Here the Act is more forgiving than the headlines suggest. AI-drafted text only requires disclosure when it is published to inform the public on matters of public interest and no human took editorial responsibility. If you review, edit and sign off what the model drafts — which you should be doing anyway — you are outside that duty. A grammar checker or translation pass counts as assistive editing and is explicitly out of scope.

Customer documents. Quotes, order confirmations and support replies a human reviews are not the target of this rule. The target is publishing machine output as if a person wrote it, on topics where the public is being informed.

What you can leave for later

Three things on the worry list can come off it. The provider-side machine-readable marking duty has a grace period until 2 December 2026 for systems already on the market before 2 August, Morgan Lewis notes — and it is your vendor's job, not yours; your only task is to prefer tools from providers that committed to marking. The high-risk regime — CV screening, credit scoring and the rest of Annex III — now applies from 2 December 2027 under the Digital Omnibus, per Gibson Dunn's analysis. And emotion recognition or biometric categorisation is something almost no small business runs; if a vendor ever pitches you software that claims to read customers' emotions, treat the compliance duty as one more reason to say no.

When this isn't worth panicking over

Keep the risk in proportion. Enforcement began days ago; national authorities will look first at large platforms and at deliberate deception, not at a bakery in Ghent whose chatbot greeting was a week late. The 3%-of-turnover ceiling is a maximum for serious cases, not the starting tariff. And transparency was already the market's direction — customers increasingly assume chat widgets are AI, and a business that says so plainly tends to gain trust rather than lose sales. What you should not do is nothing: the fixes above are cheap, visible and permanent, and the same inventory you build for Article 50 becomes the backbone of every AI Act duty that follows it.

This week: list where AI meets your customers. Next week: fix the chatbot disclosure and add labels to AI-generated visuals. This month: ask your chatbot and content vendors, in writing, how they handle machine-readable marking. If that inventory raises the bigger question of which AI tools your business should even be using, Cresly's AI Readiness Scan maps how AI fits your processes — including which transparency duties come with each use — so compliance and opportunity end up on the same page.

EU AI ActArticle 50transparencycompliancechatbotsSME
C
The Cresly Team
AI Studio for European Businesses