Today, 2 August 2026, Article 50 of the EU AI Act starts to apply. It sets no size threshold whatsoever: a two-person hair salon is caught by it exactly as a listed company is. You are about to read a great deal of advice telling you that every piece of AI-produced content now needs a label. That is wrong, and the text says so plainly. Here is the sorting: what genuinely binds you, what does not, and the half hour of work that puts you right.
What actually starts today
The AI Act has been phasing in since 2024. The 2 August 2026 milestone is the one for transparency obligations, gathered in Article 50, together with the penalty powers that back them.
The principle fits in a sentence: a person must not be misled about the fact that they are talking to a machine, or looking at something a machine fabricated. This is not a regulation of AI in general. There is no licence to apply for, no file to submit. It is a disclosure duty, in specific situations.
The rest of the regulation — the so-called high-risk systems, with their conformity assessments and heavy documentation — does not apply to you, and has in any case been pushed back. If you sell bread, cut hair or wait tables, you are not operating a high-risk system.
Provider or deployer: the distinction that settles everything
This is the point most coverage skips, and it is the one that determines what you have to do.
The regulation distinguishes two roles. The provider develops the AI system and places it on the market under its own name: OpenAI, Google, Mistral, Adobe, whoever builds your chat software. The deployer uses that system under its own authority in the course of a professional activity: you.
That distinction has a very concrete and very reassuring consequence. The most technical duties in the text fall on providers, not on you. Machine-readable marking of generated content — the invisible watermark, provenance metadata, the detectable fingerprint — is Article 50(2), addressed to providers of generative AI systems. You do not have to engineer a watermark. That is OpenAI's job, not yours.
What falls to you as a deployer is far simpler: inform people, in plain language, in four situations.
The four cases for a small business, sorted
1. The chatbot or assistant on your site — mandatory
This is the common case, and the only one that touches most small businesses. If your site shows a chat bubble, a booking assistant, or an agent answering questions about your opening hours or your menu: the visitor must know they are addressing an AI.
The text does carve out an exception where this is "obvious" to a reasonably well-informed person. Do not bet on it. A well-built widget, with a natural tone and a friendly first name, is precisely what makes the thing non-obvious. The disclosure costs one line; arguing about obviousness costs more.
Placement matters as much as wording. Article 50(5) requires the information to be clear, distinguishable, and provided at the latest at the first interaction. In practice: the disclosure must be visible before or with the first message, not at the foot of a terms page nobody opens.
Here is a wording that satisfies all three conditions, to adapt:
<div class="chat-intro">
<p><strong>Automated assistant</strong> — you are talking to an
artificial intelligence, not to a member of our team.</p>
<p>To reach a person: <a href="tel:+441234567890">01234 567890</a></p>
</div>
The second line is not required by the regulation. Put it in anyway: offering a human exit is what turns a legal notice into a commercial argument.
2. Generated photos and video — the real trap
Here the Article 50(4) duty does land on you as a deployer, and the subject is trickier than it looks.
The regulation targets what it calls deep fakes: AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and that would falsely appear to be authentic. When you publish one, you have to disclose that it was artificially generated.
The clear cases first. A generated photo of your shopfront, your dining room, your team, a smiling customer or a craftsperson at work who does not exist: that is exactly what the text is aimed at. A video where a synthetic avatar speaks in place of a member of your staff: same.
The grey case next, and I would rather tell you honestly than rule in a judge's place: a fully generated product or dish image, depicting no identifiable place or person, sits in a zone that neither the regulation nor the early guidance resolves cleanly. A visibly stylised, illustrative graphic that nobody would mistake for a photograph is defensible; a photorealistic image of a plate you do not serve, far less so.
And on that last point, the AI Act is not even your main problem. Consumer protection law across the EU already prohibited illustrating an offer with a misleading image, long before anyone mentioned AI. A generated photo of a dish you do not sell is a misleading commercial practice, AI or no AI. The common-sense rule has not changed: do not illustrate what you do not sell.
The disclosure, where it is required, is four words under the image: Image generated using AI. It has to be perceptible to a human — a caption, an overlay, an adjacent note. Metadata alone will not do, since nobody reads it with the naked eye.
Worth doing anyway, even though it is not your obligation. An IPTC standard lets you declare an image's origin in its metadata, through the DigitalSourceType field: trainedAlgorithmicMedia for a fully generated image, compositeWithTrainedAlgorithmicMedia for a composite. Most generators already write it for you; the trap is elsewhere — a simple resize or format conversion silently strips that metadata. It does not replace the visible disclosure, but it is the tidy move, and it is what search engines and platforms are starting to read.
3. AI-written copy — no, this does not apply to you
Here is the good news, and the reason to be sceptical of much of what is being written this week.
Article 50(4) does require AI-generated text to be disclosed, but only where it is published for the purpose of informing the public on matters of public interest — the Commission cites politics, justice, public health, environmental protection. This is disinformation policy, not marketing-copy policing.
Your product descriptions, your menu, your about page, your newsletters, your trade blog posts: no disclosure required. They are not matters of public interest within the meaning of the regulation.
And even inside the covered field, the obligation falls away where the text has had human review and a person holds editorial responsibility for publishing it. That is the exact description of what you do when you read something before publishing it. One caveat: the Commission specifies that editorial control means substantive examination by someone competent, with the authority to approve or reject. Running a spellchecker does not count.
In short: write with AI, review it, own it, publish it. Nothing to display.
4. Cameras that read your customers — mandatory, and never mentioned
This case touches only a minority of businesses, but it is the most overlooked, and it is the one where a failure is visible.
Article 50(3) requires the deployer of an emotion recognition or biometric categorisation system to inform the people exposed to it. Those functions are now slipping into equipment sold as ordinary: "smart" footfall counters, advertising screens that estimate the age or mood of passers-by, video-based crowd analytics.
If such a device is running on your premises, signage is mandatory — and it sits on top of your data protection duties, which remain fully in force. If in doubt, put the question to your installer in writing: does this device estimate the age, gender or emotional state of individuals? The answer doubles as evidence of diligence.
The thirty-minute checklist
- Take inventory. List everything on your site and on your premises that produces content or converses automatically: chatbot, smart form, booking assistant, voice agent, interactive screen, analytics camera. Most small businesses find between zero and two items. That is normal.
- Deal with the chatbot. If you have one, check the disclosure appears before the first message. If your vendor's widget does not show it, ask them in writing to add it, and put it in place yourself in the meantime.
- Review your imagery. Find generated images that could pass for photographs of your premises, your team or real people. Add "Image generated using AI" as a caption, or replace them with real photographs — often the better call, AI or not.
- Leave your copy alone. Genuinely. Just keep reading what you publish before it goes out.
- Question your installer if any equipment films or counts your customers.
- Write down what you did in a three-line file, with the date. Under scrutiny, a written record of your reasoning beats undocumented perfection.
One further duty is worth knowing, because it predates this deadline and tends to be discovered on the occasion: Article 4, in force since February 2025, requires businesses using AI to ensure a sufficient level of AI literacy among their staff. For a small business this does not mean a certified training programme. It means the person using ChatGPT to draft your posts understands what the tool can invent and what customer data must never be pasted into it. A one-page internal note is enough to evidence that.
Three things you will be told that are wrong
"You have to watermark all your AI content." No. Machine-readable marking is a provider obligation, Article 50(2). You are not a provider. In some cases you owe a human-readable disclosure — an entirely different and far simpler thing.
"Small businesses are exempt." No. There is no headcount or turnover threshold for Article 50. What exists for SMEs is a softer penalty regime: the applicable cap is the lower of the two figures, and authorities must take size and economic viability into account.
"There's a reprieve until December anyway." Watch this one, it is circulating widely. An additional period, to 2 December 2026, was indeed negotiated — but it covers only the Article 50(2) machine-marking obligation, only for systems already on the market, and therefore only providers. The chatbot disclosure applies today, with no deferral. That extension also rests on an agreement still being formally finalised: it is not something to build a defence on.
Who enforces this, and should you worry
Let us be factual in both directions.
The penalty ceiling for an Article 50 breach is 15 million euros or 3% of annual worldwide turnover, with the SME tempering noted above. The figure is startling; it was plainly not calibrated for a bakery.
Enforcement runs through national market surveillance authorities, and the picture is uneven. Several member states, France included, have not completed the legal designation of the bodies that will supervise this — in France the proposed split gives coordination to the DGCCRF, with the CNIL on personal data and biometrics, alongside sector regulators, but the scheme still awaits adoption. The regulation itself is directly applicable and binds you from today; the enforcement machinery, in a good many countries, is not yet at battle stations, and its first resources will go to high-risk systems rather than to corner-shop chat bubbles.
So no, there is no cause for panic. And yes, there is still a reason to do it this week: it takes thirty minutes, it saves you revisiting it under pressure in a year, and an honest chatbot disclosure has never driven a customer away. Everyone who put these notices up ahead of the deadline reports the opposite effect: telling a customer they are talking to a machine, and giving them a number to reach a human, raises trust rather than lowering it.
Frequently asked questions
Do I have to label text on my site that was written by AI?
In the vast majority of cases, no. Article 50(4) only catches AI-generated text published to inform the public on matters of public interest — politics, justice, public health, environmental protection. A product page, a menu, an about page or a trade article does not qualify. The obligation also falls away where there has been human review and someone holds editorial responsibility, which is the case when you approve before publishing.
Does my chatbot need a disclosure if a vendor supplies it?
In practice, yes. The duty to design the system so people are informed sits first with the provider, but it is on your site that the visitor must be informed. Check the widget shows it; if not, add it. It must be clear and visible at the latest at the first interaction — not buried in your terms.
Do I need to watermark AI-generated images?
Not you. Machine-readable marking is Article 50(2) and aimed at providers of generative systems. What can apply to you is Article 50(4): a human-readable disclosure on generated images or video that would pass as an authentic photograph of your premises, your products or real people.
Are small businesses exempt?
No. No headcount or turnover threshold applies to Article 50: the duties bite from the first relevant use. What the regulation provides for SMEs is a more favourable penalty cap — the lower of the two figures — and consideration of the size and economic viability of the business.
What does a small business actually risk by doing nothing?
The theoretical ceiling is 15 million euros or 3% of worldwide turnover, with proportionality for SMEs. Near-term risk to a local business is low: designation of national authorities is incomplete in several countries and their resources will go to high-risk systems first. The real argument is not the fine, it is the effort-to-benefit ratio: half an hour of work, and a signal of seriousness to your customers.
Running a chatbot, a booking assistant or generated imagery on your site, and want it clean without losing your Sunday to it? Drop me a line: I review your site, tell you what genuinely falls under Article 50 in your case, and put the disclosures where they belong — visible, understated, without wrecking your design. It is the least glamorous side of my work on AI for local businesses, and probably the fastest to pay for itself.