DxtraBETA
Back to blog
GuidesEuropean UnionSmall BusinessRegulations August 2026 8 min read

Your chatbot has to say it's AI now: the EU AI Act rules that kicked in on 2 August

The EU AI Act's transparency obligations became applicable on 2 August 2026. If your small business uses an AI chatbot or publishes AI-generated content and sells into the EU, here's what changed — and the five things to do this week.

An EU AI Act document — Regulation (EU) 2024/1689, Article 50 — standing on a warm desk beside a chat window labelled 'You're chatting with our AI assistant' and a photo card tagged AI-generated.

On 2 August 2026, a new set of EU AI Act obligations became applicable — and unlike most of the AI Act, these ones are aimed squarely at things small businesses actually do. If there's an AI chatbot answering questions on your website, if you generate product images or marketing copy with AI, or if AI writes any of the content you publish, the transparency rules now apply to you whenever you're serving customers in the EU.

And no — the delay you may have read about doesn't save you. Brussels did just postpone part of the AI Act, but only the high-risk regime. The transparency rules were expressly kept on the 2 August date; more on that below.

The AI Act doesn't just regulate Big Tech. It reaches you in much the same way the GDPR does — what matters is that your AI system's output is used by people in the EU, not where your business sits — and it has no small-business exemption from the transparency duties.

Wait — the AI Act applies to me?

Probably, yes, if two things are true: you use AI in a way your customers encounter, and some of those customers are in the EU.

You don't need an EU office. A Shopify store in Kuala Lumpur, a design studio in Melbourne, or a SaaS tool in Austin that serves EU customers is in scope, much as it would be under the GDPR. And "using AI" is broader than building it — most small businesses are deployers (they use someone else's AI system, like a chatbot widget or an image generator) rather than providers (they build or rebrand one). Deployers have fewer duties, but from 2 August 2026 they have real ones.

What actually changed on 2 August

The AI Act has been phasing in since 2024: bans on the worst practices arrived in February 2025, and obligations for general-purpose AI models (the GPTs, Claudes and Geminis of the world) in August 2025. The 2 August 2026 milestone is the big one — it's when most of the Act's remaining obligations became applicable, including Article 50, the transparency obligations. In plain language, Article 50 says four things:

1. People must know when they're talking to a machine. If your website runs an AI chatbot or voice assistant, users have to be informed they're interacting with AI — unless it's obvious from context. A chat window that behaves like a human agent, uses a human name, and never says otherwise no longer passes. Formally this is a design duty on your chatbot's provider — but you're the one facing the customer, so make sure the label actually shows up in your chat window.

2. AI-generated content must be machine-detectable. Providers of generative AI systems have to mark their outputs (images, audio, video, text) in a machine-readable way. As a small business this mostly lands on the tools you use — but it's a reason to choose tools that do this properly. (One narrow transition applies: systems already on the market before 2 August 2026 have until 2 December 2026 to implement the technical marking. A new tool you adopt today must mark from day one.)

3. Deepfakes must be labelled. If you publish AI-generated or AI-manipulated images, audio, or video that looks real — a synthetic spokesperson, an AI voice-over that sounds like a person — you must disclose that the content was artificially generated or manipulated.

4. AI-written text on matters of public interest must be disclosed. If you publish AI-generated text to inform the public on matters of public interest, you must say so — unless a human has reviewed it and someone takes editorial responsibility. For most businesses publishing ordinary marketing content, the human-review carve-out will do a lot of work. It only works, though, if a human actually reviews.

Now, about that delay. In late July 2026 the EU's Digital Omnibus package became law — Regulation (EU) 2026/1744 — and it did postpone a chunk of the AI Act: the high-risk system regime, which for most stand-alone systems now applies from 2 December 2027, and from 2 August 2028 for AI embedded in regulated products. That regime is a different, and for most small businesses irrelevant, part of the law. The transparency duties above were expressly left on 2 August 2026. In other words: the EU delayed the AI Act — just not the part that applies to you.

What this looks like in practice

For a typical small business, compliance is less frightening than the legal text suggests:

  • Chatbot on your site? Add a clear line in the chat interface: "You're chatting with our AI assistant." Do it in the interface itself, at the start of the interaction — not buried in your terms.
  • AI product images or ad creative? Ordinary AI-assisted marketing images generally just need the machine-readable marking your tool applies. But anything that could be mistaken for a real person or real event needs a visible label.
  • AI-drafted blog posts and emails? Put a human editor in the loop and keep evidence that you did. If nobody reviews, disclose.
  • AI voice on your phone line? Same rule as the chatbot: callers must be told.

And write it down. The pattern regulators reward, under the AI Act as under the GDPR, is being able to show what you use, what it does, and what you told people.

What it costs to ignore

Breaching the transparency obligations can draw fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher — although for SMEs the Act applies whichever is lower, one of its few genuine small-business concessions. The more realistic near-term risk for a small business isn't a headline fine; it's a complaint, a regulator letter, and the scramble that follows. The businesses that suffer most in those scrambles are the ones with nothing written down.

The part nobody tells you: this is a privacy job too

Your chatbot doesn't just need a disclosure — it collects personal data. Names, emails, order numbers, sometimes health details people volunteer without being asked. That means your existing privacy obligations run right alongside the new AI ones: the conversation data needs a lawful basis, a retention answer, and a mention in your privacy notice (what US readers usually call a privacy policy). The AI Act's transparency rules and the GDPR's transparency rules are two halves of the same promise: people should know what's happening with them and their data.

That's also why the sensible move is to handle both in one place, not bolt an AI disclaimer onto an outdated notice.

The AI-powered shortcut

This is exactly the gap Dxtra was built for — and yes, we're aware of the irony of an AI-powered platform explaining AI disclosure rules. It's also why we take this seriously: disclosing AI use is something we do ourselves.

Dxtra generates and maintains your privacy notice with AI (setup in about ten minutes; generation takes up to an hour), maps your obligations across regimes including the GDPR, and — through its AI & Data Use Governance capability — helps you document where AI touches personal data in your business. Your public-facing Transparency Center, hosted on your own subdomain, gives you a single place to tell customers what AI you use, what data it sees, and what rights they have — with 75 languages to choose from (plans include English plus one to ten), which matters if you're selling across the EU. Plans start at $10/month, with a 14-day money-back guarantee on the START plan.

Not sure where you stand today? Run the free privacy scan — it reads your site the way a regulator would, including your cookie and tracker behaviour, and returns a risk band with cited findings. No account needed.

Five things to do this week

1. Inventory your AI. Chatbot, image tools, writing tools, voice systems. One list, one owner.

2. Label the chatbot. In the interface, at the start of the conversation, in plain words.

3. Check your content pipeline. Human review for AI-drafted text, visible labels for anything that could pass as real.

4. Update your privacy notice. The data your AI tools collect belongs in it.

5. Put it somewhere customers can see. A Transparency Center — or at minimum a clear page — beats a buried PDF.

Common mistakes to avoid

  • Assuming "we're too small." There is no small-business exemption from Article 50.
  • Assuming "we're not in the EU." Scope follows your customers, not your address.
  • Disclosing in the terms of service. Disclosure has to be clear at the point of interaction, not discoverable by a determined lawyer.
  • Confusing the high-risk delay with the transparency rules. The delay is real — to December 2027 — but it does not touch these transparency duties.
  • Treating this as separate from privacy. One transparency story, told once, kept current, beats two half-maintained ones.

Sources

Current as of 5 August 2026. Commencement dates, fine levels and guidance move; check the linked source before you rely on any of them.

This article is general information, not legal advice. Rules change; confirm anything that matters with your national data protection or market-surveillance authority, the European Commission's AI Office, or a qualified adviser before you rely on it.

Ready to get ahead of it?

The businesses that handle new regulation well are rarely the ones with the biggest budgets — they're the ones that start before the letter arrives. Get started with Dxtra from $10/month, or take the product tour to see the Transparency Center and AI & Data Use Governance in action.

Ready to get compliant?

Start your privacy program today — from $10/month.