If your business runs a chatbot or publishes AI-generated content, you are now legally required to tell people. The EU AI Act's transparency obligations under Article 50 came into force on August 2, 2026. They apply to every business operating in Europe, regardless of size. The fine for breaking Article 50's transparency rules reaches up to EUR 15 million or 3% of your global annual turnover. For a large company, the rule is whichever of those two figures is higher. For small businesses and startups, Article 99(6) reverses it: you pay whichever is lower. The compliance conversation has mostly happened inside corporate legal teams. This article is for the ten-person service business.
What does Article 50 actually require my business to do?
Four concrete obligations sit inside Article 50. Which ones apply to you depends on the AI tools you already use.
First, if your business runs a chatbot (on your website, in WhatsApp, anywhere a customer types a message and an AI replies), that system must tell users they are talking to an AI. It must do this at or before the first interaction, not buried in a terms page. The exception is narrow: the law's test is whether it would be obvious to a reasonably well-informed, observant, and circumspect person that they are talking to an AI. A customer service assistant that sounds and writes like a human does not clear that bar.
Second, if you use AI to generate audio, images, video, or text and you publish that content, the output must carry a machine-readable mark identifying it as artificially generated. The Omnibus regulation that passed in June 2026 gave providers until December 2, 2026 to implement the technical marking solutions, but the obligation to label AI-generated content is live now.
Third, deepfakes (AI-manipulated images, audio, or video of real people) and AI-written text published to inform the public on matters of public interest must carry a visible disclosure. Artistic works are exempt, and editorial review can reduce the obligation for some media content, but standard AI-generated marketing articles and AI-voiced videos do not qualify.
Fourth, if you use any tool that analyses employees' or customers' emotions, or that categorises people by sensitive characteristics using biometric data, you must inform the people being analysed. Most small businesses are not running emotion-recognition tools, but it is worth checking if any staff-monitoring or customer-analytics SaaS you use has AI features in this category.
Does this apply to my business if I am not based in the EU?
The EU AI Act follows the same extraterritorial logic as GDPR. The trigger is where your AI output is used and whether your product or service reaches the EU market, not where your business is registered. A Swiss business with EU clients, a UK agency producing AI content for EU publications, a US software company selling an AI tool to European buyers: all are in scope.
There are no AI-Act-specific bilateral agreements that exempt Swiss, UK, or US businesses. The UK operates its own separate, principles-based AI governance framework, distinct from the EU AI Act. Switzerland has no domestic equivalent AI law. The US has no federal AI Act. None of that changes what the EU Act requires of any business with EU-market activity. One obligation is specific to non-EU companies: Article 22 requires providers of high-risk AI systems established outside the EU to appoint an authorised representative within the EU before placing those systems on the market. For most small businesses whose AI obligations sit at the Article 50 transparency level, Article 22 does not apply.
What about all the scary headlines from a year ago about the EU AI Act?
The story changed in June 2026. A simplification package called the Digital Omnibus on AI received final EU Council approval on June 29, 2026, and it pushed the heavy compliance regime back by 16 months. The rules that would have required detailed risk assessments, human-oversight systems, and conformity certifications for AI systems classified as high-risk were originally due August 2, 2026. They are now due December 2, 2027 for standalone AI systems, and August 2, 2028 for AI embedded in regulated products.
What the Omnibus did not move: Article 50. The transparency obligations were specifically left on the August 2, 2026 date. The headline news was that the big compliance crunch got pushed back. The small-print news was that the rule most likely to catch a small business stayed exactly where it was.
EU AI Act: What is in force now, and what has been delayed
| Obligation | Who it catches | Status | Fine (max) |
|---|---|---|---|
| Prohibited practices (Art. 5) | Everyone. Social scoring, manipulative dark patterns, employee emotion recognition. | In force since Feb 2025 | EUR 35M or 7% of turnover, whichever is higher (Art 99(3)) |
| AI literacy (Art. 4) | Every org using AI, all staff involved. | In force since Feb 2025 | EUR 15M or 3% of turnover, whichever is higher (Art 99(4)) |
| Transparency (Art. 50) | Anyone running a chatbot, publishing AI content, or using deepfake tools. | In force since Aug 2, 2026 | EUR 15M or 3% of turnover, whichever is higher (Art 99(4)) |
| High-risk standalone systems (Annex III) | Insurance, healthcare, education, HR, credit scoring tools. | Delayed to Dec 2, 2027 | EUR 15M or 3% of turnover, whichever is higher (Art 99(4)) |
| High-risk embedded systems (Annex I) | AI as a safety component in regulated products. | Delayed to Aug 2, 2028 | EUR 15M or 3% of turnover, whichever is higher (Art 99(4)) |
Two separate fine tiers exist, and it matters which one applies to you. The EUR 35M / 7% tier is only for banned practices under Article 5: things like social scoring, manipulative AI, and certain biometric surveillance. The EUR 15M / 3% tier covers everything else, including Article 50 transparency. That second tier is the one relevant to almost every small business. In both tiers, the rule for a large company is whichever of the two figures is higher. For small businesses and startups, Article 99(6) reverses that: you pay whichever is lower.
My business is tiny. Do these rules still apply to me?
There is no size exemption from the substantive obligations. Every business that runs a chatbot or publishes AI content must comply with Article 50, whether it has 5 employees or 500. Size only affects how the fine is calculated.
So which tier are you? The law uses the EU's standard SME definition, drawn from Commission Recommendation 2003/361/EC. You are an SME if you have fewer than 250 employees and either an annual turnover of EUR 50 million or less, or a balance sheet total of EUR 43 million or less. The headcount ceiling is a hard limit: you must be below 250. The financial test is an either/or: meet one of the two financial thresholds, and you pass. Above those numbers, you are a large enterprise. For a large enterprise, the fine is whichever of the fixed ceiling or the percentage of turnover is higher. For an SME or startup, Article 99(6) reverses that: you pay whichever is lower. One wrinkle: if your business is owned or majority-controlled by a larger group, that group's headcount and turnover may count toward your totals, so a small subsidiary of a big company may not qualify as an SME.
Here is a concrete example. A business with EUR 500,000 in global annual turnover: 3% of that is EUR 15,000. The fixed ceiling for the Article 50 transparency tier is EUR 15 million. Because EUR 15,000 is lower than EUR 15 million, that is the cap for this business. It is still real money, and national regulators are beginning enforcement, but it is not a number that ends a small business.
What do I actually need to do this week?
First, audit every AI touchpoint your customers interact with. Your website chatbot. Your WhatsApp business replies if they use AI. Your customer support tool if it drafts responses automatically. Any of these that send AI-generated replies need to identify themselves as AI at the start of each conversation.
Second, review your content. If you publish blog posts, social copy, or email newsletters written by AI, those need to be labelled. The label does not need to be alarming: a brief 'written with AI assistance' note meets the requirement, but it needs to be visible, not hidden in footer text.
Third, write down what you did. Regulators respond better to documented good-faith effort than to verbal assurances. A one-page record of the AI tools you use, what they do, and what disclosures you have added is the most useful thing you can produce right now. If a regulator ever asks, that record is your defence.
How do I know if my business counts as an SME for the lower-fine rule?
The EU AI Act uses the EU's standard SME definition from Commission Recommendation 2003/361/EC. You qualify as an SME if you have fewer than 250 employees and either an annual turnover of EUR 50 million or less, or a balance sheet total of EUR 43 million or less. The headcount ceiling is a hard limit. The financial test is an either/or: meet one of the two financial thresholds and you pass. Above those numbers, you are a large enterprise and face the higher-fine rule. One exception: if your business is owned or controlled by a larger group (25% or more of capital or voting rights), the group's figures may count toward your totals. A small subsidiary of a large company may not qualify as an SME even if it looks small on its own.
Does the EU AI Act apply to me if I just use ChatGPT or Claude for internal work?
If the AI is genuinely internal (you use it to draft documents, summarise emails, or help your team think) and its outputs never reach customers or the public, Article 50's transparency rules do not apply. The obligation kicks in when the AI interacts with or produces content for people outside your organisation. AI literacy obligations under Article 4 do apply to internal use, but those require training and documentation, not external disclosures.
I use a third-party chatbot platform on my website. Is it the platform's responsibility, or mine?
Yours. Under the EU AI Act, the deployer (the business that puts the tool in front of customers) carries the transparency obligation, even if a third-party vendor built and hosts the underlying system. The fact that you are running Intercom, Tidio, or another tool does not shift the obligation. Check your platform's settings for disclosure features; most now provide a built-in 'This is an AI assistant' message you can activate.
What is the deadline for labelling AI-generated images and videos?
The underlying obligation to label AI-generated audio, image, and video content is live since August 2, 2026. Providers of the tools that generate this content have until December 2, 2026 to implement the technical machine-readable marking solutions. In practice, you should add visible labels now: a note on an AI-generated image, an on-screen disclosure on an AI-voiced video.
What about the big compliance requirements I heard about, like risk assessments and conformity assessments?
Those apply to high-risk AI systems, and the deadline for most of them was pushed back to December 2, 2027 by the Digital Omnibus on AI (law since June 2026). High-risk systems include AI used in insurance underwriting, hiring decisions, credit scoring, healthcare triage, and educational assessment. If none of those describe your use case, the heavy regime does not apply to you yet. You have time to prepare.
Is this only an EU thing? What if I am in Switzerland, the UK, or the US?
There are no AI-Act-specific exemptions for Switzerland, the UK, or the US. The trigger is market activity, not nationality: if your AI outputs reach people in the EU, the Act applies regardless of where you are based. The UK operates its own separate, principles-based AI governance framework; Switzerland has no domestic AI equivalent law; the US has no federal equivalent. None of that creates an exemption from the EU Act for EU-market activity. One obligation is specific to non-EU businesses: Article 22 requires providers of high-risk AI systems established outside the EU to appoint an authorised representative within the EU before placing those systems on the market. For most small businesses, whose AI-Act exposure sits at the Article 50 transparency level, this does not apply.
Do I need a lawyer for this?
For most small businesses, the Article 50 requirements are practical, not deeply legal. Identifying your AI touchpoints, adding clear disclosures, and keeping a record does not require outside legal counsel. Where you do need a lawyer: if any of your AI systems might qualify as high-risk (insurance, healthcare, HR, credit), if you are considering placing an AI product on the EU market, or if you have received any regulatory inquiry.
Not sure what your actual exposure is? We run a one-session AI Act Exposure Check: we map every AI tool your business uses, classify each by risk tier, and tell you exactly what disclosures and documentation you need. Most small businesses finish at Article 50. Send us the one AI tool in your business you are most unsure about, and we will start there.