Skip to content
· 7 min read

AI Act Transparency Obligations: What Applies to Your Chatbot and AI Content from August 2026

Article 50 of the AI Act applies from 2 August 2026. Who must disclose chatbots, mark AI content, and label deepfakes, which exemptions apply, and the audit checklist to run before the deadline.

AIBusiness StrategySmall Business
Share

The AI Act transparency obligations in Article 50 start to apply on 2 August 2026. If your company runs an AI chatbot for EU users or publishes AI-generated content, you must disclose the AI and label the output, or risk fines of up to €15 million or 3% of worldwide turnover.

Most of the businesses these rules catch never thought of themselves as AI companies. A support widget answering customer questions, a product description pipeline, an AI-voiced explainer video: each one triggers a duty under Article 50. On 19 July 2026 the European Commission published guidelines that spell out who must do what, days before enforcement begins. This article breaks down the four obligations, the exemptions that matter for a typical business website, and the audit steps webvise runs on client projects.

  • Article 50 of the AI Act applies from 2 August 2026. Systems already on the market before that date get until 2 December 2026, and only for the machine-readable marking duty.
  • Chatbots and AI agents must tell users they are AI from the first interaction, unless it is obvious to a reasonably observant person.
  • AI-generated text needs a label only when it informs the public on matters of public interest without human review. Substantive review or editorial control removes the duty; spell-check alone fails the test.
  • Deepfakes always need a visible disclosure. The provider's machine-readable watermark alone fails the deployer's duty.
  • Fines reach €15 million or 3% of worldwide turnover, enforced mainly by national market surveillance authorities.

Data, privacy, and human-review requirements are a fixed step in every AI consulting sprint webvise runs. The checklist at the end of this article comes from that work.

What the Commission published on 19 July 2026

Press release IP/26/1653 announced guidelines on the transparency of AI-generated content. They clarify which providers and deployers must comply, what counts as an interactive AI system, synthetic content, or a deepfake, and which exemptions apply. They sit next to the Code of Practice on Transparency of AI-Generated Content, a voluntary code drafted by independent experts that the Commission and the AI Board confirmed as an adequate way to demonstrate compliance.

Henna Virkkunen, the Commission's Executive Vice-President for Tech Sovereignty, framed the goal as making "AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy." The practical consequence sits one paragraph further down in the release. From 2 August 2026 the Commission and national market surveillance authorities hold enforcement powers over these rules, so the guidance phase ends and the enforcement phase starts.

The four obligations, and whether you are a provider or a deployer

The AI Act splits duties between providers, who develop or commission an AI system and place it on the market under their own name, and deployers, who use an AI system under their authority in a professional context. Buying a chatbot from a vendor makes you a deployer. Selling one under your own brand makes you a provider, even when a model from OpenAI or Anthropic sits underneath. Companies outside the EU are covered whenever the system's output is used inside the EU.

ArticleWhoObligationTypical case
50(1)ProviderInform users they are interacting with AI, from the first interactionSupport chatbot, AI agent, avatar
50(2)ProviderMark generative outputs with machine-readable, detectable marksText, image, audio, and video generation
50(3)DeployerInform people exposed to emotion recognition or biometric categorisationHR screening, retail analytics
50(4)DeployerVisibly label deepfakes and AI-generated public-interest text published without human reviewNews-style articles, realistic AI video

For a typical business website, two rows matter: 50(1) covers the chatbot in the corner, 50(4) covers the blog. The FAQ the Commission published alongside, updated 24 July 2026, answers most edge cases in plain language.

If you run a chatbot: disclosure by design

The guidelines set four cumulative criteria for the disclosure duty. The system must qualify as an AI system, be built for a genuine two-way exchange, interact directly rather than through a human intermediary, and interact with natural persons. Background systems and machine-to-machine traffic fall outside the duty entirely.

Users must see the notice at the start of the first interaction, clearly distinguishable and in line with accessibility requirements. One exception exists: when the AI nature is obvious to an average person who is reasonably well-informed and observant. The Commission tells providers to read that exception narrowly, because it removes transparency from the person on the other end.

The clean way to comply is to put the disclosure in the interface, never in the terms page. A client-facing answer agent webvise shipped for a media production company opens every session with an AI label and routes low-confidence questions to a human inbox, so the safety design now doubles as the Article 50 disclosure. The build pattern behind it is documented in the AI receptionist build-vs-buy breakdown, which as of August carries a legal deadline.

If you publish AI content: the exemption that saves most blogs

Article 50(4) covers AI-generated or manipulated text published to inform the public on matters of public interest: politics, public health, consumer safety, financial, scientific, or cultural developments, and similar topics. Three conditions must all hold. The text is published, it informs the public, and it touches a matter of public interest.

The exemption does the real work here. Text that went through human review or editorial control needs no label. The guidelines define human review as deliberate examination of the substance by someone with relevant knowledge, and editorial control as a responsible editor with authority to approve, alter, or reject the text. Spell-check and grammar passes are explicitly named as insufficient.

This makes the review workflow a compliance question, and every content team should answer it this week. Every article on the webvise blog is drafted with AI assistance, then reviewed for substance, checked against sources, and edited before publication in 7 locales, and under the new guidelines exactly that review removes the labeling duty. Teams that publish model output unread carry the duty in full. The editorial standard that keeps AI content ranking on Google turns out to be the same one that keeps it exempt.

Deepfakes follow a stricter rule. Realistic AI-generated image, audio, or video that could pass as authentic needs a visible or audible disclosure at first exposure at the latest, and the provider's embedded watermark alone fails the deployer's duty. For evidently artistic or satirical work, the disclosure only has to avoid spoiling the experience.

Deadlines, fines, and who enforces

DateWhat happens
19 July 2026Commission publishes the Article 50 guidelines, FAQ, and factpage (IP/26/1653)
2 August 2026Article 50 applies; Commission and national market surveillance authorities gain enforcement powers
2 December 2026Marking and detection duties under 50(2) reach AI systems placed on the market before 2 August 2026

Content generated before 2 August 2026 needs no retroactive label, though the Commission encourages it. Fines go up to €15 million or 3% of total worldwide turnover for the preceding financial year, with proportionality for SMEs and small mid-caps. Signing the Code of Practice buys legal certainty and predictability. Companies that skip it must demonstrate compliance through their own means and should expect more information requests from authorities.

The audit to run before 2 August

  • Inventory every AI touchpoint. Chatbots, agents, content pipelines, image and voice generation, avatars, and any analytics with emotion recognition.
  • Classify your role per system. Provider when you ship it under your brand, deployer when you use a vendor's tool. The duties differ per Article 50 paragraph.
  • Chatbots: put the AI notice in the first message and check it against accessibility requirements. Do this even where you would argue the AI is obvious.
  • Content: document your human review step. Name the reviewer, keep the review substantive, and keep evidence per published piece.
  • Ask your AI vendors two questions: how they implement machine-readable marking, and whether they signed the Code of Practice on Transparency of AI-Generated Content.
  • Apply the grace period only where it exists. Systems on the market before 2 August 2026 get until 2 December 2026, and only for marking and detection.

For the wider framework, risk categories, GPAI duties, and the certifications that matter, the European AI regulation guide covers the whole AI Act. The August 2026 deadlines listed there are now live.

The rules reward companies whose AI features carried review gates and disclosure from day one, which costs far less than a retrofit the week before a deadline. webvise maps these requirements, data handling, human review points, and disclosure design in a 2 to 4 week AI consulting sprint. For a direct question about your setup, use the contact form.

Development practices are aligned with ISO 27001 and ISO 42001 standards.