Celebrating the AI Act delay? The EU AI Act’s chatbot and content rules apply this week

Hands typing on a tablet with AI superimposed in text in front
(Image credit: Getty Images)

If your business celebrated the European Union’s (EU) delay of high-risk AI penalties, don't open the champagne just yet. On August 2, 2026, Article 50 of the EU AI Act goes live, bringing new transparency requirements for the AI tools businesses already rely on. While backend compliance demands have been delayed, chatbots, AI generators, and synthetic media systems are now in the spotlight.

The AI Act delays may have dominated headlines, but Article 50 never stopped moving. The European Commission has now finalized the transparency guidelines businesses need to follow, giving regulators a clear framework to enforce consumer disclosure rules starting this weekend.

Think the EU AI Act only targets big tech? Think again. Small or medium-sized enterprises (SMEs) serving European users are also in scope, wherever they operate. The age of invisible AI is ending, and businesses that hide automated interactions may find themselves under significant regulatory scrutiny before the business week even begins.

Who is caught in the net? Providers vs deployers

To navigate the EU AI Act without getting lost in legal jargon, businesses must first understand which role they fall under. The framework separates organizations into two categories: Providers and Deployers. Mixing up these definitions is the fastest way to accidentally skip a critical regulatory step or waste time trying to solve compliance issues that aren't actually your responsibility.

If your company builds AI models from scratch, significantly modifies open-source systems, or white-labels a third-party AI tool to sell under your own brand name, you are a Provider under the EU AI Act. That puts the technical burden on your business, from building transparency infrastructure to embedding machine-readable watermarks into AI-generated text, images, and videos.

For most SMEs, however, the second category applies: Deployers. If you are a small business that simply plugs an off-the-shelf AI widget into your website to handle customer service tickets, or uses AI tools to create marketing content, you are deploying AI. Thankfully, your responsibility isn't to invent deep-tech watermarking protocols but to double-check that people interacting with your systems are notified that they are dealing with an algorithm rather than a human employee.

The AI Act timeline: What was delayed vs what is due now

When the EU delayed major AI Act deadlines, businesses were quick to assume they had more time. The May 2026 "Digital Omnibus" amendment formally rolled back the compliance deadlines for complex AI architectures, leading many burned-out business owners to assume the entire rulebook had been kicked down the road.

Unfortunately, that was a serious misunderstanding of the changes. The extensions only apply to standalone, high-risk frameworks, such as automated resume screening, biometric identity verification, and AI-powered credit scoring tools. Because these deep enterprise tools require massive infrastructure overhauls and independent third-party audits, the EU simply gave businesses a longer runway until late 2027 and 2028 to prepare.

Basic consumer transparency, however, received no free pass. The European Commission made it clear that protecting everyday users from digital deception could not be delayed. As a result, Article 50 moves forward on schedule, separate from the postponed systemic deadlines. To guide businesses through this transition, the EU has established the Code of Practice on Transparency of AI-generated Content as the benchmark for compliance.

Article 50 and the four pillars of AI transparency

If your business utilizes AI to interact with customers or create content, Article 50 is now part of your operating reality. The EU has broken down its transparency rules into four core pillars, aiming to remove the mystery around automated systems without slowing down innovation.

For SMEs, the era of set-it-and-forget-it AI is firmly over. Depending on how your business uses generative tools, you are now legally required to update user interfaces, verify compliance from software vendors, or change how AI-generated content is published.

AI chatbot transparency rules

The first pillar is the “Human-AI Interaction” rule, and it targets the conversational bots handling your customer service, lead generation, or basic troubleshooting. Under the new guidelines, you can no longer trick a consumer into thinking they are chatting with a human employee when they are actually interacting with a large language model (LLM) script.

Starting this week, deployers must stop hiding AI behind a human-looking interface. Crucially, users need a clear notification that they are interacting with an AI system before the conversation starts, not a disclaimer buried in a wall of legal text. For SMEs using AI customer support, that means updating chat interfaces immediately to include an undeniable "I am an AI assistant" disclaimer.

Synthetic media watermarking

The second pillar shifts the technical burden onto the builders of generative AI tools. If your business creates or distributes software that generates synthetic text, audio, images, or video, you must embed machine-readable digital watermarks into the assets those tools produce.

The purpose of these markers is to help other software, like social media platforms or verification services, automatically detect that a piece of media was created by an AI. While existing providers have limited time to implement this infrastructure, any new generative AI tools launched after this week must include watermarking from day one.

Labeling AI-generated content

While watermarking happens behind the scenes, the third pillar requires clear labeling on the surface of the content itself. This rule specifically targets what the EU defines as deepfakes and synthetic output that could influence public understanding. If your marketing team uses AI to create realistic images, videos, or audio that could be mistaken for real people or events, you must slap a clear “AI-generated” warning label on them.

This responsibility falls on the businesses publishing the content. So, if you publish an AI-generated image of a realistic crowd for a promotional campaign, or use an AI-voiced avatar in a public video, it must also feature an overlay or disclaimer stating that it has been artificially generated or manipulated. The only exception here is obvious artistic, satirical, or fictional content, but transparency is still the safest bet.

Emotion recognition rules

The final, and perhaps most legally sensitive, pillar targets biometric and emotion-recognition systems. If your SME utilizes software to detect emotional states, interpret facial expressions, or classify individuals based on biometric data, you must proceed with extreme caution.

The new rules require businesses to explicitly inform users whenever they are exposed to emotion recognition or biometric profiling systems. For instance, if you use an AI-driven video interviewing tool to analyze a candidate's body language, or a retail system checking customer reactions, you must secure clear user consent before the software starts collecting this type of sensitive data. Psychological and physiological tracking can no longer happen behind closed doors.

The AI Act’s hidden deadline split

Like with any major regulatory rollout, the devil is always in the details. For SMEs, the EU AI Act brings a mix of breathing room and immediate pressure. Understanding which deadlines moved (and which did not) is the only way to avoid a costly compliance mistake.

The good news for software creators and IT departments is what experts call the grandfather clause. If your generative AI model was already legally available on the market before August 2, 2026, the EU provides a four-month technical runway, which moves mandatory machine-readable watermarking requirements to December 2, 2026. This extension gives development teams a much-needed time to update systems, test metadata workflows, and prepare for compliance.

However, relying too much on this buffer is where SMEs fall into a terrible, zero-day trap. The four-month grace period applies only to the technical back-end watermarking of existing AI tools, and it doesn’t cover chatbots, public disclosures, or newly launched software.

If you’re launching a brand new AI writing tool or chatbot after this week, there is no ramp-up window. Similarly, user disclaimers for deepfakes and interactive chatbots must be active immediately on day one. Without clear AI notices on customer-facing systems, your business becomes non-compliant the moment the deadline passes.

How to comply before Monday morning

If your business is staring down the barrel of the August 2nd deadline, the answer is not panic but preparation. Since there is no single EU registry for AI tools, compliance starts with something much simpler: making your AI use visible, documented, and transparent.

You do not need to rebuild your software stack over the weekend, but you do need to secure your customer-facing AI touchpoints. Here are four steps to take before Monday:

  1. Map your stealth AI usage: Audit your teams for untracked software, plugins, and automated systems creating customer-facing content.
  2. Kill the invisible chatbots: Update AI chat tools with a clear upfront notice telling users they are interacting with an AI assistant.
  3. Verify software vendor compliance: Get written confirmation of compliance and ask how providers handle machine-readable watermarks.
  4. Document your paper trail: Log every AI update, vendor conversation, and internal policy change for future reviews.

Turning compliance into trust

For many businesses, Article 50 feels like a new burden, but for smart SMEs, it is a chance to build trust. As users grow more skeptical of hidden AI, businesses that are transparent about how they use automation can stand out from the crowd.

Compliance is no longer another box to check to avoid penalties but a powerful indicator of integrity that can set your brand apart in the new age of AI.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.