Say When It Is AI: The Transparency Rules Now in Force

by ai-intensify
0 comments
Abstract blueprint scene of a central hub linking outputs that each receive a marker tag, illustrating EU AI Act transparency rules on disclosure

AI-generated article. This article was researched and drafted using AI tools and published automatically, and its featured image was generated by AI. Facts are drawn from the sources cited in the text.

On 2 August 2026 a set of obligations that had been discussed for years stopped being a future problem. The EU AI Act transparency rules in Article 50 became enforceable, and the European Commission confirmed it had begun applying them. For most small businesses this is not the dramatic compliance event the headlines suggested. It is also not nothing, and the difference is worth understanding.

A note before anything else: this is a general summary of what the rules say, not legal advice. Anyone with real exposure should talk to a qualified lawyer about their specific situation.

Who the rules actually land on

Much of the early coverage focused on the companies building AI models. Article 50 reaches further than that. It splits duties between providers, who make the systems, and deployers, who use them. Article 3(4) defines a deployer broadly, as any person or body using an AI system under its own authority, with an exception carved out only for personal, non-professional use. A three-person marketing agency running a chatbot on a client site is a deployer. So is a shop generating product descriptions.

Guidance from firms including Cooley, Morgan Lewis and Orrick lands on the same practical point: the obligations follow the use, not the size of the company. They also reach outside the European Union. A business based anywhere with users or customers in the EU can fall within scope.

What the EU AI Act transparency rules require

Three situations carry the clearest duties. People interacting directly with an AI system have to be told they are doing so. Synthetic image, audio and video content that constitutes a deepfake has to be disclosed. AI-generated text published to inform the public on matters of public interest has to be disclosed as artificially generated, unless a human took editorial responsibility after substantive review.

The standard for how that disclosure appears matters more than most summaries admit. Commission guidance says deployers must disclose at first exposure, in a clear and distinguishable manner, understandable without any special technical tools or extra steps by the reader. A line in the terms and conditions does not do it. Neither does small grey text in a footer. The notice at the top of this page is one version of what compliance looks like.

Deadlines that are still moving

Systems already on the market before 2 August 2026 were given a transitional window under the AI Omnibus provisional agreement, running to 2 December 2026, for the machine-readable marking duty in Article 50(2). The Commission has also published a Code of Practice on Transparency of AI-Generated Content and confirmed it as adequate. Signing that code is voluntary. The underlying legal obligations are not, and they apply whether or not an organization signs anything.

The penalties, in proportion

National authorities can impose fines reaching EUR 15 million or 3% of worldwide annual turnover. That number is what drives most of the anxious commentary. It deserves context. The Act directs authorities to apply proportionality for small and medium enterprises, and the realistic first-order risk for a small business is not a headline fine. It is being the one competitor in a category doing something visibly less honest than everyone else.

There is a genuine tension here and it is worth naming. Compliance work is real overhead for a business with no legal department, arriving at a moment when the same business is still working out which tools to keep. Rules written with large platforms in mind land on small teams with the least capacity to interpret them. That is a fair complaint. It does not change what applies.

Where to start, given limited time

Write down every place AI touches something a customer sees. The chatbot, the generated images, the drafted email sequences, the product copy, the phone system. Most businesses have never made this list and it is usually longer than expected, which is the same reason shadow AI is difficult to govern. The list itself is most of the work.

Then add a plain, visible label wherever the rules point. Not a legal paragraph. A sentence, in the same size type as everything around it, saying what was generated and by what. Businesses already got used to reading past inflated claims about what a tool actually is, and disclosure runs the same way, in the opposite direction.

The interesting question is not whether the fines get enforced against small firms. It is what happens to trust in a market where some businesses label and others do not, and customers start to notice which is which.

Related Articles