EU AI Act Article 50: What Your Website Must Do From 2 August 2026
You've probably seen the headlines saying the EU AI Act was delayed. Part of it was.
The high-risk regime got pushed back. Those are the rules covering AI in hiring, credit scoring, education and access to essential services, and they moved from August 2026 to December 2027. High-risk systems embedded in regulated products got until August 2028. The reason is fairly mundane: national authorities and the technical standards they depend on weren't ready in time.
The transparency obligations in Article 50 weren't part of that package. They took effect on 2 August 2026, on the original schedule, and they reach a far wider set of websites than the high-risk rules ever would have. A chatbot puts you in scope. So does publishing AI-generated content, or running anything that analyses faces or voices.
First: are you a provider or a deployer?
Article 50 splits its obligations between two roles, so settle which one you occupy before reading the rest.
A provider develops an AI system, or has one developed, and places it on the EU market under its own name. If you built the chatbot, that's you.
A deployer uses an AI system under its own authority in a professional capacity. Bought a chatbot and put it on your site? You're a deployer. Still regulated, just under different paragraphs.
The two sets of duties aren't interchangeable. Providers get the technical ones: designing disclosure into the system, embedding machine-readable marking in output. Deployers get the contextual ones, like telling people when they're exposed to emotion recognition, or labelling deepfakes they publish. Buying your AI from a vendor moves some obligations off your plate. Never the ones tied to how you use the thing.
One useful exclusion: "deployer" doesn't cover purely personal, non-professional use. A hobby blog is out of scope. A company blog isn't.
The four obligations
1. Tell people they are talking to an AI
Any AI system designed to interact directly with people has to make clear that it's an AI. Support chatbots, AI assistants, voice agents, interactive AI features.
The obligation bites when four things are true together: the system qualifies as AI, it allows genuine two-way exchange, the interaction is direct instead of mediated by a human, and the person on the other end is a natural person.
There's an exemption where it's already obvious the user is dealing with an AI, judged from the perspective of a person who is "reasonably well-informed, observant and circumspect." It's narrow. Naming your bot "Assistant" almost certainly doesn't clear the bar, and a line in your terms of service doesn't either.
Whatever you use has to be perceivable in the interaction itself, and given at the latest at the point of first interaction. A short line at the top of the chat window, before the first exchange, does the job.
So: put explicit AI-disclosure text in the chat interface, visible before the user sends their first message. Don't lean on the bot's name, an avatar, or anything in a linked policy document.
2. Mark AI-generated output so machines can detect it
Providers of generative AI have to mark synthetic audio, image, video and text output in a machine-readable format, detectable downstream as artificially generated or manipulated. Nobody reads this marking. It's watermarking and provenance metadata.
The regulation allows technical feasibility and cost to be taken into account, and carves out several categories: short sequences of numbers, symbols or letters; source code; machine-to-machine output no person sees; closed-loop industrial and product-development contexts; and standard assistive editing functions that don't substantially alter the input.
Publishers will mostly lean on that last one. Running a draft through a grammar tool is assistive editing. Generating a whole article is a different thing.
If you build or fine-tune generative models whose output reaches the public, work out your provenance approach now. If you only use third-party tools, confirm with each vendor that they mark output. The obligation sits with them, but you inherit the risk when they haven't done it.
3. Label deepfakes visibly
Publish AI-generated or AI-manipulated image, audio or video content that appreciably resembles real people, objects or places and could be mistaken for authentic, and you have to disclose that it's artificial. This one is a deployer duty. It sits separately from the machine-readable marking above, so you can't discharge it by pointing at your vendor's invisible watermark. The label has to be clear, distinguishable, and present at the point of first exposure.
Content that's evidently artistic, creative, satirical or fictional gets an exemption, with disclosure scaled back so it doesn't spoil the work. There's a law-enforcement carve-out too, which won't apply to commercial sites.
Practically, this means auditing your marketing imagery. AI-generated hero images featuring realistic people are the common exposure, and they rarely get thought of as regulated content.
4. Disclose AI-written text on matters of public interest
Publish AI-generated text to inform the public on matters of public interest and you have to disclose it. The qualifier does most of the work: the obligation generally falls away where the content underwent human editorial review and a named person or organisation holds editorial responsibility.
Most company blogs can meet that. A real editor who reviews the piece and stands behind it is what the exemption contemplates. Passing the draft through your CMS isn't editorial control.
And one more, if it applies
Deployers of emotion recognition or biometric categorisation systems have to inform the people exposed to them, and still satisfy the GDPR on top. Niche for a typical website. But if you run session-recording or engagement tooling that infers emotional state, look closely at whether it qualifies.
The second deadline: 2 December 2026
Article 50 applied from 2 August 2026 with a limited grace period attached. Generative systems already placed on the market before 2 August have until 2 December 2026 to meet the machine-readable marking requirement. Anything launched from August onward needed marking from day one.
Content generated before 2 August doesn't need retroactive labelling.
Running a generative feature that predates August? Early December is the date to plan against.
What it costs to get wrong
Breaches of Article 50 carry administrative fines of up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher.
Enforcement sits with national market surveillance authorities in each member state instead of centrally, so practice will vary across the EU and early enforcement is likely to be patchy. Patchy isn't the same as lenient. You've no way of knowing which regulator looks at you first.
Non-EU companies get caught by scope more often than they expect. The obligations follow the market, not the company. If your system is used in the EU, or its output is used there, you're in scope regardless of where you're incorporated.
A checklist you can run today
- Inventory every AI touchpoint on your site: chatbots, assistants, generative features, personalisation, anything analysing images or voice.
- Classify each one as provider or deployer. Write it down; the obligations diverge.
- Check every conversational interface for AI disclosure visible in the interface before first exchange. Assume the "obvious" exemption won't save you.
- Ask your generative-AI vendors, in writing, whether their output carries machine-readable marking and whether they'll meet the 2 December date.
- Review published media for realistic AI-generated imagery of people, places or events that needs a visible label.
- Confirm editorial ownership of AI-assisted articles: a named human who reviewed and takes responsibility.
- Diarise 2 December 2026 for any generative system live before August.
Where that leaves you
The delay headlines created a false sense of safety. High-risk moved. Transparency didn't. Article 50 is in force now, it reaches ordinary commercial websites, and it carries a second deadline in December for systems already running when it started to apply.
Most of the work is small. A line of text in a chat window, a label on an image, a named editor on a blog post, and a straight answer from your AI vendors will cover the bulk of the exposure on a typical site.
This article is general information, not legal advice. Obligations depend on your specific systems and how they are used. If you are unsure about your exposure, particularly around biometric or high-risk classification, consult a qualified adviser.
Sources: European Commission: Transparency obligations under Article 50 · Article 50, EU AI Act (full text) · Gibson Dunn: AI Act Omnibus agreement and postponed high-risk deadlines · Jones Walker: Yes, August 2 still matters