The short version: starting August 2, 2026, the European Union’s AI Act requires businesses to tell people when they are talking to a chatbot, label AI-generated content as artificial, and disclose when AI is reading someone’s emotions or face. The European Commission finalized the guidance on July 20, giving companies less than two weeks of runway. If your website, chatbot, or AI-generated marketing content is reachable by anyone in the EU, this law can apply to you no matter where your business is registered. That is not a scare tactic, it is how the rule is written, and the fix for most small businesses is a sentence, not a rebuild.
This is a case where AI transparency rules for small business owners stop being an abstract compliance topic and become a real, dated to-do item. Here is what actually changes, who has to act, and what to do about it this week.
What is Article 50 of the AI Act, and why does it matter now?
Article 50 is the transparency section of the EU AI Act. It does not ban AI systems or rank them by risk the way other parts of the Act do. Instead, it requires that people be told, plainly, when they are dealing with AI. The Commission adopted its final guidelines on these obligations on July 20, 2026, just ahead of the rules taking effect on August 2 (Bird & Bird). There is a grace period through December 2, 2026 for the technical marking and detection tooling behind AI-generated content, but the core disclosure duties start on August 2 with no cushion.
Does this actually apply to a US small business?
This is the part owners tend to skip past. The AI Act follows what lawyers call a “market location” test, the same logic behind GDPR. A US company with no EU office, no EU staff, and no EU servers can still be in scope if its AI system’s output reaches people in the EU (Modulos). A public chatbot on your site, an AI-generated product description, or an AI voice line that any EU visitor can encounter is enough to put you inside the rule. You do not need EU customers on payroll, you just need EU eyeballs on the output.
That does not mean every small business with a website is suddenly a target for Brussels regulators. It does mean the honest answer to “does this apply to me” requires actually checking your exposure, not assuming the ocean is a compliance boundary.
What exactly do you have to disclose?
The guidance breaks down into four practical duties (Addleshaw Goddard, artificialintelligenceact.eu):
Chatbots and virtual assistants: people must be told they are interacting with AI at the first point of contact, unless it is obvious to an average person already. A support widget or booking bot on your site needs a short, clear line to that effect.
AI-generated content: text, images, audio, or video produced by generative AI needs to be marked as artificial in a machine-readable way. Basic editing tools like spell check or color correction are exempt, and so are internal, industrial, or business-to-business uses.
Emotion recognition and biometric categorization: if your systems try to read a customer’s emotional state or sort people by biometric traits, they need to be told, at first exposure.
Deepfakes and AI-written public content: AI-manipulated images or video that look real, and AI-written text published to inform the public, both require disclosure, unless a human has substantively reviewed the content and someone takes editorial responsibility for it. Artistic and satirical work gets a lighter touch.
What happens if you ignore it?
Penalties for the AI Act’s transparency rules can reach 15 million euros or 3% of global annual turnover for larger organizations, with lower caps for small and medium enterprises. In practice, a small US business with a chatbot and no EU footprint to speak of is a low enforcement priority right now. But “unlikely to get caught” is a different bet than “this does not apply to me,” and the second one is the assumption that tends to age badly once a platform, a partner, or a customer contract starts asking for compliance documentation.
What should you actually do this week?
You do not need outside counsel to take the first pass at this. Walk through your own stack the way you would review a punch list before opening night:
- List every place AI touches a customer: chatbot, voice assistant, AI-written product copy, AI-generated images, review responses.
- For each one, ask whether an EU visitor could plausibly reach it. If your site has no geo-block and no reason to exclude EU traffic, assume yes.
- Add a one-line disclosure where it is missing: a chatbot greeting that says it is an AI assistant, a footer note on AI-generated images, an “AI-drafted, human-reviewed” line on published content.
- Write down what you did and when. If this ever comes up, a dated internal note showing you reviewed and addressed it is worth far more than silence.
None of this requires fearing your own tools or pulling AI out of the business. It is the same instinct as putting a hairnet sign in a kitchen: a small, visible act of honesty that costs you almost nothing and buys real trust. Owners who already loop a human into reviewing AI output before it reaches a customer, per our earlier look at AI adoption outpacing internal rules, are most of the way there already.
For the bigger regulatory picture beyond the EU, our guide to AI ethics and regulation for businesses covers the US state-level patchwork, and the disclosure logic driving Article 50 is the same one behind Ontario’s AI hiring disclosure law: tell people when a machine is involved, before they ask.
Here is the honest question this raises: how many small businesses will actually check their exposure before August 2, versus finding out the hard way through a platform notice or a customer complaint? If you have already audited your own AI touchpoints, what did you find?
Frequently Asked Questions
When do the EU AI Act’s transparency rules take effect?
The obligations under Article 50 become applicable on August 2, 2026. A separate grace period runs through December 2, 2026, but only for the technical marking and detection tools behind AI-generated content, not for the core disclosure duties themselves.
Do these rules apply to my business if I am based in the United States?
Possibly. The AI Act uses a market location test: if your AI system’s output reaches people in the EU, such as through a public website or chatbot, you can be in scope regardless of where your company is headquartered. This mirrors how GDPR’s reach works.
What is the simplest way to comply if I run a small business?
Identify where AI touches a customer, such as a chatbot or AI-generated content, and add a short, clear disclosure that a machine is involved. For most small businesses this is a line of text, not a technical overhaul.
What are the penalties for not complying?
Fines can reach 15 million euros or 3% of worldwide annual turnover for larger organizations, with lower caps set for small and medium enterprises. Enforcement risk for a small business with limited EU exposure is currently low, but documented, good-faith compliance is the safer bet.
