Disclosure, up front
We are an automation company, not a law firm, and nothing here is legal advice. We wrote this because clients started forwarding us compliance emails from vendors that were, in several cases, selling a problem that did not apply to them. Everything below is read from the European Commission's own published guidance and the text of the Regulation, dated, and linked at the bottom. If you are genuinely in scope for the heavier parts, you want a lawyer, not a blog post, and we will say so again at the end.
On 2 August 2026 a set of EU AI Act obligations stopped being future tense. Since then the marketing has been relentless, and most of it is aimed at making a small American business believe it is one audit away from a fifteen million euro fine.
The reality is narrower and considerably less dramatic. A handful of duties are now live. Most of them land on the companies building AI systems rather than the ones using them. The genuinely heavy obligations, the high-risk regime everyone quotes the scary numbers about, were pushed back to December 2027 and August 2028 a week before the deadline, and a lot of the compliance content still circulating has not caught up with that.
Here is what actually changed, how to tell in about ten minutes whether any of it applies to you, and the specific point at which we would tell you to stop reading and call a solicitor.
The short version
- Article 50 transparency duties are live now, as of 2 August 2026, for anyone whose AI output reaches people in the EU, regardless of company size or where you are based.
- Most of them are one sentence of disclosure. Tell people when they are talking to a bot. Label synthetic media. That is the bulk of it for a typical small business.
- The expensive high-risk regime was delayed to 2 December 2027 and 2 August 2028 by the Digital Omnibus, published in the Official Journal on 24 July 2026.
- If no output of yours reaches the EU, you are very likely out of scope entirely — but that is a fact to verify, not to assume, and the check is genuinely quick.
01What actually took effect on 2 August 2026
Three things, and it is worth keeping them separate because vendors routinely blur them together:
- Article 50 transparency obligations. The disclosure rules. These are the ones most likely to touch an ordinary business, and they are the subject of most of this article.
- Enforcement powers over general-purpose AI. Aimed at model providers — the people who train and ship the large models. If you are buying AI rather than building foundation models, this is your vendor's problem, not yours.
- The full penalty regime. The fines became enforceable. For Article 50 breaches, up to €15 million or 3% of worldwide annual turnover, whichever is higher.
That last figure is the one doing all the work in vendor emails. It is real. It is also the ceiling for the worst conduct by the largest companies, applied by national market surveillance authorities that are explicitly directed to weigh proportionality and the size of the business. A two-person shop that forgot a chatbot disclosure and a multinational that systematically deceived users are not on the same page of the same enforcement playbook.
02Are you in scope? The ten-minute test
The AI Act reaches beyond the EU's borders, which is the part that surprises people. It applies to providers and deployers whose AI system output is used in the EU, whatever the size of the company and wherever it is established. Being in Ohio does not exempt you. Having EU customers does not automatically doom you either.
Work through these in order. The first "no" that is genuinely a no ends the exercise.
Four questions, in order
- Does any AI output of yours reach a person in the EU? A chatbot on a site EU visitors can use. AI-drafted emails to EU contacts. AI-generated images on a page served in Europe. If nothing does, stop here — but check your analytics rather than guessing, because "we do not really have EU customers" and "we have no EU traffic" are different statements.
- Are you a provider or a deployer? A provider builds or substantially modifies an AI system and puts it on the market under its own name. A deployer uses one under its own authority. Almost every small business buying tools is a deployer, and deployers carry the lighter half of Article 50.
- Does your AI interact with people, or generate content that could pass as real? Chatbots, voice agents, synthetic images, audio or video, and AI-written text on matters of public interest. If your AI only sorts your own invoices internally, Article 50 largely passes you by.
- Are you doing emotion recognition or biometric categorisation? Almost nobody reading this is. If you are, that is a specific disclosure duty and a conversation with a lawyer.
In our experience the overwhelming majority of small US businesses land on: yes to the first, deployer on the second, chatbot-only on the third, and no on the fourth. That combination is a small amount of work, which we will get to.
03The four duties, and whose problem each one is
Article 50 is often described as a single obligation. It is four, and they are split between providers and deployers, which is the single most useful thing to understand about it.
| Duty | Falls on | What it means in practice | Typical small business |
|---|---|---|---|
| Disclose AI interaction | Provider | People must be told they are dealing with an AI system, unless it is obvious to a reasonably observant person. From the first interaction, clearly and accessibly. | Usually yours in effect. Your vendor builds the widget, but you decide what it says on your site. |
| Machine-readable marking of synthetic content | Provider | AI-generated audio, image, video or text must carry marks that let it be detected as artificial. | Your vendor's problem. Ask them for it in writing; do not build it yourself. |
| Label deepfakes | Deployer | Image, audio or video that falsely appears authentic must be clearly disclosed as AI-generated or manipulated. | Yours, if you publish synthetic media of people or events. |
| Label AI text on matters of public interest | Deployer | AI-generated text published to inform the public on topics like politics, health, justice or the environment must be labelled. | Yours, but there is a real exemption — see below. |
Read from the European Commission's published Article 50 guidance and FAQ on 7 September 2026, and from the text of Article 50 itself. The provider/deployer split is the Act's own, not our simplification. Where a duty is marked as falling on the provider but "usually yours in effect", that is a practical observation about who controls the customer-facing surface, not a legal reallocation of the obligation.
Two exemptions in that table matter more than their length suggests.
The "unless it is obvious" carve-out on chatbot disclosure is doing real work, but do not lean on it. If your widget is called "AI Assistant" and opens with "Hi, I'm an automated assistant", that is obvious. If it has a human first name, a stock photo of a face, and writes in the first person about how much it loves helping customers, a regulator is unlikely to agree that it was obvious. The cheap fix is to make it obvious rather than to argue about it.
The editorial-control exemption on AI text is the one that quietly excuses most business blogging. Text that has gone through human review with a person or organisation taking editorial responsibility for it does not require the public-interest label. This article, for instance, is researched with AI assistance and edited and published under our name, with us answerable for every figure in it. That is the exemption working as intended. It is not a loophole to route around the rule — it is the rule saying that accountable human publishing is the thing it wanted all along.
04What the Digital Omnibus delayed, and what it did not
This is where a lot of the circulating advice is now simply out of date.
For most of 2026 the message was that 2 August 2026 would bring the high-risk obligations into force — conformity assessments, risk management systems, technical documentation, the genuinely expensive apparatus. Then the Digital Omnibus, formally Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and moved those deadlines to 2 December 2027 and 2 August 2028.
What it did not delay: the Article 50 transparency duties, the general-purpose AI enforcement powers, or the penalty regime. Those all landed on schedule.
So the accurate picture as of today is a live but light disclosure regime, with the heavy machinery more than a year out. If a vendor is quoting you for high-risk conformity work to be delivered this quarter, ask them which article obliges you to have it before December 2027. It is a fair question and the answer is informative either way.
One date that has not moved
Providers of in-scope systems that generate synthetic audio, images, video or text and were already on the EEA market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking duty. That is a provider deadline rather than a deployer one, but if you resell or white-label a generative tool under your own name, check carefully which side of the line you are on — putting a system on the market under your own name is one of the things that makes you a provider.
05The SME carve-out, which got wider
The Digital Omnibus also widened the simplified compliance track. It now extends to companies up to 750 employees and €150 million in annual revenue, which covers essentially every business likely to be reading this and a good many that would not describe themselves as small.
What the simplified track gets you: simplified guidance and standardised documentation templates, reduced fines, and access to regulatory sandboxes. What it does not get you: an exemption. The duties still apply. The paperwork and the downside are scaled to your size.
There is also a voluntary Code of Practice on Transparency of AI-generated Content, which the Commission confirmed as adequate in July 2026. Signing up is not mandatory and not signing up is not an offence. It buys a degree of legal certainty about what "good enough" looks like, and the Commission has been fairly direct that non-adherence may attract more scrutiny rather than less.
06What to actually do this month
For a deployer with a chatbot and some AI-assisted content — which is most people — the honest list is short.
- Check whether EU users reach your AI at all. Analytics, not intuition. If the answer is genuinely zero and your business has no EU footprint, document that you checked and revisit it when that changes.
- Make the bot obviously a bot. First message, plain words, before it asks anything. This costs one line of configuration and removes the single most likely complaint against a small business.
- Ask each AI vendor, in writing, what they do about Article 50 marking. You are buying their compliance posture along with their software. A vendor who cannot answer this in September 2026 is telling you something.
- Label synthetic media of people or events. If you generate images or voice that could be mistaken for real, say so visibly. This is the duty with the least wiggle room in it.
- Keep a human editorially responsible for published AI text. Not a rubber stamp — an actual person who checked the claims and would answer for them. That is what the exemption is for.
- Write down what you did and when. One page. The most common failure in a small-business compliance review is not the absence of a control, it is the absence of any evidence that anyone thought about it.
07Where we would tell you to stop and get a lawyer
We are describing a regime, not advising on your situation, and there is a real line where this stops being a reading exercise. Get proper advice if any of these are true:
- Your AI touches hiring, credit, education, insurance, essential services, or law enforcement. These sit in or near the high-risk categories. The deadline moved to December 2027; the work is substantial and starting late is expensive.
- You do emotion recognition or biometric categorisation. Distinct duties, and some practices are prohibited outright rather than merely regulated.
- You white-label somebody else's AI under your own brand. That can make you the provider, with the heavier half of the obligations, and people are frequently surprised by which side of that line they are on.
- You are being asked to sign customer contracts warranting AI Act compliance. That is a commercial risk allocation question, and it is a different question from whether you are compliant.
None of those four is something we can settle for you, and neither can a compliance SaaS subscription.
08The honest summary
For most small US businesses, the EU AI Act as it stands on 7 September 2026 is a disclosure requirement, not a compliance programme. Tell people when they are talking to a machine. Label synthetic media. Keep a human answerable for what you publish. Ask your vendors what they are doing about marking.
That is genuinely most of it, and it is work measured in hours rather than quarters. The heavy regime is real and it is coming, but it is coming in December 2027, and any urgency being sold to you on a 2026 timeline deserves a specific citation before it deserves your budget.
09Common questions
Does the EU AI Act apply to US small businesses?
It can. The Act applies to providers and deployers whose AI system output is used in the EU, regardless of company size or where the business is established, so a US company with EU users can be in scope. If no output of your AI reaches anyone in the EU, you are very likely outside it. That is worth verifying from analytics rather than assuming, because AI-drafted email to EU contacts and a chatbot on a globally reachable website both count as output reaching the EU.
What changed on 2 August 2026?
Three things took effect: the Article 50 transparency obligations, enforcement powers over general-purpose AI, and the full penalty regime. The transparency duties are the ones most likely to affect an ordinary business. The high-risk obligations that people often associate with this date were separately delayed to December 2027 and August 2028.
What are the Article 50 transparency obligations?
Four duties, split between providers and deployers. Providers must tell people they are interacting with an AI system unless it is obvious, and must mark AI-generated audio, image, video or text in a machine-readable way. Deployers must clearly label deepfakes, and must label AI-generated text published to inform the public on matters of public interest such as politics, health, justice or the environment. Deployers of emotion recognition or biometric categorisation must inform the people exposed to them.
Were the EU AI Act deadlines delayed?
The high-risk ones were. The Digital Omnibus, formally Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and moved the heavy high-risk obligations to 2 December 2027 and 2 August 2028. The Article 50 transparency duties, the general-purpose AI enforcement powers and the penalty regime were not delayed and took effect on 2 August 2026 as planned.
What are the fines for breaching the AI Act transparency rules?
Up to 15 million euro or 3% of worldwide annual turnover, whichever is higher, applied by national market surveillance authorities. That is a ceiling rather than a standard penalty, and the framework directs authorities to consider proportionality and the size of the business, with specific provisions for small and medium enterprises.
Do I have to label AI-written blog posts?
Only if the text is published to inform the public on a matter of public interest, and even then there is an exemption where the content has undergone human review and a person or organisation holds editorial responsibility for it. Ordinary marketing copy is not a matter of public interest. An edited, bylined article that your business stands behind falls within the editorial-control exemption.
Is my chatbot exempt if it is obviously a bot?
Article 50 does not require disclosure where it is obvious to a reasonably well informed person that they are interacting with an AI system. That exemption is real but it is a poor thing to rely on, because whether something is obvious is judged by a regulator rather than by you. Naming the widget as an assistant and opening with a plain statement that it is automated costs one line of configuration and removes the argument entirely.
Does the small business exemption mean I can ignore the AI Act?
No. The simplified compliance framework, extended by the Digital Omnibus to companies with up to 750 employees and 150 million euro in annual revenue, gives simplified guidance, standardised documentation templates, reduced fines and regulatory sandbox access. It scales the paperwork and the downside to your size. It does not remove the underlying obligations.
Not sure whether any of this touches you
Send us what AI you actually run — the chatbot, the content tools, the automations — and whether anything of yours reaches EU users. We will tell you which of the four duties apply and which do not, and if the honest answer is "none of them, you are fine", that is what you will get. The audit is free and we do not sell compliance software.
Ask for a scope checkSources, all read 7 September 2026: the European Commission's guidelines and FAQ on transparency obligations under Article 50 of the AI Act, and its Code of Practice on Transparency of AI-generated Content, both first-party; the text of Article 50; and Regulation (EU) 2026/1744, the Digital Omnibus, published in the Official Journal on 24 July 2026. Penalty figures and the extended SME thresholds are from those same sources. This article describes a regulation; it is not legal advice, and it is not a substitute for advice on your own circumstances. Deadlines and guidance in this area have already moved once in 2026 and may move again, so verify before you act. Related: An AI Agent Breached a Real Company and Which Decisions You Should Never Hand to an AI Agent.
Hero image from Unsplash, used under the Unsplash License.