Skip to content
managerAI

AI Adoption

EU AI Act Article 50: Transparency for SMEs

Rolling out AI in your SME? A practical guide to EU AI Act Article 50 transparency obligations: chatbot notices, content labelling, vendor checks.

Marta BrehenyPublished: 23 June 20269 min read

If your small business uses a chatbot on its website, publishes AI-written articles, or generates synthetic images and video, the EU AI Act has a date worth marking in your calendar: 2 August 2026. That is when the transparency obligations in Article 50 start to apply. The short version is reassuring rather than alarming — these rules are mostly about being honest, not about red tape.

This is an educational guide, not legal advice. It explains what Article 50 actually says, who it touches, and the handful of practical steps that get a typical SME ready. We have kept the legalese to a minimum and linked to a practical Article 50 readiness checklist you can work through with your team.

What does EU AI Act Article 50 require, in plain English?

Article 50 sets out AI transparency obligations: in four specific situations, people must be told that they are dealing with AI rather than a human or with authentic, human-made content. The principle is disclosure, not prohibition. You are not being asked to stop using AI — you are being asked to be upfront about it.

Concretely, from 2 August 2026, four duties apply:

  1. Chatbots and AI assistants must let people know they are talking to a machine, not a person.
  2. Synthetic output — AI-generated audio, image, video, or text — must be marked in a machine-readable way so software can detect it as artificial.
  3. Emotion recognition and biometric categorisation systems must inform the people exposed to them that the system is running.
  4. Deepfakes (realistic synthetic images, audio, or video) and AI-generated text published to inform the public on matters of public interest must be labelled as artificially generated or manipulated.

That is the whole substance. Everything else is detail about who carries each duty and the narrow cases where a duty is relaxed. Crucially, Article 50 contains no exemption for small companies — a five-person agency and a multinational follow the same rules. The good news is that for most SMEs the obligations are light, and several of them are already handled by the AI vendors you buy from rather than by you.

Who actually has to do what: providers vs deployers

The Act splits responsibility between two roles, and knowing which one you are is the single most useful thing to grasp about this whole topic.

  • A provider builds or develops an AI system (or has it built) and puts it on the market under its own name. Think OpenAI, a generative-image platform, or a software company shipping its own model.
  • A deployer uses an AI system under its own authority in a professional context. Most SMEs are deployers: you use ChatGPT, Midjourney, a chatbot widget, or a copywriting tool that someone else built.

Article 50 assigns each duty to one role or the other:

Obligation (Art. 50) Whose duty What it means for a typical SME
(1) Disclose interactive AI (chatbots, voice bots) Provider designs it in; deployer should verify it Make sure your chatbot says it is a bot at first contact
(2) Machine-readable marking of synthetic output Provider Usually handled by your AI tool’s vendor — confirm they comply
(3) Inform people about emotion/biometric recognition Deployer Rare in SMEs; relevant only if you run such systems
(4a) Label deepfakes Deployer If you publish realistic AI images/video/audio, add a visible label
(4b) Disclose AI text on public-interest matters Deployer Label AI-written articles about health, politics, public affairs

The pattern is clear: the technical marking of AI output (paragraph 2) is the provider’s job, while the visible, human-facing disclosure of chatbots, deepfakes, and public-interest text falls largely to you as the deployer. For a normal SME this narrows the to-do list considerably. You are not expected to invent watermarking technology; you are expected to choose compliant tools and to be transparent with your own audience.

What counts as a chatbot disclosure?

If your site has a chatbot, virtual assistant, or automated phone line that talks to people directly, those people must be informed they are interacting with AI — clearly and at the latest at the moment of the first interaction, not buried in a privacy policy.

The provider of the system carries the formal obligation under Article 50(1), but as a deployer you should still check that the disclosure is actually visible. A short opening line such as “Hi, I’m an AI assistant — I can help with X” is enough. In its June 2026 guidelines, the European Commission was explicit that weak signals do not pass: a vague name like “Assistant”, a notice hidden in the terms of service, or disclosure only in technical metadata is not sufficient. Plain-language, visible notices are what regulators expect.

There is one statutory carve-out. Disclosure is not required where it is obvious to a reasonably well-informed person that they are dealing with AI. In practice this exception is narrow, and the Commission guidance reads it conservatively — so the safe and simple move is to label the bot anyway. It costs you one sentence.

When do you have to label deepfakes and AI images?

A deepfake under the Act is AI-generated or AI-manipulated image, audio, or video that resembles real people, objects, places, or events and would falsely appear authentic. If you (as a deployer) create one, you must disclose that it is artificially generated or manipulated.

Two points matter for SMEs. First, intent to deceive is irrelevant: the Commission has confirmed that whether content “falsely appears authentic” does not depend on whether you meant to mislead anyone. A photorealistic AI image in an ad needs a label even if you never intended to fool a single customer. Second, there is a reduced obligation for evidently artistic, creative, satirical, or fictional work. You still disclose, but in a way that does not spoil the experience of the work — for example, a discreet note in the credits rather than a banner across the image.

Routine, non-realistic visuals usually fall outside the deepfake definition. A clearly stylised illustration or an obvious cartoon does not “falsely appear authentic”, so it is not a deepfake. Where you are unsure, a small “AI-generated” label is a low-cost way to stay on the right side of the line and to keep your audience’s trust.

What about AI-written articles and blog posts?

Article 50(4) also covers AI-generated text published to inform the public on matters of public interest — topics such as health, politics, public administration, or current affairs. Such text must be disclosed as artificially generated.

The most important detail for SMEs is the editorial-responsibility exemption. If a human with relevant expertise reviews the text for its content, and an identifiable person or organisation holds editorial responsibility for it, the disclosure duty does not apply. The Commission has been clear that this means genuine review — spell-checking or light grammar correction is not enough. A human has to actually engage with the substance.

For a typical company blog, this is good news. A marketing article about your own products, or a general lifestyle post, is not usually “informing the public on a matter of public interest” in the regulatory sense. And where your content does touch public-interest topics, the normal editorial workflow — a knowledgeable person reviewing and signing off — keeps you outside the labelling requirement. Build that review step into your process and document who owns it.

Is there really a grace period before everything kicks in?

For most of Article 50, the date is firmly 2 August 2026. There is, however, a targeted easing for the technical marking duty.

Under the AI Omnibus package (a provisional agreement reached in 2026, not yet finally adopted at the time of writing), generative AI systems already on the market before 2 August 2026 would get until 2 December 2026 to meet the machine-readable marking requirement of Article 50(2). Because that is the provider’s duty in the first place, it mostly affects the vendors you buy from rather than your own operations — and because it is still provisional, you should not build your plan around it. Treat 2 August 2026 as your working deadline and let any extension be a bonus.

How should an SME prepare for Article 50? A simple plan

You do not need a compliance department. For most small businesses, getting ready means walking through a handful of questions and fixing the gaps. The steps below map directly to our Article 50 readiness checklist.

  1. Make an inventory of where you use AI. List every chatbot, generative tool, image/video generator, and AI writing assistant in your business. You cannot label what you have not mapped.
  2. Decide your role for each use — provider or deployer. Almost always you are a deployer. If you genuinely build and ship an AI system, look more closely at the provider duties.
  3. Check that your chatbots disclose themselves. Confirm there is a clear, visible “I’m an AI” message at first contact. Ask your widget vendor whether their tool meets Article 50(1).
  4. Confirm your AI vendors handle machine-readable marking. For images, video, audio, and text generators, ask suppliers how they comply with Article 50(2) — this is their job, and a straight answer is a good sign of a serious vendor.
  5. Add visible labels to deepfakes and realistic synthetic media you publish — even in advertising, and regardless of intent.
  6. Set an editorial-review step for AI-written content, especially anything touching public-interest topics, and record who holds editorial responsibility.
  7. Write down what you did. A one-page note describing your AI uses and the disclosures you apply is enough to show good faith and to bring new staff up to speed.

None of this requires special software. It is mostly a matter of switching disclosure on where it is off, and asking your suppliers the right questions.

The bigger picture: transparency as a trust advantage

It is easy to read a new regulation as a burden, but Article 50 lines up with what audiences increasingly expect anyway. People want to know when they are talking to a bot or looking at a synthetic image. Telling them plainly tends to build trust rather than erode it.

For an SME, that reframing is the useful one. The AI Act for businesses is not asking you to do less with AI — it is asking you to be open about it. Companies that adopt clear AI labelling early get two things at once: they are ready for 2 August 2026, and they signal to customers that they are an honest, modern operator. Work through the readiness checklist, have a short conversation with your AI vendors, and the practical side of Article 50 is well within reach for any small team. And if you want certainty beyond Article 50, an independent AI Act compliance audit will show you where the rest of the regulation touches your business.

This article is for general information about the EU AI Act and does not constitute legal advice. For obligations specific to your situation, consult a qualified professional.

Educational material, not legal advice. As of 2026 — interpretation of the EU AI Act may change.

Frequently asked questions

When do the EU AI Act Article 50 transparency obligations start to apply?

The Article 50 transparency obligations apply from 2 August 2026. A targeted easing under the provisional AI Omnibus package would give generative AI systems already on the market before that date until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2), but since that relief is not yet finally adopted, treat 2 August 2026 as the working deadline.

Does Article 50 apply to small businesses and micro-enterprises?

Yes. Article 50 contains no carve-out based on company size, so small businesses follow the same transparency rules as large ones. In practice the burden is usually light for SMEs, because most are deployers rather than providers, and the machine-readable marking duty falls on the AI vendors they buy from rather than on the SME itself.

What is the difference between a provider and a deployer under the AI Act?

A provider builds an AI system and puts it on the market under its own name. A deployer uses an AI system under its own authority in a professional context. Most SMEs are deployers. The split matters because Article 50 assigns the technical marking of AI output to providers, while visible disclosure of chatbots, deepfakes, and public-interest AI text falls largely on deployers.

Do I have to label AI-generated images even if I am not trying to deceive anyone?

If the image is a deepfake — realistic synthetic content that resembles real people, objects, or events and could appear authentic — then yes, you must disclose it as artificially generated regardless of intent. The European Commission has confirmed that the test does not depend on whether you meant to mislead. Clearly stylised or obviously non-realistic illustrations generally fall outside the deepfake definition.

Do AI-written blog posts need a disclosure label?

Only AI-generated text published to inform the public on matters of public interest (such as health, politics, or public affairs) needs disclosure. If a human with relevant expertise reviews the text for its content and an identifiable person holds editorial responsibility, the duty does not apply — but spell-checking or light grammar fixes alone are not enough. Ordinary marketing posts about your own products usually fall outside this requirement.

How should a chatbot disclose that it is AI?

Clearly and at the latest at the first interaction, using a plain-language, visible notice such as 'I'm an AI assistant.' The European Commission considers weak signals insufficient — a vague name, a line buried in the terms of service, or disclosure only in technical metadata does not meet the standard. There is a narrow exemption when it is obvious to a reasonably well-informed person, but labelling anyway is the simplest safe approach.

What are the penalties for not complying with Article 50?

Non-compliance with the transparency obligations can attract fines of up to 15 million euros or 3% of global annual turnover, whichever is higher. For most SMEs, though, compliance is straightforward and inexpensive, so the practical focus should be on getting the simple disclosures right rather than worrying about worst-case penalties.

Where can I find a practical checklist to get ready for Article 50?

Our Article 50 readiness checklist walks through inventorying your AI use, determining whether you are a provider or deployer, verifying chatbot and synthetic-content disclosures, confirming your vendors handle machine-readable marking, and setting an editorial-review step for AI text. It turns the obligations into a short, concrete to-do list for a small team.

Find out where AI will actually save you time

A free 30-minute discovery call plus an AI readiness audit. You leave with a concrete assessment — no strings attached.

Related articles

All articles →