Ethics and Responsible Ai

EU AI Act Article 50: The SMB Checklist

Introduction

If your business runs a support chatbot, or if someone on your team uses an AI tool to draft marketing copy, you already have an AI system in scope of the EU AI Act’s transparency rules opens a new window . You don’t need to be doing anything exotic or high-risk to be covered. As of August 2, 2026, these rules are binding, and the European Commission’s AI Office, together with national market surveillance authorities, can enforce them opens a new window .

That catches a lot of businesses off guard, because most of the coverage of the AI Act so far has focused on high-risk systems: hiring tools, credit scoring, biometric surveillance. Those obligations are real, but they’re not due for a while yet, more on that below. The transparency tier is different: it applies now, and it applies broadly, to providers and deployers whose systems are placed on the EU market or whose output reaches EU users, so a US business with EU clients or site visitors is in scope too.

In this post, we’ll cover who’s actually in scope of Article 50’s transparency rules, the concrete steps you need to take, and what’s genuinely still years away.

Who’s actually in scope

Most of what got written about the EU AI Act in 2024 and 2025 focused on its risk tiers: unacceptable risk (banned outright), high-risk (strict conformity requirements), and everything else. If you weren’t building a hiring algorithm or a credit-scoring model, it was easy to conclude the Act didn’t apply to you.

Article 50 doesn’t work off that classification. It’s a separate, horizontal layer of obligations that applies based on what an AI system does, not how risky regulators judged it to be. A system that interacts directly with people, like a chatbot or a virtual agent, is in scope. A system that generates or manipulates content, text, image, audio, or video, is in scope, whether or not a person reviews the output before it goes out. A system that performs emotion recognition or biometric categorization is in scope. None of these is classified as high-risk under the Act’s own tiers, and all three are covered by Article 50 regardless.

A support chatbot on your website is the first category. AI-drafted marketing copy or blog content is the second. Neither reads as “high-risk AI” to most SMB owners, which is exactly why this tier catches people who assumed they were in the clear.

Scope isn’t limited to companies established in the EU, either. The obligations reach any provider or deployer whose AI system is placed on the EU market, or whose output is used by people in the EU. A US-based business with EU customers interacting with its chatbot, or an EU audience reading its AI-drafted content, is in scope on that basis alone.

What Article 50 requires

Per the Commission’s guidelines on Article 50 opens a new window , the obligations break down by what your system does and who you are in the transaction: provider (the business that builds or supplies the AI system) or deployer (the business that uses it). For most SMBs reading this, you’re a deployer: you didn’t build the chatbot or the generative model, you’re running one someone else built.

In practice, that means:

If you have… You must… Format
A chatbot or AI agent that talks to customers Disclose that it’s AI, unless already obvious from context Clear disclosure
AI-generated text, image, audio, or video Mark it as artificially generated Machine-readable
Deepfake-style media resembling real people, places, or events Visibly label it Visible label
AI-generated text on matters of public interest Flag it as AI-generated, unless a human reviewed it and takes editorial responsibility Visible disclosure
Emotion recognition or biometric categorization systems Inform the people being assessed Notice at point of use

If your chatbot already says “AI Assistant” in its name or interface, you likely already satisfy the first row. If your marketing team publishes AI-drafted blog posts or social copy without a human edit pass, the fourth row is the one to look at first, it’s also the easiest to miss, since “matters of public interest” is broader than it sounds and covers ordinary commentary, not just news reporting. (If AI-drafted marketing copy is new territory for your team, we’ve also covered the privacy and security side of adopting AI tools opens a new window , which is a separate concern from Article 50 but tends to come up around the same time.)

For the marking and labeling rows, you don’t have to invent a visual system from scratch. The Commission publishes a set of standard EU icons for labeling AI-generated content opens a new window : a basic icon for AI involvement in deepfake or published text, a “fully AI-generated” icon for wholly synthetic content, and a “partially AI-modified” icon for human content that’s been altered with AI. Using these specific icons is optional, but whatever marking you use has to meet the same bar: it needs to be clearly perceivable at the point someone first encounters the content, embedded directly in it rather than living in a separate disclaimer page, and it has to survive the content being reshared or downloaded. The icons themselves are free, available as SVG or PNG, in black or white with optional transparency, which makes them a reasonable default if you don’t want to design your own.

For the other two rows, disclosing a chatbot and notifying people subject to emotion recognition or biometric categorization, the guidelines don’t prescribe an exact format. A clear statement in the interface satisfies the chatbot disclosure; there’s no required certification or specific wording.

There’s one exception worth knowing about if you were already running a generative AI system before August 2, 2026: providers get a four-month transitional period to adapt existing practices to the new marking requirements. The obligation itself isn’t delayed, the grace period only covers systems that were already on the market. If you’re deploying something new now, it doesn’t apply to you.

The cheap compliance route

You don’t have to work out how to satisfy Article 50 from scratch. The European Commission published a Code of Practice on Transparency of AI-generated Content opens a new window specifically to give providers and deployers a pre-approved way to comply: one section covers marking and detecting AI-generated or manipulated content (the provider side), the other covers labeling deepfakes and AI-generated text (the deployer side, which is the one most SMBs will use).

By the end of July 2026, around 190 companies and organizations had signed it. Signing means you can point to the Code’s measures as your compliance approach, rather than building your own justification for a regulator. It also buys predictability: signatories get the same treatment across every EU member state, instead of a patchwork of national interpretations, and get a seat in the taskforces that shape how the Code evolves.

You don’t have to sign it. But if you don’t, the burden shifts to you: you have to independently demonstrate that whatever alternative measures you built are adequate, and that gets assessed case by case by whichever member state’s market surveillance authority is looking at you. For an SMB without in-house legal counsel, adopting the Code’s existing measures is very likely the cheaper path, both in setup cost and in what happens if a regulator ever asks.

What’s not due yet

The AI Act’s high-risk tier obligations, the ones for hiring algorithms, credit scoring, and similar systems under Annex III and Annex I, got a real timeline change this year. The Digital Omnibus opens a new window (Regulation (EU) 2026/1744, in force since July 27, 2026) pushed the Annex III deadline (AI systems classified as high-risk under Article 6(2)) from August 2, 2026 to December 2, 2027. It pushed the Annex I deadline (product-embedded high-risk systems under Article 6(1)) from August 2, 2027 to August 2, 2028.

If your business isn’t in one of those high-risk categories, this section doesn’t change anything for you, Article 50 still applies now, as covered above. But it’s worth knowing about for two reasons. First, if a consultant or a client asks you about AI Act “deadlines” broadly, they may be thinking of these dates, not Article 50’s. Second, a lot of what’s published online about the AI Act’s timeline hasn’t caught up with the Omnibus yet.

We checked one of the more commonly cited trackers, artificialintelligenceact.eu’s implementation timeline opens a new window , while writing this. As of this writing, it states: “2 August 2027: Application: Article 6(1) and the corresponding obligations in the Regulation start to apply,” with no mention of the Omnibus or Regulation (EU) 2026/1744 anywhere on the page. That’s the pre-Omnibus date. The actual date is now a year later, August 2, 2028. If you’re relying on a bookmarked timeline page instead of checking the regulation directly, you may be working from a schedule that’s already out of date.

Penalties and enforcement

Enforcement sits mainly with national market surveillance authorities in each member state; the AI Office’s own enforcement role is narrower, reaching only systems built on general-purpose AI models where the same company is both provider and model-maker, or systems folded into a DSA-designated very large online platform or search engine. As of August 2, 2026, both have the authority to act on Article 50 violations, not just issue guidance.

The headline number is up to €15 million or 3% of global annual turnover, whichever is higher, for non-compliance with the transparency obligations. EU institutions, bodies, and agencies face a separate, lower ceiling of €750,000.

If you’re an SME or a small mid-cap company, including a startup, the Act caps your fine at whichever of the two figures is lower, the percentage or the fixed amount, not whichever is higher, as applies to larger companies. In practice, that makes 3% of turnover the real ceiling for most small businesses, not €15 million. The obligations still apply in full either way, this only changes what a violation can cost you.

Conclusion

This should give you a very good idea of who’s actually in scope of Article 50 (probably you, if you’re running a chatbot or generating AI content), the five things the transparency tier actually requires, the Code of Practice as the lower-effort way to demonstrate compliance, and the higher-risk obligations that are still years away regardless of what an old bookmark might say.

None of this is legal advice, and guidance in this area is still evolving even as enforcement starts. If your business touches any of the five categories above, the practical next step is to check your own systems against them directly, rather than assuming a chatbot or a content workflow is too small to count. And if you’re still deciding where AI belongs in your business in the first place, that’s a question worth answering before a compliance one, we’ve written about finding the right problems to solve with AI opens a new window too.

Not sure whether your chatbot or your AI-generated content already meets Article 50? Let’s talk opens a new window .

Our AI Services

Turn your data into a competitive advantage

View AI Services opens a new window