Since 2 August 2026, a small or mid-sized business using AI in its customer relationship must inform people in three specific situations: a direct exchange with a conversational system, a published deepfake, and a public-interest text published without human review. Outside those cases, no "AI-generated" label is legally required.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Since 2 August 2026, a small or mid-sized business using AI in its customer relationship must inform people in three specific situations: a direct exchange with a conversational system, a published deepfake, and a public-interest text published without human review. Outside those cases, no "AI-generated" label is legally required. Confusing the three with the rest of your communication is expensive in both directions, through over-compliance and through blind spots.
Article 50 of Regulation (EU) 2024/1689 is probably the AI Act provision that affects the largest number of European businesses, because it does not depend on the risk level of the system. A ten-person company running a chatbot on its website is in scope, even though it falls entirely outside the high-risk obligations. If you are starting from scratch, the AI Act compliance guide for SMEs and nonprofits sets out the general framework; this article focuses on a single angle, your customer touchpoints.
Four distinct obligations, split between two different roles. The AI Act separates the provider, who designs the system and places it on the market under its own name, from the deployer, who uses it in a professional capacity. The obligation does not land on the same party in every case.
| Situation | Who is bound | What is required |
|---|---|---|
| System interacting directly with a person (chatbot, voice agent, avatar) | The provider | Inform the person from the first interaction that this is AI, unless it is obvious |
| Output of a generative AI system (text, image, audio, video) | The provider | Machine-readable marking allowing synthetic content to be detected |
| Emotion recognition or biometric categorisation | The deployer | Inform exposed persons that the system is operating |
| Published deepfake, or public-interest text published without human review | The deployer | Clear, perceivable disclosure, at the latest on first exposure |
For most SMEs, only rows 1 and 4 matter. Row 2 sits with model and system vendors, not with you. Row 3 only concerns biometric use cases, which are rare outside access control and advanced retail.
One vocabulary point with legal consequences: your employees are not separate deployers. When your community manager generates a visual with an AI tool, the company is the deployer, not the individual. And you remain the deployer even when the work is handled by a freelancer or an agency acting under your responsibility. A subcontracting agreement does not transfer the obligation.
The duty to tell a user they are talking to a machine sits with the system provider, but you can become that provider without realising it. Article 3(3) defines a provider as an entity that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.
Take the very common case of a company deploying an AI chatbot on its website, built on an off-the-shelf platform, renamed "Lea, your adviser" and dressed in the company's own branding. The company developed nothing, but it puts the system into service under its own name. The prudent reading is to assume it carries the Article 50(1) information duty and to act accordingly. Waiting for case law before displaying a ten-word sentence makes no economic sense.
The Commission has set out four cumulative criteria for the obligation to apply: the system must qualify as an AI system, be designed for genuine two-way exchange rather than mere data collection or automated replies, communicate directly with the person without a human intermediary, and address natural persons. A contact form with an automatic acknowledgement is therefore out of scope. An AI agent qualifying a prospect in free conversation is in scope.
In practice, three formal requirements:
The "obvious" exception exists, but the Commission explicitly asks for it to be read narrowly, since it deprives people of transparency. The test is that of an average person, reasonably well-informed and observant. A realistic avatar answering in natural language does not pass that test. A window labelled "Automated assistant" probably does, but the cost of an explicit mention is zero, so write it anyway.
A blog post, a product sheet or a newsletter drafted with AI assistance does not need an "AI-generated" label. This is the opposite of what a large share of published commentary suggests, and it deserves to be stated plainly.
The labelling duty for AI-generated text under Article 50(4) rests on three cumulative conditions: the text must be published, intended to inform the public, and concern a matter of public interest. The Commission lists as matters of public interest politics and democratic processes, public administration, justice, fundamental rights, public security, public health, environmental protection, consumer safety, and any economic, financial, scientific or cultural development that may be a relevant subject of public debate.
A product sheet, a sales reply, meeting minutes or a service page do not fall into that category. And even for content that would, the obligation falls away if the text has undergone human review or editorial control. The Commission is specific about what counts: deliberate examination of the substance by a person with relevant knowledge of the subject, or control exercised by an editorial entity with authority to approve, alter or reject the content on substantive grounds. Spell-checking or a formal proofread does not qualify.
The operational consequence is straightforward. If you publish on matters of public interest, which is the case for an accounting firm commenting on a tax reform or a nonprofit publishing on health, your protection is not a footer label: it is a documented review process, with a named person holding final editorial responsibility. Incidentally, that is also the only real defence against factual errors from the models, what the industry calls hallucinations.
Why over-compliance carries a real cost: an "AI-generated content" label applied everywhere dilutes the signal where it matters, feeds distrust of content you genuinely worked on, and exposes you to customer questions you have no considered answer to. Labelling what must be labelled, and only that, is a defensible position. Labelling everything as a precaution is not.
As soon as a visual or a video credibly imitates a real person, place or event, disclosure becomes mandatory for the deployer. The Article 3(60) definition rests on three cumulative criteria: strong resemblance to the simulated subject, a subject that exists or could plausibly exist, and a false appearance of authenticity.
The concrete cases that pull an SME into this obligation are more frequent than people assume:
Two important points. First, disclosure must be perceivable by a human being, through a visible or audible label, without technical tools. You cannot rely on the machine-readable marking embedded by the tool vendor: the Commission explicitly rules that out. Second, for evidently artistic, creative, satirical or fictional works, disclosure is still due but can be adapted so it does not spoil the work, for instance in the credits rather than as a permanent overlay.
Synthetic customer testimonials deserve a specific flag. Beyond the AI Act, they engage national consumer law on misleading commercial practices, enforced in France by the DGCCRF. The two regimes stack, and the second one is older and better equipped. Before running any campaign built on synthetic characters, have the setup reviewed by your legal counsel: the exposure is not only regulatory, it is contractual and competitive.
Article 50 has applied since 2 August 2026, with no general transition period. That is the date to remember. 2 December 2026 circulates widely, but it means something else: a grace period limited to the machine-readable marking duty under Article 50(2), and only for systems placed on the market before 2 August 2026. That tolerance is aimed at system vendors, not at business users.
Another useful point: content generated before 2 August 2026 does not need retroactive labelling. The Commission encourages it where possible but does not require it. There is no need to work back through three years of archives.
Keep in mind as well that the Digital Omnibus package, adopted in summer 2026, postponed the application of the rules on standalone high-risk systems to 2 December 2027, and to 2 August 2028 for those embedded in regulated products. Many articles still online date these deadlines to 2026, which is out of date. The full breakdown is in the complete AI Act timeline.
A breach of Article 50 falls under the cap of 15 million euros or 3% of total worldwide annual turnover, whichever is higher. For an SME the logic is reversed: the lower amount applies, and the Commission states that proportionality is taken into account for SMEs and small mid-cap companies.
Enforcement sits mainly with national market surveillance authorities. In France several bodies act depending on the angle, the CNIL on personal data, the DGCCRF on commercial practices, Arcom on distributed content. The precise allocation of competences is still settling, so check the current national arrangement before relying on a fixed split.
Regulatory risk is not the first one our clients meet, though. Commercial risk comes first. A prospect who later discovers they spent twenty minutes talking to a conversational agent while believing they were speaking to a salesperson does not file a complaint: they leave. A competitor who spots an undisclosed synthetic testimonial, on the other hand, has an immediate lever on unfair competition grounds. The penalty regime is covered in detail in the article on AI Act sanctions.
Article 50 compliance for an SME fits on one page, provided you reason by customer touchpoint rather than by tool.
Point 5 is the one that holds over time. The first four are one-off actions; without a written rule, your compliance degrades with the first new hire. For formalising this towards exposed individuals, the AI information notice sets out the expected structure.
Do I have to write "AI-generated" on my blog posts? No, unless the post informs the public on a matter of public interest and has had no substantive human review. A documented editorial review by a competent person removes the obligation. A simple spell-check does not.
Does my chatbot have to announce it is an AI even when it is obvious? The "obvious" exception exists, but the Commission asks for it to be read narrowly. Since an opening sentence costs nothing and the test depends on how an average person perceives the interaction, displaying it every time is the safer call.
I did not build my chatbot, am I still responsible? The information duty sits with the provider. But if you put the system into service under your own name or trademark, the provider definition may apply to you. The prudent reading is to take on the obligation rather than rely on your contract with the vendor.
Does AI retouching make a photo subject to disclosure? Not automatically. Standard editing assistance functions are excluded from the marking duty. The tipping point is when the result credibly imitates a real person, place or event and could be taken as authentic.
Does the 2 December 2026 deadline give me extra time? No. That deadline only covers the machine-readable marking duty for providers of systems already on the market before 2 August 2026. Your deployer duties and customer information duties have applied since 2 August 2026.
Are my employees personally liable for these notices? No. An employee acting under the instructions and control of the company is not a separate deployer. Liability remains with the legal entity, including where execution is handed to an external provider.
Should we sign the Commission code of practice? The code of practice on transparency of AI-generated content is voluntary. It gives legal certainty to providers and deployers who sign it, but not signing is not a fault: it simply means demonstrating compliance by other adequate means.
We treat Article 50 as a half-day piece of work, not a compliance programme. The useful part is always the same: map the customer touchpoints, settle the cases, write the internal rule, and train the people who actually produce the content. That last step is the one most often missing, because a memo does not change production habits.
Our Operational AI for SMEs programme covers the transparency angle inside the concrete use cases rather than treating it as a separate legal module. Teams learn where to place the notice at the same time as they learn to produce the content. For organisations that want a stocktake first, the AI Act practical guide for small businesses gives the full framework, and the AI Act compliance guide is the entry point to the whole topic.
If you want to know in thirty minutes where you stand on your customer touchpoints, book a free audit at cal.com/growthperf/audit-gratuit.