EU AI Act: AI Labelling Rules from 2 August 2026
EU AI Act labelling rules apply from 2 August 2026. What chatbots, deepfakes, and AI-written text must disclose – and what is exempt.

Your website has had a chatbot for six months. It answers questions, collects enquiries, and works surprisingly well. From 2 August 2026, Article 50 of the EU AI Act introduces new transparency obligations.
If your business is outside the EU, this can still matter when you offer an AI system in the EU or its output is used there. There is no reason to switch the bot off. You should, however, know who is responsible for the notice, which images and texts need a label, and where many AI Act summaries are too broad. This article is a practical guide, not legal advice.
What Changes on 2 August 2026
The European Commission's current FAQ on Article 50 essentially asks a reasonable question: Can a person tell when they are interacting with AI or looking at artificially generated content?
That leads to several obligations:
- Interactive AI systems such as chatbots, AI agents, and avatars must clearly inform people that they are interacting with AI from the start of the first interaction. An additional notice may only be unnecessary when this is already obvious to an average user.
- Deepfakes must be clearly disclosed as artificially generated or manipulated by the time a person first encounters them. This covers realistic image, audio, or video content resembling existing or plausibly existing people, places, objects, or events.
- Certain AI-generated texts need a label when they are published to inform the public about a matter of public interest.
- Businesses using emotion recognition or biometric categorisation must also inform the people exposed to those systems. That is unusual on a standard company website, but it is part of Article 50 and should not disappear between the chatbot and deepfake headlines.
The distinction between a provider and a deployer is important. A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system professionally under its authority. Depending on the setup, one company can be both.
Machine-readable marking of generative AI output is the provider's responsibility. As an ordinary website operator, you do not have to invent watermarking, metadata, or detection technology for output from OpenAI, Google, or Anthropic.
“Wasn't the AI Act Postponed?”
Parts of it were. The general start of Article 50 was not.
The Digital Omnibus moved the deadlines for high-risk systems. Stand-alone high-risk AI covered by Annex III now follows on 2 December 2027. AI embedded in regulated products under Annex I follows on 2 August 2028. These categories include systems used for recruitment, credit scoring, and certain medical devices.
Article 50 is a separate transparency layer. The visible rules for AI interactions, deepfakes, and relevant text still start on 2 August 2026. Saying “the AI Act was postponed” is about as useful as saying “the train is delayed” while five different trains are listed on the board.
There is one limited transition rule. Generative AI systems already placed on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking requirement in Article 50(2). Again, this mainly concerns system providers.
As with Germany's BFSG accessibility deadline, it is worth reading the specific rule rather than relying on the shortest headline. High-risk obligations moved. Transparency towards users remains a live issue.
Does This Affect You? Three Common Website Cases
Most businesses do not need a legal inventory with 40 categories. Three cases cover much of what happens on an ordinary business website.
Case 1: Your Website Has an AI Chatbot
Yes, the AI interaction must be apparent. However, the legal obligation in Article 50(1) falls on the provider of the system. If you use an off-the-shelf third-party widget, its manufacturer is generally the provider. Simply using the widget does not automatically make your company the provider.
That does not mean you should ignore the issue. Check whether the bot clearly identifies itself as AI from the beginning of the interaction. A notice in the terms, privacy policy, or behind an information icon does not help the person in the conversation. A bot called “Lisa” introducing itself only as “your digital assistant” also leaves unnecessary room for interpretation.
If you developed the chatbot, commissioned it under your name, or substantially modified and launched it as your own system, you may become the provider. Bespoke implementations deserve a proper assessment of that role.
Case 2: You Use AI Images or Video in Advertising
It depends on the result. An obviously illustrative key visual is not automatically a deepfake. A photorealistic image that makes a real or plausibly existing person, place, or event appear authentic may qualify.
Similarity, context, and the audience's expectation all matter. Artistic, satirical, and fictional works receive more flexible treatment, but not a complete exemption from disclosure. The notice may be presented in a way that does not unnecessarily disrupt the work.
Case 3: AI Helps Write Your Blog or Newsletter
In most cases, no mandatory label is needed. Article 50 does not cover every sentence touched by AI. Its text rule has narrower conditions and an important exemption for substantive human review.
If you do not offer a chatbot as your own system and do not publish realistically deceptive AI media, your main task is therefore simple: perform one structured review instead of placing an AI badge on everything because of a general headline.
Why Your AI-Written Blog Post Usually Needs No Label
The text-labelling obligation only applies when three conditions come together:
- The text is published.
- It is intended to inform the public.
- It concerns a matter of public interest.
The European Commission includes politics, public administration, justice, fundamental rights, public security, health, environmental protection, consumer safety, and economic, scientific, or cultural developments that may become subjects of public debate.
A product description, service page, or specialist article about your own craft is not automatically covered. “Public interest” is broader than “politics,” though. An AI-generated article about a health hazard or major economic development could certainly fall within scope.
More importantly, there is an exemption for human review and editorial control. No mandatory label is required when a knowledgeable person genuinely reviews the substance, evaluates sources, has authority to change or reject claims, and assumes editorial responsibility. Running a spell-check is not enough. A real expert review is.
Every article on this website still states that it was drafted and translated with AI assistance. That would not be legally necessary in many cases. I keep the notice because transparency costs little and a later argument about it creates even less value.
The principle resembles AI-generated code. The tool can perform a considerable amount of work, but a person remains responsible for the result. My guide to where AI reaches its limits when building a website examines that distinction in more detail.
What This Means Technically for Your Website
A notice works when it appears where confusion could arise. A single footnote covering the whole website may be convenient to implement, but it is about as useful as storing the operating manual in the building next door.
For a chatbot, the notice should be visible in the widget and no later than the start of the first interaction. One sentence is enough: “You are chatting with an AI assistant.” With a purchased tool, first check what its provider already displays and whether you can configure the wording. Record which version and setting you reviewed.
For deepfakes, place the disclosure directly with the image, video, or audio. A person must be able to perceive it without specialist tools. Metadata alone does not meet that deployer obligation. Your CMS should not force editors to remember a manually typed note every time.
In Kirby, for example, you can add a field to the relevant file. When an editor classifies the asset as a deepfake or realistic synthetic medium, the frontend automatically displays the notice. My Kirby CMS and Nuxt workflow shows how structured fields become part of the frontend instead of an item on a publishing checklist.
For text that does require a label, place it visibly on the article. Do not hide it in the legal notice or a general AI policy that nobody sees while reading.
The basic principle is simple: labelling is a structural CMS decision, not a memory test for editors. Anything that depends on someone remembering it for every publication will eventually be forgotten.
Fines and Enforcement
Breaches of Article 50 can lead to fines of up to 15 million euros or 3 percent of worldwide annual turnover under Article 99. For businesses, the higher value generally applies.
The Regulation contains an important ceiling for small and medium-sized enterprises, including start-ups: their fine must not exceed the lower of the two values. Authorities must also consider the nature, severity, duration, and consequences of the infringement. A small local company does not automatically receive a €15 million bill because a line was missing from its chatbot.
Enforcement will mainly sit with national market-surveillance authorities. In Germany, the AI Market Surveillance and Innovation Promotion Act, known as the KI-MIG, gives the Federal Network Agency a central role in supervision, coordination, and complaints. The Bundestag and Bundesrat have approved the law. According to the German government, formal promulgation was still pending when this article was finalised on 27 July 2026.
In Germany, breaches may also become relevant under competition law and potentially lead to warning letters from competitors or qualified organisations. Whether a particular AI Act obligation qualifies as a market-conduct rule will need to be assessed case by case. Just before the rules begin to apply, there is naturally no settled case law on that question.
The sensible response is therefore neither panic nor inaction. Identify your role, review visible use cases, and document the result.
The 15-Minute Check
You can answer these five questions without starting a large legal project:
- Does your website use a chatbot, AI assistant, or voicebot? Check whether it is clear from the start that an AI system is responding.
- Who is the provider? Are you using an off-the-shelf product, a white-label solution, or a system developed under your own name? Record the answer and the provider's commitments.
- Do you use realistic AI images, voices, or videos? Check your website, social ads, and active campaigns, not only the blog.
- Who approves AI-assisted text on substance? Name a responsible person and document the editorial review. Grammar correction alone is not substantive control.
- Can your CMS display notices reliably? If a label is required, attach it to the content as structured data and render it automatically in the right place.
If you can answer all five clearly, you have covered most ordinary website scenarios. If the provider role or widget notice is already unclear, that is the first task to address.
Conclusion
The EU AI Act does not require a label on every piece of content that AI has touched. Article 50 is meant to provide transparency where artificial interaction or realistic manipulation might otherwise be mistaken for a person or authentic content.
For most businesses, the practical work is manageable: check the chatbot and provider role, inventory realistic AI media, and make editorial approval of text traceable. A blog post reviewed on substance by a responsible person will usually not need a mandatory label. Adding a voluntary notice remains perfectly reasonable.
Can visitors to your website immediately tell where AI is speaking to them or simulating reality?
I can review your chatbot, media, and editorial process with you. You will know which notices are actually required and how to implement them reliably in the frontend and CMS.
mail@eugen.workThis article was drafted and translated with AI assistance.