Why this matters
The Article 50 AI Act transparency duties have applied since 2 August 2026. A customer-facing chatbot or professionally published AI content can already raise compliance questions. Small businesses do not need to treat every AI tool as high-risk, but they should deliberately document interactions, roles, disclosures, and human responsibility.
Turn knowledge into a start plan
This guide explains one topic. Whether it is really a priority for you right now depends on your answers in the start plan.
Create start planWhat has applied since 2 August 2026
The EU AI Act uses different risk levels and legal roles. For many side businesses, the first point of contact is not the high-risk chapter but Article 50. It contains transparency rules for certain interactive and generative AI systems, deepfakes, emotion recognition, and biometric categorisation.
This does not mean that every professional use of ChatGPT, Claude, Canva, or an AI assistant must be publicly labelled. What matters is what the system does, whether people interact with it directly, whether content is published, and whether you act as a provider or deployer.
Other rules continue to apply alongside the AI Act. A disclosure does not resolve data protection, copyright, unfair-commercial-practices, trade-secret, or professional-confidentiality questions.
Provider or deployer: what is your role?
A business using a ready-made AI tool is often a deployer. A business that develops a system, places it on the market under its own name, or substantially changes its intended purpose can take on provider duties. A branded chatbot built on a third-party model therefore needs a setup-specific role assessment.
A small AI register is useful in practice: record the tool, vendor, purpose, input data, affected people, output, human review, and public disclosure. This turns vague AI use into a process that can actually be reviewed.
Contractual statements from the tool vendor matter, but they do not replace your assessment as the business using the system. Customer service, employment, credit, insurance, health, and sensitive-data use cases can trigger additional rules.
Chatbots must be recognisable as AI from the start
When a system communicates directly with people, they must generally be informed clearly and distinctly that they are interacting with AI. The notice should appear no later than the start of the first interaction and meet accessibility requirements. The exception for interactions that are already obvious to an average, reasonably informed person is interpreted narrowly in the EU guidance.
A clear opening could say: ‘Freya is an AI assistant and can make mistakes.’ A fictional name, a vendor reference only in the privacy policy, or a small notice appearing after several messages is an unnecessarily risky stand-alone solution.
The disclosure should match the real function. It must not imply that a human professional is reviewing the conversation live when that is not true. Visible limits also matter: no binding legal or tax advice, avoid sensitive data, and verify critical results against official sources.
When AI-generated content needs disclosure
Providers of generative systems have duties including machine-readable marking that makes synthetic or manipulated output detectable. A business merely using a third-party tool usually cannot implement that provider-side measure itself, but it should check which provenance signals the tool creates and whether they survive export and editing.
Deployers must visibly disclose deepfakes in particular. AI-generated or manipulated text published to inform the public about matters of public interest can also require disclosure. For that type of text, an exception can apply where the content underwent human review or editorial control and a natural or legal person holds editorial responsibility.
This does not automatically make every product description, draft, or internal email suggestion subject to a label. Published facts, quotations, images, voices, and videos should still be checked carefully. Transparency is not a substitute for accuracy and editorial responsibility.
A workable AI process for a small business
Start with risk rather than a long policy: does AI only suggest internal wording, does it communicate directly with customers, or does it influence decisions about people? The closer it gets to individuals, money, health, or legal effects, the more important human and specialist review becomes.
Define which data must not be entered, who approves output, how errors are reported, and which vendor information you retain. Employees and collaborators need AI literacy appropriate to their tasks; the duty to ensure sufficient AI literacy has applied since February 2025.
Review the process regularly. Models, functions, subprocessors, and terms change. A short repeatable review is therefore more useful than a one-time tool approval.
Quick checklist
- List every AI tool used professionally, including its purpose and vendor.
- Check whether you are a deployer, provider, or potentially both.
- Disclose direct AI interaction clearly from the first message.
- Make the notice and interaction understandable with a keyboard and assistive technology.
- Check deepfakes and relevant AI content for disclosure duties before publication.
- Document human review and editorial responsibility.
- Restrict confidential, personal, and third-party protected content.
- Train employees and collaborators for their actual use cases.
- Recheck the tool, privacy setup, disclosure, and approval process regularly.
Common mistakes
- Treating every AI use as high-risk—or ignoring the AI Act completely.
- Assuming a fictional name makes it obvious that users are interacting with AI.
- Hiding the AI notice only in the privacy policy or terms.
- Confusing an AI label with a substantive quality review.
- Removing machine-readable provenance signals during editing or export without noticing.
- Entering customer or employee data into public AI services without a clear approval process.
Frequently asked questions
Does every AI-assisted social media post need a label?
No, not automatically. For deployers, the main Article 50 questions include deepfakes and AI-generated or manipulated text about matters of public interest. Advertising rules, factual accuracy, and third-party rights still apply regardless of an AI label.
Is naming the AI vendor in the privacy policy enough?
For direct AI interaction, a privacy notice alone is generally not the practical safe approach. The person should be able to recognise clearly from the start of the first interaction that they are communicating with an AI system.
Do I automatically become a provider when I add an AI API to my website?
Not automatically. Branding, intended purpose, your role in placing the system on the market, and any substantial modifications matter. A customer-facing product under your own name deserves a setup-specific assessment.
What this guide can and cannot do
This guide helps with
- sort your AI use cases into internal, customer-facing, and public uses
- create a disclosure and approval checklist for your setup
- flag common questions about data, content, and legal roles
This guide does not replace
- make a binding determination of your provider or deployer role
- replace a legal review of high-risk, privacy, or copyright questions
- guarantee that AI output is accurate or free of third-party rights