All articles

AI Act

On 2 August, Your Chatbot Must Say It's a Bot. The AI Deadline the Omnibus Didn't Move.

Everyone heard the AI Act was delayed sixteen months. Article 50 wasn't. From 2 August 2026, your chatbot must say it's a bot — fines up to €15M or 3%.

Sylvio Sorel··5 min read
A 3D-rendered white robot with an AI badge working at a laptop, illustrating the EU AI Act Article 50 chatbot disclosure obligation.

If you followed the AI Act news this spring, you probably retained one headline: the big deadlines moved. The Omnibus package — politically agreed on 7 May, endorsed by Parliament on 16 June, adopted by Council on 29 June — pushed high-risk deployer obligations to December 2027 and product-embedded AI rules to August 2028. We covered why that reprieve is smaller than it looks in our AI Omnibus analysis.

Here is the part that got lost in the coverage: Article 50 was not delayed. The AI Act’s transparency obligations apply from 2 August 2026, exactly as scheduled. If your website runs a customer-service chatbot, if your team publishes AI-generated images or video, if your call centre uses an AI voice agent — you have obligations that bind in under two weeks, backed by fines of up to €15 million or 3% of worldwide turnover under Article 99(4).

The four obligations, in plain terms

Article 50 is short by AI Act standards. It creates four transparency duties, split between the people who build AI systems (providers) and the people who use them in business (deployers).

One — your bot must introduce itself. AI systems intended to interact directly with people — chatbots, virtual assistants, automated phone agents — must be designed so the person knows they are talking to a machine, unless that is obvious from context. The design duty sits with the provider; if the bot speaks under your brand to your customers, the practical exposure is yours.

Two — synthetic content must be machine-readable. Providers of systems that generate synthetic audio, images, video or text must mark outputs in a machine-readable format, detectable as artificially generated. If you use third-party tools, this marking duty belongs to the tool’s provider — but verifying that your tools comply belongs on your vendor checklist.

Three — emotion recognition and biometric categorisation must be disclosed. Deployers of these systems must inform the people exposed to them. Most SMBs are nowhere near this territory; HR analytics and customer-sentiment tools are where it quietly appears.

Four — deepfakes and public-interest text must be labelled. Deployers who publish AI-generated or manipulated image, audio or video content that resembles real people, places or events must disclose the manipulation — irrespective of intent to deceive. AI-generated text published to inform the public on matters of public interest needs the same disclosure, unless it went through human editorial review with someone taking responsibility.

Article 50 at a glance Article 50 at a glance — four transparency obligations, who bears each one, and the everyday systems they catch.

This is not a law about AI companies

The obligations read like they target Silicon Valley. They don’t. A 60-person accounting firm with a website chatbot, a manufacturer whose marketing team generates product visuals with Midjourney, a broker whose customer line is answered by an AI voice agent — all of these are in Article 50 territory on 2 August.

The pattern will be familiar if you read our DORA and NIS2 coverage: the businesses most exposed to a new EU regulation are rarely the ones it was written about. They are the ones who concluded it was written about someone else.

The tooling arrived just in time

Two Commission instruments landed this summer, and both are worth knowing before you spend money on advice.

The Code of Practice on transparency of AI-generated content was published in final form in June 2026. Once assessed by the Commission and the AI Board, adherence to the Code becomes a recognised way to demonstrate compliance with the marking and labelling duties — signatories carry a lighter evidential burden. The signatory window closes on 22 July 2026. For most SMBs the Code matters less as something to sign than as the clearest available description of what “machine-readable marking” and “clear labelling” actually mean in practice.

Alongside it, the Commission’s draft guidelines on Article 50 — covering scope, definitions and the exemptions — completed consultation, with the final version expected before the deadline. One transitional detail matters for planning: systems already on the market before 2 August benefit from an extended window, to 2 December 2026, for the machine-readable marking requirement specifically. The disclosure duties themselves are not deferred.

What it costs to ignore

Article 99(4)(g) sets the fine for Article 50 violations at up to €15 million or 3% of total worldwide annual turnover, whichever is higher — the middle tier of the AI Act’s penalty ladder, calibrated downward for SMEs. Enforcement sits with national market surveillance authorities, and the reputational mechanics are worse than the fine: an unlabelled deepfake or an undisclosed bot is exactly the kind of finding that surfaces in a customer due-diligence questionnaire, a procurement review, or a journalist’s inbox.

And the quieter cost: Article 4 AI literacy has been binding since February 2025. A staff member who publishes unmarked synthetic content because nobody trained them is evidence of two failures, not one. Literacy obligations integrate cleanly into existing training and awareness programmes — this is the cheapest gap on the list to close.

The two-week sprint

The two-week sprint The two-week sprint: what a deployer can close before 2 August.

Two weeks is enough, because for most SMBs this is an inventory-and-disclosure exercise, not an engineering project. Step one: inventory every customer-facing AI touchpoint — chatbots, voice agents, published AI-generated content — and note which of the four obligations each one triggers. Step two: fix the disclosures — bot self-identification copy, deepfake labels on published content, a vendor question to every generative-AI tool provider about their marking compliance. Step three: document it — a one-page Article 50 register, the vendor answers, and the training record showing staff know the rules. That file is what turns “we think we comply” into something you can show a market surveillance authority, a customer, or your board.

Our AI Governance & Security service runs this as the opening move of a broader AI Act readiness engagement — the same inventory feeds the high-risk classification work the December 2027 deadline will eventually demand.

Sylvio Sorel

CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor — founder, Cyber-Management.

Take the next step

Talk to a security practitioner, not a salesperson.

Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.