On May 7, 2026, the European Commission's Digital Omnibus reached political agreement. On June 16, 2026, the European Parliament gave final approval โ€” 423 votes to 57, with 174 abstentions. Headlines everywhere read: "EU delays AI Act." Small business owners across Europe read those headlines, breathed a sigh of relief, and moved on.

They shouldn't have.

The delay applies to high-risk AI systems under Annex III of the AI Act โ€” things like AI used in hiring, credit scoring, or biometric identification. Those obligations move to December 2, 2027.

What did not move is Article 50 โ€” the transparency rules that apply the moment your business lets a customer talk to a chatbot, or publishes AI-generated text, images, audio, or video that could be mistaken for something human-made. Those obligations take effect on August 2, 2026 โ€” regardless of your company's size, sector, or risk level.

If your business runs a website chatbot, a customer-support bot, an AI voice assistant, or publishes AI-generated marketing copy, images, or video to EU customers, this deadline applies to you. Here's exactly what the law requires, who enforces it, what the fines look like, and a same-week checklist to close the gap.

The AI Act was delayed for high-risk systems until December 2027 โ€” but the chatbot and AI-content transparency rules (Article 50) were not delayed, and they apply from August 2, 2026.

What the Digital Omnibus Actually Changed โ€” and What It Didn't

What was delayed

What was not delayed

The confusion is understandable โ€” and it's exactly why this gap matters. Multiple law firms have flagged the same pattern: executives read "AI Act delayed," assume their AI chatbot or AI-generated content is now exempt, and take no action. It isn't, and inaction here carries real financial exposure.

What Article 50 Actually Requires

Article 50 is built around a simple principle: people interacting with AI, or consuming AI-generated content, have a right to know it. In practice, it creates four separate disclosure obligations. Not every business will trigger all four โ€” but most SMBs with any customer-facing AI will trigger at least one.

1. Chatbots and conversational AI

If a customer or website visitor interacts with an AI system โ€” a support chatbot, a booking assistant, a voice IVR โ€” they must be informed they are interacting with an AI system, unless it is obvious to a reasonably well-informed person given the circumstances and context of use.

2. AI-generated or manipulated content ("deepfakes")

AI-generated or manipulated image, audio, or video content that resembles real people, objects, places, or events, and would falsely appear authentic, must be labelled as artificially generated or manipulated.

3. AI-generated text on matters of public interest

AI-generated or manipulated text published to inform the public on matters of public interest must be disclosed as artificially generated, unless it has undergone human review and a natural or legal person holds editorial responsibility for its publication.

4. Emotion recognition and biometric categorisation

Deployers of an emotion-recognition system or a biometric categorisation system must inform the individuals exposed to it of the system's operation.

Who This Applies To

Any business โ€” EU-based or not โ€” whose chatbot, AI content tool, or AI-generated marketing reaches users in the EU. Company size and risk classification do not exempt you from Article 50. Like the rest of the AI Act, it applies based on where your users are located, not where your company is headquartered.

What Happens If You Don't Comply

Article 50 non-compliance is enforced under the AI Act's own penalty regime, separate from GDPR fines. Multiple EU law firms confirm the exposure: non-compliance with the Article 50 transparency obligations may attract administrative fines of up to โ‚ฌ15 million, or up to 3% of total worldwide annual turnover โ€” whichever is higher.

For context on how seriously EU regulators pursue transparency and disclosure failures more broadly: cumulative GDPR fines have now passed โ‚ฌ7.1 billion since May 2018, across more than 2,800 decisions, with โ‚ฌ1.2 billion issued in 2025 alone, and European data protection authorities now receive an average of 443 data breach notifications every single day. Regulators are resourced, active, and increasingly willing to act on smaller companies โ€” not just large platforms.

Your Same-Week Compliance Checklist

You do not need a legal department to close this gap. Most SMBs can complete the following in a single working session.

  1. Inventory every customer-facing AI touchpoint: website chatbot, WhatsApp/Messenger bot, voice IVR, AI email responder, AI-generated ad creative or product images. (This week)
  2. Add a clear, plain-language disclosure at the first point of contact with any chatbot (e.g. "You're chatting with an AI assistant") before or at the start of the conversation. (Before Aug 2)
  3. Label AI-generated or edited images, audio, or video used in marketing with a visible or embedded disclosure where it could otherwise be mistaken for authentic content. (Before Aug 2)
  4. Review any AI-written blog posts, articles, or public-interest content; add a disclosure unless a named person has taken editorial responsibility after human review. (Before Aug 2)
  5. Check contracts with any AI vendor (chatbot platform, AI writing tool, image generator) for who is responsible for the disclosure obligation โ€” you or the vendor. (This week)
  6. Update your privacy notice and terms of use to reference AI-system use consistent with your Article 50 disclosures. (Within 2 weeks)
  7. Document what you did and when โ€” a simple compliance log is your best evidence if a regulator or customer ever asks. (Ongoing)

Sample Disclosure Language You Can Use Today

The law does not require specific wording โ€” only that the disclosure be clear, timely, and understandable to an average user. Below are starting templates; adapt them to your brand voice and language.

For a chatbot

"Hi! You're chatting with our AI assistant, not a human. I can help with [common tasks]. If you'd like to speak with a team member, just ask."

For AI-generated images or video

"This image/video was created or modified using AI." โ€” displayed visibly on the asset or in an adjacent caption/metadata field.

For AI-assisted articles or blog content

"This article was drafted with AI assistance and reviewed and approved by [Name], [Role]." โ€” or, where no named reviewer takes responsibility: "This content was generated using artificial intelligence."

If you serve customers in more than one EU member state, your disclosure should appear in the language of the interface the user is using โ€” not only in English.

Frequently Asked Questions

Does this apply if I'm not based in the EU?

Yes. Article 50, like the rest of the AI Act, applies based on where your users are located, not where your company is headquartered. If your chatbot or AI content reaches people in the EU, the obligation applies.

Does my business need to be "high-risk" for this to apply?

No. This is the most common and costly misunderstanding. Article 50 transparency obligations apply regardless of risk classification โ€” they are a separate, universal layer of the AI Act, not part of the high-risk regime that was delayed.

Is a simple "Powered by AI" badge in my footer enough?

It depends on visibility and timing. The disclosure needs to reach the user before or at the point of interaction, in a way a reasonably informed person would notice โ€” a small permanent footer badge may not be sufficient on its own for a chatbot conversation, though it can be part of a layered approach.

What if my chatbot platform (e.g. a third-party vendor) already displays an AI label?

Check your vendor contract and the actual user experience. Responsibility for the disclosure obligation typically sits with the deployer (you, the business using the tool with your customers), not automatically with the platform provider โ€” verify rather than assume.

Will the Digital Omnibus eventually simplify this further?

Possibly, over time โ€” elements of the Digital Omnibus package affecting GDPR recordkeeping and SME thresholds are still moving through trilogue negotiations. But the Commission's adoption of final Article 50 guidelines on July 20, 2026 confirms this specific obligation is proceeding as scheduled for August 2.

The Bottom Line

The "AI Act delayed" headlines are true for one part of the regulation and misleading about the rest. If your business talks to customers through a chatbot, or publishes AI-generated marketing content, Article 50 already applies to you as of August 2, 2026 โ€” no exemption for size, sector, or risk level.

The fix is not complicated: a clear disclosure line, a labelled asset, an updated privacy notice, and a short compliance log. Most of it fits into a single working session.

If you want help mapping your AI touchpoints against Article 50 and GDPR obligations together โ€” book a free consultation with GDPRGard โ†’

This article is for informational purposes and does not constitute legal advice. Regulatory guidance continues to evolve; consult a qualified lawyer for advice specific to your business.

Also read:

โš ๏ธ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance โ€” verify current obligations with your legal adviser.