Short answer: Article 50 requires that people be told when they're interacting with an AI system, that emotion recognition and biometric categorisation be disclosed to those subject to them, that synthetic audio, image, video and text be marked in a machine-readable way, and that deepfakes and certain AI-generated public-interest text be labelled. It became enforceable on 2 August 2026. For most small businesses, compliance is a notice and a labelling habit.
General information, not legal advice.
1. Interaction disclosure. If you operate an AI system that interacts with people — a chatbot, a voice agent, an AI-powered support widget — those people must be informed they're dealing with an AI system, unless it's obvious to a reasonably observant person in the circumstances.
2. Emotion recognition and biometric categorisation. If you deploy such a system, you must inform the people exposed to it. Note that emotion inference in workplaces and education is separately prohibited outright, not merely subject to disclosure.
3. Synthetic content marking. Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format detectable as artificially generated. This duty sits primarily with providers, but it affects your tool selection — you want tools that do this.
4. Deepfakes and public-interest text. Deployers of systems producing deepfakes must disclose that the content is artificially generated or manipulated. AI-generated or manipulated text published to inform the public on matters of public interest must also be disclosed, unless it has been through human editorial review with someone holding editorial responsibility.
Far fewer businesses than the headlines imply, and more than many assume. You're likely in scope if you:
You're likely not in scope if AI is used internally for drafting, analysis or automation with no direct interaction with the public and no synthetic media output.
For the common case — a website chatbot — a short, visible statement at the start of the interaction is sufficient. Something on the lines of "You're chatting with an AI assistant. Ask for a human at any time." Clear, present before the conversation begins, not buried in terms and conditions.
The requirements specify that the information be provided in a clear and distinguishable manner at the latest at the point of first interaction, and be accessible — which matters for screen reader users and for people with disabilities.
For AI-generated marketing content, an internal labelling practice and a public statement about your approach covers most of it. For anything published on public-interest matters, keep a record of human editorial review, which is the exemption route.
Businesses routinely over-comply here, adding disclosure to everything and diluting the disclosures that matter.
Transparency breaches fall in the tier attracting fines up to €15 million or 3% of global annual turnover, with SMEs subject to the lower of the two figures rather than the higher.
Where output is used in the EU or the system is placed on the EU market, yes.
Not where a human has reviewed and taken editorial responsibility. Keep evidence of that review.
We check where Article 50 actually applies and fix the gaps with the lightest possible touch. See what's covered.