Back to Blog
AI & ML9 readSeptember 22, 2026

The EU AI Act Kicked In in August 2026: A Transparency Guide for Chatbots and AI Content

As of 2 August 2026, the EU AI Act's transparency rules apply: the chatbot on your site must identify itself, and realistic AI imagery must be labeled. What did the Digital Omnibus that entered into force in July postpone — and what didn't it? A practical checklist for businesses selling into the EU.

Ebrar Altunkaynak

Ebrar Altunkaynak

Full Stack Engineer

#EU AI Act#AI Regulation#AI Transparency#Chatbot#Deepfake
The EU AI Act Kicked In in August 2026: A Transparency Guide for Chatbots and AI Content

At the start of August 2026, many companies were asking the same question: "Wasn't the EU AI Act postponed?" The answer: partly. The Digital Omnibus, which entered into force in July 2026, pushed the heavy obligations for high-risk AI systems back to 2027 and 2028. But the transparency rules (Article 50) — the part that directly affects most businesses — were not postponed, and they started applying on 2 August 2026. Any company that runs a chatbot on its site, generates AI imagery for marketing, or serves customers in the EU may fall within their scope.

This article is general information, not legal advice. Consult a legal professional about your specific situation.

Why It Matters Even If You're Not Based in the EU

The AI Act's reach doesn't stop at the EU's borders: even if you're established outside the EU, the law can apply to you if your AI system's output is used in the EU. For example:

  • the chatbot on an e-commerce site that sells to customers in the EU,
  • AI-generated ad visuals shown to buyers in Germany,
  • the AI assistant in a mobile app available to users in the EU

can all fall within these rules. For businesses in countries with deep trade ties to the EU — Türkiye among them — this belongs on the agenda of every exporter and digital service provider.

Timeline: What Was Postponed, and What Wasn't?

ObligationDateStatus
Prohibited AI practices2 February 2025In force
Rules for general-purpose AI (GPAI) models2 August 2025In force
Transparency rules (Article 50): chatbot disclosure, deepfake labeling2 August 2026Applying now — not postponed
Machine-readable marking of AI outputs (Article 50(2)), for systems placed on the market before 2 August 20262 December 2026Transition period
New ban on AI that generates non-consensual intimate content or child sexual abuse material2 December 2026Added by the Omnibus
High-risk systems (Annex III: recruitment, credit scoring, education, etc.)2 December 2027Postponed from 2 August 2026
AI embedded in regulated products (Annex I: medical devices, toys, machinery, etc.)2 August 2028Postponed

What Exactly Does Article 50 Require?

There are four core rules:

  1. The right to know you're talking to AI (50(1)): AI systems that interact directly with people — the support chatbot on your site, a WhatsApp assistant, a voice assistant — must tell users they're interacting with an AI. There's an exception when this is obvious from context, but a bot chatting under the name "Sarah from customer service" hardly qualifies.
  2. Machine-readable marking (50(2)): Providers of AI systems that generate synthetic audio, images, video, or text must ensure outputs are detectable as artificially generated (watermarks, metadata, etc.). This burden falls mostly on the companies building AI tools — but it applies to you if you build your own generation tool.
  3. Emotion recognition and biometric categorization notice (50(3)): If you use these kinds of systems, you must inform the people exposed to them.
  4. Deepfake and public-interest AI text labeling (50(4)): Deployers who use AI-generated or manipulated images, audio, or video that appreciably resemble real people, places, or events must clearly disclose that the content is artificial. AI-generated text published to inform the public on matters of public interest must also be labeled — unless it has undergone human review and someone holds editorial responsibility for it.

The disclosure must be made at the latest at the time of the first interaction or exposure — clearly, distinguishably, and in line with accessibility requirements.

A Practical Checklist

  1. Build an AI inventory: Which AI systems do you use on your site, in your app, and in marketing? Chatbots, automated email replies, AI image generation, voice cloning, recommendation engines...
  2. Add one sentence to your chatbot: A clear notice at the start of the conversation — something like "Hi, I'm [Brand]'s AI assistant" — is a sufficient start; offering a handoff to a human agent is good practice too.
  3. Label realistic AI visuals: Use a visible "Generated with AI" notice on AI-generated ad images and videos that resemble a real person, place, or event.
  4. Document the editorial process for blog and news content: If AI-assisted content goes through a human editor, record that as a process; the editorial exception only holds when that responsibility is genuinely taken on.
  5. Question your vendors: Do the AI image and audio tools you use mark their outputs in a machine-readable way? From 2 December 2026 at the latest, that's the providers' responsibility.
  6. Build AI literacy in your team: The Omnibus softened the AI literacy obligation in Article 4; companies are now expected to "support" the development of their staff's AI literacy. Even so, a short internal training session is cheap insurance for both compliance and security.
  7. Think alongside GDPR: If your chatbot collects personal data, the AI Act disclosure doesn't replace your GDPR transparency obligations (or KVKK in Türkiye); both apply together.

Penalties

Violations of Article 50 can bring administrative fines of up to €15 million or 3% of worldwide annual turnover (whichever is higher; for SMEs, whichever is lower). For prohibited practices, the ceiling is €35 million or 7%. Still, for most businesses the real risk isn't the fine — it's trust. Being seen as "the brand that hid its AI" can cost more than any penalty.

Transparency Is Also a Visibility Signal

There's a positive side effect too: content with a named author, a clear publication date, and a defined editorial process carries the signals Google's E-E-A-T approach values. Author bylines, sources, and transparent AI use support both regulatory compliance and getting cited in AI search. For internal processes against threats like cloned voices and fake video calls, see our deepfake guide.

Frequently Asked Questions

Was the EU AI Act postponed? Partly. The Digital Omnibus pushed obligations for high-risk AI systems back to December 2027 and August 2028. Transparency rules like chatbot disclosure and deepfake labeling, however, started applying on 2 August 2026.

What should I do about the chatbot on my site? Tell users clearly, at the start of the conversation, that they're talking to an AI. If you've given your bot a human name, this disclosure matters even more.

Do I have to label every image I generate with AI? Article 50(4) specifically targets content that appreciably resembles real people, places, or events and could be mistaken for authentic. An obviously illustrative or fantastical image may be assessed differently; in borderline cases, labeling is the safest route.

Does this affect a company outside the EU that doesn't sell to the EU? If your AI system's output isn't used in the EU, you may fall outside the direct scope. However, a website, app, or campaign that's open to users in the EU can widen that scope; it has to be assessed against your actual use.

Conclusion

2 August 2026 was the day the AI Act stopped being "a distant Brussels matter" and reached all the way down to the chatbot on your website. The good news: most transparency obligations can be met with a few sentences of disclosure and a clear content process. If you'd like to bring your chatbot, AI assistant, or content workflows in line with these rules, get in touch — we'll build the technical side together.