The short answer
If your website uses an AI chat widget, generates images or video with AI, or publishes AI-written content about public-interest matters, the EU AI Act now requires you to say so. The transparency obligations in Article 50 applied from 2 August 2026, they reach businesses outside the EU whose output is used there, and the maximum penalty is 15 million euro or 3 percent of worldwide turnover.
For most company websites this is a small job done badly or a small job done well, not a re-platforming exercise. The risk is not the technology, it is that nobody owns the sentence that has to appear on screen.
Who this actually applies to
The Act splits duties between providers, who build and place an AI system on the market, and deployers, who use one in their own operations. A business that buys a chat widget is a deployer; the vendor is the provider. That matters because the obligations differ, and because the vendor's compliance is not automatically yours.
The territorial reach is what surprises people. The rules apply where the system is used in the EU or its output is used there, so a studio in Delhi, an agency in London or a SaaS company in Austin can all be in scope through their EU visitors and customers. If you have already worked through GDPR and DPDP consent on your site, this is the same shape of problem: a global website, a regional rule, a decision about whether to build two experiences or one honest one.
The four obligations in plain language
Article 50 covers four situations. Read them as questions about your own site rather than as legal categories, and most businesses find that only the first two apply to them.
- Talking to a machine. Any AI system that interacts directly with people must tell them so, clearly, at the first interaction. This is the chatbot rule, and it covers voice assistants and AI agents as well.
- Synthetic content marking. Providers of generative systems must mark AI output — text, image, audio, video — in a machine-readable way so it can be detected downstream. Existing systems have until 2 December 2026 for this part.
- Deepfakes. Deployers who publish AI-generated or manipulated images, audio or video of real people, places or events must disclose that it is artificial. Creative and satirical work discloses in a way that does not spoil the work.
- Emotion recognition and biometric categorisation. If a system infers emotion or categorises people biometrically, the people exposed to it must be told. Rare on marketing websites, common in recruitment and retail analytics tools.
There is a fifth case that trips up content teams: AI-generated text published to inform the public on matters of public interest must be disclosed as artificially generated, unless it has been through human review with a named person or organisation taking editorial responsibility. Ordinary product copy is not caught. A news-style explainer published by a brand might be.
What this looks like on a real website
The compliant version is unglamorous, which is the point. A chat widget that opens with a line naming itself as an AI assistant, in the same type size as the rest of the interface, before the first question is answered. Not a tooltip, not a line in the privacy policy, not a disclosure that appears after the conversation ends.
Three failures we see repeatedly on client sites we inherit:
- The human-sounding persona. A widget that introduces itself with a first name and a photograph, with the word AI nowhere on screen. If your design implies a person, the exemption for the obvious does not save you.
- Disclosure buried in the footer. The obligation is at the point of interaction, not somewhere on the site.
- Handover left unmarked. If conversations pass from AI to a human agent, say when that happens. It is also simply better service, as we argued in whether an AI support agent is worth it.
For AI imagery, the practical question is your production pipeline rather than your website. Ask the tool whether it embeds provenance metadata, keep a record of which assets are synthetic, and decide a house rule for visible labels on anything showing recognisable people or real events.
Does disclosure cost you conversions?
The honest answer from the available evidence is: less than teams fear, and it depends on what you are disclosing. Customers largely accept AI in support and increasingly expect it; they react badly to discovering it was hidden. We went through the research on that in whether customers care about AI disclosure, and the pattern is consistent: the penalty attaches to concealment, not to use.
There is also a competitive argument. Once every widget in your market must say it is AI, the differentiator becomes how good the thing is — whether it answers accurately, knows your pricing, and hands over cleanly when it should.
A checklist to work through this quarter
Most sites need an hour of inventory and a day of changes. The inventory is the part that gets skipped, and it is where the surprises are.
- List every AI feature touching customers: chat, search, recommendations, generated images, voice, AI-written pages.
- For each, record whether you are the provider or the deployer, and what the vendor already does about marking and disclosure.
- Add first-interaction disclosure to every conversational surface, in the interface itself.
- Decide and document a labelling rule for synthetic imagery, especially anything featuring people.
- Name an owner. Article 50 duties do not sit naturally with marketing, engineering or legal, so they end up unowned.
- Keep a dated record of what you decided. It is the difference between a compliant posture and a hopeful one.
Where this sits alongside everything else
The AI Act joins a stack that already includes GDPR, the European Accessibility Act, and in India the DPDP rules with their November 2026 consent deadlines. Businesses selling into several markets increasingly find that the strictest rule sets the build, because maintaining separate experiences costs more than complying once, properly. That is the same logic that makes accessibility compliance worth doing globally rather than per region.
None of this is legal advice, and the guidelines approved in July 2026 are non-binding interpretation rather than settled law. If AI sits anywhere in your customer experience and you want the disclosure designed rather than bolted on, we can review what your site currently says.