TL;DR
On August 2, 2026, the EU AI Act's transparency rules (Article 50) became enforceable — with fines up to €15 million or 3% of worldwide turnover. If you run a restaurant, dental clinic, car dealership or any local business in the EU, here is the honest summary: the heavy obligations you've seen scary headlines about were postponed to December 2027 and don't apply to businesses like yours anyway. What does apply is narrow and manageable: if a chatbot talks to your customers, it must say it's AI; if you publish realistic AI-generated images of people or events, they must be labeled. Using AI to draft replies to Google reviews remains legal and does not require a public disclaimer. Most of what you need to do fits in 30 minutes — the checklist is below.
What actually happened on August 2, 2026
Two things happened in the same two weeks, and mixing them up is the source of most of the misinformation circulating in business groups:
1. The transparency rules went live. Article 50 of the AI Act applies from August 2, 2026. It covers four narrow situations: chatbots must disclose they're AI, providers of generative AI must mark synthetic content in machine-readable form, emotion-recognition systems must inform the people exposed to them, and realistic "deepfake" content plus AI-written public-interest journalism must be labeled.
2. Almost everything else got postponed. On July 27, 2026, the EU's "Digital Omnibus on AI" entered into force and moved the deadlines for high-risk AI systems — the genuinely burdensome part of the Act — to December 2, 2027 (stand-alone systems in areas like hiring and credit) and August 2, 2028 (AI embedded in regulated products). The European Commission also published final guidelines on the transparency rules on July 20, 2026, which resolved most of the open questions.
So if someone tells you "the whole AI Act now applies and you need an AI compliance officer" — that is simply not what happened.
Does the AI Act even apply to your business? The 5-question test
Work through these in order:
1. Do you use any AI at all? Review-response tools, chatbots, AI post generators, booking assistants. If no — the Act doesn't touch you. (Note: it applies based on where your users are, not where the software company is. A US tool used by your Madrid restaurant is in scope for the tool's provider.)
2. Do you build AI, or just use it? The Act splits the world into providers (who build or rebrand AI systems) and deployers (who use them). A restaurant using an AI review tool is a deployer — the lightest category. Most of the technical obligations fall on your software vendor, not on you.
3. Is what you do "high-risk"? High-risk means AI making consequential decisions about people: hiring, credit scoring, education access, essential services. Replying to reviews, scheduling posts, analyzing your Google ranking — none of this is high-risk. And even genuine high-risk uses now have until December 2027.
4. Does an AI system interact directly with your customers? A chatbot on your website, an AI phone assistant taking bookings. If yes — this is your one real obligation: the customer must be told they're talking to AI, clearly, at the start of the conversation. A visible "AI assistant" label satisfies this.
5. Do you publish AI-generated content? Here precision matters, because this is where the myths live — next section.
The myth-busting table
| Claim you may have seen | Reality |
|---|---|
| "All AI-generated content must be labeled from August 2026" | False. The deployer labeling duty covers two cases: realistic deepfakes, and AI-written text published to inform the public on matters of public interest (politics, public health, justice). Your menu descriptions, social posts and review replies are neither. |
| "AI replies to Google reviews are now illegal / must carry an AI disclaimer" | False. Nothing in the AI Act prohibits AI-drafted business replies or requires a public disclaimer on them. The machine-readable marking duty sits with the provider of the AI tool, not with the restaurant posting the reply. |
| "You need an AI officer / audit / certification" | False for SMBs. No such role or certificate is required for deployers of ordinary business tools. Beware of consultants selling "mandatory AI Act certification" — for a local business there is no such thing. |
| "Sentiment analysis of reviews is banned emotion recognition" | False. The Act's emotion-recognition rules target biometric systems (face, voice). Analyzing the text of a review to route it as positive or negative is not biometric emotion recognition. |
| "Fines of €35M apply to everyone" | Misleading. The €35M tier is for prohibited practices (social scoring, manipulative AI). Transparency violations cap at €15M/3% — and enforcement targets providers and systematic violations first. Regulators are also directed to consider proportionality for SMEs. |
What you actually must do — the 30-minute checklist
If you use a customer-facing chatbot (website, WhatsApp, phone):
- Make sure it identifies itself as AI at the start of the conversation. A header label plus a first message ("I'm an AI assistant…") is the pattern the Commission's guidelines describe as clear and distinguishable.
- Check that handoff to a human is visible when it happens — the reverse disclosure matters too.
If you use AI to draft review replies, posts or emails:
- Keep a human in the loop where it matters. Review-before-publish isn't just good practice — human editorial review is exactly what the Act's own exemptions reward. (It's also what keeps a 1-star response from sounding robotic.)
- Ask your tool vendor one question: "How do you handle the AI Act's Article 50 transparency obligations?" A serious vendor has an answer; silence is a signal.
If you generate AI images:
- Don't publish realistic AI images of real people, places or events without a visible label — that's the deepfake rule, and it applies to you as the publisher.
- Illustrative and obviously stylized images are fine. Keep the metadata your image tool embeds (don't strip it when editing).
If you send SMS/email campaigns: nothing changed here in August — but remember these were already regulated (consent under GDPR/ePrivacy), and the EU's fake-review rules already prohibit review gating and undisclosed incentives. The AI Act adds nothing new to review collection — the consumer-protection rules were always the ones with teeth for local businesses.
The fines, without the fear-mongering
Article 50 violations carry fines up to €15 million or 3% of worldwide annual turnover, whichever is higher. Enforcement sits with national market-surveillance authorities, several of which were still being set up in mid-2026. Realistically, first-wave enforcement will target AI providers and flagrant cases — not a trattoria whose chatbot label was two pixels small. But "realistically low priority" is not "exempt": the disclosure duty is yours if the chatbot is yours, the burden of proof sits with the business, and a competitor's complaint is all it takes to trigger a check. The checklist above costs half an hour; a dispute with a regulator costs months.
Why this is good news for honest businesses
There's a pattern across the EU's last three years of digital regulation — the fake-review liability rules, the review-gating crackdown, and now AI transparency: each round removes a shortcut that dishonest competitors were using. Bought reviews became a legal liability. Gated ratings became a misleading practice. Undisclosed bots are next. If your reviews are real, your replies are honest, and your chatbot says what it is, every one of these laws works in your favor — it's your competitors who have a problem.
That's also the standard we build to: our support chat identifies itself as AI from the first message, AI-drafted review replies come with a human review mode built in, and there is no review-gating anywhere in the product — because collecting reviews the legal way outperforms the banned way anyway.
FAQ
I'm outside the EU but have EU customers. Does this apply? Yes — the AI Act applies based on where the people affected are, not where your business is registered. If your chatbot talks to customers in the EU, the disclosure duty applies.
Does ChatGPT-drafted content make me a "provider"? No. Using a general-purpose tool to draft content makes you a deployer at most. You'd become a provider if you built or white-labeled an AI system and offered it to others under your brand.
Do I have to disclose that a human-edited reply started as an AI draft? No. Text that has gone through genuine human review and editorial control is exempt from the labeling duty even in the public-interest cases — and business replies aren't public-interest publications in the first place.
My website chat is a human during the day and a bot at night. What then? Disclose the AI whenever the AI is answering. The pattern that works: the bot session opens with an AI label, and escalation to a human is visibly marked as such.
Where do I check the official rules instead of LinkedIn posts? The European Commission's Article 50 FAQ and the July 2026 guidelines are the primary sources. National authorities publish local guidance as they stand up — your chamber of commerce will know which body covers your country.
The AI Act's transparency rules are, for a local business, closer to a labeling standard than to GDPR-scale compliance. Say what's AI, keep humans in the loop where judgment matters, don't fake reality — and you're not just compliant, you're ahead of every competitor still pretending their bot is a person named "Emma".
New blog posts. No spam.
Get the next reputation playbook delivered when it drops.