Since August 2, 2026, Article 50 of the EU AI Act requires every business to be transparent about its AI usage. This is no longer a deadline to prepare for: enforcement powers are active, with fines that can reach €15 million or 3% of worldwide turnover. And contrary to a common assumption, this duty isn't limited to tech giants — it applies to any SMB using a chatbot, a conversational agent, or generating content with AI.
À retenir — Key Takeaways
- Deadline: obligation active since August 2, 2026 (AI Act Article 50) — this is no longer an upcoming deadline
- 2 distinct duties: disclosing that you're interacting with an AI, and labeling content generated or modified by AI
- Maximum fine: €15 million or 3% of worldwide annual turnover (AI Act Article 99)
- Important nuance: machine-readable technical marking gets a grace period until December 2, 2026 for systems already in service before August 2 — the visible notice for end users, however, has no grace period
- External audit cost: €3,500 to €10,000 depending on company size
- Time to compliance: most fixes (a banner, a notice) deploy within a few days once the inventory is done
- Don't confuse with: the AI Act's "high-risk" obligations (recruitment, credit scoring) — a separate, heavier regime, see below
- Not applicable to: an AI used purely internally, never touching a customer or a published piece of content, falls outside the scope of this duty
What Article 50 actually requires
The AI Act sets out two distinct obligations:
1. Disclose that the user is interacting with an AI. If a customer is chatting with a chatbot or virtual agent on your site, they need to know clearly — not through a notice buried in the terms of service, but visibly at the moment of interaction.
2. Label content generated or modified by AI. Images, videos, synthetic voice: any synthetic content must carry a readable notice and, in certain cases, a machine-readable technical marking (metadata, digital watermark).
On this second point, one nuance matters: machine-readable technical marking gets a grace period until December 2, 2026 for systems already placed on the market before August 2, 2026 — but the visible notice for the end user applies with no grace period since August 2.
These rules add to GDPR, without replacing it: AI compliance doesn't exempt you from personal data compliance — the two apply together.
Who's affected among French and European SMBs
Concretely, if your business has deployed at least one of these, you're affected:
Many SMBs have adopted these tools over the past two years without formalizing the transparency notice that goes with them — that's exactly the blind spot the AI Act closes now. None of this requires ripping out an existing tool or vendor: the obligation sits on top of what's already deployed, not instead of it.
Who enforces it, and how a check actually starts
In France, the CNIL is preparing to be designated as the market surveillance authority under the AI Act, alongside its long-standing role on GDPR — meaning the same authority could end up checking both at once. In practice, a check rarely starts with a surprise inspection: the most common trigger is a complaint from a customer or employee who realizes, after the fact, that they were talking to an AI without being told, or a flag raised during a GDPR audit already planned for another reason. In other words, compliance isn't just about an abstract sanction risk — it's also about what your own customers notice and report, often well before any regulator gets involved.
Article 50 (transparency) vs "high-risk" obligations: don't confuse them
The AI Act contains several different obligation regimes, and mixing up the two is common among SMBs.
| Criteria | Article 50 — Transparency | Title III — "High-Risk" Systems |
|---|---|---|
| Who's affected | Any business using a chatbot or generating AI content | Automated recruitment, credit scoring, employee evaluation |
| Nature of the obligation | Disclose and label | Human oversight, usage log, documentation |
| Deadline | August 2, 2026 (active) | August 2, 2026 (active) |
| Implementation complexity | Low — add a notice | Heavier — a process and log to maintain |
| Maximum fine | €15M or 3% of worldwide turnover | €15M or 3% of worldwide turnover |
An SMB can be subject to both regimes at once — a recruitment chatbot that screens applications, for instance, combines the information duty (Article 50) with the high-risk obligations. For the second regime, see our full AI Act compliance guide for SMBs, which details the 5-step action plan for high-risk systems.
A concrete example
Take the illustrative case of a 20-employee e-commerce SMB using a chatbot to answer customer questions and generating its product visuals with AI. Without a transparency notice or labeling on the visuals, it's been in breach since August 2. Neither omission was intentional — the chatbot was rolled out by the customer service team, the visual generator by marketing, and neither team thought to check whether the other's tool needed a notice too. A compliance audit for a company this size typically costs €3,500 to €10,000 on the market — well below the risk in the event of a check, and most fixes (a transparency banner, a notice on visuals) deploy within a few days once the inventory is done.
3 steps to compliance this week
1. Inventory your AI usage (1 to 2 hours). Chatbot, visual generator, AI-assisted writing tools, automated emailing. A simple list is enough to start: tool name, where it's used, what type of content it produces.
2. Add a visible notice at every AI touchpoint (a few hours of development). A clear message at the top of a chatbot conversation ("You're talking with an AI assistant"), an "AI-generated image" label on the relevant visuals. This is the fastest fix to deploy and the one that covers most of the risk.
3. Document your tools and prompts (ongoing). Keeping a record of what was generated, with which tool and on what date, lets you demonstrate good faith in the event of a check — the same traceability principle we covered in our article on Shadow AI at work.
Checklist: is your SMB compliant with Article 50?
Five questions to assess your exposure right now:
1. Do your chatbots and conversational agents display a clear notice at the start of the exchange?
2. Do your AI-generated visuals or videos carry a notice readable by the user?
3. Are your written contents (articles, emails) rewritten by AI with no human review flagged when relevant?
4. Do you have a written list of all your active AI tools and their use?
5. Do you know who, internally, is responsible for this compliance?
If you answered no to three questions or more, your SMB is probably already in breach without knowing it — most fixes remain quick to implement.
What to remember
Article 50 isn't a heavy technical constraint: it's a transparency duty that's simple in principle, but easy to forget once an AI tool has been running for a few months. The good news: unlike the AI Act's "high-risk" obligations, compliance most often just means adding visible notices, not redesigning a technical architecture. The teams that struggle with this aren't the ones with complex AI stacks — they're the ones who never wrote down which tools they were using in the first place.
---
Further reading
🔍 Not sure where to start your compliance work? NeuraWeb offers a free audit of your AI usage to identify, in 30 minutes, what needs fixing first. Request my free audit →
Let’s discuss your project
30-min discovery call: ask your questions, we sketch a concrete first plan with rough numbers.
30 min · no commitment
Book a meetingWeb, AI & automation
Discover our full range of tailor-made services for SMBs and freelancers.
See our services