The EU AI Act from 2 August 2026: the obligation isn't on your website, it's on the AI inside it

From 2 August 2026 the EU AI Act's transparency obligations (Article 50) apply. What really changes for businesses and publishers: chatbots, AI-generated content, deepfakes, AI literacy, and what doesn't affect you after the Digital Omnibus.

On 2 August 2026 the transparency obligations of the European AI Act become applicable: the rules that touch anyone using artificial intelligence to interact with the public or generate content. Over these past weeks the same question keeps landing on my desk: “is my website compliant with the AI Act?” It is the wrong question. But before explaining why, let’s line up the facts, because there has been a lot of confusion about the deadlines.

The real AI Act timeline

Let’s start with the facts. Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024. The general rule sets application from 2 August 2026, but with some milestones already live.

AI Act

The key dates to mark

Source: European Commission · Regulation (EU) 2024/1689

In force1 August 2024

The AI Act enters into force

Regulation (EU) 2024/1689 becomes law and the countdown to application begins.

In force2 February 2025

Prohibitions and AI literacy

Bans on unacceptable-risk practices apply, along with the AI literacy duty for staff.

In force2 August 2025

General-purpose AI (GPAI)

Governance rules and the obligations for general-purpose AI models become operative.

Mark this date2 August 2026

Transparency (Article 50)

Full applicability: the transparency obligations for those who use AI kick in. The only technical extension: watermarking of outputs for generative systems already on the market moves to 2 December 2026.

Postponed · Digital Omnibus2 December 2027

High-risk, standalone systems

The deadline for standalone high-risk systems was pushed back by the Digital Omnibus.

Postponed · Digital Omnibus2 August 2028

High-risk embedded in products

High-risk systems as safety components in products regulated by EU sectoral legislation.

From 2 February 2025, the initial rules and the bans on practices deemed to be of unacceptable risk apply. These include, among others, harmful behavioural manipulation, some forms of social scoring, and particularly intrusive uses of biometric identification. This is not a future concern: it is already reality.

From 2 August 2025, several provisions on general-purpose AI models are also operative. Then 2 August 2026 brings the major application threshold for most provisions, including many transparency rules.

Onto this calendar came the digital simplification package, the so-called Digital Omnibus on AI. Here we need to be precise: the European Parliament approved the text on 16 June 2026, and Council documents indicate adoption of the legislative act at the session of 29 June. The core of the change is the postponement of certain obligations for high-risk AI systems: 2 December 2027 for standalone high-risk systems, 2 August 2028 for those embedded as safety components in products regulated by EU sectoral legislation.

Does this mean we can wait? No. It means something different: some companies will have more time to adapt on specific categories of high-risk systems, but the AI Act has not been suspended. The prohibited practices are already relevant. AI literacy is already a corporate matter. The transparency rules remain close, and organizational responsibility cannot be improvised at the last minute.

The AI Act doesn’t regulate websites. It regulates the AI you put inside them

Back to the wrong question. The AI Act is not a piece of website legislation the way the Cookie Law or the privacy consent rules were. It imposes no requirements on your domain as such. It regulates artificial intelligence systems and, crucially, it distinguishes two roles: the provider (whoever develops or places an AI system on the market) and the deployer (whoever uses that system in their own activity).

This distinction changes everything. If you integrate a third-party model on your site via API, or generate text with a tool you did not build, in the vast majority of cases you are a deployer, not a provider. Several of the heavier technical obligations, such as marking generated output in a machine-readable way, stay with whoever builds the model, not with you.

In practice: a showcase site, a blog, an e-commerce that do not run user-facing AI features have, in themselves, no new obligations on 2 August. The impact only arises from the specific AI features you switch on. So the right question is not “is my website compliant”, but “which AI features do I run, in which role, and what obligations apply to each of them”.

What actually kicks in: transparency (Article 50)

The heart of what touches businesses and publishers is Article 50, the transparency obligations. Three concrete situations.

Chatbots and conversational assistants. If your site has an AI assistant that users converse with, you must inform them they are interacting with an artificial intelligence system, unless it is already obvious from the context. In practice: a line, a badge, an opening message. It costs nothing, but it has to be done.

AI-generated text. Here the rule is more subtle than it is usually told. The obligation to disclose that a text is AI-generated applies when the content is published to inform the public on matters of public interest (news, politics, health and the like). And there is a decisive exemption: if the content undergoes human review, with a person taking editorial responsibility for it, the disclosure obligation falls away. For most corporate blogs and commercial content this scope does not strictly apply. For a publisher pushing news automatically, it does: and the editorial-review exemption becomes the point around which to build the process.

Deepfakes: images, audio, video. If you use AI to generate or manipulate content that resembles real people, places or events and makes them appear authentic, you must disclose it. Note: an AI illustration that is openly fictional is not a deepfake and does not fall here. What matters is the resemblance to reality.

One last note on the dates, because the Digital Omnibus created noise here too: the only postponement affecting Article 50 is technical and does not concern you. Machine-readable marking of outputs (watermarking), which is an obligation of the model provider and not yours, has been extended to 2 December 2026 for generative systems already on the market. For you, the one who uses the AI, the reference date stays 2 August.

What you should already have been doing since February: AI literacy

There is an obligation many discover late, because it does not kick in this August: it has been in force since 2 February 2025. It is Article 4, AI literacy. Whoever uses AI systems must ensure that the people operating them have an adequate level of competence. You don’t need a master’s degree: you need documented training, proportionate to how you use these tools. For most companies it is half a day put on record, but it is a real obligation and one that is often ignored.

What does NOT concern you (to clear the field)

It is worth spelling out what to leave out too, because the AI Act has generated more alarm than substance.

The high-risk systems of Annex III (recruitment, credit scoring, biometrics, critical infrastructure and the like) carry heavy obligations, but they do not concern the typical use of AI in marketing, publishing or customer care, and the Digital Omnibus has in any case pushed their deadlines to 2027-2028. And the obligations of general-purpose model providers do not touch you unless you train your own models: using someone else’s model via API does not make you its provider.

Penalties, in proportion

Breaches of the transparency obligations fall in the band up to 15 million euro or 3% of worldwide annual turnover (Article 99). The higher cap you often read about, 35 million or 7%, applies to prohibited practices, not to transparency: confusing the two is a common mistake. These figures convey the weight of the rule, not scare tactics: for a missing disclosure the practical risk is remote, and that is precisely why it pays to sort out now obligations that cost so little.

What to do now: the checklist

  1. Map your AI features, one by one: chatbots, text, image or video generation, personalization. For each, establish whether you are a provider or a deployer.
  2. Add a transparency note wherever a user interacts with an AI or reads content generated without supervision.
  3. If you publish content with AI, formalize the human review: who holds editorial responsibility. That is what brings you within the exemption.
  4. Document a minimum of AI literacy training for the team.
  5. Don’t over-engineer: if you have no user-facing AI features, you have no new obligations on 2 August.

Transparency isn’t just an obligation: it’s reputation

I’ll close with the part that interests me most. Treating the AI Act as a nuisance to be handled with the bare minimum is a mistake of perspective. Clearly declaring where and how you use artificial intelligence is a signal of reliability, towards users and towards the very systems that today decide who to cite when they generate an answer. It is the same logic I have been repeating for a while, and that I set out in From Brand to Source: in the era of generated answers it is not those who hide who win, but those who become a recognizable, verifiable source. Compliance, done well, works in the same direction as visibility.

If you want to understand which of your tools fall under the transparency obligations and how to sort them out without slowing down the business, that is exactly the kind of work we do every day.

Sources

Frequently asked questions

The AI Act (Regulation EU 2024/1689) entered into force on 1 August 2024 and is fully applicable from 2 August 2026, when the transparency obligations of Article 50 kick in. Some milestones started earlier: prohibitions and AI literacy from 2 February 2025, general-purpose AI models from 2 August 2025.

Only in part. The Digital Omnibus (approved by the European Parliament on 16 June 2026 and adopted by the Council on 29 June) postponed the obligations for high-risk systems to 2 December 2027 (standalone systems) and 2 August 2028 (systems embedded in products). The transparency obligations for those who use AI still apply from 2 August 2026.

Not to the website as such. It applies to the AI systems you use. A site with no user-facing AI features has no new obligations on 2 August: it only has them for the specific AI features it runs (chatbots, content generation, deepfakes).

Yes for chatbots (users must be told they are talking to an AI) and for deepfakes. For text, the obligation applies to content published to inform the public on matters of public interest, and it falls away if there is human review with someone holding editorial responsibility.

Breaches of Article 50 fall in the band up to 15 million euro or 3% of worldwide annual turnover (Article 99). The 35 million or 7% cap applies to prohibited practices, not transparency. For a single missing disclosure the practical risk is low, but it pays to fix obligations that cost almost nothing right away.

It is the adequate AI competence of the staff who use these systems, required by Article 4 and mandatory since 2 February 2025. For most companies a documented training session, proportionate to how the tools are used, is enough.