Sinton Agency Logo

Published

·

5 min

read

What the EU AI Act Means for Your Website and Chatbot

The EU AI Act's transparency rules took effect on 2 August 2026. No SME exemption, but less work than the headlines suggest. A practical guide for service businesses running a Framer or Webflow site.

Line-drawn browser window with a chat bubble carrying a small blank label tag, beside a sealed document in soft sage wash

TL;DR

  • Article 50 of the EU AI Act, the transparency chapter, has applied since 2 August 2026. It covers almost any business that uses AI in public, not just big tech.

  • Three things touch your website: a chatbot must make clear it is AI, AI generated content must be machine readable as AI, and deepfakes need a visible label.

  • Most of the technical marking is the job of the AI tool you use, not yours. Your job is to check that it does it, and to handle the disclosures that clearly sit with you.

  • There is no small business exemption. Fines reach €15 million or 3% of worldwide annual turnover, although the Act requires regulators to scale penalties for SMEs.

  • The high risk rules did not start in August 2026. They were pushed to December 2027 and August 2028. A lot of current coverage gets this wrong.

If you run a service business with a website, the past few weeks have probably brought a wave of alarming posts about the EU AI Act. Most of them are either scare stories or written for compliance officers at large enterprises.

This guide is neither. It covers the three parts of the law that touch a normal business website, the kind built in Framer or Webflow with a chat widget in the corner, what you actually have to do, and what you can safely ignore.

Legal note

We design and build websites. We are not lawyers, and this article is general information rather than legal advice. For your own circumstances, read the European Commission guidance on transparency and speak to a qualified solicitor.

What changed on 2 August 2026

Article 50 of the AI Act is the transparency chapter, and it has applied since 2 August 2026. It works differently from the rest of the law. It is not limited to high risk uses, so it reaches anyone who provides or deploys AI in one of four situations: AI that interacts directly with people, AI that generates synthetic content, emotion recognition or biometric categorisation, and deepfakes or AI generated text published to inform the public on matters of public interest. The Commission sets this out in its transparency guidelines.

For a typical service business, the first, second and fourth situations are the ones worth reading twice.

Your chatbot has to make clear it is a chatbot

If your site has an AI chat widget, visitors need to be able to tell that they are talking to software rather than a person. The disclosure has to be clear and given at the first interaction, not buried in a policy page.

In practice, that means three things:

  • Name it honestly. "AI-assistant" works. "Anna from reception" with a stock photo does not.

  • Put the disclosure where the conversation starts, in the opening message and ideally in the widget header too.

  • Keep a human route visible, such as a phone number, an email address, or an option to ask for a person.

One nuance worth flagging. The duty to design the system so that people are informed sits with the provider of the chatbot, which is usually your vendor. If you white label the bot heavily, give it a human persona and present it as your own product, you move closer to being treated as the provider yourself. If that describes your setup, get advice on it.

AI images and copy: who actually has to mark what

This is where most coverage goes wrong. Article 50(2) requires AI generated or manipulated audio, image, video and text to carry a machine readable mark so that it can be detected as artificially produced. That obligation sits with the provider of the generative AI system, so with the tool, not with you as the business publishing the output.

You are therefore not expected to hand code watermarks into your hero images. What you should do is more mundane:

  • Use tools that mark their output. The Commission's Code of Practice on AI generated content expects a layered approach, typically signed metadata plus imperceptible watermarking.

  • Do not strip the metadata. Some export, resize and compression steps quietly remove it. Check what your image pipeline does before files reach the site.

  • Know the grace period. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the marking obligation, an extension added by the recent amendment to the Act.

And the detail that saves most people a weekend of work: content that was generated and published before 2 August 2026 does not need to be labelled retrospectively. If it was generated earlier but published on or after that date, the labelling rules do apply.

Want a custom-designed website?

Reach out today.

Deepfakes and public interest text

Two disclosures sit squarely with you as the deployer.

If you publish image, audio or video that constitutes a deepfake, meaning it realistically depicts real people, places or events, you have to disclose that it is artificially generated or manipulated. Where the work is evidently artistic or satirical, the disclosure can be lighter, enough to make the position clear without spoiling the piece.

If you publish AI-generated or manipulated text to inform the public on matters of public interest, you have to disclose that too. A page about your own services is not that. A news-style piece or public commentary may well be.

What you do not need to do

  • You do not need a compliance framework, an AI register or a consultant for a brochure site with a chat widget.

  • You do not need to label ordinary marketing copy that you wrote with AI assistance, reviewed and published as your own commercial content.

  • You do not need to relabel your old blog posts and images.

  • You do not need to act on the high-risk obligations yet, for the reason below.

The high-risk deadline that did not happen

Plenty of articles claim that the AI Act's high-risk obligations landed in August 2026. They did not. The AI Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved standalone high-risk systems listed in Annex III to 2 December 2027, and high-risk AI embedded in regulated products to 2 August 2028.

Article 50 came out of that process almost untouched, apart from the four-month marking extension mentioned above. So the transparency rules are live now, while the heavy conformity work is not.

Penalties, and what enforcement realistically looks like

Breaching the transparency obligations carries fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The Act also requires proportionality for small and medium businesses, so a three-person studio is not carrying the same exposure as a global platform.

Realistically, a small Polish service business is not a regulator's first target. But "unlikely to be audited" is a weak reason to keep an unlabelled chatbot on a site that asks visitors for their phone number. The fix takes an afternoon.

A short check for your own site

  • The chat widget states that it is AI in its first message, and in its header.

  • A human contact route sits next to the widget.

  • Your AI image and copy tools mark their output, and your export process does not strip it.

  • Any deepfake style media carries a visible disclosure.

  • Any public interest article produced with AI is disclosed.

  • Content published before 2 August 2026 has been left alone.

Frequently asked questions

Does the EU AI Act apply to my small business?

Yes. There is no exemption from the transparency rules for small businesses. The Act does require regulators to apply penalties proportionately to SMEs, but the obligations themselves still apply.

Do I have to visibly label every AI generated image on my site?

Usually not. The requirement is a machine readable mark, and it falls on the AI tool that produced the image. A visible label is required for deepfakes, meaning realistic depictions of real people, places or events.

My website is in Polish and I only sell in Poland. Does this still apply?

Yes. The AI Act is an EU regulation, so it applies directly in Poland without national implementing legislation.

Do I need to relabel old blog posts and images?

No. Content generated and published before 2 August 2026 does not need retrospective labelling, although the Commission encourages it where it is easy to do. Content generated before that date but published afterwards is in scope.

Is a notice in my privacy policy enough for the chatbot?

No. The disclosure has to reach the visitor at the point of interaction, which means in the chat itself rather than in a document they will never open.

Profile Picture of Thomas Sinton

Thomas Sinton

Author

Share this post via

We will create a website that attracts customers.

We will design a website or branding for conversion that will help your business increase sales and gain more customers.

Know what you want? Get a quote.

Sinton Agency Logo

We will create a website that attracts customers.

We will design a website or branding for conversion that will help your business increase sales and gain more customers.

Know what you want? Get a quote.

Trusted by

Trusted by

Trusted by