AI transparency from 2 August 2026: what SMEs must do
The EU AI Act's transparency obligations apply from 2 August 2026. If your business runs a chatbot, generates content with AI, or publishes AI-assisted text, some of these duties are yours. A plain-language brief on what applies, what is exempt, and the five steps to take now — based on the European Commission's final Guidelines of 20 July 2026.
On 2 August 2026 the EU AI Act’s transparency obligations (Article 50) become applicable. On 20 July 2026 the European Commission adopted its final Guidelines on how they will be read in practice. This brief translates both into what a small or medium-sized business actually has to do — and what it does not.
Cite as: Hubnix, 2026. AI transparency from 2 August 2026: what SMEs must do. hubnixco.com/publications/ai-transparency-obligations-smes-2026.
License: CC BY 4.0 — free to redistribute and adapt with attribution.
1. What changes on 2 August 2026
Article 50 of the EU AI Act (Regulation (EU) 2024/1689) creates four transparency duties. They are not reserved for AI companies: they attach to any business that provides or deploys in-scope AI systems in the EU, whatever its size or sector.
| If your business… | The duty | Who carries it |
|---|---|---|
| Offers a chatbot, voice agent or any AI that talks to people | People must be told they are dealing with AI, clearly, at the first interaction | Provider (the party that developed the system or offers it under its own name) |
| Operates AI that generates or edits audio, image, video or text | Outputs must carry a machine-readable “AI-generated” mark and be detectable as such | Provider |
| Uses emotion recognition or biometric categorisation | Exposed persons must be informed | Deployer (the business using the system under its authority) |
| Publishes deepfakes, or AI-generated text meant to inform the public on matters of public interest | Content must be clearly labelled as artificially generated | Deployer |
Two points SMEs regularly miss:
- You can be both provider and deployer. A company that builds an AI tool in-house and uses it under its own name carries both sets of duties (Guidelines, paras 11 and 15).
- “Deployer” means the business, not the employee. The company under whose authority the system is used is responsible — including for how outputs are used (para 12). Staff using the tool under instruction are not separate deployers (para 14).
Penalties reach €15 million or 3 % of worldwide turnover. For SMEs and start-ups the Act expressly caps each fine at whichever of those amounts is lower, and requires authorities to weigh economic viability (para 152).
2. What is exempt — often more than you fear
The final Guidelines draw practical boundaries. No duty applies where:
- It is obvious you are dealing with AI. A reasonably well-informed person’s perspective decides; an evidently automated tool does not need a banner stating the evident (Art 50(1) exception).
- The AI only assists standard editing. Spell-check, grammar, formatting, technical clean-up — and notably AI translations of your own text — do not trigger the marking duty (para 90). Substantive rewriting that changes meaning or style does.
- Output stays inside the business. Strictly internal or business-to-business technical outputs, seen only by a defined professional audience and not intended to leave the company, are exempt from marking (para 87).
- Published text passed real human review. AI-drafted text published to inform the public needs no label if it underwent substantive human review — fact-checking included — and a person or company holds editorial responsibility for it (paras 133–138). Cursory sign-off does not qualify (para 135), and the responsible editor must be identifiable somewhere findable, such as your website’s legal notice (para 138).
- It is ordinary commercial copy. Product descriptions and advertisements are generally not “text informing the public on matters of public interest” (para 131) — though consumer-safety, health or sustainability claims can change that.
One date-related relief: generative AI systems already in service before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement. Nothing else is deferred — chatbot disclosure and labelling duties apply from 2 August regardless (para 153). Content generated before 2 August does not need retroactive labelling (para 154).
3. The five steps to take now
- Inventory your AI. List every AI system you operate, offer or embed — including AI features inside third-party tools. For each, note whether it interacts with people or generates content, and which duty or exemption applies. This single document is the backbone of every other obligation, and the first thing an authority will ask for.
- Fix your chatbot’s first line. If customers can interact with your AI, the AI must announce itself clearly at the start of the first interaction — not in the terms and conditions, not behind a menu (para 142).
- Sort your content marking. If you provide generative AI, implement machine-readable marking; you may build on the marking your upstream model provider embeds, but the compliance responsibility remains yours (para 74). The Commission’s voluntary Code of Practice on marking and labelling AI-generated content (10 June 2026) is the recognised route, with an optional EU “AI” label. Non-signatories are expected to show equivalent measures — a gap analysis against the Code is the Commission’s stated benchmark (para 148).
- Put a review gate on published AI text. If AI-assisted articles, reports or posts go public under your name, either label them or run genuine editorial review — and name who holds editorial responsibility in your site’s legal information.
- Allocate roles in your contracts. When you commission, resell or distribute AI systems or AI-made content, state in the contract who is provider, who is deployer, and who ensures the label survives to the audience — the Guidelines expect exactly this in content value chains (para 12).
4. Key dates
| Date | What applies |
|---|---|
| 2 August 2026 | All Article 50 duties: chatbot disclosure, emotion-recognition information, deepfake and public-interest text labelling; marking for systems placed on the market from this date |
| 2 December 2026 | Machine-readable marking deadline for generative systems already in service before 2 August 2026 |
Enforcement sits with national market surveillance authorities (in Italy, within the AI Act’s national supervision framework), with the AI Office competent for some GPAI-based systems. The Guidelines are non-binding — final interpretation belongs to the Court of Justice of the EU — but authorities have stated they will follow them.
How Hubnix can help
Hubnix runs EU AI Act readiness audits for SMEs — AI inventory, risk classification, Article 50 gap analysis and remediation plan — built on the same methodology we apply to our own AI operations. Get in touch or see our services.
Transparency note, practising what we advise: this brief was drafted with AI assistance from primary sources — the Commission Guidelines C(2026) 5054 final of 20 July 2026 and the Code of Practice of 10 June 2026 — and underwent substantive human review before publication. Editorial responsibility: Hubnix.
Sources: Commission Guidelines on Article 50 transparency obligations (20 July 2026) · Commission FAQ on Article 50 · Code of Practice on Transparency of AI-Generated Content