# What transparency obligations the AI Act places on small businesses too

> As of 2 August 2026, Art. 50 of the AI Act requires a chatbot to identify itself, and AI-generated content to be labeled. What that means for your business.

URL: https://thenichesociety.ro/en/blog-transparenta-ai-act-pentru-afaceri

The AI Act isn't just about “high-risk” systems, scheduled only for 2027; Article 50, which requires transparency for any conversational system and for synthetic content, has already applied since 2 August 2026. **If a shop or a restaurant uses a chatbot on its site, or AI-generated images and clips in marketing, these obligations already apply, regardless of company size**. It's not a regulation just for Big Tech.

## What Article 50 of the AI Act actually is — and why it already applies

The European regulation on artificial intelligence is being phased in gradually over several years, and most of the confusion comes from the fact that most news coverage talks about the distant 2027 or 2028 deadlines, which apply to systems considered “high-risk.” Article 50, by contrast, has already applied since 2 August 2026, and it covers something far more common than a high-risk system: transparency obligations for any interactive system a person talks to, and for any synthetic content generated automatically.

In concrete terms, the article requires two things that are simple to understand, even if they're phrased technically, in legal language: people must know when they're talking to an automated system rather than a real person, and they must know when an image, a video clip or an audio recording has been generated or significantly modified by AI. The size of the company using that system doesn't matter — the rule applies to anyone who makes such a system available to the public in the European Union, not just to the big platforms.

## Obligation 1: conversational systems must clearly state that they're automated

If an online shop or a restaurant has a site chat that automatically answers questions about stock, orders or bookings, the regulation requires that system to clearly communicate, from the first message, that the user isn't talking to a human. There's no need for a lengthy disclaimer or an intrusive pop-up — usually a simple wording, visible right from the first line of the conversation, is enough to make the automated nature of the system clear to the other party.

The exception the regulation recognizes is a situation where it's “obvious” from a reasonable person's perspective that the other party is talking to an automated system — a voice assistant with a clearly synthetic voice, for example. For most chatbots on e-commerce sites or HoReCa booking sites, where the interface visually resembles an ordinary messaging conversation, this exception doesn't apply automatically, so explicit disclosure remains the safest way to comply.

## Obligation 2: AI-generated images and videos must be labeled as such

The second major obligation concerns synthetic content — images, video or audio generated or substantially modified by artificial intelligence, presented as real or authentic without any labeling. For a shop or a restaurant using AI-generated product images, a hero video for the site, or social media visuals, correctly labeling that content as AI-generated or AI-assisted becomes part of the publishing process, not an optional detail to add later.

Labeling doesn't necessarily mean a visible logo stamped on the image — it can be technical metadata, a visible notice next to the content, or both, depending on the distribution channel. What matters for compliance is that the information is accessible and clear to anyone who wants to check that content's origin, not buried in a general terms-and-conditions page that almost no one but lawyers ever reads.

## The grace period for content already published before 2 August 2026

For synthetic content already published before Article 50 came into force, the regulation grants a grace period until 2 December 2026 for retroactive labeling, mainly through technical watermarking. In practice, any AI-generated content already live — on the site, in catalogs or in presentation materials — has a limited window to be updated, not a permanent exemption just because it was published before the deadline.

For a business that has consistently used visual generation tools over the past few years — product images, campaign visuals, short social media clips — that realistically means an audit of published content, not just a process change for what gets created going forward. Putting off that audit until close to the deadline needlessly raises the risk of missing forgotten material, published years ago and still publicly visible.

## What's still off the table for now — so you don't panic for nothing

The much stricter obligations tied to “high-risk” systems — used, for example, in recruitment, credit scoring or critical infrastructure — have staggered enforcement dates stretching into 2027 and 2028, with significantly higher fines attached to non-compliance. For most online shops, restaurants or small service businesses, the systems in use today — a site chatbot, image generation, writing assistants — generally don't fall into the high-risk category.

The difference matters because alarmist posts, common on social media, often blend these two categories of obligations into a single narrative along the lines of “the AI Act bans everything starting tomorrow.” The reality is less dramatic, but just as concrete: the basic transparency obligations already apply, today, and ignoring them isn't about a blanket ban on using AI, but about missing the correct label on what's already being published.

## What it means in practice for an online shop or a restaurant

For an online shop, the practical points to watch are the site's support chat, any automated product-recommendation assistant, and product images or videos generated fully or partly with AI. For a restaurant or a HoReCa business, the situation more often involves automated chat bookings, menus with AI-assisted descriptions, or photo and video marketing material generated for social media — exactly the areas where AI tool adoption has grown fastest in recent years.

In both cases, the practical fix is simple to describe, even if it takes discipline to apply: every automated interaction with a customer identifies itself as such, and every piece of AI-generated visual or audio content gets a visible notice about its origin. The cost of this compliance is usually minor compared to the risk of a complaint or a negative public image tied to a lack of transparency, especially for a brand that speaks directly to end consumers.

## A quick audit to run internally, before asking for outside help

A reasonable internal audit starts with a simple list: everywhere the business currently uses any form of automated conversational system, and everywhere it has published AI-generated or AI-assisted visual or video content over the past two or three years. For each item on the list, the question is whether the automated or synthetic origin is communicated clearly and visibly to anyone who interacts with that content or system — not just noted technically in an internal document.

You don't need a legal department for this first step — it's really just honest inventory work, done by someone who knows the business's marketing channels and customer support well. Only once the list is complete and clear is it worth bringing in an outside consultant, for ambiguous cases or the exact wording of notices, not for the initial identification of risk points.

- 01List every automated customer touchpoint — site chat, voice assistants, automated messaging.
- 02List all AI-generated or AI-assisted visual and video content published in the last few years, across every channel.
- 03Check, for each automated touchpoint, whether its automated nature is communicated clearly from the first interaction.
- 04Add visible provenance labels to any synthetic content still live publicly, before 2 December 2026.
- 05Set a simple internal rule for future content, so labeling becomes automatic, not an afterthought chore.

## Transparency costs little now; its absence costs more later

For most small businesses, the AI Act remains far less dramatic than alarmist headlines suggest, but the basic obligations under Article 50 are real, already active, and easy for anyone to verify by looking closely at a website or a social media page. In most cases, the cost of compliance is a visible notice and a clear wording, not a fundamental change to how the business uses AI tools.

The safest approach remains treating transparency as part of the publishing process, not as a correction rushed through before a deadline. A business that openly discloses where it uses AI, both in automated conversations and in visual content, builds more trust with its customers over the long term than one that hides this detail until someone notices and makes it public. When you introduce AI into internal processes, transparency requirements belong in the [AI implementation](https://thenichesociety.ro/en/ai-engineering/ai-implementation) plan from the start, not at the end.

## Sources and further reading.

- 01[Regulation (EU) 2024/1689 — Artificial Intelligence Act, consolidated version — EUR-Lex](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng)
- 02[AI Act update: EU resolves to change rules and extend deadlines — Latham & Watkins](https://www.lw.com/en/insights/ai-act-update-eu-resolves-to-change-rules-and-extend-deadlines)
- 03[EU AI Act timeline and deadlines — Legiscope](https://www.legiscope.com/blog/eu-ai-act-timeline-deadlines.html)

## Frequently asked questions

### What is Article 50 of the AI Act, in short?

A transparency obligation requiring automated conversational systems to identify themselves as such, and synthetic content — images, video, audio generated or modified with AI — to be visibly labeled, regardless of the size of the company using them.

### Since when does this obligation actually apply?

Since 2 August 2026, for new systems and new content. For synthetic content published before that date, there's a grace period for retroactive labeling, until 2 December 2026.

### Do I really have to label AI-generated product photos?

Yes, if they're presented as real photos with no notice at all. The label can be a visible notice next to the image or technical metadata, as long as the information is accessible to anyone who wants to check the origin.

### What real risk does a small company face if it doesn't meet the transparency obligation?

The main risk is reputational and about compliance — possible complaints and, in the long run, alignment with a framework that's increasingly scrutinized publicly, not just by authorities, but by attentive customers too.

### Does Article 50 apply to very small companies too, with just a few employees?

Yes — the transparency obligation under Article 50 has no company-size threshold; it applies to anyone who makes an automated conversational system or synthetic content available to the public in the EU.

### What exactly does “synthetic content” mean in this context?

Any image, video clip or audio recording generated entirely by an AI system, or significantly modified by AI from the real original, presented publicly with no indication of that origin.

### Let's see what can be automated in your business.

A free 30-minute session: we'll tell you what can be automated, how long it takes and what it costs, with a fixed price after discovery.

We reply the same business day.
