LibraryThe daily read10 min read
The AI Act just made you the vendor
The EU transparency rules went live on Sunday, and for a normal small business the whole obligation is about forty minutes of unpaid work. The part nobody is saying out loud: the moment you build the customer-facing bot yourself instead of buying one, the duty moves off your vendor's desk and onto yours.

The chat widget on your website has to tell people it is a bot. If you bought that widget from a vendor, the legal duty to say so belongs to the vendor and you can go back to work. If you built it yourself on an API over a couple of evenings, which is precisely what this audience has spent the last year learning how to do, the duty is yours, because as of Sunday you are not a customer of an AI system anymore. You are the provider of one. For a normal small business the entire obligation is roughly forty minutes of work and costs nothing but the time, and there are consultancies quoting four and five figures this week to do those forty minutes on your behalf.
What actually came due on Sunday
Article 50 of the EU AI Act started applying on 2 August 2026. It is four short paragraphs, and it is the part of that law aimed at ordinary businesses rather than at credit scorers, medical device makers, and the rest of the high risk crowd.
Providers of AI systems built to interact directly with people have to design them so a person knows they are talking to an AI, unless that is obvious. Providers of systems that generate synthetic audio, image, video or text have to mark the outputs in a machine readable format so they can be detected as artificially generated. Deployers running emotion recognition or biometric categorisation have to tell the people exposed to it. And deployers publishing deepfakes, or AI written text that informs the public on matters of public interest, have to label it. All of it has to arrive clearly and, at the latest, on first contact. The Commission's own FAQ on Article 50, last updated 24 July, is the readable version, and it is written better than most of the law firm alerts summarising it.
Two dates are worth holding onto. The Commission adopted its guidelines on 20 July, and the Code of Practice on Transparency of AI-generated Content was judged adequate by the Commission and the AI Board in the first half of the month, with about 190 organisations signed by the end of July. Systems already on the market before 2 August get until 2 December 2026 to satisfy the machine readable marking duty specifically, and nothing generated before 2 August has to be labelled retroactively.
Then there is the bit half the coverage fumbled. Yes, the AI Act got delayed. Not this part. The Digital Omnibus, which the Council green lit at the end of June, pushed the heavy high risk regime for standalone Annex III systems out to 2 December 2027 and product embedded systems to August 2028. It did not touch Article 50. If you saw a June headline saying the August deadline moved and quietly filed the whole thing under next year's problem, you filed the wrong deadline.
Provider or deployer is the only question that matters
Everything downstream turns on which of two words describes you, and most people reading their own compliance summary this week are reading the wrong half of it.
A deployer is anyone using an AI system under their own authority in the course of business. That is the boring case. You pay for a chat product, you switch it on, you are a deployer, and your obligations under Article 50 are narrow: emotion recognition and biometric categorisation, which you almost certainly are not doing, and labelling deepfakes and certain published AI text, which we will get to.
A provider is whoever develops an AI system, or has one developed, and puts it on the market or into service under their own name. That is you the moment you wire a model to your own knowledge base, brand it, and stick it on your contact page. The Commission is unambiguous that this applies whether or not you are established in the EU. And the provider carries the two duties that actually have teeth: the disclosure in Article 50(1) and the machine readable marking in 50(2).
Read that again, because it inverts the usual shape of software risk. Normally the thing you build yourself is the thing you control and the thing you buy is the thing that surprises you. Here it runs the other way. Buying moves the legal surface to somebody with a compliance department. Building pulls it back to your desk, next to the invoicing and the truck insurance.
That is not a reason to stop building. The whole argument for building your own tools is that the six week engineering queue and the agency retainer are worse than the alternative, and one line of disclosure copy does not change that arithmetic. But it is an honest cost of the build path, and I have not seen a single person selling no code agent builders mention it.
There is a scope question sitting underneath all of this that a US operator should settle first. The Act reaches providers and deployers located in a third country where the output of the AI system is used in the Union. Your bot answers a prospect in Dublin at two in the morning and that output was used in the Union. If you genuinely have no EU customers, no EU visitors converting, no EU staff, you are out of scope and you should spend zero euros on this. If you are not sure, you are almost certainly in, because "not sure" usually means the analytics say otherwise.
The forty minutes, spelled out
Start with an inventory, and keep it to one page. The only question is which of your AI touches a human being who does not work for you. The internal assistant summarising your own meeting notes is not in scope for the disclosure duty. The website chat, the after hours voice intake, the AI that replies to inbound leads from a shared mailbox, those are.
For anything on that list that talks to people, put the disclosure at the top of the first message and stop worrying about it. "You are chatting with our AI assistant, ask for a person any time" clears the bar. Do it even if you bought the tool and technically owe nothing, because the exception for cases where the AI is obvious is, in the Commission's own words, to be interpreted restrictively, and nobody has litigated where obvious ends. The cost of being generous here is one sentence.
Published text is narrower than the panic suggests. The labelling duty bites only where the text is published, informative to the public, and on a matter of public interest, which the guidance frames as politics, public administration, health, consumer safety, environmental protection, and economic or scientific developments that are genuinely subjects of public debate. Your maintenance tips post is not that. A piece explaining a new tax rule to your customers might be. And there is a clean exemption either way: text that has undergone real human review, by someone with relevant knowledge who can reject it on the substance, under a named person holding editorial responsibility, does not need a label at all. Spell checking does not count. Skimming does not count. An actual editor who reads it and can kill it does, and that person costs less than a labelling programme and improves the writing.
Images are the one where people get the rule backwards. A deepfake, in the Act's definition, needs three things at once: it has to resemble something, that something has to exist or plausibly could, and it has to falsely appear authentic. Your AI generated abstract header illustration is not a deepfake. An AI generated photo of your team standing in front of your shop, or of a finished job you did not actually do, is. And you cannot lean on the invisible watermark the image tool embedded to satisfy your own duty. The Commission spells this out: the deployer's disclosure has to be perceivable by a human without special tools, so a visible label, and the EU has published a set of icons for exactly this if you want something that is not a sentence.
What the compliance emails are not telling you
The fine number being waved at you is wrong for your business. Yes, Article 50 breaches sit in the tier that reaches fifteen million euros or three percent of worldwide turnover, whichever is higher. But the penalties article then says that for SMEs, including start ups, the fine is capped at whichever of those is lower. For a company doing four million a year, the ceiling is around a hundred and twenty thousand, not fifteen million, and the actual amount takes into account how you cooperated, whether it was negligent or deliberate, and what you did to fix it. That is still real money and I am not telling you to ignore it. I am telling you that the number in the subject line of the email you got on Monday was chosen to make you buy something.
Enforcement in month one is close to nothing, and pretending otherwise is its own kind of dishonesty. This gets policed by national market surveillance authorities, member state by member state, and several of them are still assembling. The AI Office only holds the reins in narrow cases. Nobody is auditing a ninety person distributor's chat widget in August. That is an argument for calm, not for skipping it, because the work is free and the exposure compounds quietly: the day somebody does complain, the question will be what you had in place, and "we added a sentence in August" is a very good answer.
The genuinely hard obligation is the one almost nobody talks about, and it belongs to providers. Marking generated output in a machine readable, robust, interoperable way is a solved problem for images and a much worse one for text. If you have built a system that generates content and you are now the provider of it, the Code of Practice is the pragmatic move, because signing it lets you point at an approved framework instead of arguing adequacy with whichever national authority happens to ask. Not signing is allowed. It just means the burden of proving your approach was adequate is entirely yours, in a conversation you did not schedule.
What breaks in month three is drift. Somebody rewrites the chat greeting to lift conversion, or the prompt gets tuned, or the widget gets swapped during a site redesign, and the disclosure line goes with it. There is no monitor for this, no alert, no dashboard. Put it wherever you keep the cookie banner and the privacy policy, on the list of things a person physically checks on a schedule, because it is exactly the sort of small correct thing that survives six weeks and then quietly does not.
And who is this genuinely wrong for? Anyone with no EU exposure and no intention of getting any. Do nothing, and mean it. Although notice which way the wind is blowing. California has had a bot disclosure statute since 2019, Utah added its own in 2024, and the direction of travel is that telling a person they are talking to a machine becomes ordinary practice rather than a jurisdictional quirk. The forty minutes you spend this week is not really EU compliance work. It is the version of your product you were going to end up shipping anyway.
The pitch for building your own tools was always that you get to keep the leverage that used to belong to the vendor. Nobody mentioned you also inherit the vendor's paperwork.
Sources
Every claim above traces back to one of these. Go read them yourself.
- 01Transparency obligations under Article 50 of the AI Act (Commission FAQ)
European Commission / digital-strategy.ec.europa.eu / retrieved Aug 04, 2026
- 02Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal text
Official Journal of the European Union / eur-lex.europa.eu / retrieved Aug 04, 2026
- 03Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems
Future of Life Institute / artificialintelligenceact.eu / retrieved Aug 04, 2026
- 04Article 99: Penalties
Future of Life Institute / artificialintelligenceact.eu / retrieved Aug 04, 2026
- 05Article 2: Scope
Future of Life Institute / artificialintelligenceact.eu / retrieved Aug 04, 2026
- 06Code of Practice on Transparency of AI-generated Content
European Commission / digital-strategy.ec.europa.eu / retrieved Aug 04, 2026
- 07EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes
Gibson Dunn / gibsondunn.com / retrieved Aug 04, 2026
Related reading
Nearest neighbours by meaning, drawn from the whole library rather than from matching tags. Some of these are from a different series on purpose.
The daily read
Your spreadsheet just got a front end
A twelve-person team pays about $2,880 a year for a tool whose actual job is putting a usable view on data that already lives in a spreadsheet. Google now builds that view from one sentence and writes changes back to the sheet, and it fixes none of the reasons the spreadsheet was a bad system of record.
The daily read
The mark that survives the paste
Every Claude model launched since August 2 weaves an invisible watermark into the text it generates, worldwide, and it travels when the text is copied and pasted. The detector that reads it has not shipped yet, which means for now the mark is a liability you carry and not a check you can run.
The daily read
Your required fields were never required
The required field you configured in HubSpot has been optional for every robot pointed at your CRM: the AI agent, the nightly script, the Zap nobody owns. HubSpot said on Tuesday that changes with the September API version, and the part worth reading twice is that it changes on your schedule, not theirs.