
EU AI Act Transparency Rules: What Applies to You Now
EU AI Act Transparency Rules: What Applies to You Now
Something changed on 2 August 2026, and the advice about it has been all over the place.
The EU AI Act transparency rules under Article 50 became legally applicable that day. Since then I have watched small business owners get told they must now label every caption, every email and every blog post written with any AI help at all. That is not what the rules say. The panic is doing more damage than the regulation.
Here is the direct answer. The EU AI Act transparency rules require you to tell people when they are dealing with an AI system rather than a human, and to label deepfakes and unreviewed AI-generated content published on matters of public interest. They have applied since 2 August 2026, with penalties reaching EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Everyday AI-assisted marketing, written and edited by you, does not need a label.
Let me separate what is real from what is noise.
Does this reach a business in New Zealand?
Yes, if any part of what you put out lands in front of people in the EU.

The Act follows the output, not your address. A business outside the EU is covered where its AI system, or that system's output, is used inside the EU. There is no exemption for small businesses. A one-person practice in Christchurch selling a course to someone in Dublin sits under the same rules as a company with a legal department.
So the honest test is not "am I in Europe". It is "does anything I publish or sell reach someone who is".
The four situations Article 50 covers
Article 50 is narrower than the headlines suggest. It covers four specific situations, not all AI use.
The words doing the work there are provider and deployer. A provider develops an AI system, or has one developed, and puts it on the market under their own name. A deployer uses one in their business.
Most small business owners assume they are only ever deployers. That assumption is where people get caught.
The trap: you might be a provider without realising
Build a custom GPT or a chatbot, give it your branding and put it on your website, and you have not merely used someone else's tool. You have placed an AI system on the market under your own name. You are its provider, and the provider's disclosure duty comes with it.
This is the most common gap I see. Someone spends a weekend building a lovely little assistant for their site, gives it a friendly name and a photo, and never tells a soul it is AI. The friendlier and more human it feels, the more clearly the disclosure is needed.
The fix takes about ten seconds. A visible line at the start of the conversation saying it is an AI assistant, and whose business it belongs to.
Here's what you can add:
For a Custom GPT in ChatGPT
OpenAI currently gives GPT builders user-facing Name and Description fields, plus Instructions that apply to conversations.
I would configure it like this:
Name:[Business Name] AI Assistant
Description:An AI assistant provided by [Business Name] to help with [purpose].
Then put this near the top of the GPT's Instructions:
AI TRANSPARENCY At the beginning of the first response in every new conversation, clearly state: "You’re chatting with an AI assistant from [Business Name]." Give this disclosure before answering the user's substantive request.
Do not hide or omit the disclosure.
It only needs to be given once per conversation unless repeating it is necessary to avoid confusion.Where AI avatars and cloned voices sit
If you use an AI avatar or a cloned voice of a real person, you are in deepfake territory, and as the deployer the disclosure duty is yours.
I build AI avatars for people, so I will be plain about it. An avatar of yourself, presenting your own words, is still synthetic media of a real human. Label it. One short line in the caption is enough. Nobody has ever unsubscribed over "this video uses an AI version of me". Plenty of people would lose trust finding out later.
The exemption almost nobody mentions
Here is the part that should take the pressure off.
The duty on AI-generated text applies to text published on matters of public interest where there has been no human editorial review. Where a person reviews the content and takes editorial responsibility for it, that duty does not bite.
Read that twice if you have been worrying about your blog. Your reviewed, edited, approved content is not the target. Unreviewed machine output published as though it were journalism is.
The regulation is pointed at content nobody stood behind. If you stand behind yours, you are already doing the thing it asks for. Content generated before 2 August 2026 does not need labelling retroactively either, and systems already on the market before that date have until 2 December 2026 to meet the marking obligation.
A short checklist
- List every place AI speaks to a customer for you: website chatbots, voice agents, DM autoresponders. Add a visible AI disclosure to each.
- Check whether you built any of them under your own brand. If so, you are the provider, not the deployer, and the heavier duty is yours.
- Label AI avatars, cloned voices and synthetic video of real people.
- Keep a human reviewing anything you publish, and record that you do.
- Put it in one written AI policy, so the answer exists before anyone asks for it.
That last one matters more than it looks. When a client, a platform or a regulator asks what you do, "we have a policy and here it is" is a completely different conversation from working it out on the spot.
Frequently asked questions
Do I have to label every social post I wrote with AI help?
No. If you wrote it, edited it and stand behind it, the Article 50 text duty is not aimed at you. It targets unreviewed AI text on matters of public interest.
When did the rules start?
2 August 2026. Systems already on the market before that date have until 2 December 2026 to meet the marking obligation.
What are the penalties?
Up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.
Are small businesses exempt?
No. There is no size exemption. The duties follow what the system does and where its output is used.
Does this apply if I have never sold into Europe?
Not directly. The rules bite where output is used in the EU. Even so, disclosure is becoming the baseline expectation everywhere, so building the habit now costs you nothing.
Key takeaways
- The EU AI Act transparency rules have applied since 2 August 2026, with fines up to EUR 15 million or 3% of global turnover and no small-business exemption.
- They reach businesses outside the EU whose AI output is used inside it.
- The duties cover four narrow situations, not all AI use.
- Build a chatbot under your own brand and you become its provider, with the heavier duty.
- Human review is what the regulation is really asking for, and you are probably already doing it.
Most of this is a documentation job, not a technology job. If you would rather have the disclosure lines and the written policy sorted in an afternoon than left as a nagging worry at the back of your mind, that is exactly what my AI Usage Policy covers.
Need some help with this? Let's chat.
