On 2 August 2026 the transparency rules of the European AI regulation started to apply. A week later a client asked me his first question about it: “Do I have to put something about AI on my website now, or will I be fined?”
Short answer: probably yes, something - but not the thing people expect, and not where they expect it. Here is what actually concerns the owner of an ordinary small business website, point by point.
One disclaimer first. I am a webmaster, not a lawyer. What follows is the technical side of the subject with links to the official texts. If your case is heavier - say an AI takes part in screening job applicants or assessing creditworthiness - you are in a different risk category, and that calls for a lawyer rather than a webmaster.
What actually happened
Regulation EU 2024/1689, better known as the AI Act, was adopted in 2024 and comes into force in stages. On 2 August 2026 its Article 50, the one about transparency, became applicable.
The logic of the text matters: it sorts AI systems by risk level. Most small business uses - help with texts, handling enquiries - fall into minimal or limited risk. The heavy obligations target high-risk cases: recruitment, credit decisions, healthcare.
There is no size threshold. A sole trader and a company of five hundred people are in exactly the same position. That is usually the unwelcome part of the conversation.
Point one: the chatbot has to own up
If a chatbot runs on your site, the visitor must understand they are talking to a machine rather than a person. There is one exception: when it is obvious from the context anyway.
In practice that means checking three things:
- the welcome message, or a note beside the chat window, says plainly that an automated assistant is answering;
- the bot does not carry a human first name and a staff photo that would make the visitor think they are writing to a person;
- there is a clear route to a real human when the question gets complicated.

The wording does not have to be legal. “Vous discutez avec un assistant automatique” in the first message covers it.
The most common mistake I run into: a bot signed “Julie” with a stock photo of a young woman. This used to be sold as a way to build trust. It is now exactly what the regulation describes as misleading.
Point two: marking AI content, and a lot of panic
This is the part where you can relax.
The requirement for machine-readable marking - watermarks and metadata that let a machine recognise generated content - is addressed to model providers. That is the job of OpenAI, Google, Mistral and the rest, not yours. You do not have to embed invisible markers into your own texts and images.

There is a separate duty to inform people, and that one can reach whoever publishes content. Its scope, though, is narrow: it targets deepfakes and text published to inform the public on matters of public interest. A news piece about an election is one thing; a plumber’s services page is another.
More importantly still: content that AI merely helped to fix or rephrase does not fall under this at all. Editing help does not turn a text into generated content.
For machine-readable marking there is a technical grace period until 2 December 2026, and only for systems that were already on the market before 2 August.
Point three: the part almost nobody mentions
The regulation contains one requirement that slips past everyone. A company that uses AI in its work counts as a “deployer”, and it has to make sure the people working with that AI understand it well enough.
Formally this is not about the website. In practice it means that if you give a colleague access to an AI tool, they need to know where it makes things up, what must never be pasted into it, and why the output gets checked. No certification is required, but “I gave them the ChatGPT password” does not meet the requirement either.
Model provider
Machine-readable marking: watermarks and metadata that let a machine recognise generated content. This is not your obligation.
Website owner
It is visible that an automated assistant answers. The bot has no borrowed name or photo of a person. A route to a human contact exists.
Employer
The employee knows where the tool makes things up and what must not be pasted into it. No certification needed, a shared password is not enough.
What you can check yourself in ten minutes
Take your site and walk through the list:
- Is there a chatbot, a support widget or a pop-up with automated replies.
- Does the first message make clear that a human is not answering.
- Does the bot avoid an invented staff name and a photo of a person.
- Is there a route to a human contact: form, phone, e-mail.
- If the chat comes from a third party, do you know where visitor conversations go and do you have a data processing agreement with the provider.
- Are there images or videos on the site where a real person says something they never said. That is deepfake territory, and the requirements there are stricter.
The first four points the owner checks alone, no specialist needed. The fifth almost always stalls on the same thing: nobody remembers which widget was installed two years ago, or on what terms.
What the real risk looks like
The numbers in the regulation are frightening: up to fifteen million euros or three per cent of worldwide turnover for a breach of transparency obligations.
Realistically: supervisory authorities start with large players and systemic breaches, not with a hairdresser’s website in Marseille. That is still no reason to leave alone something that takes half an hour to put right.
A different risk sits much closer. A visitor who works out that “Julie” is a script loses trust not in the bot but in the business. On this point the regulation and common sense agree.
When to call a specialist
The chat wording and dropping the fake name you can handle yourself. It gets harder when you need to know what is actually running on the site: which widget, where it sends data, whether there is an agreement with its provider, what ends up in cookies and how all of that connects to your consent banner. That part is reading code and settings, not reading a regulation.
If you have the time and the inclination, some of this is fine to do yourself. If you would rather run your business than work through European regulations and other people’s widgets, I can take the technical part: I check what is running on the site, where it sends data, and put the wording and the settings in order.
Sources and data date: Regulation EU 2024/1689 (AI Act), Article 50, applicable from 02.08.2026; technical grace period for machine-readable marking until 02.12.2026. Data verified on 17.08.2026.