August 2 Already Happened: The EU AI Act Clauses That Now Bite Your AI-Enabled Services
Many UK businesses believe the Digital Omnibus paused the EU AI Act. It didn't. Article 50 transparency rules and GPAI enforcement went live on 2 August 2026, and SMEs running chatbots or generative AI for EU-facing clients have obligations right now.
A Nottingham marketing agency called us in September, quietly panicking. They'd built a customer service chatbot for a client in Dublin, and someone on the client's legal team had asked a simple question: does this thing comply with the EU AI Act's transparency rules? The agency's answer had been, in effect, "Isn't all that on hold now?"
It isn't. And that gap between what people assume and what's actually in force is exactly where the risk sits.
The Digital Omnibus didn't hit pause on everything
Here's where the confusion started. In late 2025, the European Commission published its Digital Omnibus — a package of simplifications aimed at easing the compliance burden on businesses. The headlines were generous. "EU delays AI Act." "Brussels blinks on AI rules." You could be forgiven for reading those and concluding the whole thing had been kicked down the road.
What actually got adjusted was the timeline for high-risk AI systems — the category covering things like AI used in recruitment, credit scoring, medical devices and critical infrastructure. Those obligations, which were among the heaviest, got breathing room. That's real, and if you're building high-risk systems it matters.
But the Act was never a single switch. It rolls out in stages, and two of those stages landed on 2 August 2026 and were not delayed:
- Article 50 transparency obligations — the rules that govern chatbots, AI-generated content and synthetic media.
- Enforcement powers over general-purpose AI (GPAI) models — the machinery that lets regulators actually investigate and fine.
So the date has passed. The obligations are live. And a lot of the AI-enabled services that SMEs are quietly running — often without thinking of them as "AI systems" at all — now fall squarely inside the rules.
Why this catches UK businesses too
A quick reminder, because people get this wrong as well: Brexit doesn't put you outside the AI Act.
The Act follows the market, not the borders. If your AI system's output is used inside the EU, or you're providing a service to someone in the EU, you're in scope. That Nottingham agency building a chatbot for a Dublin client? In scope. A Leicester SaaS firm whose generative tool is used by customers in France and Germany? In scope. A Derby consultancy deploying an AI assistant on a client's public-facing website, where EU citizens will interact with it? In scope.
You don't need an office in Frankfurt. You need one EU-facing use case.
What Article 50 actually requires
Article 50 is about honesty. The principle is simple: people have a right to know when they're dealing with a machine or looking at something a machine made. In practice, it breaks into a few concrete duties.
Tell people they're talking to a bot. If you deploy a chatbot or voice assistant that interacts with people, those people must be informed they're interacting with AI — unless it's blindingly obvious from the context. "Obvious" is doing a lot of work there, and it's not a safe assumption to lean on. A friendly little chat widget in the corner of a website that answers in fluent, human-sounding sentences is not obviously a bot to most visitors. So you tell them.
Label AI-generated content. If your system produces synthetic audio, image, video or text, that output needs to be marked as artificially generated, in a machine-readable way where technically feasible. This is aimed at the deepfake problem, but it reaches ordinary generative tools too. If you're churning out product descriptions, images or generated copy on behalf of clients, this is your clause.
Disclose deepfakes and manipulated media. Where content has been generated or altered to resemble real people, places or events — the deepfake category — there's a clear obligation to disclose that it's synthetic.
The recurring theme is that the burden lands on the deployer as much as the developer. You might not have built the underlying model. You bought an API, wrapped a nice interface around it, and sold it as a service. Under Article 50, you're still the one who has to make sure the disclosures are there.
The GPAI enforcement powers that switched on
The second half of what activated on 2 August is less about a specific duty and more about teeth.
General-purpose AI models — think the large foundation models that sit underneath most of the tools you're using — carry their own obligations around documentation, copyright policy and transparency. As of that August date, the regulators gained the power to enforce those rules. Investigations, requests for information, penalties: the enforcement apparatus is now switched on rather than sitting dormant in the text.
For most SMEs, you're not the one training a foundation model, so you're not the direct target here. But it changes the environment you operate in. Your suppliers are now under active scrutiny, which affects the assurances you can and should be getting from them. If a model provider can't tell you how their system meets its obligations, that's a supply-chain problem that flows straight down to you.
The number that should focus minds
Breaching the transparency obligations can cost up to €15 million, or 3% of global annual turnover, whichever is higher.
Read that again with an SME's finances in mind. The percentage figure is calculated on turnover, not profit, and on a global basis. For a small firm, the €15m ceiling is the scary part; for a larger group, the 3% is. Either way, this is not a parking-fine level of penalty. It's an existential one.
Whether regulators go after small deployers first is a separate question, and enforcement in the early months tends to focus on the big players. But "they probably won't come for us yet" is not a compliance strategy. It's a bet.
What to actually do about it
The good news is that Article 50 compliance is, for most SMEs, achievable without a huge project. It's mostly about knowing what you're running and being upfront about it.
-
Inventory your AI. List every service you provide that uses AI — chatbots, content generators, image tools, recommendation engines, anything with a model behind it. Include the ones you built for clients and the ones running on your own site. You can't comply with rules for systems you've forgotten you have.
-
Check the EU exposure of each one. For each system, ask: could its output or interaction reach someone in the EU? If yes, it's in scope.
-
Add the disclosures. Make sure chatbots announce themselves. Make sure generated content is labelled. This is often a small change — a line of text, a badge, a metadata tag — but it needs to actually be there.
-
Pin down responsibility with clients. If you're deploying on a client's behalf, the contract should say who owns the compliance duty. Don't leave it as an assumption that unravels the first time a regulator asks.
-
Get supplier assurances in writing. Ask your AI vendors how they meet their GPAI obligations. A vendor who can answer clearly is a lower risk to carry.
The date on the calendar has already gone. The obligations didn't wait for anyone to notice. If you've been telling yourself the whole thing is on hold, this is the moment to check your actual exposure rather than the headlines — and it's a conversation worth having before someone else forces it.
If you're not sure which of your services are in scope, we can help you map it out. Better to spend an afternoon on an inventory now than to explain a gap to a regulator later.
