The EU AI Act's Transparency Rules Are Live — Your Chatbot & Deepfake Labeling Checklist
Article 50 of the EU AI Act became enforceable on 2 August 2026, covering chatbot disclosure and synthetic content marking. Here's a practical checklist for UK IT teams that thought they had until 2027.
Ask most UK SME owners about the EU AI Act and you'll hear a version of the same shrug: "That's a 2027 problem." It's an understandable mistake. The headlines about high-risk AI systems, conformity assessments and the bulk of the Act's obligations really did land on dates well into 2026 and 2027. But one slice of the rules quietly became enforceable on 2 August 2026 — and it applies to far more businesses than the phrase "high-risk AI" suggests.
That slice is Article 50, the transparency chapter. It covers chatbots, AI-generated text, images, audio and video, and deepfakes. If your business uses generative AI in a way that reaches people in the EU — customers, prospects, job applicants, anyone — these rules apply to you regardless of where you're based. A software firm in Derby that runs a support chatbot for European clients is in scope. So is a Nottingham marketing agency producing AI images for a client selling into Germany.
Let's clear up the confusion and turn it into something you can act on this week.
Why "the UK left the EU" doesn't get you off the hook
The AI Act uses the same extraterritorial logic as GDPR. It isn't about where your servers or your office sit. It's about who your AI output reaches. If the results of your AI system are used by people located in the EU, the obligations follow.
For an SME, that usually means one of three situations:
- You sell products or services to EU customers and use AI in that relationship (a chatbot, automated emails, generated content).
- You provide AI-powered tools or software to businesses that operate in the EU.
- You produce synthetic media — images, voiceovers, video — that gets published to an EU audience.
If none of that applies and your entire footprint is UK-only, Article 50 doesn't reach you today. But be honest about your customer base before you conclude that. Plenty of "UK" businesses have a scattering of European clients they've never thought of in these terms.
What Article 50 actually requires
The rules break down into four duties. None of them demand expensive engineering. Most are about disclosure and labelling, which is why IT teams can handle them without a compliance overhaul.
1. Tell people when they're talking to a machine. If a person interacts with an AI chatbot or voice assistant, they must be informed they're dealing with AI — unless it's obvious to a reasonably observant person. "Obvious" is doing a lot of work in that sentence, and it's not a licence to stay quiet. A slick, human-sounding assistant is exactly the kind of system regulators had in mind.
2. Mark AI-generated content as machine-readable. Synthetic text, images, audio and video produced by your systems must be marked in a way machines can detect — think watermarking or embedded metadata that signals "this was AI-generated." This is the most technical requirement, and the one most SMEs have overlooked entirely.
3. Label deepfakes clearly to humans. If you produce or manipulate image, audio or video content that resembles real people, places or events in a way that could mislead — a deepfake — you must disclose that it's artificially generated or manipulated. There are carve-outs for obvious art, satire and creative work, but the default is transparency.
4. Flag AI-generated text on matters of public interest. Text published to inform the public about matters of public interest must be disclosed as AI-generated, unless a human has reviewed it and someone takes editorial responsibility. For most SMEs this is narrow, but news-adjacent or public-information content should be checked.
The checklist: do this now
Here's the practical sequence I'd give an IT lead who's just realised this is live.
Step 1 — Inventory your AI touchpoints. You can't label what you haven't found. Walk through every customer-facing surface and list anything driven by generative AI: website chatbots, WhatsApp or Messenger bots, AI email responders, voice IVR systems, AI-generated marketing images, product copy, video content. Include tools bought from vendors, not just things you built. A surprising number of SME chatbots are white-labelled third-party products.
Step 2 — Add or check chatbot disclosure. For every conversational AI, confirm there's a clear, upfront statement that the user is talking to an automated system. A line in the opening message — "Hi, I'm an AI assistant. I can help with X, or connect you to a colleague" — does the job. Don't bury it in a privacy policy nobody reads. If you use a third-party chatbot platform, check whether disclosure is enabled by default; often it isn't.
Step 3 — Sort out content marking. For AI-generated images, video and audio, you need machine-readable marking. The emerging standard here is C2PA / Content Credentials, backed by Adobe, Microsoft and others, which embeds provenance metadata into files. Many mainstream tools now support it: Adobe Firefly, some Microsoft and OpenAI image outputs, and a growing list of others. Your job is to confirm your generation tools apply it, and that your publishing pipeline doesn't strip the metadata out. (Resizing and re-exporting through the wrong tool often does exactly that — test it.)
Step 4 — Handle deepfakes and synthetic media labels. If you produce any content featuring realistic synthetic people or scenes — AI avatars in videos, cloned voiceovers, composite imagery — add a visible label. "AI-generated" on the image or in the video caption is enough. Build this into your content sign-off so it isn't left to memory.
Step 5 — Write it down. Regulators reward businesses that can show a considered approach. A short internal policy — what you use, how you disclose it, who's responsible — is worth its weight when questions come. It also stops the knowledge living only in one person's head.
What can wait
Equally important is knowing what not to panic about. The heavier obligations — risk management systems, technical documentation, conformity assessments for high-risk AI — sit on later timelines, largely 2026 into 2027, and many won't apply to a typical SME at all. If you're using off-the-shelf generative tools for support and marketing, you're a deployer, not a high-risk provider, and your burden is mostly the transparency duties above.
So don't let a consultant frighten you into a six-figure compliance programme for a support chatbot. The proportionate response is disclosure, labelling and a written record — not a rebuild.
Where this tends to go wrong
The two failure points we see most often are both mundane. First, businesses forget about the AI inside tools they didn't build — a booking widget, a helpdesk plugin, a marketing suite that quietly added an AI feature in an update. Second, content marking gets stripped somewhere in the workflow, so an image that started with proper credentials arrives on the website naked. Both are easy to fix once you look, and both are invisible until you do.
If you're not sure where your AI touchpoints are, or whether your content pipeline preserves provenance data, that's exactly the kind of audit we can run quickly. Getting the transparency basics right now is far cheaper than explaining to a regulator later why nobody was told they were talking to a robot.
