The truth is, there weren’t many of us… and then all hell broke loose!
After nearly two years of waiting, as of August 2—with half the country on vacation—part of the European Artificial Intelligence Act is now in effect. This law directly impacts something that almost every company I know has set up: the customer service bot on its website
Complying with that specific part of the law literally takes just one sentence.
What has gone into effect?
It is called Article 50 of the European AI Regulation and deals with transparency. The Commission itself confirms this unequivocally: the obligations under this article have been in effect since August 2, 2026. Not “will apply,” not “are expected to,” but THEY ARE ALREADY IN EFFECT NOW!
But let’s not get too worked up… or should we? This article doesn’t ban anything at all (that’s the misunderstanding I’ve been encountering over the past few weeks). People assume that Brussels is here to tell them which AI they can and can’t use, but it’s actually a bit more boring—and much more reasonable. You can use as much artificial intelligence as you want, but you can’t let the person on the other end think they’re talking to a human when they’re actually talking to a machine.
In practice, this comes down to four things: if a machine interacts with a person, you must indicate that it is a machine; if content is generated by AI, you must label it so that it can be detected; if you publish a deepfake, it must be labeled as such; and if your system categorizes people based on biometric features or reads their emotions, you must inform that person.
That’s it, the full text of the article is quite a bit longer, of course, with its nuances about who is a provider and who is an implementer, but the gist of it fits into a single paragraph.
(And yes, the distinction between provider and implementer matters, because it’s not the same to be the one who builds the system as it is to be the one who uses it in your business. Most of you are probably in the latter category.)
This legislation is being counted backward
This is what prompted me to write this article: for the past few days, I’ve been seeing this figure misrepresented on LinkedIn and in some reputable media outlets.
What it says Article 99 of the regulation is that failure to comply with the transparency obligations set forth in Article 50 is punishable by a fine of up to 15 million euros or up to 3% of the company’s global annual turnover for the previous fiscal year, whichever is greater.
The phrase is phrased as “up to 15 million or 3%,” which sounds like you can choose whichever number suits you best, but that’s not the case.
You can do the math: a company with annual revenue of 40 million doesn’t risk 15 million—it risks 1.2 million (3%, which is less)—but a company with annual revenue of 2,000 million doesn’t risk 15 million; it risks 60 million.
Fifteen million isn’t the upper limit for large companies; it’s the lower limit (it’s exactly the same mechanism we’re already familiar with from the GDPR), yet we still tend to interpret it as a flat rate.
For small and medium-sized businesses and startups, the logic is reversed: the lower of the two amounts is applied (otherwise, this would simply be unaffordable for a company with 20 employees).
I sincerely hope that the sanctions won’t be imposed on small and medium-sized businesses, but it’s important to start doing our homework as soon as possible.
The Extension Nobody Is Talking About
This is the piece of information that’s really worth taking away, and I haven’t seen it anywhere in Spanish.
There is a grace period, but it is very short, and it is important to understand exactly how long it lasts. According to the Commission itself, it applies only to systems already on the market before August 2, 2026, and only to the obligation to label and detect AI-generated content (Article 50(2)). Those systems have until December 2, 2026.
If your concern is labeling AI-generated images or text in a system you already had set up, you can breathe easy until December, but if your concern is the bot that talks to your customers, you can’t breathe easy at all. That takes effect in August. And I’ll bet anything you want that there are plenty of consultants out there selling the extension as if it covered the entire article—and it doesn’t.
In addition, there is a third aspect that almost no one mentions and that I think is important: the Commission has promoted a code of best practices regarding the transparency of AI-generated content, and signatories can rely on its guidelines to demonstrate compliance. By the end of July, nearly 190 organizations had signed it, but keep in mind that it’s not mandatory. Labeling content at the source (Anthropic is already labeling all content generated by its systems). I’ll definitely talk more about this in another article.
So now, what can we do?
The first step is to take stock, and this takes less time than it seems: Where in my business does a machine interact with a person? The website chat, the WhatsApp bot, the system that automatically responds to emails, the voice agent that answers the phone if you have one—and don’t forget that “smart” form someone set up eight months ago that nobody remembers anymore. If a user might get confused, we have a problem.
We can fix this simply by using the phrase: “Hello, I’m the virtual assistant for such-and-such company.” No asterisks in the footer, no complex privacy policy, and no legal text that nobody reads. Most importantly, it needs to be clear from the start, not at the end.
Next comes the content, and here it’s important to be honest with yourself. If you publish AI-generated images, video, or audio, label them as such. If they’re deepfakes, that’s all the more reason to do so. And if the content is generated by a third-party system, ask the provider if its output includes machine-readable tags, because that responsibility falls on the system’s developer, not on you—but you’ll be the ones held accountable.
And finally, something that isn’t in the rules, but that I learned the hard way: write down somewhere who is responsible for this in your company, including their first and last names. Because a responsibility that belongs to everyone ends up belonging to no one in practice.
My thoughts on this matter
To begin with—and I’m surprised to say this—I think Article 50 is actually quite well thought out. There’s plenty to criticize about European regulations (I’ve been among those who’ve grumbled about the bureaucratic burden), and I still think the “high-risk” category is going to be a major headache for small businesses, but this specific provision calls for something anyone would support in a bar conversation: knowing whether there’s a real person on the other end.
On the other hand—and this is where I feel a little more uncomfortable—I suspect that actual compliance is going to be terrible for months, not because of bad faith, but out of sheer ignorance.
Most Spanish companies with a chatbot on their website don’t even know that Article 50 exists, and those that do are waiting for someone to tell them exactly what to do.
If you’re reading this at a company that uses an automated chatbot, I’ll bet you a cup of coffee that no one has reviewed the welcome message since it was set up.
And there’s one more thing: this turns transparency into a competitive advantage, not a cost. When, a year from now, half of the content (I think most of it) is generated by machines, clearly stating what you’ve done and what the system has done will be a selling point, not just a formality.
A company that gives advance notice seems more professional—not any less modern—and the ones that get caught out will be precisely those that are currently trying to make their bot sound as human as possible so that the customer doesn’t notice a thing.
While preparing this article, I realized that a large portion of the infographics circulating that explain the AI law are actually generated by AI (without being labeled as such, of course). In other words, we’re explaining the requirement to label synthetic content using unlabeled synthetic content. It’s not a violation, but the irony is undeniable.
If you have a chat feature on your website, take a look at it this week—it’ll only take ten minutes, and you’ll solve a problem you didn’t see coming.
Have a good week!
LINKS OF INTEREST:
- European Commission — “Transparency Obligations Under Article 50 of the AI Act” (Official FAQ)
- AI Regulation (EU) — Article 50: Transparency Requirements for Providers and Operators of Certain AI Systems
- AI Regulation (EU) — Article 99: Penalties
- European Commission — Code of Best Practices on Transparency for AI-Generated Content
- European Commission — Guidelines on Transparency Requirements for Suppliers and Implementers
