Back to Blog Security

EU AI Act: what your company actually has to do before 2 August 2026

Zespół ESKOM.AI 2026-07-22 Reading time: 6 min

On 2 August 2026 the provisions of the EU Artificial Intelligence Act (AI Act) that matter most to the majority of companies enter into application, including the transparency obligations under Article 50. If your company runs a chatbot, generates content with AI or uses AI tools in customer communication, this deadline applies to you directly. The good news: for a typical SME the scope of work is limited and can be wrapped up in a few weeks. The bad news: you can't wrap it up if you don't know where in the company you're using AI in the first place.

Below, a practical guide. No panic and no legalese.

What exactly takes effect on 2 August 2026

From that day, the transparency obligations under Article 50 of the AI Act apply. In practice they mean that:

  • chatbots and other AI systems that interact with people must clearly inform the user that they are talking to artificial intelligence, unless this is obvious from the context;
  • content generated or substantially modified by AI (text, images, audio, video) should be labelled accordingly, particularly when it is published to inform the public;
  • deepfakes, meaning content that deceptively imitates real people, places or events, must be clearly disclosed as artificially generated.

The calendar has two nuances:

  • Watermarking (Article 50(2)), the technical marking of machine-generated content (machine-readable metadata). New generative systems placed on the market from 2 August 2026 must have it from day one; systems already on the market before then were given a transition period until 2 December 2026. The obligation to inform people, however, applies from August.
  • High-risk systems (Annex III): the Digital Omnibus package, finally adopted by the European Parliament on 16 June and by the Council of the EU on 29 June 2026, pushed their obligations back to 2 December 2027 (Annex I: 2 August 2028). So if you're considering, say, AI in recruitment or scoring, you have more time for full compliance, but not for thinking the topic through. The Omnibus did not postpone the Article 50 transparency rules: earlier ideas of deferring them to 2027 did not make it into the final text.

What penalties non-compliance carries

The maximum fines in the AI Act reach EUR 35 million or 7% of annual worldwide turnover (whichever is higher), but the top tier applies only to prohibited practices and has been in force since August 2025. Breaching the transparency obligations under Article 50 carries a separate ceiling: up to EUR 15 million or 3% of turnover, enforceable from 2 August 2026. A proportionate approach is foreseen for SMEs, but a "proportionate" fine can still sting, and on top of that comes the reputational risk when a customer discovers an unlabelled bot.

A fresh development from June: on 10 June 2026 the EU AI Office published a voluntary Code of Practice on the transparency of AI content (covering Article 50(2), (4) and (5), with two-layer labelling: metadata plus a visible notice). Companies can sign it until 22 July 2026. Signing is not mandatory, but it can be the cheapest evidence of due diligence before the Commission issues full guidelines on Article 50.

Step 1: an inventory, or where AI actually lives in your company

Most companies use more AI than they think. Make a simple list and go department by department:

  • customer service: a chatbot on the website, a voicebot, automated email replies;
  • marketing: generating copy, graphics, video, social media posts;
  • sales and HR: tools for CV analysis, lead scoring, call transcription;
  • operations: AI assistants in office suites, machine translation, document analysis;
  • IT and product: AI features built into your own software or services for customers.

For each item note: who the provider is, who uses it, whether the output reaches customers or the public, and whether personal data is processed.

Step 2: classification into the four risk categories

The AI Act divides AI systems by risk:

Prohibited practices

Among others: subliminal manipulation, social scoring, emotion recognition at work and in education. These bans have been in force since February 2025. If anything on that list sounds familiar, the matter is urgent and calls for a lawyer.

High risk (Annex III)

For example AI in recruitment, creditworthiness assessment, education, critical infrastructure. Full obligations from 2 December 2027, but preparations (documentation, human oversight, risk management) are better started earlier.

Limited risk: this is where August 2026 lives

Chatbots, content generators, deepfakes. This is exactly Article 50 and the transparency obligations. For most SMEs it's the only category that requires action now.

Minimal risk

Spam filters, autocomplete, most "background" features. No additional obligations: just record them in the inventory.

Step 3: a July plan, week by week

Week 1: inventory. A list of all AI systems and tools (see step 1). Appoint one person to own the topic.

Week 2: classification and gaps. Assign a risk category to each system. Write down where labels are missing: a chatbot with no "you are talking to AI" notice, published AI content without an annotation, video and audio materials without disclosure.

Week 3: implement the labels. Add notices to chatbots, annotations to AI-generated content, provisions in your terms and policies. Update your processes: who labels content before publication and how.

Week 4: training and documentation. A short training session for your teams (marketing, customer service, HR) on the new rules. Write down an internal AI usage policy; this is also part of the AI literacy the regulation already requires of organisations today. Keep documentation of what you did: in the event of an inspection, it demonstrates due diligence.

The most common traps

  • "We only use ChatGPT, this doesn't apply to us". It does. The transparency obligations attach to how you use the outputs, not just to who built the model.
  • "Our provider has surely taken care of it". Partially. The provider is responsible for technical marking, but informing your customers is on you as the deployer of the system.
  • Putting it off until August. The labels still need testing and the team needs training. July is the last sensible moment.

FAQ

Is an "AI-generated content" label required on every email written with an AI assistant?

Not every one. The obligations focus on interaction with an AI system (chatbots), on published content, especially content informing the public, and on deepfakes. Internal working correspondence drafted with AI help and verified by a human is a different situation, though it's wise to have a consistent company policy here too.

We only have a chatbot from an external provider. What do we need to do?

Make sure the user sees a clear notice that they are talking to AI before they start using the bot. Also check your contract with the provider: who is responsible for configuring the notices and for compliance updates.

Does the Digital Omnibus postponement mean August 2026 could slip too?

No. The Digital Omnibus postponed the obligations for high-risk systems (Annex III to 2 December 2027), but the Article 50 transparency rules remained unchanged: 2 August 2026.

Start with a conversation, not with panic

ESKOM AI has walked this path on its own website and products: from inventory, through classification, to implementing labels compliant with Article 50. We also develop tools that make compliance easier (including data anonymisation and monitoring of regulatory changes) and provide advisory and implementation services in AI compliance.

If you want to check where your company stands against the 2 August deadline, book a free consultation via the form at eskom.ai/pl/kontakt.

This article is for information purposes and does not constitute legal advice. Consult a lawyer before making decisions on EU AI Act compliance.

#EU AI Act #art. 50 #compliance #transparentność #MŚP

Facing a similar challenge with your software?

Book a free 30-minute consultation — no strings attached. We'll show you how to do it faster and cheaper with AI.

Book a free consultation

Monthly: how companies modernize software with AI

Concrete insights, no jargon. Zero spam — unsubscribe in one click.

Free checklist: Is your legacy application a good candidate for AI modernization?