AI Act for businesses – what to disclose on your website in 2026

Okładka: AI Act dla firm - co oznaczać na stronie od sierpnia 2026

What actually changed on 2 August 2026?

Since 2 August 2026, the transparency rules in Article 50 of the AI Act apply: chatbots have to introduce themselves as AI, and deepfakes plus unreviewed AI texts on important public matters need a visible label.

It is easy to mix up two headlines: “the AI Act now applies” and “every AI Act obligation now applies”. The second one is false. The heavy requirements for high-risk systems arrive in December 2027 and August 2028. What touches most WordPress businesses is simpler: do not pass a bot off as a human, and do not let artificial content pass for authentic reality.

This guide is for you if:

  • you run a chatbot or voicebot on your site,
  • your team publishes AI images or video for ads and social media,
  • you draft blog content with AI,
  • you use AI in support, hiring, or marketing.

Key Takeaways

  • Chatbots should say they are AI – in the first message or chat header, not in the terms of service.
  • You do not label everything. Visible labels cover deepfakes and unreviewed public-interest texts.
  • Real human review of a health, legal, or finance article usually closes the labelling question.
  • AI literacy has applied since February 2025 – a focused team briefing is enough.
  • Small companies get simplifications, not an exit from transparency duties.
AI Act decision map: tool, role, duty, disclosure, and a short note
Five steps instead of panic: the tool, your role, the duty, the notice, a short note.

Important: This is an informational guide, not legal advice. For unusual or high-risk deployments, talk to a lawyer who knows AI and data protection.


Do you need a label? A 60-second map

Skip the full regulation for a moment. Walk a short path: what you publish, how it looks, and who owns the outcome.

Quick path (works without JavaScript too):

  1. Do you run a chatbot or voicebot? Check that the first message makes the AI nature obvious.
  2. Are you publishing content that looks like a real person, place, or event even though AI made it? Label it as artificial.
  3. Are you publishing AI text about health, law, finance, or politics without substantive human review? Label it.
  4. Is it a clear illustration, an edited draft, or a grammar pass? A visible label is usually unnecessary.
SituationYour roleWhat to do
A SaaS chatbot widget on your siteUser / deployerCheck the “I am AI” notice survived your customisation
You commission and launch a bot under your brandOften already a providerBuild the AI disclosure into the project, not as a post-launch patch
An agency makes AI creatives, you publish themYou own the publicationPut labelling responsibility in the contract
You sell an image generator to other businessesProviderOutputs must be machine-detectable as AI

Tip: Make a simple table: tool, what it does, who owns it. Fifteen minutes of work, and every future “does this apply to us?” question has a ready answer.


Your chatbot should introduce itself

Users should know they are talking to AI from the first message. That is the whole requirement – say it in the widget, clearly.

Formally, designing the disclosure sits with the system’s provider. On your site, though, you will collect the complaints – so check the live widget:

  • the first message or chat header says it is AI,
  • the notice did not vanish after branding and prompt changes,
  • it is readable on a phone,
  • the bot does not pretend to be human – “Anna from support” with no mention of AI is a bad pattern.

Example notices:

  • “Hi, I’m an AI assistant. If you’d rather talk to a human, just say so.”
  • “This is an automated AI chat. For important matters, double-check with our team.”
  • Voicebot: “Hello, this is a virtual assistant. You are talking to AI.”
Website chatbot widget with a clear first message that the user is chatting with an AI assistant
First message or widget header. Not the terms of service and not the privacy policy.

There is an “unless it is obvious” exception – use it carefully. What is obvious to you is not necessarily obvious to a first-time visitor.

Tip: While you are in the widget settings, add a path to a human agent. The AI Act does not require it, but customers do – and it is often one line of configuration.


Images, texts, and deepfakes – what actually needs a label

No, you do not have to stamp every Midjourney illustration. You label what could genuinely mislead someone.

The rules separate two different jobs:

  • A machine-readable mark in the file – the generator provider’s job (metadata, technical watermark). Usually not yours to add.
  • A visible label for humans – on you for deepfakes and for unreviewed AI texts on matters of public importance.
Three decision paths for AI content: label, usually no label, or check first
Three drawers instead of one: label, no label, check first.
ExampleLabel?Why
An abstract AI illustration for a blog postNoNobody will mistake it for a photo
A photorealistic “team photo” of people who do not existYesLooks real, is not
A promo newsletter drafted with AI and reviewed by marketingNoNot an unreviewed public-interest text
A health or legal article shipped straight from the generatorYesImportant topic + zero human review
A grammar pass in an AI editorNoThat is editing, not generating

In marketing practice, a deepfake is AI content that resembles real people, places, or events and could pass for authentic. If you publish one, disclose that it is artificial. File metadata is not enough – a person has to be able to see the notice.

Practical rule: if the content looks like a report from reality and there is no reality in it – label it. If it is clearly an illustration, decoration, or a text that went through human editing – do not invent a labelling panic.


When human editing settles the labelling question

An AI text about health, law, finance, or politics needs a label only when nobody seriously reviewed it before publishing.

You write with AI, but a competent person reads it, checks the facts, and stands behind the publication? A label is usually unnecessary. You ship a generated article without reading it? Then yes.

“Review” does not mean running spellcheck. The point is substantive judgement: a human can reject, correct, or rewrite the text. On a company blog, a simple habit covers it – note who reviewed and approved each piece. That habit also strengthens credibility with Google and AI engines. More in WordPress GEO for AI search.


Emotion analysis, biometrics, and team training

Emotion analysis at work and school is mostly banned. AI literacy has applied since February 2025 – no certificates required, but a real briefing for the people who use the tools.

If you are considering “mood analysis in the call centre” or emotion scoring in hiring – pause before you buy the tool. Where such systems are allowed at all, the people exposed must be informed. GDPR still applies on top.

A simple 30-60 minute AI briefing:

  1. Site admin: AI plugins, API keys, what data may go into a prompt, backup before experiments.
  2. Editor: fact-checking, when a text needs a label, when editing is enough.
  3. Marketing and support: the chatbot, social creatives, what counts as a deepfake, how the customer-facing notice reads.

Write down the date and who attended. That is usually enough to show the topic is handled. Details: the Commission’s AI literacy FAQ.


A WordPress plan for one afternoon

Start with a list of places where AI touches your site and marketing. Then walk through them with four questions: role, duty, notice, note.

  1. List the tools: chatbot plugin, content and image generators, ChatGPT/Copilot in the team, voicebot, personalisation.
  2. Set the role: are you using the system, or shipping it under your brand?
  3. Check the chatbot: does it introduce itself as AI in the first message?
  4. Review your content: anything that looks like a deepfake or an unreviewed text on important matters?
  5. Check the image pipeline: optimisers and CDNs can strip metadata from files.
  6. Name one person who revisits the topic, for example quarterly.

Evaluating a whole AI-built site, not just transparency? Use AI website – what to check before you launch. For AI inside WordPress 7.0: WordPress 7.0 – what’s new.

Tip: Save a block pattern with an “AI-generated content” label and drop it in only where disclosure is actually needed.

Checklist for today:

  1. I have a list of AI tools on the site, in marketing, support, and HR.
  2. I know where I am a user and where a provider.
  3. The chatbot and voicebot introduce themselves as AI from the first message.
  4. I know which materials need a visible label and which do not.
  5. Deepfakes in campaigns carry a label.
  6. Texts on important matters pass through a human before publishing.
  7. No emotion or biometric analysis without checking the bans and GDPR first.
  8. The team had a briefing on the AI tools and their risks.
  9. Agency contracts say who labels the materials.
  10. I keep a few screenshots and notes proving the above works.

Timelines, fines, and the usual slip-ups

The ceiling for transparency violations is EUR 15 million or 3% of worldwide turnover. That is a ceiling for the worst cases – not a price list for a missing sentence in your chatbot.

DateWhat applies
February 2025Prohibitions (incl. emotion analysis at work and school) + AI training
August 2026Transparency: chatbots, labels, deepfakes + fuller supervision starts
December 2026End of the grace period for machine marking in older generators
December 2027High-risk systems (incl. hiring, education, biometrics)
August 2028AI embedded in regulated products

Enforcement runs through national market surveillance authorities. The rules apply regardless of how quickly any office finishes hiring. Sources: the Commission FAQ on Article 50 and the consolidated AI Act text.

The usual slip-ups:

  • the AI notice only in the terms,
  • labelling everything “just in case”,
  • “it’s just an ad” as a deepfake excuse,
  • assuming the plugin vendor already handled disclosure,
  • “we’re small, this does not apply”,
  • high-risk panic while transparency is already live,
  • no agreement with the agency on who labels the materials.

Summary

August 2026 did not bring a revolution for ordinary businesses. It brought a simple principle: do not pass AI off as human, and do not let the artificial pass for real.

  • The chatbot says it is AI – from the first message.
  • You label deepfakes and unreviewed texts on important matters. Nothing else by default.
  • A short team briefing closes the AI training topic.
  • Getting WordPress in order usually takes one afternoon: tool list, notices, notes.
  • High-risk requirements arrive in 2027/2028. Transparency is for today.

FAQ

Quick answers to the questions company sites ask most often.

1. Do I have to label every text and image made with AI?
Answer: No. You label deepfakes and unreviewed texts on matters of public importance. A regular blog graphic or an edited newsletter usually needs no label.

2. Who owns the chatbot notice: me or the plugin vendor?
Answer: Formally the provider designs the disclosure. In practice, verify it on your own site – especially if you changed the widget’s look, copy, or prompts. It is your site and your customers.

3. I write articles with AI but edit them. Do they need labels?
Answer: No, as long as the editing is real: someone checks the facts and stands behind the publication. Fixing typos alone does not count.

4. Is an AI ad graphic a deepfake?
Answer: Usually not. A deepfake has to resemble real people, places, or events and look authentic. A stylised illustration fails that test; a photorealistic “report” from an invented event passes it.

5. We are a small company – does the AI Act apply to us?
Answer: Yes, if you use AI. Size thresholds bring simplifications, but no exemption from transparency or team training.

6. Since when does AI training apply?
Answer: Since February 2025. Certificates are not required – a reasonable briefing matched to who uses what is enough.

Loading (streaming)