The transparency rules in Article 50 of the AI Act have applied since 2 August 2026. For a typical AI assistant on a company website, the main concern is making the AI interaction recognisable. This does not mean that every chatbot has had to meet every high-risk requirement since that date. The system's actual task and your role as a provider or deployer determine which obligations you need to assess.
The legal position changed in 2026. This article takes account of the implementation changes in July and the European Commission's transparency guidelines. Sources checked: 10 September 2026. It offers practical guidance, not a binding classification of your individual case.
The timetable is more nuanced than “everything from August”
The AI Act applies in stages. Small businesses should distinguish the following:
| Date | What needs to be considered | Relevance to a website assistant |
|---|---|---|
| 2 February 2025 | Prohibitions on certain AI practices and AI literacy | These are not new topics that only start in August 2026 |
| 2 August 2026 | Article 50 transparency rules | The AI interaction must be recognisable where the obligation applies |
| 2 December 2026 | Limited transition for Article 50(2) for systems already offered before August | No general postponement of the chatbot notice |
| 2 December 2027 | High-risk applications under Annex III | Relevant, for example, to certain employment and education applications |
| 2 August 2028 | High-risk systems associated with regulated products | A different scope from an ordinary FAQ chat |
The updated high-risk deadlines follow from the amendment that entered into force in July 2026. Older summaries may therefore be outdated. Commission: Current AI Act timetable. The transition until December 2026 applies only to machine-readable marking and detectability under Article 50(2), subject to the stated conditions. Commission: Article 50 FAQ.
Assess the task, not the word chatbot
An assistant explaining opening hours and linking to service pages needs a different assessment from a system evaluating job applicants. The same chat interface can provide access to entirely different tasks. Adding a function such as “screen applications” is therefore also a reason to reassess the legal classification.
| Planned function | Initial assessment |
|---|---|
| General information from approved company pages | Organise transparency, privacy and reliable answers |
| Collect contact details and pass them to a person | Also establish the data purpose, recipients and retention |
| Evaluate applicants or filter them for selection | Assess high-risk classification against the specific intended purpose |
| Help decide creditworthiness or access to essential services | Arrange specialist and legal assessment before releasing it for operational use |
These examples provide orientation. A binding assessment must also consider exceptions and the precise decision-making function. The sensitive application areas are described in Annex III of the AI Act.
Write the intended purpose as specifically as a work instruction: “Answers service questions using approved pages; does not prepare quotations or make employment decisions.” This kind of sentence is much more useful for development, the relevant business team and later assessment than “Our company uses AI”.
Are you a provider or a deployer?
A business using another company's AI system is typically a deployer. An organisation that develops a system, or has it developed, and places it on the market or puts it into service under its own name may be a provider. Using someone else's language model in the background does not rule out being the provider of the system built around it. Roles must be clarified for the actual product. Article 3: Definitions and roles.
The information obligation for direct interaction in Article 50(1) is addressed to the provider. As the person responsible for the website, you still need to integrate the intended disclosure correctly and avoid designing it out of the experience. Ask your service provider explicitly: Who provides this assistant, who deploys it, and who checks the finished integration?
For an in-house development or an assistant offered under your own brand, clarify this before introduction. A hosting contract alone does not answer the question.
What visitors should actually see
A clear notice belongs at the start of the interaction, not only on a distant subpage. It must be distinguishable and accessible. Rely on the exception that “it is obviously AI” only after careful assessment. Article 50: Transparency obligations.
A practical example for an information assistant:
You are speaking with an AI assistant. It helps answer questions about our services. For a binding answer, please contact our team.
This text is not a universal legal template. It works only if the assistant's task and the contact route actually fit. When handing a conversation over, also show when a person takes over. A human profile photograph with the name of a nonexistent employee would make the distinction unnecessarily difficult.
Check the notice on a mobile phone, using a keyboard and with enlarged text. A correctly worded sentence is of little use if it is cut off or only appears after the first input.
Organise AI literacy in everyday work
Your team needs to know what the assistant is allowed to do and where its limits lie. The current AI literacy provision requires measures to support the development of relevant knowledge, tailored to the staff and context of use. It does not require a guarantee that every individual reaches a particular level of competence. Nor does this create a general requirement for a particular paid certificate. The Commission explains the July 2026 amendment on its page on AI literacy and skills. Older reproductions of Article 4 may still show the previous wording.
For a small service team, a concrete exercise is useful: handle five typical enquiries, identify two incorrect answers and pass one case to the right person. Discuss data that should not go into the chat and demonstrate how to stop the automation if a problem occurs. Record the topic, participants and unanswered questions. This is a practical suggestion, not a legally prescribed curriculum.
What you can achieve in one working day
One day is enough for an inventory and initial improvements. It does not replace a full compliance assessment. The following sequence helps avoid a situation where the team fills in forms first and overlooks the assistant already running.
- Take an inventory: Which AI systems are actually in use, including tools set up independently by staff? Who is responsible internally?
- Define the task: Does the system merely collect enquiries, or influence decisions about people? Limit unclear extensions until they have been assessed.
- Record the roles: Distinguish the product provider, model provider and your own operation; ask the service provider about unresolved responsibilities.
- Test the interface: Check the AI notice, understandable limits and contact route in the actual desktop and mobile chat.
- Collect data questions: Work through transfers, training, retention periods and contracts using the GDPR chatbot checklist.
- Brief the team: Practise error examples, handover and shutdown together. Record the owner and deadline for remaining questions.
What this does not automatically resolve
A visible AI notice does not make data processing lawful. An EU server does not prove that every legal requirement is satisfied either. Generated images, voices and published text can raise their own transparency questions; their rules are not the same as chatbot disclosure. For text on matters of public interest, the Commission explains the importance of actual human review or editorial control and responsibility. A spelling check alone is not sufficient. Commission: Transparency FAQ.
For a manageable start, choose a narrow scope with verifiable sources and a team people can reach. Our AI Platform page provides the product context. What matters for your project remains the task the assistant takes on and how people can check its work.
