Five Things SMEs Keep Getting Wrong About EU AI Act Article 50
August 2, 2026. Article 50 of the EU AI Act went live. The coverage mostly focused on what it means for "AI companies." The coverage mostly missed the small business owner using ChatGPT to write their weekly newsletter, or the e-commerce site with an AI chat widget on the product page.
Article 50 is not a regulation for AI companies. It is a transparency regulation for anyone who deploys AI systems that interact with users, produce synthetic content, or categorise people. That's a wide net, and most SMEs are already inside it.
Here are the five mistakes I see most often.
Mistake 1: Thinking it only applies to AI product companies
Article 50 targets deployers — businesses that put AI systems in front of people. Not the companies that built the models.
If you have a chatbot answering customer questions on your website, you are a deployer. If you use an image generator to create product photos for your shop, you are a deployer. If you use AI to write marketing copy that goes out under your brand, Article 50 is talking to you.
What it requires: Users must be informed they are interacting with an AI system at the point of first interaction. The only carve-out is if it would be "obvious to a reasonable person" — and courts will not stretch that interpretation to cover an AI that you've given a human name and a profile picture.
This applies to tools built on third-party models (GPT, Claude, Gemini) just as much as anything custom-built. You chose to deploy it; the obligation is yours.
What to do: Add a clear, explicit AI disclosure before users interact with any AI-powered interface. Not in the footer. Not in the terms of service. Before the conversation starts.
Mistake 2: Missing the two-track deadline
Most coverage says "August 2026 deadline" and leaves it at that. There are actually two deadlines, and conflating them is a real compliance risk.
Deadline 1 — August 2, 2026: All four Article 50 obligations apply to new AI systems launched from this date. If your chatbot, image generator, or AI personalization feature went live after August 2, full compliance applies now.
Deadline 2 — December 2, 2026: Systems that were already on the market before August 2, 2026 have until December 2, 2026 specifically for the machine-readable marking requirement (see Obligation 2 below). The other obligations — AI interaction disclosure, deepfake disclosure, biometric/emotion recognition disclosure — apply immediately regardless.
The practical implication: if you're publishing AI-generated images or video, and the tool you're using went live before August 2, you have a few more months to implement the technical marking standard. But your chatbot disclosure and deepfake labels can't wait.
What to do: Audit which AI features existed pre-August 2026 and which didn't. Apply the December 2026 deadline only to the machine-readable marking component on pre-existing generative systems — not as a blanket extension.
Mistake 3: Burying the disclosure in your terms of service
This is explicitly addressed in the regulation: notices must be given clearly, separately from other information, at the first point of interaction or exposure. Not in a T&Cs footer. Not in an on-boarding email sent after sign-up. First interaction, clearly labelled.
The EU's own guidance (digital-strategy.ec.europa.eu) is unambiguous on this. A disclosure buried in page 47 of a privacy policy does not satisfy Article 50. The regulation was written specifically to prevent compliance-by-small-print.
This matters particularly for AI-generated content posted publicly — a product image created by AI and posted to your website or social media needs a disclosure that meets this standard, not a vague watermark people won't see.
What to do: Treat AI disclosure the same way you treat cookie consent: it has to be front-facing, at the moment it's relevant, and independently legible from everything else on the page.
Mistake 4: Not realising emotion recognition and biometric categorisation are in scope
Article 50's fourth obligation catches businesses who would never describe what they're doing as "AI" at all.
If you use any system that:
- categorises users by emotional signals (sentiment scoring, engagement analysis)
- makes inferences about a person's characteristics from their behaviour or biometrics
- uses emotion recognition to adjust personalisation or content
...you have an active Article 50 obligation. Users must be informed when these systems are operating on them.
This catches more businesses than it sounds like it would. Behavioural personalization engines, adaptive content systems, customer sentiment scoring dashboards fed by real-time interaction data — these are commonly deployed by SMEs through third-party analytics platforms, often without realising the privacy/AI Act implications.
What to do: Review your third-party analytics, personalization, and customer insight tools. Ask vendors directly whether emotion recognition or biometric categorisation features are active in what you've licensed — and if yes, add the required disclosure.
Mistake 5: Assuming SME fine caps mean the risk is negligible
There is SME relief built into the penalty structure. Fines are capped at whichever is lower: €15 million, or 3% of worldwide annual turnover for that particular category of violation.
That sounds protective. It is, relative to what larger companies face. But 3% of worldwide annual turnover for a mid-sized SME is a real, painful number. "Lower cap than a multinational" does not mean "consequence-free."
There are also reputational and commercial consequences that sit alongside formal fines. If a data protection regulator flags a company for non-compliant AI deployment — particularly on something as visible as a public-facing chatbot — the headline is the damage, not the fine amount.
What to do: Price the actual exposure, not the theoretical maximum. Three percent of your revenue is your real risk ceiling, not zero. Build the compliance checklist around what that number means for your business.
The four Article 50 obligations at a glance
For quick reference, here is what the regulation actually requires:
1. AI interaction disclosure
If a user is interacting with an AI system, tell them — clearly, at first contact, unless it would be "obvious to a reasonable person" that they're talking to AI.
2. Machine-readable synthetic content marking
AI-generated audio, images, and video must carry a machine-readable mark in a standardised, detectable format. Caption-only disclosure does not satisfy this. (Grace period applies for pre-August 2026 systems until December 2, 2026.)
3. Deepfake disclosure
Any artificially generated or manipulated audio, image, or video that depicts real or realistic people must carry a clear, visible disclosure that it is AI-generated or AI-modified. This applies to marketing materials, not just social media content.
4. Emotion recognition and biometric categorisation
People must be informed when these systems are being used on them, at the point of use. Not in a privacy policy: at the point of use.
One open question worth flagging
Multiple sources have noted a possible interaction between Article 50 obligations and EU Digital Omnibus legislation that could affect implementation timelines or scope. I have not verified the full extent of this interaction. If your legal team is advising on Article 50 compliance, specifically ask whether the Digital Omnibus package changes anything before you finalise your compliance posture.
Practical starting point
Run through this checklist:
- [ ] Every AI-powered user interface has a clear, front-facing disclosure before first interaction
- [ ] AI-generated images and video being published publicly have disclosures that go beyond captions (machine-readable standard needed)
- [ ] Deepfake/AI-manipulated content is clearly labelled at point of publication
- [ ] Third-party tools have been audited for emotion recognition / biometric categorisation features
- [ ] The December 2, 2026 grace period has been correctly scoped to machine-readable marking only — not used as a blanket extension
- [ ] Actual fine exposure has been calculated (3% of worldwide turnover) not waved away
This post reflects my understanding of Article 50 as of August 2026. It is not legal advice. Verify against current EU Commission guidance (digital-strategy.ec.europa.eu) and the official regulation text before making compliance decisions. The EU Code of Practice on Transparency is also available as a voluntary compliance framework.
This article was written with AI assistance (Claude). NAS Digital uses AI as part of its content workflow.
Top comments (0)