The EU AI Act and your website: what the chatbot and AI-content rules mean from August 2026

· 10 min read · Web Involved

What does the EU AI Act mean for my website, and what do I actually have to do?

From 2 August 2026, the EU AI Act’s transparency rules ask one simple thing of any website that puts AI in front of people in the EU: say so. The main obligation for a typical business site is chatbot disclosure — if you run an AI chatbot or virtual assistant, it must tell users they’re interacting with an AI at the first point of contact, and that disclosure has to be perceivable in the conversation itself, not buried in your terms and conditions. If you publish AI-generated synthetic media, deepfakes and certain AI-generated text must be labelled, and a broader machine-readable marking duty for AI-generated content follows from 2 December 2026. Like the GDPR and the European Accessibility Act, this reaches businesses outside the EU whenever their AI’s output is used there, so a non-EU company with a chatbot serving EU customers is in scope. Penalties run up to €15 million or 3% of global turnover. But the tone here matters: this is the “limited risk” transparency tier, and for most sites the obligation is genuinely light — disclose clearly, label synthetic media, keep it accessible. We’re not lawyers and this isn’t legal advice, but the honest summary is that the AI Act rewards exactly what we build toward anyway: a site that’s transparent about what it is, and that doesn’t bolt on an AI feature it never needed. The simplest compliance is often the simplest site.

What the AI Act actually requires of a website

The EU AI Act is a large, risk-based law, but the part that touches an ordinary website is narrow and specific: the transparency obligations in Article 50, which take effect on 2 August 2026 (European Commission, 2026). These apply regardless of whether you use any “high-risk” AI — an organisation with no high-risk systems at all can still have Article 50 duties simply because it runs a customer-facing chatbot or publishes AI-generated content (EU AI Act, 2026). The through-line of the whole article is trust through disclosure: people should know when they’re dealing with a machine or with synthetic content (European Commission, 2026).

For a website, that resolves into two practical questions. Do you have an AI system that talks to visitors — a chatbot or assistant? And do you publish content that AI generated — images, video, audio, or certain kinds of text? If the answer to either is yes, Article 50 has something to say to you. If the answer to both is no, as it is for many lean marketing sites, your obligations here are minimal. This guide sits alongside our pillar on respecting privacy because, like data protection, it’s part of the growing body of digital law your site has to live within — and, handled early, it’s not onerous.

The chatbot rule: disclose, and do it right

The obligation most websites will meet first is chatbot disclosure. When an AI system is intended to interact directly with people — chatbots, virtual assistants, automated phone systems — its provider must design it so users are informed they’re interacting with an AI (EU AI Act, 2026). There’s an exemption where the AI nature is obvious to a reasonably well-informed, observant person from the actual audience, but the Commission’s draft guidance sets that bar high: most consumer-facing chatbots will not qualify for it, and the threshold is lower still where children, elderly people or people with disabilities are part of the audience (EU AI Act, 2026).

The detail that trips businesses up is how you disclose. A statement tucked into your terms and conditions, a metadata watermark on its own, or a vague reference to an “assistant” does not satisfy the chatbot duty — the information has to be perceivable in the interaction itself (Bratby Law, 2026). In practice that means a clear, visible line at the start of the conversation: something like “You’re chatting with an AI assistant.” It also has to be done in a way that meets accessibility requirements, so the disclosure reaches everyone (EU AI Act, 2026) — the same standard our guide on web accessibility sets for the rest of the interface. None of this is hard; it just has to be deliberate.

AI-generated content and deepfakes

The second strand covers synthetic content. Providers of generative AI must embed machine-readable marks in AI-generated audio, image, video and text so it’s detectable as artificial — an obligation the AI Omnibus deferred to 2 December 2026 (Travers Smith, 2026). Separately, deployers who publish deepfakes — AI-generated or manipulated image, audio or video resembling real people, places or events — must disclose that the content is artificially generated (EU AI Act, 2026). The same disclosure duty extends to AI-generated text published to inform the public on matters of public interest.

For most business sites, the everyday version of this is modest. Ordinary AI-assisted marketing copy generally escapes the text-labelling duty where a human has reviewed it and holds editorial responsibility for what’s published (EU AI Act, 2026). Purely fantastical imagery — content that’s evidently impossible, not a realistic depiction of real people — falls outside the deepfake definition (EU AI Act, 2026). Where the honest caution applies is realistic synthetic media of real people, and AI imagery in commercial advertising, which can’t shelter under the artistic carve-out. The workable posture is to keep track of which of your published content is AI-generated, label realistic synthetic media clearly, and keep a human in the loop on anything you’d rather not have to label.

Does it apply to you?

The reach of the AI Act surprises people, in the same way the GDPR and the European Accessibility Act do. It applies to providers placing AI systems on the EU market wherever they’re established, and to providers and deployers in third countries where the system’s output is used in the EU (Bratby Law, 2026). A UK, US or Canadian business running a chatbot that serves EU customers engages the chatbot rule; a marketing team generating synthetic content shown to EU users engages the content rules (Bratby Law, 2026). Being outside the EU is not, on its own, a shield.

On timing, the transparency obligations apply from 2 August 2026 to in-scope systems regardless of when they were first deployed, though content generated and made available before that date doesn’t need retrospective labelling (Bratby Law, 2026). This piece pairs naturally with our guide on the European Accessibility Act: between them, they’re the two EU digital laws most likely to catch a business that assumed neither applied because it isn’t based in Europe. Our guide on GDPR for non-EU businesses is the third leg of the same stool.

Don’t panic: most website AI is “limited risk”

It’s worth stepping back from the penalty figures — up to €15 million or 3% of global turnover (TechTimes, 2026) — to keep proportion. The AI Act is deliberately tiered by risk, and the transparency obligations sit in the “limited risk” band. The vast majority of AI in everyday use — spam filters, search ranking, recommendation engines, basic automation — is minimal-risk and carries no transparency duty at all (Decode the Future, 2026). The obligations bite specifically when you add a system that interacts with people or generates synthetic content.

That framing matters because it points to the simplest compliance strategy of all: don’t add AI features you don’t have a genuine use for. A business that runs a chatbot it doesn’t really need has taken on a disclosure obligation and a maintenance burden for a widget that often deflects more customers than it helps. A business that answers questions with a clear contact form and good content has nothing to disclose. This is the same restraint we bring to third-party scripts and cookie banners in our work on privacy: every feature you add is a surface you now have to govern. The AI Act quietly rewards doing less.

What we’d tell you

To be clear about our footing: we build websites, we’re not lawyers, and none of this is legal advice — for a definitive read on your specific situation, talk to a qualified professional, especially if you operate high-risk AI or publish synthetic media at scale. What we can offer is the practical map. If your site has a chatbot serving anyone in the EU, add a clear, visible disclosure that it’s an AI, at the start of the interaction, in an accessible way. If you publish realistic AI-generated media, label it. Keep a record of which content is AI-generated so you can answer the question if asked. And treat 2 August 2026 as the date the chatbot and deepfake rules are live, with the broader content-marking duty following in December.

Then take the step that’s easy to miss: ask whether each AI feature on your site earns its place at all. The version of compliance we like best isn’t a banner bolted onto a chatbot bolted onto a page — it’s a site that adds AI only where it genuinely serves the visitor, discloses it honestly and accessibly, and stays simple everywhere else. Transparent about what it is, light in what it loads, and easy to stand behind: that’s a good website and a compliant one at the same time.

Frequently asked

Does the EU AI Act require me to disclose my website chatbot?
Yes, in most cases, from 2 August 2026. Article 50 of the EU AI Act requires that any AI system designed to interact directly with people — a chatbot, a virtual assistant, an automated phone line — inform users they are dealing with an AI, at the first point of contact. There's a narrow exemption where the AI nature is obvious to a reasonably observant person, but the Commission's guidance makes clear most consumer-facing chatbots won't qualify. Importantly, the disclosure has to be perceivable in the interaction itself: a line buried in your terms and conditions, or a vague label like 'assistant,' does not satisfy the rule. We're not lawyers, so treat this as a map rather than advice, but the practical takeaway is simple — if your site has a chatbot serving EU users, tell people plainly that it's AI.
Does the AI Act apply to businesses outside the EU?
It can, and this catches a lot of people out. Like the GDPR and the European Accessibility Act, the AI Act reaches beyond the EU's borders: it applies to providers and deployers established anywhere when the AI system's output is used in the EU. A UK, US or Canadian business running a customer-service chatbot that serves EU customers, or generating synthetic marketing content shown to EU users, is within scope. So 'we're not an EU company' is not, by itself, a reason the rules don't apply. If your website's AI features reach people in the EU, the transparency obligations reach you.
What are the penalties for breaking the AI Act's transparency rules?
Non-compliance with the Article 50 transparency obligations can carry fines of up to €15 million or 3% of global annual turnover, whichever is greater, enforced by national market surveillance authorities in each member state. Beyond fines, authorities can order a non-compliant AI system withdrawn from the market and require public disclosure of the violation. That said, this transparency tier is the 'limited risk' category, and the obligation itself is light — mostly a matter of disclosing clearly rather than a heavy conformity process — so the realistic risk for a small business is manageable if you handle the disclosure properly rather than ignore it.
Do I have to label AI-generated images and text on my site?
For synthetic media, increasingly yes. Under Article 50, providers of generative AI must mark AI-generated audio, image, video and text as artificially generated in a machine-readable way — an obligation deferred to 2 December 2026 under the AI Omnibus. Separately, deployers who publish deepfakes (AI-generated or manipulated content resembling real people or events) must disclose that it's artificial, and AI-generated text published to inform the public on matters of public interest must be labelled. Ordinary AI-assisted marketing copy that a human reviews and takes editorial responsibility for generally escapes the text-labelling duty. The safest posture is to know which of your content is AI-generated and to label synthetic media clearly.
Is a simple website with no AI features affected?
Largely no, and that's worth saying plainly. The AI Act is risk-based, and the vast majority of everyday website technology — spam filters, search, recommendations, basic automation — falls into the minimal-risk category with no transparency obligations. The transparency rules bite when you add an AI system that interacts with people (a chatbot) or generates synthetic content. So a lean site that doesn't bolt on an AI chatbot it didn't need has little to do here. In many cases the simplest route to compliance is the same as the simplest route to a fast, private, maintainable site: don't add the feature you don't have a real use for.