Skip to content
All posts
AISeptember 29, 2026·Md Fahad Mia

EU AI Act for Small Businesses, What Your AI Features Need

EU AI Act transparency rules have applied since 2 August 2026. What small businesses adding chatbots and AI features must build now, and what can wait.

A ring of twelve dots around the letters AI, with the EU AI Act transparency and high-risk deadlines for small businesses

The short answer: if your business runs a chatbot or generates content with AI for people in the EU, the transparency rules in Article 50 of the EU AI Act have applied since 2 August 2026. People must be told they are dealing with an AI unless it is obvious, and AI-generated content must carry a machine-readable mark. Most features a small business builds are not high-risk. The strict high-risk rules, which cover uses such as screening job applicants and credit scoring, now start on 2 December 2027, after the Digital Omnibus moved them back.

I am Md Fahad Mia, a software and AI engineer who builds AI features for companies in Europe and elsewhere. I am an engineer, not a lawyer, so treat this as the build checklist I work from, and have your legal counsel confirm how it applies to you. Everything below is checked against the primary sources as of late September 2026.

Where the EU AI Act stands in autumn 2026

The Act entered into force on 1 August 2024 and has been switching on in stages. In November 2025 the Commission proposed a "Digital Omnibus" to simplify it. That package was adopted as Regulation (EU) 2026/1744, published on 24 July 2026 and in force three days later. It moved the high-risk deadlines back. It did not move the transparency deadline.

DateWhat appliesWho it matters to
2 February 2025Banned practices (Article 5) and AI literacy (Article 4)Everyone using AI at work
2 August 2025Rules for general-purpose AI modelsModel makers such as OpenAI, Anthropic, Google and Mistral
2 August 2026General application, including Article 50 transparencyAny business with a chatbot or generative AI feature
2 December 2026End of the grace period for marking AI output (Article 50(2)), for generative systems on the market before 2 August 2026Existing generative features
2 December 2027High-risk rules for Annex III uses (moved from 2 August 2026)Hiring, credit, insurance and education tools
2 August 2028High-risk rules for AI inside regulated products, Annex I (moved from 2 August 2027)Medical devices, machinery, toys and similar

Sources: the Commission's AI Act overview, its Article 50 FAQ and the Omnibus regulation. One thing to keep separate: there is a second Digital Omnibus, covering GDPR, cookies and the Data Act, and that one is still being negotiated. It does not change anything in this post.

Provider or deployer: which one is your business

The AI Act puts different duties on different roles. The provider develops an AI system, or has one developed, and puts it on the market under its own name. The deployer uses an AI system in its work. The distinction matters, because most of Article 50 lands on providers.

A small business that builds a support chatbot on top of the OpenAI or Claude API and offers it to customers under its own brand is likely to be treated as the provider of that chatbot, even though someone else built the model. The Commission's FAQ does not give a definitive ruling on this exact case, so the safe engineering assumption is that the provider duties are yours.

What Article 50 means inside your product

These are the duties, in the order you will meet them when building. The legal text is on the Commission's AI Act Service Desk.

1. Tell people they are talking to an AI

Article 50(1) requires AI systems that interact directly with people to be designed so those people are informed they are dealing with an AI, unless it is obvious. Article 50(5) says this must happen at the first interaction at the latest. The Commission published its final guidelines on Article 50 on 20 July 2026, and legal summaries read them as ruling out a line buried in the terms of service or a vague "assistant" label.

What I build in:

2. Mark AI-generated content

Article 50(2) requires providers of generative AI systems to make sure outputs are marked in a machine-readable format and detectable as AI-generated. That covers generated images, audio, video and text. The Commission's Code of Practice on transparency of AI-generated content, finalised on 10 June 2026, describes how signatories intend to meet this. If your feature was already live before 2 August 2026, the marking duty applies from 2 December 2026.

In practice, most small businesses rely on the marking built into the model they use, then make sure their own pipeline does not strip it. Resizing an image, re-encoding audio or copying text into a template can throw away metadata. I test for that the same way I test any other feature.

3. Disclose deepfakes and AI-written public information

Article 50(4) is a deployer duty. If you publish AI-generated or manipulated images, audio or video that look real, you must disclose it. If you publish AI-generated text to inform the public on matters of public interest, you must disclose that too, unless a person has reviewed it and taken editorial responsibility. Marketing teams using image generators should agree a labelling rule now.

4. AI literacy for your team

Article 4 has applied since February 2025. As amended by the Omnibus, it asks providers and deployers to take measures to support the AI literacy of their staff, without requiring them to guarantee a specific level. For a small business, a short internal guide covers most of it: what the AI feature does, where it fails, and when to hand over to a human. I write one as part of every AI handover.

When a small business does hit the high-risk rules

Most chatbots, content tools and internal assistants are not high-risk. The strict regime applies to the uses listed in Annex III, and a few of them are common in small companies:

If your feature does any of these, the obligations from 2 December 2027 include risk management, data governance, logging, human oversight, technical documentation and a conformity assessment. About fourteen months is not long for that, so design for it now. The Act does offer help: Article 62 gives SMEs priority access to regulatory sandboxes, and SMEs may provide the technical documentation in a simplified form. GDPR's Article 22 already limits purely automated decisions with legal or similarly significant effects, so a human reviewer in the loop is worth building in from day one.

What getting it wrong can cost

Article 99 sets three tiers of fines: up to €35 million or 7% of worldwide turnover for banned practices, up to €15 million or 3% for most other breaches, including Article 50 transparency, and up to €7.5 million or 1% for giving regulators misleading information. For SMEs and startups, each fine is capped at whichever of the two amounts is lower. That makes the numbers survivable, not irrelevant. The bigger cost for most small companies is having to pull a feature from the EU market and rebuild it.

How I build AI features for EU clients

Compliance is cheapest when it is part of the design rather than a patch. On every AI project for a client serving the EU, the Article 50 disclosure, output marking and logging go into the plan as acceptance criteria, next to the features themselves. The data side, including which model providers keep processing inside the EU, is covered in GDPR-compliant LLM integration. My production AI work includes the Tryneth backend, which orchestrates five AI agents with usage-based billing.

Projects are fixed-price and paid in four milestones: 25% after each 25% of the work is finished and reviewed, with no deposit. How that works is in milestone payments for software projects, and if you are weighing a remote engineer against a local hire, read hiring a remote developer in Europe.

Questions small businesses ask about the EU AI Act

Does the EU AI Act apply to my small business chatbot?

Yes, if the chatbot talks to people in the EU. Since 2 August 2026, Article 50 requires that people are told they are interacting with an AI unless it is obvious, at the first interaction at the latest. A business that offers a chatbot under its own brand is likely treated as its provider, even when the model comes from OpenAI, Anthropic or Google.

Was the EU AI Act delayed by the Digital Omnibus?

Partly. Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk rules for Annex III uses to 2 December 2027 and those for regulated products to 2 August 2028. It did not delay the Article 50 transparency duties, which apply from 2 August 2026, apart from a grace period to 2 December 2026 for marking the output of generative systems already on the market.

Is a customer-support chatbot a high-risk AI system?

Normally not. High-risk status comes from the use cases in Annex III, such as screening job applicants, credit scoring of individuals, life and health insurance pricing, and education admissions. A support bot that answers questions and hands over to humans is a transparency case under Article 50, not a high-risk one.

Does the EU AI Act apply to UK and other non-EU businesses?

It can. The Act covers providers that place AI systems on the EU market and providers and deployers outside the EU when the output of their AI system is used in the EU. A UK company whose chatbot serves customers in Germany or France should plan for Article 50 just as an EU company would.

What are the EU AI Act fines for small businesses?

Article 99 sets ceilings of €35 million or 7% of turnover for banned practices, €15 million or 3% for most other breaches including transparency, and €7.5 million or 1% for misleading information. For SMEs and startups, each fine is capped at the lower of the two amounts rather than the higher.

What should we build first to comply?

An honest AI disclosure in the interface, visible from the first message, plus a log that it was shown. Then check that any AI-generated images, audio or video keep their machine-readable marking through your pipeline, agree a labelling rule for marketing content, and write a short internal guide for staff on what the AI does and when to escalate.

Need AI features built for the EU market

If you are adding a chatbot, an assistant or an automation and want it compliant from the first release, start with a scoping call. You get a written plan with the AI Act items built into the acceptance criteria, a fixed price and four milestones you only pay for once they are done. See what hiring me looks like, read more about AI and automation, or start a project today.

Thanks for reading. Want to talk about this? Get in touch.