The most immediate AI Act question for many small companies is not whether their system is “high risk.” It is whether a customer can tell when AI is involved.
On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act started to apply. The European Commission's guidance covers certain interactive and generative AI systems, including duties connected with direct AI interaction, machine-readable marking of synthetic content, deepfakes, and AI-generated text published to inform the public on matters of public interest.
At the same time, the AI Omnibus moved some high-risk-system deadlines. That created an easy misunderstanding: some dates moved, but the Article 50 transparency date did not disappear.
This article turns that distinction into an operating checklist. It is not legal advice. The precise obligation depends on the system, your role, the audience and the context in which the output is used.
Start with the use, not the brand of model
A subscription to an AI product does not by itself tell you what to disclose. Begin with the customer-facing situation:
- a website visitor chats with an automated assistant;
- a voice system answers or places calls;
- marketing publishes an AI-generated image or video;
- a team edits real footage so that a person appears to say or do something they did not;
- a company publishes AI-generated text about a public-interest matter;
- a system infers emotion or uses biometric categorisation.
Then identify your role. In simplified terms, a provider develops an AI system or has it developed and places it on the market or puts it into service under its own name. A deployer uses an AI system under its authority in a professional context. A small business can be a deployer in one workflow and take on broader responsibilities in another, especially when it substantially modifies or rebrands a system.
Do not settle the role question from a marketing page. Record it for each use case and confirm it against the contract and the official guidance.
Four transparency situations worth finding first
1. A person interacts directly with AI
If a customer reasonably believes they are dealing with a person, the experience needs a clear disclosure that it is AI. The notice should appear at the right moment, not behind a remote policy link that a customer is unlikely to see.
A practical pattern is a short statement at or before the first interaction:
You are chatting with an AI assistant. A member of our team can review or take over when needed.
That wording is an operational example, not a prescribed legal formula. It works because it identifies the nature of the interaction and explains the human route.
2. The system generates or manipulates content
Providers of certain generative systems have obligations connected with making outputs detectable as artificially generated or manipulated, including machine-readable marking where required. A small-business deployer should therefore know what provenance or marking capability its supplier provides and whether the publishing workflow preserves it.
Exporting, resizing or rebuilding an asset can strip metadata. “The vendor adds a mark” is not enough; test the final file that reaches the public.
3. The business publishes a deepfake or public-interest text
Deployers face specific disclosure duties for deepfake content. There are also rules for certain AI-generated or manipulated text published to inform the public on matters of public interest, with an important distinction where content has undergone human review or editorial control and a person or organisation holds editorial responsibility.
This is why “a human looked at it” should be a real editorial control, not a box automatically ticked by the workflow.
4. Emotion recognition or biometric categorisation is used
These systems raise distinct transparency and data-protection questions. If such a feature is present in recruitment, customer analytics, education, access control or monitoring, escalate it for specialist review rather than treating it as another chatbot setting.
The 60-minute transparency audit
Use one row for every customer-facing or public-facing AI workflow.
| Check | Question | Evidence to keep |
|---|---|---|
| Inventory | Where does AI interact with people or create material they see? | Named workflow, owner and channel |
| Role | Are we acting as provider, deployer, distributor or more than one? | Contract, configuration and written role assessment |
| Disclosure | What does the person see, and when? | Approved wording plus screenshots or test recordings |
| Marking | Does synthetic content retain required machine-readable information? | Supplier documentation and a test of the final exported asset |
| Human review | Which outputs require genuine editorial or operational approval? | Reviewer, criteria, decision log and escalation route |
| Record | Can we show what ran, which version was used and what reached the public? | System version, prompt or input class, output, approval and timestamp |
Do not attempt to catalogue every internal use of autocomplete in the first hour. Prioritise external exposure and consequential actions.
A minimum control set for a small team
Make the disclosure part of the interface
Store disclosure copy as a managed content element, not as text improvised inside a prompt. That makes it easier to translate, approve and test.
Check at least:
- first website interaction;
- reopened conversations;
- voice-call opening;
- mobile layouts;
- embedded third-party widgets;
- hand-off from AI to a person;
- emails or messages drafted and sent by an automated workflow.
Separate drafts from external actions
An AI draft inside a private workspace is different from a message sent to a customer. Configure the boundary explicitly:
- generate a draft;
- validate required fields and prohibited claims;
- show evidence to the reviewer;
- require approval where the consequence justifies it;
- send through a deterministic service;
- record the event.
The model should not decide for itself whether its own output deserves review.
Keep a lightweight evidence trail
A small business does not need to copy an enterprise governance office. It does need to answer basic questions after a complaint:
- Which system produced this interaction or asset?
- Which version and configuration were active?
- What disclosure did the customer see?
- Was a person expected to approve it?
- Who changed the workflow most recently?
- Can the output be corrected or withdrawn?
Use proportional logs. Avoid retaining personal data “just in case”; set a purpose and retention period.
Test suppliers beyond the sales claim
Ask an AI supplier for:
- documentation of user-notification features;
- details of synthetic-content marking and what transformations preserve it;
- data locations and subprocessors;
- incident and change-notification terms;
- export and deletion capabilities;
- a clear description of who is responsible for the end-user interface.
The answer “we are AI Act compliant” is too broad to operate. You need to know which feature supports which obligation in your workflow.
Do not confuse transparency with consent or accuracy
A label saying “AI-generated” does not make an output accurate, fair or lawful. It also does not replace a lawful basis for processing personal data, a privacy notice, marketing consent, employment rules, consumer-protection duties or sector-specific requirements.
Treat transparency as one layer:
- identity: the person knows AI is involved;
- data: personal data has an appropriate purpose, basis and protection;
- content: material claims are accurate and reviewed;
- action: the system has only the authority it needs;
- evidence: the business can reconstruct what happened.
The UK and companies serving the EU
The United Kingdom is part of the European market context but is not an EU Member State. A purely UK use case should not be described as automatically governed by the EU AI Act. A UK company offering or using AI in connection with the EU market may still need a territorial-scope assessment.
For a Europe-wide content or product rollout, maintain a country and legal-scope field in the launch checklist instead of treating “Europe” as one jurisdiction.
What to do this week
Choose the three AI workflows with the greatest public exposure. For each one:
- capture the live customer experience;
- name the owner and determine the role;
- approve the disclosure wording and placement;
- test synthetic-content markings after export;
- document the review and escalation rule;
- save evidence of the test;
- schedule a review when the model, supplier or use changes.
The goal is not a long policy document. It is an observable system in which customers can recognise AI involvement and the business can explain how the output reached them.
References
- European Commission. “Guidelines on transparency obligations for providers and deployers of AI systems.” 20 July 2026. Official guidance (opens in a new tab).
- European Commission. “AI Omnibus enters into force.” 27 July 2026. Official update (opens in a new tab).
Apply the checklist in Methodfield
Use FMEA to identify where a missed disclosure or stripped provenance marker could fail, Mistake Proofing to place controls at the publishing boundary, and PDCA/PDSA to test the live customer experience after every material system change.
This article provides general operational information and is not legal advice. It was last checked against the European Commission guidance and AI Act implementation update on 11 August 2026.
