Almost every headline last summer was about the delay. The European Commission was softening the AI Act, Brussels was backing down, business owners could breathe out. That is half true — and the half that is not true is exactly the half about your website.
What was deferred affects manufacturers of high-risk systems. What was not deferred affects anyone with a chatbot, an AI-generated campaign image or a generated video on their site. That part has applied since 2 August 2026.
1. What was deferred, and what was not
The Digital Omnibus was published in the Official Journal of the EU on 24 July 2026 and entered into force on 27 July 2026 — six days before the original deadline. It is no longer a proposal under negotiation but law in force.
What it defers:
- Standalone high-risk AI systems (Annex III) move from 2 August 2026 to 2 December 2027.
- AI embedded in products already covered by EU product-safety law (Annex I) moves to 2 August 2028.
What it does not defer: Article 50, the transparency obligation. That has applied in full since 2 August 2026. There is a transitional period until 2 December 2026 for systems already placed on the market before 2 August, specifically for the marking and detection duties.
The result is faintly ironic: the part most business owners will never encounter has been pushed back, and the part that touches nearly every website came quietly into force.
2. A chatbot has to identify itself
If you put a chatbot, AI assistant or avatar on your site, the visitor has to know they are talking to a machine. Not somewhere in your privacy statement, but before or at the very beginning of the conversation.
The regulation allows one exception: disclosure is not required where it is obvious to a reasonably well-informed, observant and circumspect person that AI is involved. That sounds like a generous escape route, but it is not. The chatbots that work well — the ones that write fluently and human — are precisely the ones that fall outside it. The better your bot, the more firmly you need the notice.
In practice this is not a demanding requirement. A single line at the top of the conversation window does it: “You’re talking to an AI assistant.” What it does demand is that you think of it while designing the bot, because a disclaimer pasted in afterwards almost always looks like exactly that.
3. Image, video and audio: mark it and label it
There are two separate duties here, falling on two different parties, and they are routinely confused.
The provider of the AI system — Midjourney, OpenAI, Adobe, whoever — must ensure that what the system produces is marked in machine-readable form so that it can be automatically detected as AI-generated or manipulated. That marking has to be effective, reliable and interoperable. This is not your job, but it is why your choice of tool matters: use something that does not mark its output and you are publishing material that does not meet the standard.
You, as the user, take on your own duty the moment you publish a deepfake — image, audio or video that imitates an existing person, place or event. Then you must disclose that the content has been artificially generated or manipulated. For artistic, creative or satirical work the disclosure may be made in a way that does not spoil the work, but it cannot be absent.
For most marketing imagery — a generated background, a retouched product shot, an atmospheric image with people who do not exist — the deepfake duty does not apply, because nobody is being imitated. That does not put you in the clear: the provider’s marking obligation still stands, and sensible brands choose openness anyway. An audience that works it out later punishes that harder than a label would ever have cost.
4. Text: when it counts, when it doesn’t
The rule for text is narrower than most people assume. You must disclose that text was AI-generated when it is published to inform the public on matters of public interest — news, public affairs, matters of societal concern.
And even then, the duty falls away once a human has reviewed the text and someone holds editorial responsibility for it. Write a product description, a services page or a piece about your own field with AI and check it yourself, and you are generally outside the rule.
The line is not always sharp. Publishing as a business about regulation, health or safety sits closer to “public interest” than a product page does. Where you are in doubt, a short note costs less than the argument afterwards.
5. What this means for how your site gets built
For us this is not a compliance pass at the end but a design condition. In practice that means three things.
The chatbot notice is part of the design of the conversation window, not something stuck on top of it. That saves legal trouble and it also looks like it belongs there.
AI-generated imagery used in a design keeps its marking. Metadata that carries the marking does not get stripped during image compression — which happens more easily than you would expect, since most optimisation steps discard metadata by default.
And it is written down, in your privacy statement and terms: which AI is used, what for, and what happens to data. Not because it is required, but so that you can simply show it the first time a client asks.
6. What you can do this month
Four steps and you have covered most of it:
- Take stock of everywhere AI reaches your audience: chatbot, imagery, video, text, email campaigns.
- Check the chatbot: is the notice there before the first message?
- Check your image library: do you know where each generated image came from and whether it is marked?
- Write it down in your privacy statement and terms, and keep a record of the tools you use.
What it costs to leave it: breaching Article 50 can reach 15 million euro or 3% of total worldwide annual turnover, whichever is higher. Enforcement sits with the national market surveillance authorities. That ceiling is plainly aimed at large offenders, but it tells you which category the legislator put this in.
This article describes the position as at 12 August 2026 and is general information, not legal advice. The rules are still moving: the Digital Omnibus shifted deadlines this summer and that can happen again. Have decisions with financial or legal consequences reviewed by a lawyer, and check the current text of Regulation (EU) 2024/1689 on EUR-Lex.
Frequently asked
Does the AI Act apply to me as a small business?
Yes. Article 50 sets no lower limit on company size. Sole trader or corporation: if you put a chatbot on your site or publish AI-generated imagery, the same transparency rules apply. What does differ is supervision — enforcement is risk-based, and a small business with a correctly labelled chatbot is not at the top of anyone's list.
I only use AI to write text. Do I have to disclose that?
Usually not. The disclosure duty for text covers text published to inform the public on matters of public interest, and it falls away once a human has reviewed the text and holds editorial responsibility for it. A product page or an article about your field generally sits outside it. Image and video are treated more strictly.
What does 'marked in machine-readable form' mean?
That the marking is not only visible to people but automatically detectable — through file metadata or an embedded watermark, for instance. A line in the caption does not satisfy that particular obligation. For deepfakes, a visible disclosure is required on top of it.
Wasn't the whole AI Act delayed?
No. The Digital Omnibus moves the obligations for high-risk AI systems, not the transparency rules. Precisely the part that touches websites, marketing and chatbots took effect on 2 August 2026 as planned.