What does the EU AI Act ask of your chatbot and AI content?

Article 50 of the EU AI Act has applied since 2 August 2026. What an SME must do with its chatbot, AI images and AI texts, and who supervises.

What does the EU AI Act ask of your chatbot and AI content?

Summary

  • Article 50 of the EU AI Act has applied since 2 August 2026: a chatbot must say that it is AI, and deepfakes and certain AI texts get a visible label
  • The chatbot's notification obligation lies with the provider. If you have a chatbot built and use it under your own name, you fall under that definition yourself according to the letter of the law
  • The watermark is an obligation of the providers of generative AI. Anthropic, Google and OpenAI signed the European code of practice; that watermark does not replace the label on a deepfake
  • According to the Commission, advertising copy and product descriptions do not need a label in principle, except for claims about, for example, health, consumer safety or sustainability
  • On 14 September 2026, Belgium still has no designated supervisory authority; the fine for a breach of Article 50 goes up to 15 million euros or 3% of worldwide annual turnover, for SMEs the lower of the two
  • Article 50 has not been postponed: the Omnibus only gave existing systems until 2 December 2026 for the marking

Since 2 August 2026, a chatbot on your website has to say that it is an AI, and an AI image that makes your product look better than it is gets a label, according to the European Commission. It comes from Article 50 of the EU AI Act, the European AI regulation. At the same time, the makers of ChatGPT, Claude and Gemini mark their images or text with an invisible watermark, and Belgium has not yet designated a supervisory authority. We looked into what the law asks exactly, who carries the obligation and what an SME does now in practice. Our sources are the legal text, the European Commission’s guidelines and the guide of the Belgian FPS Economy. This article is not legal advice: it says what the rules are and where they are written.

What is the EU AI Act and what does Article 50 cover?

The EU AI Act is Regulation (EU) 2024/1689, the European law on artificial intelligence, in force since 1 August 2024. Article 50 covers transparency and has applied since 2 August 2026: people must know when they are talking to AI, AI output is marked in machine-readable form, and deepfakes and certain AI texts get a visible disclosure. The obligation lies with the provider or the deployer.

Paragraph Who has the obligation What Example for an SME
Paragraph 1 Provider AI systems that talk directly to people make clear that it is AI The chatbot on your website, an AI agent that emails customers
Paragraph 2 Provider Mark image, audio, video and text from generative AI in machine-readable form The image and text tools of OpenAI, Anthropic and Google
Paragraph 3 Deployer Inform people about emotion recognition or biometric categorisation Rare for SMEs; emotion recognition in the workplace is prohibited
Paragraph 4, first subparagraph Deployer Disclose deepfakes An AI product photo that makes your product look better than it is
Paragraph 4, second subparagraph Deployer Disclose AI text on matters of public interest, unless there is human editorial control An AI blog about nutrition and health that goes online without review
Paragraph 5 Provider and deployer Give the information clearly and accessibly, at the latest at the first interaction or exposure The notice appears before your chatbot's first answer

Two concepts from Article 3 determine who has to do what. The provider is whoever develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark. The deployer is whoever uses an AI system under its authority in a professional capacity (EUR-Lex). Under the same law, a deepfake is image, audio or video content that resembles existing persons, objects or events and would falsely appear to be authentic. Text does not fall under that definition; for AI text, the second subparagraph of paragraph 4 applies.

These rules affect many companies. In 2025, 34.54% of Belgian enterprises with at least 10 persons employed (excluding agriculture and the financial sector) used at least one AI technology, against 24.71% a year earlier and 19.95% on average in the EU (Eurostat). According to the FPS Economy, that puts Belgium in the European top 5 (FPS Economy). For the European Commission, it is about trust:

“Europeans have a right to know whether what they see, hear or read has been made or altered by AI, especially when such content can shape public debate. Transparency is how we protect trust.”

— Henna Virkkunen, Executive Vice-President of the European Commission, June 2026

ClickForest, which builds AI chatbots and AI content for Flemish SMEs in Mechelen and Antwerp, sets out below what that means in practice.

Does your chatbot have to say that it is an AI?

Yes. Since 2 August 2026, a chatbot must clearly tell people, at the latest at the first interaction, that they are talking to an AI system, unless that is already obvious to a reasonably observant person. The law places that obligation on the provider of the chatbot. According to the European Commission’s guidelines, one clear notice before the first interaction is sufficient in most cases.

The FPS Economy gives a simple example: a message saying that you are chatting with an AI assistant and that the answers are generated automatically (FPS Economy). The guidelines also mention an opening message from the chatbot or a clear label or banner, such as “You are interacting with an AI system” (European Commission). What does not suffice, according to the Commission:

  • a notice that only appears in the terms and conditions, a link or the documentation
  • a general sentence such as “Services on this website use AI”
  • a vague name like “assistant” or a human avatar that may mislead
  • a watermark or metadata that the visitor does not see at that moment

Lawyer Joris Deene of Everest puts it this way on LegalNews: a mere mention in the terms and conditions is rarely enough (LegalNews). The “it is obvious” exception is narrow, according to the Commission, and does not apply to a helpdesk chatbot. It can apply to an internal assistant for trained staff who know they are working with AI, for example for HR or IT support. An employee who answers personally and uses an AI helper for it does not fall under paragraph 1. An AI agent that emails customers in your name does; more about such agents in what is an AI agent.

On clickforest.com itself, when you open the chatbot, the notice “You are chatting with an AI assistant. Errors are possible.” appears just above the input field. It stays until you ask your first question or close it, in Dutch, English and French. That is the kind of label before the first interaction that the guidelines give as an example. How an AI chatbot for customer service works and what it delivers is covered in a separate article.

As an SME, are you a provider or a deployer?

That depends on who builds the chatbot and under whose name it runs. If you put a vendor’s chatbot on your site unchanged, that vendor is the provider and carries the notification obligation. If you have a chatbot built and use it under your own name, you are a provider yourself under the literal definition.

Situation Role under the AI Act Who takes care of the notice, the marking or the label
You put a ready-made chatbot from a vendor on your site unchanged Deployer (FPS Economy); the vendor is the provider The vendor
You have an agency build a chatbot on a language model and put it online under your own name Falls under the literal definition of provider ("has an AI system developed"); the Commission does not work out this case You; set out the division of roles in the contract
You develop a chatbot yourself and use it under your own name Provider You
You modify an existing generative system, for example with your own training data, and use it under your own name Provider of the new system You
You have an advertising agency make a campaign without deciding on the use of AI yourself Not a deployer; the agency may be one Not applicable
You create deepfakes for your marketing with your own system Provider and deployer You, for the marking and for the label

The guidelines state explicitly that a vendor offering a chatbot under its own name remains the provider, even if customers integrate it into their own processes without modification. A company that develops a chatbot in-house and uses it under its own name is itself the provider (European Commission). The definition says “develops or has developed”, and the FPS Economy describes the provider as the party that builds the AI system or has it built (FPS Economy). The exact case of an agency building the chatbot and an SME using it under its own name is not worked out with an example by the Commission or the FPS. In the same guide, the FPS calls the company that integrates the chatbot on its website a deployer, if someone else developed it; both readings therefore exist. Anyone who substantially modifies an existing generative system, for example with their own training data, and uses it under their own name does become the provider of that new system, according to the Commission. So set out the division of roles in the contract, and have a lawyer look at it in case of doubt.

The language model behind the chatbot, such as Claude or GPT, does not fall directly under Article 50. According to the guidelines, the provider of the chatbot may rely on the marking of that underlying model, provided that it meets paragraph 2. Demonstrating that it does remains the task of the chatbot’s provider. If you use a vendor’s chatbot unchanged, then under the letter of paragraph 1 you have no notification obligation of your own. The FPS Economy and the Flemish SME organisation UNIZO do ask companies to be transparent, and consumer law may impose a duty to inform independently of this. According to UNIZO, most self-employed people and small businesses will mainly be users, and users also have obligations, for example around AI literacy, prohibited applications, human oversight and transparency (UNIZO).

Anyone who has an AI chatbot built should therefore discuss that division of roles before delivery, together with the place and wording of the notice.

What is the watermark, and do ChatGPT, Claude and Gemini already use it?

The watermark is the machine-readable marking that Article 50, paragraph 2, imposes on providers of generative AI; in the voluntary code of practice, that means signed metadata and an invisible watermark. Anthropic marks text from models released after 2 August 2026, OpenAI images and audio, Google image, audio, video and text. Systems that were on the market before 2 August 2026 have until 2 December 2026.

The code of practice is voluntary, was drafted by six independent experts and has been final since 10 June 2026 (European Commission). By the end of July, about 190 organisations had signed it, including Anthropic, Google, Meta, Microsoft and OpenAI (European Commission). For text, one layer is enough, because free-form text cannot carry metadata; for free-form text longer than 200 tokens, the code requires a watermark. This is how the big three approach it:

  • Anthropic (Claude): a watermark on text from models released after 2 August 2026, with older models following in the coming months. Image files get C2PA metadata, and a detection API is in private preview for regulators, media and fact-checkers, among others (Anthropic)
  • OpenAI (ChatGPT): images from ChatGPT, Codex and the API get C2PA metadata and a SynthID watermark, audio an inaudible SynthID watermark (OpenAI). We found no information from OpenAI about a watermark on text
  • Google (Gemini): SynthID for image, audio, video and text; for image and video, designed according to Google to withstand cropping, filters and compression (Google DeepMind)

A watermark is not an indelible stamp. OpenAI warns that metadata sometimes disappears through platforms, editing tools or a different file format. Anthropic puts it this way about text:

“Light editing probably won’t remove the watermark completely; a complete rewrite where every word is replaced will.”

— Anthropic, August 2026

Important for marketers: the maker’s watermark is not enough as a label on a deepfake. According to the guidelines, that marking is not clear enough for the people who see the content, so the visible label remains the task of whoever publishes the deepfake. Which models are otherwise in ChatGPT, Claude and Gemini is covered in our comparison of Claude, ChatGPT, Gemini and Perplexity.

Which AI content do you have to label yourself?

A visible label is mandatory for deepfakes and for AI text that informs the public on matters of public interest, unless a person reviewed that text substantively and someone holds editorial responsibility for it. According to the Commission, advertising copy and product descriptions are in principle outside this, except for claims about, for example, health, consumer safety or sustainability.

Content Visible label required? Why
AI product photo that shows your product more attractively or differently than it is Yes According to the Commission a deepfake: the image misleads about the real product
Real product against an AI background No, as long as the ad does not mislead Not a deepfake according to the guidelines
Realistic AI avatar of your managing director or a synthetic influencer testing your product Yes Deepfake; the lighter rule for creative work does not apply here
Clearly fictional AI video, such as talking mice in a cheese commercial No Not a deepfake: nobody takes it for real
Advertising copy and product descriptions In principle not Outside paragraph 4, except for claims about, for example, health, consumer safety or sustainability
AI blog or newsletter on a topic of public interest Yes, unless there is human editorial control The exception requires a substantive review, a fact-check and a visible responsible person
Internal texts and business emails to one person No Not published within the meaning of paragraph 4

The examples in the table come from the Commission’s guidelines (European Commission). For the human editorial exception, according to the Commission a fact-check is the minimum: a spell check, an automated review or a quick approval is not enough. The name or function of whoever holds editorial responsibility is findable on the site. And anyone who has the text substantively reworked with AI after that review loses the exception. That is also how content production with final editing works; what AI and a human writer are each good at is covered in AI copywriting versus the human.

The code of practice describes the label itself: the letters “AI”, for images and video for example in the top right corner, for video at the start and where possible at intervals, for text above the text or near the headline. The EU provides icons for this (“AI + GENERATED” and “AI + MODIFIED”); those icons are optional, the labelling obligation is not (European Commission). For video specifically, see our video marketing trends.

There are a few more nuances. Meta, LinkedIn and YouTube label content with C2PA metadata themselves. If a large platform offers you a labelling tool, the Commission says you may use it for what you publish on that platform; if you put the same deepfake on your site or in your newsletter, you label it there yourself. LinkedIn itself says that it does not yet recognise all AI content (LinkedIn). Content that was created and published before 2 August 2026 does not need a label retroactively. An older AI text that you only publish after that date does fall under it. And a label does not automatically make content permissible: a labelled deepfake can still be misleading advertising.

Who supervises in Belgium and what fine do you risk?

On 14 September 2026, Belgium still has no designated supervisory authority: the European list names none. According to the FPS Economy, the BIPT, the Belgian telecoms and postal regulator, will become the AI watchdog, but a law must first pass parliament. For a breach of Article 50, fines can reach 15 million euros or 3% of worldwide annual turnover; for SMEs, the lower of the two applies.

The Commission’s list of national market surveillance authorities, updated on 7 September 2026, shows only a dash for Belgium (European Commission). According to VRT NWS, the FPS Economy is working on a preliminary draft law, which the government must then submit to parliament. For applications in, for example, education or employment services, it is not yet clear who will supervise, because those are regional competences (VRT NWS). Anyone who wants to invoke the new rules can, for now, only go to court. The FPS Economy put it this way to VRT NWS:

“The interpretation that there is currently a legal vacuum is correct. (…) From 2 August, these rights can, as things stand, only be enforced through the courts.”

— Etienne Mignolet, FPS Economy, to VRT NWS, August 2026 (translated from Dutch)

So the rules already apply; only the enforcement by a Belgian authority is still missing. The European AI Office is only competent for AI systems of the same provider as the underlying model and for systems in very large platforms; for an SME’s AI, the national authority is competent (European Commission). The amounts of 15 million euros or 3% are European maximums from Article 99 (EUR-Lex). Which penalties Belgium will impose exactly, and who will impose them, the Belgian law still has to lay down.

Does your team have to follow AI training?

No, a course or certificate is not mandatory. Article 4 has applied since 2 February 2025 and now asks companies that use AI to take measures to support the AI literacy of their people. Since the Omnibus, in force since 27 July 2026, that no longer has to be a guaranteed level. According to the Commission, a company whose employees use ChatGPT for advertising copy falls under it.

The original text asked for “a sufficient level of AI literacy”. The Omnibus changed that into measures to “support the development of AI literacy”, adding that this obligation does not require a specific level to be guaranteed (EUR-Lex). According to the Commission, employees do need to be informed about the specific risks, such as hallucinations, and it writes: “There is no need for a certificate.” Organisations can keep an internal record of which trainings or other initiatives they provided (European Commission). UNIZO confirms this:

“The law does not require every employee to follow a specific course, take an exam or obtain a certificate.”

— UNIZO, entrepreneurs’ guide on artificial intelligence (translated from Dutch)

That obligation also applies to those covered by Article 50, as provider or as deployer. A short, practical training is a logical way to meet it. ClickForest gives Flemish SMEs in Mechelen and Antwerp AI training for the whole team.

What else changes after 2 August 2026?

Article 50 has not been postponed. The Digital Omnibus, in force since 27 July 2026, only gave providers of systems that were already on the market before 2 August 2026 until 2 December 2026 for the marking. The chatbot notice and the labels got no delay. The rules for high-risk AI did move, to 2 December 2027 and 2 August 2028.

Date What
1 August 2024 The AI Act enters into force
2 February 2025 Prohibited practices (Article 5) and AI literacy (Article 4)
2 August 2025 Rules for general-purpose AI models, such as the models behind ChatGPT, Claude and Gemini, and the penalty rules
27 July 2026 The Digital Omnibus enters into force
2 August 2026 Article 50 and the general application of the regulation; national supervision of AI literacy
2 December 2026 Marking (paragraph 2) for systems that were already on the market before 2 August 2026; new prohibitions on AI for non-consensual sexual images and child sexual abuse material
2 December 2027 High-risk AI from Annex III, such as applications for HR, education and credit
2 August 2028 High-risk AI in products (Annex I)

The Omnibus is Regulation (EU) 2026/1744. The Commission proposed it on 19 November 2025 and the political agreement followed on 7 May 2026 (European Commission); the text was published in the Official Journal on 24 July 2026 (EUR-Lex). The text of Article 50 itself remained unchanged; the transitional rule for the marking is in a new paragraph of Article 111. Agoria reacted critically at the time of the agreement in May 2026: in its view, there are few real simplifications for SMEs in the whole AI Omnibus (Agoria).

What do you do now as an SME?

Start with an overview of where you use AI: your chatbot, your images and videos, your texts and your internal tools. Then check for each place who the provider is, whether the notice appears at the first contact and which content needs a label. Decide who reviews your texts substantively, and support your team’s AI knowledge.

  1. Make an AI inventory. List every chatbot, AI agent, image and video tool, text tool and internal assistant you use. An AI audit helps with that.
  2. Chatbot: decide who the provider is and put a clear notice before the first answer, such as “You are chatting with an AI assistant”. A sentence in the terms and conditions is not enough.
  3. Images and video: show your product as it is. An AI image that may mislead, or a realistic avatar, gets a label, for images for example in the top right corner.
  4. Texts: have AI texts on health, safety, sustainability or other matters of public interest reviewed substantively and fact-checked, and make visible who holds editorial responsibility. Without that editorial control, the text gets a label.
  5. Leave the marking in place: do not strip metadata or watermarks from AI files when exporting or editing.
  6. AI literacy: explain the risks, such as hallucinations, to your team and keep track of who followed which training.
  7. Follow the Belgian law: as soon as Belgium designates a supervisory authority, according to the FPS Economy the BIPT, and the penalties are set, enforcement changes.

What to look out for when building AI into your business is covered in our article on AI consultancy for SMEs and in our AI marketing guide.

Conclusion: Article 50 is mostly a matter of showing what AI is

For most SMEs, Article 50 does not require heavy procedures. A chatbot that says it is AI, AI images that show your product honestly or carry a label, and AI texts that a person reviews: that covers most of it. The watermark is, in most cases, handled by the makers of your AI tools. The notice and the label remain your responsibility as soon as you are a provider or deployer, and you become one faster than you think.

In Belgium, a supervisory authority is still missing, but the rules already apply. We recommend arranging what is simple now, and setting out the division of roles around your chatbot before the Belgian law arrives. Belgium’s Minister of Economy David Clarinval called AI a great growth engine for Belgian companies at the end of 2025 (FPS Economy).

ClickForest builds AI chatbots and AI content with final editing for Flemish SMEs in Mechelen, Antwerp and the rest of Flanders, and provides AI training for teams. Want to know what Article 50 means for your chatbot or your content? Get in touch.

Grow with AI, practically and without unnecessary complexity

Ready to use AI to save time and accelerate your marketing? Discover our AI services

Discuss your challenge directly with Frederiek: Book a free strategy call or send us a message

Prefer email? Send your question to frederiek@clickforest.com or call +32 473 84 66 27

Strategy without action remains theory. Let's take your next step together.

FAQ

Frequently asked questions

Article 50 is the transparency article of the European AI regulation and has applied since 2 August 2026. It requires providers to make chatbots say that they are AI and to mark AI output in machine-readable form. Deployers must disclose deepfakes and AI text on matters of public interest without human editorial control.

Yes, at the latest at the first contact and clearly visible in the conversation itself; according to the Commission, a sentence in the terms and conditions is not enough. The obligation lies with the provider, and that can be you if you have the chatbot built and use it under your own name. ClickForest, which builds AI chatbots for Flemish SMEs in Mechelen and Antwerp, shows that notice on its own chatbot above the input field, until the first question.

No, Article 50 has applied since 2 August 2026. The Digital Omnibus only gave providers of systems already on the market until 2 December 2026 for the marking, and moved the rules for high-risk AI to 2027 and 2028.

No. The watermark is an invisible marking by the maker, and according to the European Commission it is not clear enough for people who see a deepfake. Whoever publishes a deepfake therefore adds a visible label themselves.

A course or certificate is not mandatory. Anyone who uses AI does take measures under Article 4 to support the team's AI literacy, and should keep track of who followed which training. ClickForest gives Flemish SMEs in Mechelen and Antwerp AI training for the whole team.

Sources and references

Legislation and European Commission documents:

Belgium:

Makers and platforms:

Ready to use AI practically in your business?Discover AI for growth
Ready to grow

One call and it becomes clear.

No noise, short lines, monthly rolling. Book a no-obligation intro call with Frederiek.