On 2 August 2026 a part of the EU AI Act becomes applicable that affects many local businesses directly - including those that do not think of themselves as AI companies: the transparency obligations under Article 50 of Regulation (EU) 2024/1689 (Regulation (EU) 2024/1689). If your website runs a chatbot, shows AI-generated images in a gallery or in your references, or publishes texts written with AI support, you should know from that date what needs labelling - and what expressly does not. This is considerably less dramatic than some guidance suggests, but it is concrete. This article explains which content is affected, which duty falls on providers and which on deployers, what machine-readable actually means in practice, and where a notice belongs in the layout without disfiguring the page. As a web agency from the Hildesheim region we guide businesses through this calmly - without scare tactics, but with the seriousness the topic deserves.
What applies on 2 August 2026
The AI Act - formally Regulation (EU) 2024/1689 - entered into force on 1 August 2024 but becomes applicable in stages. The prohibited practices came first, the rules for general-purpose AI models followed, and the broad main body of the regulation takes effect on 2 August 2026 (Regulation (EU) 2024/1689). That same date makes the transparency obligations of Article 50 applicable. The final building block, the requirements for AI in already harmonised product areas, follows only on 2 August 2027 (Bundesnetzagentur).
Article 50 is not a high-risk topic. It requires no conformity assessment, no quality management system and no technical documentation. It asks for something far simpler: that people can tell when they are talking to a machine and when a piece of content was machine-generated. That is precisely why it reaches the trades business, the medical practice or the car dealership - namely when their website contains such elements. And that is increasingly the case: 35 per cent of the companies surveyed already use AI, and a further 34 per cent plan to adopt it within the next three years (DIHK Digitalisation Survey 2026). Among the applications, generating texts, images or code leads clearly at 78 per cent, followed by customer communication and support at 43 per cent (DIHK Digitalisation Survey 2026). Both regularly end up on the website.
One deadline, two levels
Provider or deployer: who owes which duty
Article 50 consistently distinguishes between two roles, and that distinction decides what you as a business actually have to do. A provider develops an AI system and places it on the market under its own name. A deployer uses such a system under its own authority - that is you, when you embed a bought-in chatbot on your site or use an image tool for your reference gallery. The technically demanding duties sit with the providers. What remains on the deployer side is manageable, but clearly named.
Provider, paragraph 1: disclose the interaction
Anyone developing an AI system intended to interact directly with people must design it so that the person is informed they are interacting with an AI system - unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person (Art. 50(1) AI Act).
Provider, paragraph 2: mark machine-readably
Providers of generative AI systems must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Systems performing an assistive function for standard editing are exempt (Art. 50(2) AI Act).
Deployer, paragraph 3: emotion and biometric systems
Anyone operating an emotion recognition or biometric categorisation system must inform the people exposed to it and comply with data protection rules (Art. 50(3) AI Act). On the typical website of a local business this practically does not arise.
Deployer, paragraph 4: disclose deepfakes
Anyone using AI to generate or manipulate image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. For AI text the duty applies only to publications informing the public on matters of public interest (Art. 50(4) AI Act).
| Element on your website | Who is responsible? | What to do in practice |
|---|---|---|
| Bought-in chatbot in a dialogue window | The chatbot's provider | Check whether the tool discloses this itself - otherwise add it yourself |
| AI image in a gallery or references | The image tool's provider | Machine-readable marking comes from the tool; a visible notice only where the image has deepfake character |
| Convincing image of a real person | Your business as deployer | Disclose that the content was artificially generated or manipulated |
| Service copy written with AI | Usually no additional duty | No disclosure duty as long as it is not a matter of public interest |
| Editorially reviewed guidance article | Your business as deployer | Where editorial responsibility exists, the text exemption applies |
The practical short version
Two duties that are often confused
This is where guidance literature regularly muddles things, and it creates unnecessary work. Article 50 contains two entirely different concerns that only happen to share an article number. One concerns the interaction: a person should know that their counterpart is a machine. The other concerns the content: a synthetically generated image or video should be recognisable as such. Conflate the two and you end up labelling every mood shot on the homepage while overlooking the chatbot.
Disclosing an interaction is not labelling a piece of content
An example makes the difference tangible. A business embeds an AI assistant that gives opening hours and suggests appointments. Paragraph 1 applies: the user must be able to tell from the outset that they are not writing to a member of staff. The assistant's answers are text and do not by themselves trigger a labelling duty, because the text duty in paragraph 4 only covers publications informing the public on matters of public interest - an opening-hours answer is not that. Anyone who solves the advisory function through online appointment booking without a dialogue system does not run into Article 50 at this point in the first place.
The question is not whether AI was involved. The question is whether someone could be deceived - about who they are talking to, or about whether what they see is real.
Which content on your website is affected
Before anything gets labelled, an honest inventory pays off. On a typical local business website, AI elements appear in four places - and only two of them create a duty of your own.
Chatbot and assistant dialogues
Every dialogue window that answers automatically falls under paragraph 1 - no matter how simple it is. Assistants that merely pre-fill forms are covered too, provided they talk to the user. After all, 43 per cent of AI-using companies deploy AI in customer communication and support (DIHK Digitalisation Survey 2026).
AI images in gallery and references
Mood shots, symbolic graphics or visualised equipment variants are synthetic content within the meaning of paragraph 2. The machine-readable marking is supplied by the generating tool. A visible notice only becomes mandatory once the image has deepfake character.
AI-assisted texts
Service descriptions, product copy or blog posts created with AI trigger no general labelling duty. The duty in paragraph 4 applies only to text informing the public on matters of public interest - and falls away where there is editorial review and responsibility (Art. 50(4) AI Act).
Convincingly real depictions
An image showing a real person, place or event so that it appears authentic is a deepfake within the meaning of the regulation - a composited team photo, say, or a visualised reference that passes as a genuine project shot. Here the disclosure duty falls on you as deployer (Art. 50(4) AI Act).
- Chatbot in place? Then it must be recognisable as an AI system - at the latest at the time of the first interaction (Art. 50(5) AI Act).
- AI images in use? Note which tool created them and whether it applies a machine-readable marking.
- Real people or places depicted? Then check whether the depiction looks convincingly authentic - that is the deepfake threshold.
- Texts on matters of public interest? Only then does the text question arise at all, and even then editorial control resolves it.
- Tools documented? A simple inventory of the AI tools in use is the basis for any later assessment.
- Notice accessible? The information must meet the applicable accessibility requirements (Art. 50(5) AI Act).
The obviousness threshold in paragraph 1 is worth noting. Disclosure falls away where it is obvious, from the point of view of a reasonably well-informed, observant and circumspect person and given the circumstances and context, that they are dealing with an AI system (Art. 50(1) AI Act). In its draft guidelines the European Commission cites examples such as coding assistants for professional developers or AI-driven non-player characters in video games (European Commission). A dialogue window in the bottom right corner of a tradesperson's website does not meet that threshold as a rule - nobody there automatically expects a machine.
Deepfake: what the term really means
Few terms in the Article 50 debate are stretched as far as this one. The regulation defines it narrowly: a deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful (Art. 3(60) AI Act). Two features must coincide: a link to something real, and the capacity to deceive about authenticity. Take one away and it is not a deepfake.
Not every mood shot is a deepfake
For businesses this is both good news and a warning. Good, because a website's visual language does not have to be blanketed in warnings. A warning, because the critical cases sit exactly where trust is at stake: reference photos, team pictures and before-and-after depictions. Anyone using AI there should disclose it - not only because of Article 50, but because an invented reference would be a fair-trading problem regardless of the AI Act. How to present references convincingly without invented figures and images is one of the questions we regularly work through in web design from Hildesheim anyway.
Art, satire and fiction
What machine-readable means in practice
The term unsettles many businesses because it sounds like technology they would have to build themselves. That is a misunderstanding. The duty in paragraph 2 falls on providers of generative AI systems, not on their users: they must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, and the solutions must be effective, interoperable, robust and reliable as far as is technically feasible (Art. 50(2) AI Act). Machine-readable means: not intended for the human eye, but for software that checks the content later.
- Watermarks in the content: patterns invisible to people, embedded into image, audio or video during generation, that allow later machine detection.
- Provenance metadata: information attached to a file documenting which system created it and whether it was altered afterwards.
- Markers in the file header: standardised fields that image editing and content systems can read without touching the visible content.
- Detection tools: software that reads the embedded signals back out - only then does the marking become usable for platforms and reviewers.
To harmonise these methods in practice, the European Commission published the final Code of Practice on the transparency of AI-generated content on 10 June 2026 (European Commission). It is expressly voluntary and addresses providers and deployers of generative AI systems; one section covers machine-readable marking under paragraph 2, a second the labelling of deepfakes and text under paragraph 4. Signatories can rely on it to demonstrate compliance. It was preceded by a draft of the Article 50 guidelines dated 8 May 2026, on which the Commission ran a consultation until 3 June 2026 (European Commission).
What you notice - and what you do not
Where the notice belongs in the layout
Paragraph 5 sets three requirements as to form, and all three are easy to solve in design terms. The information must be provided to the people concerned at the latest at the time of the first interaction or exposure, it must be clear and distinguishable, and it must meet the applicable accessibility requirements (Art. 50(5) AI Act). The last point ties Article 50 to a duty many businesses are already dealing with: what applies to websites under the German accessibility act for websites also shapes the design of the AI notice. A notice that exists only as light grey small print, or that screen readers skip, meets neither requirement.
At the chatbot entry point
The natural place is the header of the dialogue window and the first message: a clear title such as AI assistant, plus one sentence saying that an AI system is answering and how to reach a human. That satisfies the first-interaction requirement without forcing an extra overlay.
In the image caption
Where an image has deepfake character, the disclosure belongs with the image - as a caption or as a small but legible marker in the gallery. It does not have to shout; it has to be findable before someone takes the image for a real photo.
On a dedicated notice page
A short, linked explanation of which AI elements the site uses bundles the detail and takes pressure off the surface. It does not replace the notice at the object, but complements it sensibly - much as a privacy policy sits alongside a consent banner.
In design terms this is less delicate than many fear. A notice that matches the rest of the page reads as care rather than as a warning sign - the same effect a fairly built cookie banner under the TDDDG rules achieves. If you are considering a revamp anyway, plan the labelling in from the start instead of sticking it on later as a foreign body. And if you want to know why transparency also helps on the visibility side, our article on AI overviews in search tells the other half of the story.
Fines put in perspective
For completeness the sanction framework belongs here, but without drama. Breaches of the Article 50 transparency obligations fall into the regulation's middle penalty tier: up to 15 million euros or up to 3 per cent of total worldwide annual turnover of the preceding financial year, whichever is higher (Art. 99(4) AI Act). That figure circulates through many articles and creates alarm that is unfounded for small businesses. Because the regulation contains a rule that is quoted less often: for small and medium-sized enterprises, including start-ups, the lower of the two figures applies (Art. 99(6) AI Act). For a business with regional turnover that is not the multi-million sum but the percentage.
On top of that, the regulation expressly takes the size and situation of the addressee into account when setting a fine. In its statement of 3 June 2026 the DIHK argued for making the guidelines workable, exempting minor cases via thresholds, and considering a company's margin and its actual influence on the AI system when imposing sanctions (DIHK). That legal uncertainty weighs on businesses is measurable: 32 per cent of the companies surveyed name legal uncertainty as a challenge of digitalisation (DIHK Digitalisation Survey 2026). The survey is based on 4,686 responses collected in November 2025 (DIHK Digitalisation Survey 2026).
Perspective, not alarm
Taking stock and ongoing upkeep
The most honest sentence about Article 50 is this: the real work is not the labelling, it is knowing what would need labelling. On websites that have grown over years, nobody quite knows any more which images came from which source, whether the dialogue window in the footer is still live, or which tool produced the copy in the services section. Taking stock does not take a day - but it does need someone to do it.
- Build the inventory: capture every place where AI is involved - chatbots, image tools, text tools, assistants embedded by service providers.
- Clarify the role: for each element, determine whether you are the deployer and whether a duty under paragraph 1, 3 or 4 arises at all.
- Run the deepfake check: review images and videos for whether they depict real people, places or events convincingly enough to pass as authentic.
- Draft the notices: work out short, clear wording and place it correctly - accessible, and at the latest at the first interaction.
- Document the tools: record which providers are in use and whether their outputs carry machine-readable markings.
- Set a review date: new tools, new images and new guidance from the authorities lead to adjustments - a fixed review rhythm prevents drift.
Keep the inventory current
When a new tool arrives or a service provider switches systems, the basis for the labelling changes. A maintained inventory of the AI elements in use keeps the assessment sound instead of ticking it off once.
Maintain the notices
If the chatbot is replaced, the gallery extended or a reference image swapped, the notice has to move with it. Wording and placement are updated so that labelling and actual content match.
Watch the legal situation
The Commission's guidelines and the Code of Practice continue to develop (European Commission). Following that development means adjusting in good time instead of reacting after a complaint.
This is exactly where ongoing website maintenance from Hildesheim comes in: taking stock of the AI content in use, matching notice texts, and regularly checking that the two still fit together. It is deliberately something other than the technical protection against attacks and outages covered in our article on website maintenance and security - and something other than the data protection that takes centre stage with the consent banner. Article 50 is about transparency: making clear what is machine.
And as with every duty attached to a website, the rule holds: you can only maintain what you have access to. If you are not certain who actually owns your domain, hosting and access credentials, settle that before 2 August - otherwise the labelling fails not on the law but on a missing login. The same goes for the classic mandatory imprint details under the DDG, which are part of the basic programme of any commercial website anyway. If you are unsure which AI elements your site even contains, talk to us - taking stock is quick and creates clarity for everything that follows. Visibility in search and clean labelling are not at odds: both belong to a site that gets found in search and holds up in front of a visitor.