The AI Act rule that already applies to ordinary websites
Most of the AI Act is aimed at high-risk systems, and in July 2026 those deadlines moved to December 2027. One part did not move. Since 2 August 2026 the transparency rules apply, and they reach further than high-risk: a chatbot has to say it is a chatbot, AI-generated media has to be marked so a machine can spot it, and some AI-written text has to be labelled. None of it applies to a site that uses no AI at all. If yours does, three duties are worth knowing.
What happened on 2 August, and what did not
The AI Act arrives in stages, and the stage everyone was watching was the one for high-risk systems: recruitment, credit, education, law enforcement, critical infrastructure. That stage moved. The AI Omnibus, Regulation (EU) 2026/1744, was published on 24 July 2026 and entered into force on 27 July, and it pushed the obligations for the high-risk systems in annex III from 2 August 2026 to 2 December 2027.
Article 50, the transparency rules, was not in that deferral. It applies from 2 August 2026. There is one narrow extension inside it: for AI systems that were already on the market before that date, the machine-readable marking duty in article 50(2) applies from 2 December 2026 instead. That extension is for providers of those systems. It does not postpone what you have to do as the party using an AI system.
So the headline that the AI Act was delayed is true for the part most articles were about, and not true for the part most websites will actually meet.
Three duties that reach an ordinary website
A chatbot has to say it is a chatbot. Article 50(1) puts this on the provider of the system: it must be designed so that the person is informed they are interacting with an AI system, unless that is obvious to someone reasonably well-informed. Article 50(5) adds the timing: the information is given clearly and distinguishably at the latest at the first interaction. In practice that is a line in the widget before the first message, not a sentence in your privacy policy.
Generated media has to carry a machine-readable mark. Article 50(2) asks providers of systems that generate synthetic audio, image, video or text to mark the output in a machine-readable format so it is detectable as artificially generated or manipulated, as far as that is technically feasible. It carries its own exceptions: systems that perform a standard editing function, and systems that do not substantially alter the input or its meaning. A colour correction is not a synthetic image.
Some AI-written text has to be labelled, and some does not. This one sits with you as the deployer. Article 50(4) asks for disclosure of text that is artificially generated or manipulated and published with the purpose of informing the public on matters of public interest. The Commission reads that category broadly: politics, public administration, justice, rights, security, health, the environment, consumer safety, and economic, scientific or cultural developments.
The exemption is the part worth reading twice, because it is where most of the misunderstanding sits. It is the last sentence of article 50(4), and recital 134 gives the reasoning behind it. The duty does not apply where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publishing it. Both conditions have to be met. The Commission's guidance sets the bar: human review means that someone with knowledge of the subject deliberately examines the substance, and editorial responsibility means that a person holds the ultimate legal responsibility for the publication. Spell-checking, grammar correction and other formal checks do not count. An article that a person actually read and stands behind is not an unlabelled AI text. A batch of generated pages that nobody read is.
The exemption is also narrower than it sounds, because it covers only this text duty. The same paragraph asks you to disclose deep fakes, meaning generated or manipulated image, audio or video that would falsely appear authentic, and human review does not lift that duty; for evidently artistic, satirical or fictional work the disclosure only becomes lighter. Nor does human review lift the chatbot notice in article 50(1) or the machine-readable mark in article 50(2).
What this is not
It is not a licence and there is no certificate. Nothing here asks an ordinary website to register anywhere, and no authority approves your disclosure. As with the accessibility rules, any amount you see quoted for a breach is national: the regulation leaves penalties to the member states.
It is also not a rule about using AI. You can build your site with it, write with it, translate with it. The rule is about telling people when the thing in front of them came out of a model, at the moment they meet it.
Where this leaves the pre-launch checklist
We added this to a twenty-item pre-launch checklist on this blog as a twenty-fourth item, deliberately set apart from the other three. Those three apply to anyone launching into the EU. This one applies only if your site uses AI, and for a growing number of sites that condition is quietly met by a support widget, a translation layer or a content pipeline that nobody thinks of as an AI system.
That is the practical test, and it is a better first question than any checklist: walk your own site and ask, at each place a visitor meets text, an image or an answer, whether a model produced it and whether a person would be able to tell.
One honest note about what we do and do not check
We do not scan for the AI Act. Our scanner tests accessibility, and only the part of the WCAG AA criteria a machine can judge, in full or in part. The rest needs a person. That is a different law and a different obligation, and it is the other one from that checklist.
The reason we write about this one anyway is that it fails the same way. Both are rules where the visible work is a small part of it, both have an exemption that reads like an escape and turns out to ask for real effort, and both are easiest to meet at the moment you are already looking at your own site.
Different law, same starting point: look at what you can measure first.
Start the free accessibility scanFrequently asked questions
- Does this apply if my site uses no AI?
- No. Article 50 attaches to AI systems and to content generated by them. A site with no chatbot, no generated media and no generated text has nothing to disclose under it.
- Do I have to label a translation?
- It depends on who stands behind it. The duty is about text published to inform the public on matters of public interest, and it does not apply where the text has undergone human review or editorial control and a person holds editorial responsibility for it. A machine translation that someone with knowledge of the subject checked for substance, and that you publish under your own responsibility, sits inside that exemption. One that went straight to the page, or was only checked for spelling, does not.
- Is the AI Act not postponed?
- The high-risk obligations in annex III moved to 2 December 2027 through Regulation (EU) 2026/1744. The transparency rules in article 50 were not part of that and apply from 2 August 2026.
- What does a breach cost?
- That depends on the country. The regulation leaves the penalties to member states, so any figure you see quoted is national and worth a source.
- Is a banner saying we use AI enough?
- For a chatbot the information has to reach the person at the latest at the first interaction, so a disclosure somewhere else on the site is not where the rule points. For generated media the duty is a machine-readable mark on the output, which a banner cannot provide.
Sources
- Regulation (EU) 2024/1689 (AI Act), article 50 and recital 134: transparency obligations for providers and deployers of certain AI systems
- European Commission, FAQ on the transparency obligations under article 50 of the AI Act, including the reading of “matters of public interest” and the human review exemption
- European Commission, guidelines on transparency obligations for providers and deployers of certain AI systems
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689, Official Journal L series of 24 July 2026
- European Commission, the AI Omnibus enters into force on 27 July 2026, with the annex III high-risk rules applying from 2 December 2027
Correct as of 16 September 2026. This article is information, not legal advice. Wexlo scans websites for accessibility, which is a different obligation from the one described here, and is open about what automated testing does and does not see.