Skip to main content
All resources

From 2 August you have to tell customers they are talking to an AI

On 2 August 2026 the transparency obligations of article 50 of the EU AI Act start to bite, and most of what is being written about them is wrong: the Digital Omnibus — adopted by the European Parliament on 16 June and by the Council on 29 June 2026 — postponed the obligations on high-risk systems (Annex III to 2 December 2027, Annex I to 2 August 2028), not article 50. What the rule says paragraph by paragraph and, above all, who it binds: paragraph 1 falls on the provider, paragraph 4 on you, the deployer. The “unless this is obvious” exception, and the decisive one for text that has been through human editorial review with a named person responsible. The real arithmetic of the fines: article 99 runs up to 15 million or 3% of worldwide turnover, but for an SME paragraph 6 sets the cap at the lower figure — the 3%, not the 15 million everyone quotes at you. And the part almost nobody writes: disclosing AI costs nothing in itself, what costs is the timing and the framing of the disclosure — Luo's field experiment (2019, over 6,200 customers, purchases down more than 79.7% if you disclose before the interaction, the effect softened if you disclose after), the task dependence in Castelo (2019), the counter-evidence in Logg (2019) and the joint human-plus-AI framing in Ulqinaku (2025). With the AGCM investigations into DeepSeek, Mistral and NOVA AI closed with commitments on disclaimers, Legislative Decree 145/2007 for B2B claims, the Klarna case on automation promised and then walked back, and the list of what to do before 2 August.

Compliance 11 min read
Written by the Innesti Digital team
In this article

There is one date to get into the diary right now: 2 August 2026. From that day, across the Union, an AI system that talks to people has to make itself known as one, and certain machine-made content has to be declared for what it is. This is article 50 of the EU AI Act, the transparency chapter. Almost everything you will read about the deadline is wrong, and for one specific reason: over the past few weeks the Union did move some AI Act deadlines, and half the commentary concluded that all of them had moved. They did not.

The postponement is real — it just does not touch this deadline

The Digital Omnibus on AI was adopted by the European Parliament on 16 June 2026 and by the Council on 29 June 2026. What it pushed back are the obligations on high-risk systems: Annex III to 2 December 2027, Annex I to 2 August 2028 (Gibson Dunn analysis). Article 50 is not on that list: it sits in Chapter IV, which article 113 does not carve out, so it applies from the regulation's general date (a precise reconstruction). Translated: the heavy obligations have moved further away, the ones your customer can see have not.

The reverse holds too, for the other alarm being raised out of context: article 14 on human oversight binds only the high-risk systems in Annex III. If someone tells you that from 2 August you have to document human supervision of every use of AI, they are selling you something. To work out which risk tier the AI you use falls into, there is the dedicated piece on what changes (and what does not) with the EU AI Act for SMEs; here we stay on transparency.

What article 50 actually says, paragraph by paragraph

The article is short, and its structure matters more than its wording: each paragraph speaks to a different party. Confusing them is why so many companies end up worrying about the wrong thing.

Paragraph 1 — the chatbot has to declare itself, but the duty is the provider's

The text requires providers to design systems intended to interact directly with natural persons so that those persons are informed they are interacting with an AI system, unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person, taking into account the circumstances and the context of use. Note the subject: provider. You bought the chatbot on your site — but the customer talking to it sees you. Your exposure runs down three roads: paragraph 4; your contract with the provider; and Italian law on commercial practices, further down.

Paragraph 2 — marking synthetic content

Providers of generative AI have to mark synthetic outputs — audio, images, video, text — in a machine-readable format, detectable as artificially generated or manipulated; for systems already placed on the market before 2 August 2026 the duty starts on 2 December 2026. The weight sits upstream, but the consequence for you is concrete: from the end of the year a growing share of what you publish will carry a technical marker with it, and detectability will no longer depend on you saying so.

Paragraph 4 — this is the one that is about you

Here the subject changes: it is the deployers, whoever uses the system. Two duties:

  • deep fakes have to be disclosed — image, audio or video content, artificially generated or manipulated, depicting people, places or events in a way that appears authentic;
  • AI-generated or manipulated text has to be disclosed when it is published to inform the public on matters of public interest.

And two exceptions that weigh as much as the duties. The first covers artistic or creative works. The second touches most companies: text that has been through human editorial review, with an identified person or entity holding editorial responsibility for it, needs no disclosure.

It is the most operational exception in the whole article. The rule is not asking you to stop writing with AI: it is asking you to put a name on top — and an editor who genuinely reviews is at once the compliance and the reason the text will be better.

Two short paragraphs are left. Paragraph 5 fixes manner and timing: the information must be clear and distinguishable, at the latest at the time of the first interaction or exposure — an outer limit, not a placement instruction, and we will come back to it. Paragraph 6 closes a door: these duties do not replace Chapter III or the other transparency rules.

The “unless this is obvious” exception: what it really means

This is the clause companies kid themselves about most. “Obvious” is not measured from your point of view: the yardstick is the reasonably well-informed, observant and circumspect person, dropped into the actual context. A chat window with a human name, an avatar and fluent writing is not an obvious case — the context is actively suggesting there is a person on the other side; a widget labelled “virtual assistant” is. The harder the interface works at seeming human, the less you can lean on the exception: if you are wondering whether it is obvious, it is not.

In practice: chatbots, AI-written posts, generated images

  • Chatbots on your site or on WhatsApp. The notice has to exist, be live and appear before the first exchange — not in the footer, not in the terms of use. Ask your provider, in writing, how they satisfy paragraph 1: that is a perfectly legitimate contractual question. And make the handover from bot to person visible: the case a customer remembers badly is the one where they worked it out for themselves.
  • Articles written or polished with AI. If they inform the public on matters of public interest, either you disclose them or you run them through human editorial review with a named person responsible. A “how we work on content” page, with the name and role of whoever reviews, is worth a hundred disclaimers.
  • Generated images or video. They have to be disclosed if they depict people, places or events in a way that appears authentic. An abstract cover illustration is another matter: the rule is chasing believability, not generation as such.

The fines: for an SME the cap is the lower figure, not the higher one

The number people will wave in your face is 15 million euro. It comes from article 99, paragraph 4: for breaches of provisions other than article 5 — and article 50 belongs here — fines run up to 15 million or, for an undertaking, up to 3% of total worldwide annual turnover, whichever is higher. Anyone who stops there is giving you half the rule: paragraph 6 says that for SMEs and start-ups each fine runs up to the percentages or the amount in paragraphs 3, 4 and 5, whichever is lower. The test flips: the cap is not the greater of the two figures, it is the smaller one — in practice 3% of turnover, not the 15 million.

It is the most useful fact in the whole affair, and the one almost nobody will hand you: the headline figure is calibrated for Big Tech, your risk is proportionate to your size. Which moves the question from panic to design: not “how much am I risking”, but how do I disclose this without losing customers.

Does disclosing AI cost you customers?

A business owner's real objection is not the fine: it is the suspicion that writing “you are talking to an AI” sends people running. The suspicion is well founded — and the research says something rather more precise than yes or no.

The evidence everybody cites badly (Luo and colleagues, 2019)

The reference study is “Machines versus Humans: The Impact of AI Chatbot Disclosure on Customer Purchases” (Luo, Tong, Fang and Qu, Marketing Science 38(6), 2019): a field experiment, over 6,200 customers, outbound sales calls. Undisclosed chatbots converted as well as the best human sellers; saying “I am a bot” before the interaction made purchases collapse by more than 79.7%. Half the market stops reading here. The second half, which nobody passes on: the effect was softened when the disclosure came late, once value had been established, and when the customer was already familiar with AI. It is not transparency that costs you, it is where you put it.

One caveat is owed, and I will make it once: the setting is real-time telephone selling to consumers. The mechanism — placement and framing matter enormously — carries across; the magnitude does not, and should not be assumed to be yours.

It depends on the task — and sometimes it reverses (Castelo 2019, Logg 2019)

Castelo, Bos and Lehmann (Journal of Marketing Research 56(5), 809-825) show that algorithm aversion depends on the task: people trust algorithms less on tasks they read as subjective — judgement, taste, ethics — and as much or more on tasks they read as objective. And perceived objectivity is malleable: it shifts with framing and with demonstrated performance.

It would be convenient to stop there, but there is an opposing strand, and an article that keeps quiet about it is selling you a thesis. “Algorithm Appreciation” (Logg, Minson and Moore, OBHDP 151, 90-103, 2019) documents across six experiments that lay people followed advice presented as algorithmic more than the same advice attributed to a human source, especially on numerical, objective tasks. The two literatures interlock: on a task read as objective, saying an algorithm is involved raises trust; on one read as subjective, it erodes it.

Human plus AI holds up better than “AI only” (Ulqinaku and colleagues, 2025)

The last piece comes from Ulqinaku and colleagues (Psychology & Marketing, 2025): aversion is lower under a joint framing, human plus algorithm, than under a pure-algorithm one — which is how most SMEs work anyway, with a machine that prepares and a person who decides. And there is one more reason not to present yourself as “fully automated”: Dietvorst, Simmons and Massey (JEP: General 144(1), 114-126, 2015) show that after a mistake people lose confidence in an algorithm faster than in a human, even when the algorithm is better on average.

The thesis of this article: transparency is not the cost — the cost is transparency badly placed. A cold, pre-emptive declaration, fired off before the customer has grasped what they are getting, is the expensive version. The same declaration, clear and distinguishable, put where the value is already obvious and framed as “person plus machine”, is the one that costs you nothing. The rule sets the first interaction as the outer limit: inside that limit, the design is yours.

In Italy, enforcement is not waiting for the AI Act

Anyone who thinks nothing happens before 2 August has not been watching the AGCM, Italy's competition and consumer authority. It has opened unfair-commercial-practice investigations into DeepSeek, Mistral AI and Scaleup's NOVA AI chatbot, closed with commitments providing for prominent, contextual disclaimers about the reliability of AI-generated content (a reconstruction of the three cases, May 2026). Two words there deserve attention, the same two as in paragraph 5: prominent and contextual — not buried in the terms of use, not at the bottom of the page. The Italian direction of travel is already legible, using an instrument that has been on the books for years and is fully operational.

If your customer is another business: Legislative Decree 145/2007

If you sell to businesses, consumer protection is not your perimeter, but you are not uncovered: Legislative Decree 145/2007 on misleading and comparative advertising covers B2B and is enforced by the same AGCM. A statement about how automated your service is amounts to an advertising message, and if it overstates what the machine really does, that is the ground it gets fought on. One warning, and I will make it once: no precedent is known that applies Legislative Decree 145/2007 to a claim about an AI system's level of autonomy. That is a reasoned inference, not a ruling.

The opposite risk: promising more automation than you have

There is a mirror-image risk, and it costs just as much: claiming more automation than you can sustain. The best-documented case is Klarna: between 2024 and 2025 it cut around 700 roles in customer support and replaced them with AI — 2.3 million chats handled by AI in a month, average resolution under two minutes. In 2025 it reversed course over quality and satisfaction, and CEO Sebastian Siemiatkowski admitted as much:

“We focused too much on efficiency and cost... The result was lower quality.”
Sebastian Siemiatkowski, CEO of Klarna (Forbes, a reconstruction of the case)

The end state was not a return to humans but a hybrid model: AI on routine requests, escalation to a person — exactly the joint framing the research points to as the sturdiest, only reached the long way round. The disclosure that holds up over time is the accurate one: under-declaring AI is a regulatory risk, over-declaring it is a reputational one and, in B2B, potentially an advertising one.

What to do before 2 August

You do not need a compliance project. You need one afternoon, worked through in order:

  1. Inventory your AI touchpoints — chatbot, WhatsApp autoresponder, automated emails, blog, social images, product descriptions — with the provider's name against each. Ask every one of them, in writing, how they satisfy paragraphs 1 and 2: if they cannot answer, you have learned something worth more than this deadline.
  2. Check where the notice appears: clear and distinguishable, at the latest at the first interaction. The footer is not the first interaction.
  3. Decide your route for text — disclosure, or human editorial review with a named person responsible. Choose, put it in writing, and make sure it is true.
  4. Go back over your images and video: do they depict people, places or events as though they were authentic? Then they have to be disclosed.
  5. Reread what you promise about automation and line it up with what the system actually does. If the process is hybrid, say so: it is also the framing that converts best.
  6. Put 2 December 2026 in the diary for the marking of generative systems already on the market: it is the second half of the same deadline, and it goes unmentioned.

The right way to read all this is not as a box to tick. On 2 August disclosure becomes mandatory for everyone: from that day it stops being a differentiator and becomes the floor. The window in which it still buys you something is now, and it is the difference between whoever designs their own transparency — where to place it, how to frame it, with which person alongside — and whoever, come August, pastes a legal notice written by somebody else at the bottom of the page. The research is reasonably clear about which of the two will lose customers.

This article is purely for orientation and does not constitute legal advice or a compliance assessment. The references to articles 50, 99 and 113 of the EU AI Act and to the postponement of the high-risk obligations decided by the Digital Omnibus reflect the text consulted on 27 July 2026 and should be re-checked against the text in force. The experimental evidence cited comes from specific research settings and does not transfer automatically to your market. For your concrete obligations, refer to the regulation, to the competent authorities and to qualified legal support.

Compliance Written by the Innesti Digital team

Every resource grows out of the research we do for SMEs and the products we build ourselves: cited sources, a method we state openly, no claim you cannot check.

The sources are cited in the text. We encourage you to always check them directly at the original source.

Put it into practice

Where this analysis becomes work.

From theory to your business. We graft AI in.

Want to know which department to start from in your company? The free assessment gives you a first answer in two minutes — then, if it makes sense, we talk.

We use cookies

We use cookies and similar technologies to improve your experience, analyse traffic and personalise content. You can accept all cookies or customise your preferences.

Cookie preferences

Necessary cookies Always on

Essential for the site to work. They cannot be disabled.

They help us understand how you use the site so we can improve your experience.

Used to show you relevant ads and measure campaigns.

They let us personalise content and features.