The EU AI Act is now hitting the tools you actually use: as of August 2026, AI systems in Europe must tell you when you’re talking to a machine, and by December 2026 AI-generated content must be machine-readably marked — while the law’s strictest rules just got pushed back to late 2027 and 2028. If you’ve seen headlines swinging between “the AI crackdown is here” and “Brussels caves on AI rules,” both are sort of true. Here’s the plain-English version: what’s in force, what got delayed, and what any of it changes for a normal person or a small business — including one outside the EU.
The 60-second version of the law
The AI Act, in force since August 2024, sorts AI by risk rather than regulating “AI” as one thing:
- Banned outright (since February 2025): social scoring by governments, AI that manipulates people into harm, scraping the internet to build face-recognition databases, emotion recognition on employees and students, and similar practices.
- General-purpose AI models — the GPT, Claude, and Gemini class — have had transparency and copyright obligations since August 2025.
- Transparency rules for AI that interacts with people or generates content — this is the August 2026 tranche, and the part you’ll actually notice.
- High-risk systems — AI used in hiring, credit, insurance, education, medical devices — face the heaviest requirements: risk management, human oversight, audits. These were due in 2026–27 and are the part that just got delayed.
What just changed: the Digital Omnibus delay
Under industry and member-state pressure, the EU passed a package amending the Act — the “Digital Omnibus on AI,” which entered into force on 27 July 2026. The headline change: high-risk obligations are postponed. Stand-alone high-risk systems (the hiring and credit-scoring class) now have until 2 December 2027; AI embedded in regulated products like medical devices and cars gets until 2 August 2028.
What the Omnibus did not touch: the bans, the general-purpose model rules, and the transparency obligations. Those stay on schedule.
What’s actually in force now (and what you’ll notice)
The August 2026 transparency rules — Article 50, if you want to sound informed — boil down to four things:
- Chatbots must disclose they’re AI. If it isn’t obvious, a bot talking to customers in the EU has to say so. The “human” sales agent that types suspiciously fast now needs a label.
- Deepfakes must be labeled. AI-generated or manipulated images, audio, and video of real people and events must be disclosed as such.
- AI-generated content must be machine-readably marked. Providers of generative systems must watermark or otherwise mark output so software can detect it’s synthetic — with a compliance deadline of 2 December 2026 for the technical marking requirement. This is the rule behind the watermarking moves we covered in Claude is about to watermark your drafts.
- Emotion recognition and biometric categorization systems must inform the people exposed to them.
For everyday users, the practical effect is more labels: “AI” badges on chat widgets, disclosure lines on synthetic videos, and invisible watermarks in generated text and images. It won’t make deepfakes disappear — bad actors don’t follow labeling law — but it makes honest platforms distinguishable from dishonest ones, which also matters if you’re teaching kids what to trust online (our guide on how to talk to your kid about AI pairs well with this).
What it means for a small business
If you sell to EU customers, even from the US:
- Using AI tools internally — drafting, coding, analysis — triggers nothing. The obligations fall overwhelmingly on the companies building the AI, not on you for using ChatGPT to write a newsletter.
- A customer-facing chatbot needs a disclosure. If your site’s support widget serves EU visitors, add a plain “You’re chatting with an AI assistant” line. Most chatbot vendors now ship this by default — check that it’s on.
- Publishing AI-generated media? Label synthetic images and video of realistic people or events. Marking obligations for the raw output sit with the tool vendors, but the deployer-side disclosure is on you.
- Using AI in hiring or credit decisions? You just got breathing room until December 2027 — but the direction of travel is clear, so choose vendors who are preparing for it.
And your website is already talking to AI whether you label anything or not — half your traffic may be bots reading you for chatbots’ benefit. Our guide on feeding AI visitors without ruining your site covers that side.
Honest caveats
- Enforcement is the open question. Rules on paper since August don’t mean inspectors at the door. Expect enforcement to start with big platforms and egregious cases, not your bakery’s chatbot.
- The delay may not be the last one. The high-risk deadlines moved once under pressure; they could move again. Treat every future date here as “reported as of this writing.”
- Watermarking tech is immature. The law mandates machine-readable marking by December; robust, unstrippable watermarks — especially for text — remain genuinely hard. Expect a messy first year.
- This is a summary, not legal advice. If AI touches hiring, credit, health, or minors in your business, spend the money on an hour with a lawyer.
The bottom line
The EU AI Act’s scary parts got postponed; its visible parts just arrived. For most people it means more honesty labels on AI, and for most small businesses it means one disclosure line on the chatbot and some vendor due diligence — not a compliance project. The companies with real work to do are the ones building AI, and they’ve known for two years.
Related reading: Claude is about to watermark your drafts — what that actually means · Half your visitors are now bots — how to feed them without ruining your site · How to talk to your kid about AI without turning it into a lecture
Share this article

Leave a Reply