← Blog
  • regulation
  • ai
  • transparency

From 2 August your chatbot has to say that it's an AI

7 min read

The high-risk rules slipped to 2027, but transparency didn't: from 2 August your chatbot must say it's an AI. What that means in practice, and what it doesn't.


For two years the EU AI Act has been something that was going to happen. As of 2 August 2026, it's happening. The one part of that law that genuinely touches an ordinary small business — transparency — is now enforceable, and unlike almost everything else in the Act, it wasn't postponed. The good news: complying is an afternoon's work at most. Here's what it actually requires, the wording that satisfies it, and the parts you can safely ignore.

What applies now, and what slid to 2027

The EU's simplification package (the Digital Omnibus on AI) is published and it moved a lot of dates. Not all of them. The honest state of the calendar:

  • Transparency (Article 50): applies from 2 August 2026. No extension.
  • Standalone high-risk systems (Annex III): pushed to 2 December 2027.
  • High-risk AI embedded in regulated products (medical devices, machinery — Annex I): 2 August 2028.
  • Prohibited practices and AI literacy: already applicable since February 2025.

That high-risk delay grabbed the headlines and left a lot of owners with the impression that "the AI Act got postponed". It didn't. What got postponed is the heavy end — technical files, conformity assessment, CE marking — which rarely applies to a small business anyway. The light end, telling customers they're talking to a machine, landed exactly on schedule.

One more thing that happens on the same date: member states were required to have their market surveillance authorities designated, with powers to inspect and fine. In Spain that's primarily AESIA, working alongside the data protection authority and sector regulators, though the national law setting the exact penalty regime is still going through parliament. Most member states are behind on this. Practical translation: nobody is knocking on your door on Monday, but the machinery now exists.

What your agent has to say

Article 50 asks for something fairly reasonable. If you run an AI system that talks to people, those people need to know they're talking to an AI — and they need to know it up front, not ten messages in.

No legalese required. Clarity required. On WhatsApp, this already does the job:

Hi, I'm the virtual assistant for Duero Clinic. I can help with appointments and questions — and if you'd rather speak to someone on the team, just say so.

Notice what that line does: it says it's an assistant, says what it's for, and offers a way out to a human. The last part isn't a legal requirement, but it's what stops the disclosure from feeling like a door slamming.

Where it goes, channel by channel:

  • WhatsApp or Instagram: in the first message of every new conversation. If a thread reopens weeks later, say it again.
  • Website chat: in the opening greeting, and ideally in the widget header too, where it's always visible.
  • Voice agent: spoken aloud in the greeting, before you ask anything. A notice on your website is worthless to someone on the phone.
  • Automated email: if the agent drafts and sends replies on its own, one line at the foot ("This reply was generated by our automated assistant — reply to this email to reach a person").

"But the AI isn't mine, it's my vendor's"

This is the bit almost everyone misses, and it's the one worth understanding properly.

The duty to disclose falls on whoever puts the system out there under their own name. If the bot on your site carries your logo, your tone of voice and your trading name, then as far as the law is concerned you're the one offering it — even though a third party's technology is doing the work underneath. You can't assume your vendor has you covered.

What you can do, and it costs one email:

  1. Ask whether the AI disclosure is on by default or has to be switched on.
  2. Check it's still there after you edit the welcome message. This is the classic failure: someone rewrites the greeting for a promotion and takes the disclosure with it.
  3. Ask about machine-readable marking of generated content. The Act requires AI-generated output to be detectable as such in a machine-readable format. That specific obligation has breathing room until 2 December 2026 for systems already on the market, and in practice it depends on your model provider, not on you. Ask anyway, and keep the answer in writing.

The part nobody checks: images, video and voices

Transparency isn't only about chatbots. If you publish AI-manipulated content that resembles real people, places or events — a deepfake, in plain English — you have to label it.

That sounds remote until you bring it down to earth. Real small-business examples:

  • A shop generating "model" photos wearing its own products for the catalogue.
  • A restaurant cloning the owner's voice for social media audio.
  • An estate agent digitally furnishing an empty flat and posting it as if it were the real photo.

In those cases a visible note does it: "Image generated with AI". It won't wreck the campaign. In plenty of sectors it makes it more credible, not less.

And a third category, far less common but worth naming: if you use emotion recognition or biometric categorisation — in-store cameras analysing faces, say — you have to inform the people affected. Note also that using emotion recognition on your own staff has been outright prohibited since February 2025. No disclosure makes that one legal.

When this doesn't apply to you

Knowing where to stop matters as much as complying. Cases where you owe nothing:

  • You use ChatGPT to draft an email and send it yourself. You're not operating a conversational system facing a customer, you're using a tool. Article 50 doesn't bite.
  • It's obvious from context. The Act waives the notice where it would be evident to a reasonably attentive person. That said, don't lean on this exemption — it's arguable, and saying it costs one sentence.
  • Your agent isn't high-risk. Booking slots at a salon, answering delivery questions or qualifying leads is nowhere near Annex III. You need no technical file, no CE marking, no AI compliance platform. If someone is selling you that for a booking bot, they're selling you air.
  • Don't turn the notice into a legal wall. I've seen bots that open with a paragraph of terms and a privacy policy link. One clear sentence complies just as well — and one clear sentence doesn't scare the customer off.

Ten minutes, today

Pick up your phone and actually do this:

  1. Message your own business WhatsApp as if you were a new customer. Does the first reply say it's a virtual assistant? If not, fix it today.
  2. Repeat on the website chat, and if you have a phone agent, call it.
  3. Add an explicit human escape hatch to the greeting ("say 'human' and I'll pass you to the team").
  4. Review the AI-generated photos and videos you've already published, and label anything depicting real people or real spaces.
  5. Send that email to your vendor: disclosure by default, content marking, confirmed in writing.
  6. Spend fifteen minutes explaining to your team what the agent does and doesn't do. The AI literacy obligation has been in force since 2025, and this is how you meet it — by talking, not by buying a course.

If you'd rather see it built in from the start, our virtual receptionist opens every conversation by identifying itself, with a handover to a person one message away. Not because Brussels says so — because a customer who knows what they're talking to asks better questions and gets annoyed far less often.

Official sources worth checking yourself: the European Commission's AI Act FAQ and the Code of Practice on transparency of AI-generated content.