AI regulations: does your chatbot need to say it is an AI?
6 min read
On 2 August 2026 a set of rules on ‘labelling AI’ came into force in the European Union. The same day, a broadly similar law became operative in California, which had moved its own start date to match Europe's, so that companies selling in both places would not need two labelling systems.
These are narrow laws. They ban nothing, they say nothing about auditing models, and there is no form to file. They deal with labelling: telling people when they are dealing with software rather than a person, and marking material that software produced. Most of the technical work falls on the companies that build AI tools rather than the businesses that use them. But some of it does fall on users, and that is the part that gets missed.
The four situations
The relevant text is Article 50 of the EU AI Act, which deals with four things:
- Chatbots, voice assistants and anything else built to interact with a person directly. Whoever provides the system has to make sure the user knows they are dealing with software, unless it would already be obvious. An assistant that introduces itself as an assistant satisfies this. One designed to pass as a named member of staff does not.
- Tools that generate text, images, audio or video. The provider has to embed a machine-readable marker in the output so it can later be identified as machine-generated. This one belongs to the tool vendors. The visible effect for everyone else is that generated files increasingly arrive with provenance data attached to them.
- Emotion recognition and biometric categorisation. If you run either on customers or staff you have to tell the people involved. Few small companies do this on purpose, though it turns up inside some retail analytics and recruitment software.
- Deepfakes, and AI-generated text published on matters of public interest. Whoever publishes has to say the material was generated or manipulated, with an exception where a person has genuinely reviewed and edited it and taken responsibility for the result.
The Commission published guidance on all of this on 20 July, and there is a voluntary code of practice on marking generated content, with a standard set of icons, which tool vendors can sign. Fines for breaching Article 50 reach €15 million or three per cent of worldwide turnover, whichever is higher, with smaller companies liable for the lower figure rather than the higher one. Those are ceilings written for large providers behaving badly. Nobody has been fined yet.

Providers and deployers
The Act divides organisations into ‘providers’ and ‘deployers’. Most owners assume they are deployers, on the grounds that they did not build anything.
A deployer uses someone else's system under its own authority. A provider develops a system and puts it on the market under its own name or trademark. But, licensing a chatbot, putting your logo on it, naming it after your company and removing any sign of the vendor can make you the provider of that system, which shifts the labelling duty from the software company to you. White-labelling is how most of these products are sold, so this is ordinary rather than exotic. Checking your own site with the question in mind should only take about ten minutes.
If you are not in the EU
The scope is written around where the AI is used rather than where the company is registered. The Act covers providers, deployers, importers and distributors that put AI systems on the EU market, and anyone whose AI output is used inside the Union.
For a company in Brazil, Argentina or Canada the question is therefore not whether you have a European office, but whether you have any European customers or users. A Brazilian software firm with clients in Portugal is covered for that product. A Canadian retailer whose support chatbot answers customers in Ireland is covered for the chatbot. A Mexican business selling only to customers at home is not covered at all.
Anyone who went through GDPR will find the mechanism familiar, including the temptation to treat distance as protection. The requirements here are considerably lighter than GDPR's were.
The delay
In July the EU passed an amending regulation, the Digital Omnibus, which pushed back obligations for high-risk AI systems, the category covering uses like hiring and credit scoring. Standalone systems now fall due in December 2027 and embedded ones later. The reason was administrative rather than political: the technical standards companies were meant to comply against were not finished.
Article 50 stayed where it was. It contains one four-month extension, running to 2 December 2026, which applies only to the machine-readable marking of generative systems already on the market before August. That belongs to the vendors again. The user-side duties started in August.
Rest of the world
California's AI Transparency Act, SB 942 as amended by AB 853, applies to generative AI providers with more than a million monthly users in the state. It requires them to offer a free detection tool, an option to add a visible label, and a hidden provenance marker in generated images, video and audio. Duties for large platforms follow in 2027 and for camera manufacturers in 2028. For almost every reader this is a law about your suppliers, and the main reason to know about it, is that the tools you use are being rebuilt to comply with it.
Texas brought in a wider AI governance framework in January, with disclosure elements but no marking requirement. Brazil's Chamber of Deputies is still working through PL 2338, which the Senate passed in December 2024 and which borrows the European risk-based structure along with rights to transparency and explanation. It is not law and has no start date. Canada has no comprehensive federal AI statute yet: the bill that would have created one lapsed when Parliament was prorogued in early 2025, leaving sectoral rules and public sector directives in place.
The regulatory map will stay patchy and uneven for years. Where these frameworks agree, is on the labelling question, that people should be told when they are dealing with AI, or looking at something AI produced.
What to do
For most small companies this is at most one or two hours of work.
List every AI system that touches a customer or an employee, including anything a marketing agency or contractor bought on your behalf. Establish whose name is on each one, since that determines whether you are a provider or a deployer. Check that anything conversational identifies itself as software in its first message, which costs nothing and removes most of the exposure. Ask your vendors in writing how they mark generated content and whether they have signed the European code of practice, then keep the replies. Decide your own line on labelling AI-assisted marketing material and hold to it.
There is also an older requirement that tends to get overlooked. Since February 2025 the EU has expected companies providing or using AI to maintain a reasonable level of AI literacy among the staff who work with it. There is no certificate and no register. A single internal session satisfies it, and if you have never held one there is nothing to point to.
Enforcement, and customers
Regulators are not the near-term risk. The enforcement structures are new, and attention will go to large AI tool providers first, so a five-person company in Belgium or Chile is not really high on anyone's list. The likelier problem is a customer working out for themselves that the email, the case study or the support agent they were dealing with was AI generated, and then wondering what else they were not told.
Which is roughly what the labelling rules ask for anyway, so companies that already say when AI is involved have little to change. But the error in the other direction is worth watching too. Labelling everything, including work a person actually did, is its own way of misleading people, and it is becoming a habit at firms that are nervous about the subject.
This is a general explanation, not legal advice. If you sell into the European Union and use AI in customer-facing work, it is worth a short conversation with a lawyer in the relevant jurisdiction.
