All writing
7 October 2026Product, 5 min read

What the EU AI Act asks your website to say

The transparency rules apply since August 2026. Most of them come down to a few honest sentences in the right places.

Visar IsufiFounder

When people hear “EU AI Act”, they think of risk classes, conformity assessments and large AI labs. Most of that does not touch an ordinary company website. One part does, and it applies since 2 August 2026: the transparency rules in Article 50.

I spent a lot of time with these rules while designing Euvalid, a scanner that checks what a website says about its use of AI. This is the plain version. It is not legal advice, and the details of your own setup are worth checking with someone who knows your case.

The short version

Article 50 is about one idea: people should know when they are dealing with AI. On a website, that usually shows up in three places.

A chat that is run by AI should say so.

Images, audio or video that are generated or manipulated by AI and look real should be disclosed.

Content generated by AI systems should carry a machine-readable marking, so software can recognise it.

None of this bans anything. It asks for honesty in the places where people could be misled.

Chat widgets: tell people it is AI

If a visitor talks to an AI system, they have to be informed that it is an AI, unless that is already obvious from the situation. This duty sits with the provider of the AI system, but the place where visitors actually see it is your website.

In practice, a lot of support chats look exactly like a human conversation: a name, a friendly photo, a typing indicator. If an AI is answering, a short and visible line at the start of the conversation solves it. “You are chatting with an AI assistant” is enough. A sentence hidden in the terms and conditions is not the point of the rule.

Generated images and video: say what is real

Deployers who publish AI-generated or manipulated images, audio or video that resemble real people, places or events have to disclose that the content is artificial. This is the part of the rule usually described as deepfakes.

There is room for creative work. Clearly artistic, satirical or fictional content only needs a disclosure that does not ruin the work. A product render that nobody would mistake for a photograph of a real event is a different situation from a realistic photo of a person who never existed.

AI-written text has its own rule. Text published to inform the public on matters of public interest has to be disclosed as AI-generated, unless a person has reviewed it and someone takes editorial responsibility for it.

Machine-readable marking: the part with a later date

Providers of generative AI systems have to mark the content those systems produce in a machine-readable way, so it can be detected as AI-generated. For systems that were already on the market before 2 August 2026, there is a transition period for this duty until 2 December 2026.

This is mostly a responsibility of the companies that build the AI models and tools. For a website owner, the practical question is simpler: do the images you publish keep the markings your tools add, or does your workflow strip them out? Standards such as C2PA Content Credentials exist exactly for this.

Why this matters more than it seems

A breach of the transparency rules can be fined up to €15 million or 3% of worldwide annual turnover, whichever is higher. Large fines are unlikely to be the first thing a small business meets. But visibility is.

Customers, journalists and competitors can see a website. An AI chat that pretends to be human, or a generated “customer photo” on a landing page, is exactly the kind of thing that gets noticed. The reputational cost arrives long before any regulator does.

A simple checklist

Look at your website the way a visitor does.

Is there a chat? If an AI answers, does the conversation say so at the start?

Are there realistic images, voices or videos that were generated or heavily changed by AI? Is that disclosed where people see them?

Do you publish AI-written articles on public topics without human review? If so, are they labelled?

Do the generated images you publish still carry their content credentials?

If the answer to all four is yes, you are most of the way there.

Why we built Euvalid this way

When we designed Euvalid, the brief was not to scare companies into compliance. It was to make the honest version easy. The scanner reads a page the way a visitor would, shows what it finds and what it cannot confirm, and points to the smallest fix. A disclosure can be added with one script tag, and the result can be checked again on a schedule.

Transparency is not a legal burden dressed up as design. It is good design that the law now writes down.