AI Act, August 2026: what actually applies to an SME that uses an assistant
Since 2 August 2026, transparency rules apply. Not a full compliance programme. Here is what changes if you already have a chatbot, an agent, or AI-generated content, and what can wait.
· 6 minute read
Short answer: since 2 August 2026, an SME that lets an AI speak to a customer must say so clearly. Some synthetic content must be identifiable. Most heavy obligations for so-called high-risk systems are deferred to December 2027.
The AI Act (EU Regulation 2024/1689) does not apply all at once. What changes in August 2026 is mainly Article 50: transparency obligations, plus AI literacy already required since February 2025. Here is what that means in practice for an SME that already runs an assistant or publishes generated content.
1. Definition: what is Article 50?
Article 50 of the AI Act sets transparency obligations for certain AI systems: tell a person they are interacting with AI; mark or disclose certain generated or manipulated content (including deepfakes); disclose emotion recognition or biometric categorisation where applicable.
It is not a certification and not a multi-hundred-page file. It is an information rule. In France, DGCCRF and Arcom mainly oversee chatbots and synthetic content; CNIL is more involved for emotion recognition and biometric categorisation.
2. Who is in scope now, and who is not
You are likely in scope if: a chatbot or agent answers your customers (website, WhatsApp, phone, support); you publish realistic AI-generated or manipulated images, audio or video; you publish AI-generated text to inform the public on a matter of public interest without assumed human editorial control.
You are probably not in the 2026 high-risk workstream if you do not use AI for automated hiring, credit scoring, access biometrics, or other listed high-risk cases. Those obligations have largely been deferred to 2 December 2027.
Using ChatGPT or similar internally to draft an email, a product sheet or a LinkedIn post that a human reviews does not, by itself, usually trigger Article 50 transparency duties aimed at the public.
3. If you have a customer-facing chatbot or agent
Simple rule: from the first interaction, the person must understand they are talking to AI, unless that is already obvious from context. A clear opening message is often enough. Labelling the bot as « team » or « advisor » with no clarification is not.
What we see in audits: the tool shipped fast, the opening copy was never re-read, and visitors may think they are talking to a human. Five minutes of review fixes half the cases.
Machine-readable marking of generative outputs mainly sits with system providers. If you buy a market tool, check what it already offers; an SME usually should not reinvent watermarking.
4. If you publish AI-generated content
Not every AI-assisted text needs an « AI-generated » stamp. The duty mainly targets deepfakes (image, audio, video) and certain generated or manipulated texts published to inform the public on a matter of public interest, with an exception when a human exercises real editorial control and takes responsibility for publication.
Content generated before 2 August 2026 does not need retroactive labelling. For systems already placed on the market before that date, technical output marking has a provider-side grace period until 2 December 2026.
5. AI literacy: what it means in practice
Since 2 February 2025, any organisation that uses AI systems must ensure staff have a level of understanding suited to their uses (Article 4). There is no mandatory certified course and no fixed hour count.
In practice: a short, dated briefing tailored to what your teams actually use, with a trace (materials, attendance list). Doing nothing at all becomes an aggravating factor in a control or a dispute tied to AI use.
6. AI Act, GDPR and answer reliability: three different topics
AI Act (transparency, August 2026): say when someone is talking to AI; disclose certain content.
GDPR: what you send to the model, where it goes, who can access it. That does not go away because the AI Act exists.
Reliability: an assistant on inconsistent data answers wrongly, confidently. No regulation replaces a sound data foundation and an explicit scope. That is engineering, not cosmetic compliance.
7. Five-point checklist
1. List where an AI already speaks to someone outside the company (site, messaging, phone, support).
2. Check that this is stated clearly from the first exchange.
3. List realistic content (image, audio, video, public-interest text) published without assumed human review.
4. Keep a dated trace of awareness training for teams that use AI tools.
5. Do not start a high-risk programme if you are not in those cases. The calendar largely gives you until late 2027.
What this changes in practice
For most SMEs, August 2026 is not a regulatory tsunami. It is a reminder: if an assistant talks to your customers, say so; give AI-using teams a minimum briefing and keep the trace; do not confuse transparency, data protection and answer reliability.
Reliability comes before the model: first a usable data foundation and a clear perimeter, then the conversational layer.
Already running an assistant in production?
Thirty minutes is enough to review your real contact points: chatbot, content, data sent to the model. Separate what is urgent from what can wait.