The EU Started Enforcing Mandatory AI-Content Labeling on August 2. If Your Product Talks to EU Users, You're Already Non-Compliant or You Got Lucky.
On August 2, 2026, the European Commission's AI Office and national market surveillance authorities started enforcing a new set of AI Act transparency rules. Chatbots and interactive AI systems now have to tell users they're talking to a machine, not a person. Deepfakes need labels. AI-generated or AI-altered content needs machine-readable marks. I've spent the last few days reading the actual regulation text instead of the takes about it, and the part that should get a solo operator's attention isn't the requirement list: it's who it applies to. Spoiler: probably you, if any of your signups come from the EU, regardless of where your company is registered.
What actually started on August 2
This is Article 50 of Regulation (EU) 2024/1689, the AI Act's transparency chapter, and it's been on the calendar since the regulation entered into force back in 2024. The Commission's own August 2 announcement lays out three concrete obligations. Providers of AI systems that interact directly with people (chatbots, voice assistants, AI agents) have to make it clear the user is dealing with AI, not a human. Providers and deployers of systems that generate or manipulate audio, image, or video content that resembles real people, places, or events (the "deepfake" category) have to label that content. And providers of systems generating AI content more broadly have to attach machine-readable marks so the content can be identified as AI-generated after the fact.
The disclosure bar is stricter than it sounds. Legal guidance on Article 50 that's circulated ahead of this date is consistent on one point: burying "you're chatting with a bot" in your terms of service doesn't satisfy the rule, and neither does a vague label like "assistant" in your UI copy. The disclosure has to be perceivable in the interaction itself: visible, at the point of contact, before or as the conversation happens.
Enforcement sits with the AI Office at the EU level and national market surveillance authorities in each member state, alongside the European Data Protection Supervisor for EU institutions. Penalties for Article 50 violations top out at €15 million or 3% of global annual turnover, whichever is higher, with a lower ceiling that applies specifically to SMEs and startups. The Commission also published a list of more than 180 organizations that have already signed onto its voluntary Code of Practice on transparency of AI-generated content: proof this isn't a rule that snuck up on anyone paying attention.
Where your company is incorporated doesn't matter
Here's the claim worth being precise about, because it's the one most solo operators get wrong. I went to the regulation's actual scope article (Article 2 of Regulation 2024/1689) rather than trust a summary. Article 2(1)(c) states plainly that the regulation applies to providers and deployers "that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union." Article 2(1)(g) extends coverage to "affected persons that are located in the Union": meaning the people on the receiving end of your product, not your company's mailing address, are what triggers scope.
Translate that: a one-person SaaS incorporated in Ohio, with a chatbot widget and EU users signing up through your marketing site, meets the Article 2 test the same way a Berlin-based team does. Nobody checks your Companies House or Delaware filing before this applies. What matters is whether output from your AI system reaches someone sitting in the EU. If you've got EU signups (even a handful) and an undisclosed chatbot or an AI image generator with no labeling, you're inside the rule as written, not adjacent to it.
I want to be careful here, because this is a legal conclusion and I'm not a lawyer. The territorial-scope language in Article 2 is unambiguous on the text, and I'm reading it straight off the regulation rather than a paraphrase. But how a specific solo operator's setup maps onto "provider," "deployer," or "affected person" in a contested case is a question for someone who bills by the hour, not a blog post.
The gap between "the rule applies" and "someone's coming for you"
The honest complication is enforcement capacity. The AI Act's prohibited-practices provisions (social scoring, untargeted facial-recognition scraping, emotion inference in workplaces) have been enforceable since February 2, 2025, and the public enforcement actions and guidance that have followed have clustered around high-risk categories: biometrics, critical infrastructure, large-platform content systems. I found no public record, as of this week, of a national authority bringing an Article 50 transparency action against a small non-EU SaaS operator. That's not surprising three days into a new enforcement window, and it's consistent with how new EU tech regulation usually rolls out: big, visible targets first.
But "no one's enforced it against operators our size yet" and "we're not required to comply" are different sentences, and it's easy to accidentally swap one for the other. Article 50 doesn't carve out an exemption for company size: the SME accommodation shows up in the penalty ceiling, not in whether the obligation applies to you at all. Low enforcement priority today is a bet on regulatory bandwidth, not a legal defense if a complaint gets filed. The AI Act complaints tool the Commission published alongside this enforcement date means any EU user who notices your chatbot doesn't disclose itself can file one directly.
The actual weekend fix
None of this requires a compliance department. If you've shipped a chatbot, an AI writing assistant, or any interactive AI feature reachable by EU users, here's what closes the gap in a weekend:
- Add a static, visible disclosure to the interface itself: "You're chatting with an AI assistant," placed where the conversation happens, not in a linked terms page.
- If your tool generates or edits images, video, or audio and your stack supports embedding provenance metadata (C2PA-style, or whatever your generation API exposes), turn it on. If it doesn't, add a visible watermark or caption instead.
- Do the same for long-form AI-generated text where the tool realistically resembles human-authored content: a visible note that a piece was AI-drafted or AI-assisted covers the intent of the rule even if your stack doesn't produce machine-readable marks yet.
- Don't wait for a complaint to show up in your inbox before doing this. The fix is cheap now and expensive as a response to an actual inquiry.
What I'd actually do
If your product touches EU users at all, I'd add the disclosure this week: not because I think a two-person SaaS is about to get a formal notice, but because the fix costs an afternoon and the alternative is carrying open legal exposure indefinitely for no reason. Treat the Article 2 territorial-scope text as the trigger, not your company's registration paperwork, and treat "check where your signups come from" as a five-minute audit worth doing today.
The honest counter-take: enforcement priorities and the real fine mechanics against small non-EU businesses are genuinely unsettled just days into this window. The AI Office has finite staff, the biggest early targets are obviously going to be large platforms and high-risk categories like biometrics, and it's entirely plausible this stays a large-company story in practice for years. I could be overstating the urgency for someone running a niche SaaS with a dozen EU users. But the legal exposure exists the moment the rule took effect on August 2, independent of how aggressively anyone chooses to police it against operators our size, and "cheap to fix, expensive to ignore" is reason enough to close the gap regardless of how the enforcement story plays out. This isn't legal advice; if you've got real revenue at stake, a lawyer who does EU tech regulation can tell you in an hour whether your specific setup is in scope.
Author
Lukas
@lukcombinatorSources
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission
- Safer and more transparent AI — European Commission
- Article 2: Scope — EU Artificial Intelligence Act (Regulation (EU) 2024/1689 text)
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems — EU Artificial Intelligence Act
- Transparency obligations under Article 50 of the AI Act — FAQ, European Commission