
The European Union's transparency rules for artificial intelligence started to apply on 2 August 2026. From that date, people in the EU must be told when they are dealing with a chatbot or other AI system instead of a person, and certain AI-generated content must be labelled. The rules can reach an Australian business that has no office in Europe, because they follow where the AI output is used. If you sell to EU customers, run a website chatbot they can talk to, or publish AI-generated images and video for a European audience, this is the week to check where you stand.
This article is general information for business owners and managers, not legal advice.
What changed on 2 August 2026
The European Commission confirmed in its news item Safer and more transparent AI that new rules on the transparency of AI systems took effect on 2 August 2026. They sit in Article 50 of the EU AI Act, which entered into force on 1 August 2024 and applies in stages.
The Commission describes two groups of obligations:
- Telling people they are interacting with AI. Users must be clearly informed when they are not interacting with a real person but with an AI system, for example a chatbot, an AI agent or an avatar.
- Marking and labelling AI-generated content. Certain AI-generated or manipulated content must be clearly and visibly labelled and carry machine-readable marks. The Commission lists deepfakes (images, audio and video that resemble existing persons, objects, places, entities or events), emotion recognition and biometric categorisation tools, and text published to inform the public on matters of public interest where there has been no human review or editorial control.
The Commission has also published guidelines, a voluntary code of practice and a set of icons that can be used for labelling.
Who the rules apply to: providers and deployers
The AI Act splits responsibility between two roles. The Commission's questions and answers on Article 50 explain them this way:
- A provider develops an AI system, or has one developed, and places it on the EU market or puts it into service under its own name or trademark. Providers must design chatbots and similar systems so people are informed they are interacting with AI, and must make sure the output of generative AI systems carries machine-readable marks.
- A deployer uses an AI system under its authority in a professional capacity. Deployers must tell people when emotion recognition or biometric categorisation is used on them, clearly label deepfakes, and label AI-generated text published on matters of public interest unless it has had human review or editorial control.
Most small and medium businesses that use off-the-shelf AI tools are deployers. A software business that ships its own product with an AI feature to European customers is more likely to be a provider.
Does this cover an Australian small business?
It can. Location does not decide the question. Article 2 of the AI Act says the regulation applies to providers placing AI systems on the market in the Union whether they are established in the Union or in a third country, and to providers and deployers located in a third country where the output produced by the AI system is used in the Union.
The Commission's material does not describe a small business exemption from Article 50. What it does say is that fines take proportionality into account for small and medium-sized enterprises and small mid-cap companies.
On the other hand, a business with only Australian customers, whose AI output is not used in the EU, is not the target of these rules. Use by a person in a purely personal, non-professional capacity is also outside the Act.
| Your situation | Likely role | What to check |
|---|---|---|
| An online store with EU customers and an AI chatbot on the website | Deployer (the chatbot supplier is usually the provider) | The chat states at the start of the first interaction that the customer is talking to an AI system |
| A marketing team publishing AI-generated or AI-edited images, audio or video of real people or places to an EU audience | Deployer | A visible or audible label at first exposure if the content could falsely appear authentic |
| A software company selling an app with a built-in AI assistant to EU businesses | Provider | Disclosure built into the product, and machine-readable marking of generated content |
| A trades business serving one Australian city, using AI to draft quotes | Outside the EU rules | Nothing under the EU AI Act |
The details that matter in practice
Chatbot disclosure
The Commission's answers say people must be notified that they are interacting with an AI system from the start of the first interaction, in a clear and distinguishable manner. The exception for interactions where it is obvious is to be read narrowly. Systems that only run in the background, with no direct contact with people, are outside this obligation. The duty to build the notice in sits with the provider of the chatbot. As the business using it, check that the notice is switched on and has not been removed by custom branding or a renamed assistant.
Deepfake labels
A deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. Deployers must disclose it at first exposure at the latest. The Commission is explicit that a deployer cannot rely only on the hidden machine-readable mark added by the tool; the label has to be something a person can see or hear without special tools.
AI-written text
The text rule is narrower than many people expect. It covers text that is published, informs the public, and deals with matters of public interest such as public health, consumer safety or economic and political developments. Text that has had genuine human review or editorial control, with a person holding responsibility for publication, does not need the label. Spell-checking alone does not count as review.
A short grace period for one obligation
Article 50 applies from 2 August 2026. The Commission notes one limited grace period: for AI systems placed on the market before 2 August 2026, the provider's machine-readable marking and detection obligation applies from 2 December 2026. Content generated before 2 August 2026 does not need to be labelled retroactively, although the Commission encourages it.
Penalties and who enforces
National market surveillance authorities in each member state do most of the enforcement. The European AI Office covers a narrower group of systems, and the European Data Protection Supervisor covers EU institutions. Fines can reach €15 million or 3% of total worldwide annual turnover.
The stricter rules for high-risk AI systems are not part of this step. According to the Commission's AI Act overview, high-risk rules for sensitive areas such as employment, education and biometrics now apply from 2 December 2027, and rules for AI built into regulated products from 2 August 2028, after the simplification package known as the AI Omnibus entered into force on 27 July 2026.
A checklist for Australian SMEs
- List the AI tools in use. Include website chat, marketing image and video tools, voice assistants on phone lines, and AI features inside your CRM or help desk.
- Mark which ones touch EU customers or audiences. Look at shipping destinations, website analytics by country and your mailing lists.
- Fix chatbot wording. Add a plain statement at the start of the chat that the customer is talking to an AI system, and offer a path to a person.
- Set a labelling rule for synthetic media. Any realistic AI-generated image, audio or video of real people, places or events gets a visible label.
- Keep a human reviewer on published text. Record who reviewed and approved it.
- Ask suppliers three questions. Does the tool disclose AI interaction by default? Does it add machine-readable marks to generated content? Will it meet the 2 December 2026 date for existing systems?
- Write it down. A one-page AI use policy and a register of tools is enough to start with.
Comingwave is a technology company that provides IT consulting, websites and digital transformation services to small and medium businesses. If you would like help building a register of the software your business relies on, or changing how your website chat introduces itself, you can request a quote.
Key takeaways
- The EU AI Act's transparency rules have applied since 2 August 2026.
- They can cover an Australian business when the output of its AI system is used in the EU.
- Chatbots must say they are AI from the first interaction; realistic synthetic media needs a visible label.
- Published text is only caught when it informs the public on matters of public interest and has had no human review.
- Providers of existing systems have until 2 December 2026 for machine-readable marking; high-risk rules start later.
Frequently asked questions
Does the EU AI Act apply to an Australian business with no European office?
It can. Article 2 applies the Act to providers and deployers located outside the EU where the output produced by the AI system is used in the Union. A business that serves only Australian customers is not the target.
Do we have to label every blog post written with AI help?
No. The text obligation covers published text that informs the public on matters of public interest, and it falls away when a person has genuinely reviewed the content or holds editorial responsibility for it.
Is there a small business exemption from the transparency rules?
The Commission's material does not describe one. It says fines take proportionality into account for small and medium-sized enterprises and small mid-cap companies.
What is the maximum fine for breaching the transparency rules?
The Commission states that fines can reach €15 million or 3% of total worldwide annual turnover for companies.
When do the high-risk AI rules start?
The Commission's current timeline is 2 December 2027 for high-risk uses in sensitive areas such as employment and education, and 2 August 2028 for AI built into regulated products.