EU rules on labelling AI content have applied since August 2026. What they actually require from a small business website, and which scare stories to ignore.
If you have seen headlines saying that AI content now has to be labelled by law, and you are wondering whether that means slapping a warning on every AI-drafted paragraph on your website, here is the straight answer: the rules are real, they have applied across the EU since 2 August 2026, and for a typical small business they boil down to three small habits. Most of the heavy obligations, and most of the scary fines, are aimed at the companies that build AI tools, not at the businesses that use them.
This is general information, not legal advice, but it should replace the scare stories with a short to-do list you can finish this week.
What is actually in force
The rules come from Article 50 of the EU AI Act, the transparency chapter. It became applicable on 2 August 2026, across the whole EU, directly, with no national law needed. The European Commission adopted detailed guidelines in July 2026, and a voluntary Code of Practice on marking AI-generated content was published in June, with around 190 signatories by late July. Signing the code is optional. The underlying duties are not.
There is also a set of official EU labelling icons ("AI involved", "Fully AI-Generated", "Partially AI-Modified"). Using the icons is optional too. They exist so nobody has to design their own label.
The distinction that deflates most of the panic
The law splits the world into providers, the companies that make AI tools (Google, OpenAI, Adobe and so on), and deployers, the businesses that use them. That is you.
The heavy technical duty, embedding machine-readable markers in every AI-generated image, video, audio clip and text, sits with the providers. Google embeds its invisible SynthID watermark at generation. OpenAI attaches C2PA provenance metadata to images. Adobe Firefly attaches Content Credentials. You do not have to watermark anything yourself, ever. For tools already on the market before August 2026, a grace period for that marking duty has been agreed, running to 2 December 2026, but that is the providers' problem, not yours. The duties that touch small businesses applied from day one, and here they are.
The three things you actually have to do
1. Your chatbot must say it is a chatbot
If your website has an AI chat widget, visitors must know they are talking to a machine. One clear line at the start of the conversation does it: "You're chatting with an AI assistant." Strictly speaking, designing that in is the tool provider's duty, but the disclosure has to reach your visitor, so check that it is there. The law allows an exception where it is obvious, but the guidance reads that exception narrowly, so do not rely on it. This is a five-minute fix, and the AI chatbots we build introduce themselves in the first message, so that box is ticked from the start.
2. Visibly label anything that fakes reality
This is the deepfake rule. It covers AI-generated or AI-manipulated image, audio or video that shows real people, places, products or events in a way that could pass as authentic. An AI "photo" of your actual shopfront looking busier than it is, a fabricated before-and-after of a job, a cloned voice, all of that needs a visible label from the first moment someone sees it. Hidden metadata alone is not enough. A person has to be able to see the disclosure without special tools. AI text is not a deepfake under the definition. This rule is about media.
The working test is simple: if it shows something real looking authentic when it is not, label it. Illustrations, stylised graphics and obviously artificial images are not deepfakes and need no label. Our own blog illustrations are AI-generated concept images, deliberately illustrative rather than photorealistic, which is exactly why they are fine unlabelled.
3. Keep a human editor on AI-drafted text
The text rule is far narrower than the headlines suggested. A label is only required when AI-generated text is published to inform the public on matters of public interest, think news-style content on politics, health or consumer safety, and nobody has reviewed it. If a human reviews the text and a person or business takes editorial responsibility for it, it is exempt. Ordinary marketing copy, service pages and business blogs are outside the duty entirely.
So the practical rule is the one good businesses already follow: never publish raw, unreviewed AI text dressed up as news. That is how we run our own AI content service: AI drafts, a human edits, checks and signs off every piece.
What you do not have to do
- No labelling ordinary AI marketing content. AI-assisted product descriptions, blog posts, illustrations and social captions carry no labelling duty. The rules for businesses cover deepfakes and unreviewed public-interest text, nothing else.
- No watermarking anything yourself. Machine-readable marking is the tool provider's job.
- No retro-labelling. Content generated before the rules applied does not need labels added after the fact.
- No compulsory EU icons. They are there if you want them.
- No Google penalty for AI content. Google's published position is quality over origin. What it acts against is churning out masses of low-value pages, which was already against the rules.
The fines, honestly
The headline number for transparency breaches is up to €15 million or 3% of worldwide turnover, whichever is higher. But the same law caps fines for small businesses and start-ups at the lower of the two, a detail most scary articles skip. And the enforcement reality is quieter still: as of September 2026, six weeks in, no Article 50 fine or formal action has been publicly reported anywhere in the EU, and as of mid-2026 only nine of the 27 member states had fully designated their enforcement authorities. None of that exempts anyone, but it does tell you the sensible response is a calm afternoon of housekeeping, not panic.
What about UK businesses?
As of September 2026 there is no UK law requiring AI content to be labelled, a point the government's own March 2026 report on copyright and AI confirms. A taskforce on best practice for labelling AI content has been promised, but that is policy exploration, not legislation. The advertising regulator's position is that there is no blanket duty to disclose AI in ads. Disclosure is needed only where the audience would otherwise be misled. The sharper UK risk is ordinary consumer law: the CMA can now fine up to 10% of global turnover for misleading commercial practices, and a March 2026 ASA ruling against an AI-generated toy advert made the key point. The footage was labelled as AI and was still ruled misleading, because the real product did not match. A label never rescues a misleading ad.
One catch: a UK business is caught by the EU rules when its AI output is used in the EU, for example a chatbot serving EU visitors or campaigns aimed at EU customers. Where the line falls for a site that is merely reachable from the EU is untested, so the safe assumption is that if you actively sell to EU customers, you follow the same three habits. They cost almost nothing anyway.
Your five-minute checklist
- Chatbot on the site? Make its first message say it is an AI assistant.
- Audit your images and video. Realistic AI depictions of real people, places, products or jobs get a visible label. Illustrations need nothing.
- AI-drafted text gets a human review before publishing, with a named person or the business taking responsibility.
- Never publish AI content dressed up as news or reviews.
- Leave old content alone. There is no retro-labelling duty.
Frequently asked questions
Do I have to label AI images on my website?
Only if they could pass as authentic depictions of real people, places, products or events. Illustrations, icons and obviously stylised AI graphics need no label under the EU rules.
Do blog posts written with AI need a label?
Not if a human reviews them and someone takes editorial responsibility, and ordinary marketing content sits outside the rule entirely. The label only applies to unreviewed AI text published to inform the public on matters of public interest.
What is the fine for getting it wrong?
Up to €15 million or 3% of turnover for transparency breaches, but small businesses are capped at the lower of the two figures, and as of September 2026 no Article 50 enforcement action had been publicly reported.
Will Google rank my AI-assisted content lower?
No. Google says it rewards quality regardless of how content is produced. Its policies target mass-produced pages that add no value, not AI-assisted writing with real substance.
Want a chatbot that gets the disclosure right out of the box, or AI-assisted content with a human editor built into the process? Get in touch and we will set you up without the drama.