This article’s text was drafted with the help of AI systems and reviewed by the WIT ICT team, in line with Article 50 of the EU AI Act (Regulation (EU) 2024/1689) on the transparency of AI-generated content. The featured image was also produced using AI.
On 2 August 2026, the transparency obligations set out in Article 50 of the EU AI Act became applicable. For most Italian and European small businesses the news barely made a ripple, yet it directly concerns anyone who publishes online content, runs a WordPress site, uses a chatbot for customer support, or relies on generative AI tools for marketing copy. This is not a rule reserved for big tech: any company using AI to produce text, images, or automated interactions with the public now has to make that clear to the people on the other end. Even a professional studio or a small in-house marketing team that occasionally leans on an AI writing tool falls within scope, often without realising it. Here is what actually changes and how a small or mid-sized business can adapt without turning its workflow upside down.
What Article 50 of the AI Act actually requires
Article 50 sets out transparency duties that are separate from the better-known rules on “high-risk” AI systems. It targets everyday situations instead: a chatbot answering customer queries, a text drafted with the help of a language model, an image created or retouched by AI. The underlying logic is straightforward — people should be able to tell when they are dealing with a machine, or when a piece of content wasn’t produced entirely by a human. On 20 July 2026 the European Commission published operational guidelines to clarify how the rule applies in practice, a sign that the obligation is meant to be checked, not just declared on paper.
Providers and deployers: two roles, two sets of duties
The AI Act separates the entity that builds an AI system (the provider) from the one that uses it in its own operations (the deployer). For a small business that simply uses off-the-shelf tools, the relevant role is almost always the latter one:
- providers must design systems so that generative outputs carry a machine-readable marker;
- deployers must inform people when AI is used for emotion recognition or biometric categorisation;
- deployers must also label public content — text or images — that was generated or manipulated with AI.
Working out which role applies to your business is the first step toward knowing what actually needs to be done.
Text, images, audio and video call for different kinds of disclosure
There is no single label that covers everything. For a blog post or a social media caption generated with AI, a visible note — something like “content generated or manipulated with artificial intelligence” — placed where readers will notice it is usually enough. Images work similarly, though the Commission’s guidelines also mention standardised transparency icons at EU level. Audio and video pieces, where confusion with genuine footage is a bigger risk (think deepfakes), need even clearer marking. For a business website or blog, the simplest solution remains a clear note next to the content in question, much like the one at the top of this very article. Even a product photo reworked with generative tools — say, to remove the background or place it in a setting that was never actually photographed — falls into this category: what matters is that a generative model created new elements, not present in the original shot, rather than a routine touch-up.
Chatbots and virtual assistants: users have a right to know
Many small businesses have added chatbots for first-line customer contact over the past few years, often through WordPress plugins or third-party tools connected to social channels. Article 50 requires that users know, from the start of a conversation, that they’re talking to an automated system rather than a person. That doesn’t mean giving up automation — a well-designed chatbot is still an effective way to handle repetitive requests and free up staff time. It simply means stating the nature of the system upfront, with a short line at the start of the chat, rather than letting customers discover it on their own and lose trust as a result. In practice, on a WordPress site this often takes nothing more than a fixed line in the chat widget or the plugin’s welcome message.
Why this connects to cybersecurity: deepfakes and social engineering
These transparency rules didn’t appear out of nowhere. Recent months have seen a rise in scams built around synthetic audio and video impersonating company executives, often over collaboration platforms like Microsoft Teams, with urgent requests for wire transfers or confidential data. A business that builds a habit of transparency around its own AI content is also one that’s better placed to notice when something feels off in a message it receives. Training staff to ask “could this have been generated artificially?” is now part of basic cyber hygiene, not a theoretical exercise reserved for security specialists.
Practical steps, without overcomplicating things
For most small businesses, adapting is manageable if approached in order:
- map where generative AI is used across the business — website, blog, social media, email marketing, customer support;
- add a visible note to text and visual content produced or edited with AI;
- check that any chatbot discloses its automated nature to users;
- update privacy notices and internal policies on AI tool use where needed;
- keep a record of the decisions made, useful if questions come up later.
A limited grace period runs until 2 December 2026 for systems already on the market, but it only covers the technical marking obligation — it’s worth not leaving this until the last moment.
Where specialised IT consulting makes the difference
Correctly working out which obligations apply to a given business, telling the deployer role apart from the provider role, and adding the required disclosures without cluttering the user experience calls for a mix of technical know-how and regulatory understanding. An IT partner already managing the website, the Microsoft 365 environment, and the company’s cybersecurity is well placed to handle this in a coordinated way, rather than through improvised fixes that look correct on paper but turn out ineffective — or even damaging to customer trust — in practice. A single coordinated pass can combine a website check, a chatbot update, and a short training moment for whoever writes content or handles customer replies, so compliance becomes a habit rather than a once-a-year scramble.
Want to know more? Contact us for a free consultation.