Gian Luca Partengo Gian Luca Partengo

Guides

EU AI Act from 2 August 2026: what changes for chatbots, AI content and websites

Not every website that uses artificial intelligence needs the same label. Role, function, content and human control determine what must be checked and how it should be implemented.

Short answer

If a website lets a person interact with an AI system, that interaction must be recognisable from the start unless it is already obvious. Synthetic content, deepfakes and public-interest text follow different rules. A visible notice does not replace technical marking, privacy, accessibility or security.

Gian Luca Partengo

Gian Luca Partengo
Web developer since 1995 · bespoke websites · Updated

Does your website need changes? It depends on what it actually does

The word “AI” in a product is not enough. What matters is the behaviour the user experiences and how an output is published.

Chatbot or conversational agent

When a person exchanges messages directly with an AI system, check that the notice appears at the start of the first interaction and can genuinely be perceived.

Generated images, audio, video or text

Machine-readable marking, required of providers in certain cases, must be distinguished from the visible disclosure required of deployers for particular content.

AI used only as an assistant

Editing, research, drafting or internal support do not automatically require every page to carry a label. Purpose, transformation and human control remain decisive.

No exposed AI function

A brochure website with no chatbot, dynamic generation or relevant synthetic content does not fall under Article 50 merely because AI tools helped build it.

2 August 2026: the deadline is real, a blanket extension is not

The Commission’s new guidelines clarify how the Article 50 transparency rules apply.

  1. 0120 July 2026 — Commission guidelines published
  2. 022 August 2026 — Article 50 transparency obligations start to apply
  3. 032 December 2026 — limited deadline for marking certain systems already on the market
  4. 04No general duty to relabel every item published before the application date
The period until 2 December only concerns the provider obligation to mark and make outputs detectable for certain systems placed on the market before 2 August.

Do not wait until December to review the chatbot

The transition does not postpone interaction notices, deployer disclosures or website checks as a whole. It must be applied only to the scope defined in the rules.

Provider, deployer, integrator and editor: who does what

A single website may involve several parties. Contracts help, but they do not replace an assessment of the role each party actually performs.

Role Who they are Website example Decisive check
Provider Develops an AI system or places it on the market or puts it into service under their name or trade mark. A platform supplying the conversational engine or a proprietary system offered to customers. Notice design, documentation and technical output marking where applicable.
Deployer Uses an AI system under its authority in a professional activity. A company adding a third-party chatbot to its website. Configuration, use context, required disclosure and compliance with provider instructions.
Integrator or developer Connects model, interface, data and tools on behalf of the website owner. Builds the widget, RAG flow, APIs and agent actions. Preserve safeguards, document choices and establish whether substantial modification changes the role.
Responsible editor The person or organisation that controls, approves and accepts responsibility for publication. An editorial team checking and rewriting an AI-assisted article. Substantive human control and real responsibility, not a formal approval step.

An employee or contractor using a system under the company’s responsibility does not automatically become a separate deployer. Authority, setup and modifications must be assessed in context.

Chatbots and AI agents: users must understand immediately

Article 50 covers systems intended to interact directly with natural persons. The “obvious” exception should be interpreted carefully.

Interface rule

The notice appears before confusion becomes possible

The Commission calls for clear, distinguishable information no later than the start of the first interaction. Text buried in a privacy policy does not perform the same function.

The communication must meet applicable accessibility requirements. It should remain understandable with a keyboard, screen reader, zoom and high contrast.

Explicit name

“AI-powered virtual assistant” is clearer than a human name with no explanation. The character’s tone must not conceal its nature.

Persistent indicator

The initial notice can be supported by a stable indicator in the chat header, especially when a conversation is long or reopened.

Limits and human handoff

Explain what it can do, what users should not submit and how to reach a person to reduce errors, false expectations and unnecessary data sharing.

No dark patterns

Do not fade the notice, hide it behind a button, show it only after the first message or make it unreadable to protect the visual design.

Technical marking and visible disclosure are not the same

One supports detectability across the value chain; the other directly informs the person exposed to the content.

Provider marking

Providers of systems that generate synthetic audio, image, video or text must make outputs detectable and mark them in a machine-readable format where the rules apply and technical feasibility allows.

Deployer disclosure

A deployer using AI to generate or manipulate a deepfake must clearly disclose its artificial origin. A specific rule applies to public-interest text.

Targeted exceptions

Standard editing, outputs that do not substantially alter input or meaning, and certain technical contexts may fall outside marking. This is not a blanket exemption for every assistant.

Human-readable label

Metadata, watermarks or content credentials do not automatically replace a visible message where the deployer must inform people.

Two layers, two checks

The website should preserve available technical signals and display a disclosure where required. Adding only “made with AI” does not prove that the value chain has been handled correctly.

AI-generated text: editorial control changes the outcome

The specific duty does not cover every product description, email or draft. It concerns text published to inform the public on matters of public interest.

Publication, an intention to inform the public and a public-interest subject all need to be present. The Commission asks organisations to consider context, audience and the text’s real function.

The exception requires human review or editorial control and a natural or legal person holding editorial responsibility. Correcting typos or approving without verification is not substantive control.

AI draft, human rewrite

Checked sources, verified claims, reworked structure and documented editorial responsibility describe a real process rather than a final click.

Automated article

Automatic publication about health, politics, security or another matter of public interest needs much stronger assessment and may require disclosure.

Commercial description

A product page does not automatically fall under the public-interest text rule, but accuracy, advertising law, intellectual property and other rules still apply.

Editorial record

Versions, sources, reviewer, date and approval criteria make a claimed process verifiable.

Eight website cases to check before publication

The table is not legal advice, but it prevents the same solution being applied to completely different functions.

Scenario Type of use Prudent action Why
Traditional FAQs Static answers written and published on a page. No chatbot notice; retain author and sources. No direct interaction with an AI system occurs during the visit.
Generative chatbot Two-way exchange with output generated at the time. Clear start notice, limits, privacy and human contact. The person directly interacts with an AI system.
Agent that takes actions Can book, change data or call tools. Notice, pre-action confirmation, least privilege and logs. Transparency and security must cover operational effects too.
AI-assisted product copy AI drafts reviewed by a person. Substantive control, evidence and editorial responsibility. Not automatically public-interest text, but still required to be truthful.
Synthetic decorative image Clearly illustrative visual, not presented as a real event. Preserve provenance and assess contextual disclosure. The deception risk differs from a deepfake, but the technical chain still matters.
Automatically published news AI text about a public-interest matter with no review. Clear disclosure and process review before publication. It most closely matches the specific rule for informative text.
Editorially verified article AI as support, substantive human control. Document review, sources and editorial responsibility. The exception may apply where control is real rather than cosmetic.
Back-office AI only Internal classification or summarisation not directly exposed. Assess privacy, risk and processes; no automatic chat notice. The AI-person interaction that triggers that specific disclosure is absent.

The absence of an Article 50 duty does not remove GDPR, consumer law, copyright, editorial responsibility or other applicable rules.

The AI Act and GDPR are separate checks

Telling visitors they are speaking to AI does not authorise the collection, storage or transfer of everything they enter into a conversation.

Purpose and legal basis

Define why messages are processed, which data are necessary and which basis makes that processing lawful.

Suppliers and transfers

Check privacy roles, contracts, subprocessors, location and international transfers associated with the AI service.

Retention and training

Set retention periods, logs and deletion and establish whether the supplier may reuse content to train or improve models.

Sensitive data and secrets

The interface should discourage unnecessary submission of special-category data, credentials, health information or business secrets.

Transparency does not equal lawfulness

Even a perfectly disclosed chatbot can process data incorrectly. AI Act, GDPR and ePrivacy need to be mapped separately and then recombined in the same flow.

Disclosure works only when people can perceive it

Article 50 requires the information to meet applicable accessibility requirements. That requirement belongs in the component, not only in a policy.

Focus and keyboard

Open, close, history, send, confirm and escalation must work without a mouse and retain a visible focus indicator.

Names and states

Fields, buttons and dynamic messages need accessible names and must communicate loading, errors, responses and completion.

Readable notice

Copy, contrast, reading order and persistence must let a person understand that AI is involved before interacting.

Human alternatives

Where the chatbot is difficult or unsuitable, phone, email or an accessible form should not be hidden behind the same interface.

A transparent agent can still be dangerous

A label informs the user; it does not stop prompt injection, tool abuse, data leakage or unauthorised action.

Prompt injection

Page content, retrieved documents or user input can attempt to alter system instructions and behaviour.

Tool permissions

An agent should see and execute only what it needs. Reading, writing, purchasing, sending and deleting require distinct boundaries.

Action confirmation

Operations with external effects should show recipient, data and consequence and require confirmation before execution.

Logging and shutdown

Record necessary events, protect logs, detect anomalies and provide a rapid way to disable the system without taking down the website.

To understand why autonomy does not mean a will of its own, read the OpenAI–Hugging Face case ; for the broader scope, also see the website security guide.

How to implement an AI component without adding a last-minute label

A sound process starts with an inventory and ends with checks on the published website, not a standard sentence copied into a policy.

  1. 01

    Inventory functions and suppliers

    List chatbots, generation, classification, models, APIs, widgets, data, connected tools and every party involved.

  2. 02

    Assign roles and duties

    Separate provider, deployer, integrator and editor; gather documentation and send legal uncertainties to the appropriate adviser.

  3. 03

    Design notices and controls

    Write microcopy and define position, persistent state, limits, human escalation, confirmations and error handling.

  4. 04

    Minimise data and permissions

    Reduce payloads, retention, tools, secrets, actions and dependencies to the minimum needed for the objective.

  5. 05

    Test people and machines

    Check keyboard, screen readers, responsive layout, network, cookies, marking, logs, adversarial cases and fallback without JavaScript or the AI service.

  6. 06

    Document and maintain

    Record versions, suppliers, decisions, tests and owners; repeat checks when the model, prompts, data or functions change.

What I can implement on the website

I can design and implement the interface, disclosure, accessibility, technical minimisation, permissions, logs, fallbacks and policy links. Legal qualification and compliance for the specific case remain the responsibility of the appointed legal professional.

See how I build bespoke websites and functions or request a technical review.

Verified primary sources

Law, guidance and technical references used to separate transparency, privacy, accessibility and security obligations.

  1. European Commission — Article 50 guidelines

    Scope and interpretation of transparency obligations for providers and deployers.

    Open source
  2. European Commission — Article 50 questions and answers

    Clarification of roles, chatbots, synthetic content, human review, dates and exceptions.

    Open source
  3. European Commission — Quick facts on transparency rules

    The four main cases and the limited period for certain systems already on the market.

    Open source
  4. EUR-Lex — Regulation (EU) 2024/1689

    Official AI Act text, including Article 50 and the relevant recitals.

    Open source
  5. European Commission — Code for AI-generated content

    Publication of the voluntary code with practical measures for marking and disclosing synthetic content.

    Open source
  6. EUR-Lex — General Data Protection Regulation

    Principles, lawful bases, transparency, minimisation, security and rights in personal-data processing.

    Open source
  7. EDPB — Opinion on AI models

    Model anonymity, legitimate interests and the consequences of unlawfully processed personal data.

    Open source
  8. W3C — Web Content Accessibility Guidelines 2.2

    Testable criteria for perceivable, operable, understandable and robust web content and components.

    Open source
  9. OWASP — Top 10 for LLM applications

    Application risks including prompt injection, sensitive information disclosure and improper output handling.

    Open source
  10. European Commission — AI Act regulatory framework

    Official overview of the risk-based approach, categories and application timeline.

    Open source

Sources accessed and verified on 24 July 2026. This guide is informational and technical: it does not replace legal advice for a specific case and does not constitute compliance certification.

Frequently asked questions about the AI Act and websites

Direct answers to common questions about chatbots, generated content, policies and implementation.

Does every website that uses AI need a notice?

No. It depends on the function. A chatbot interacting directly with a person differs from an assistant used internally to edit a draft or analyse data not exposed to the visitor.

When does Article 50 of the AI Act apply?

From 2 August 2026. A limited period to 2 December 2026 applies only to output marking and detectability for certain systems placed on the market before 2 August.

Where should the chatbot notice appear?

Clearly and distinguishably no later than the start of the first interaction. As a prudent design choice, show it before the first message is sent and keep the nature of the interface recognisable.

Is calling it a “virtual assistant” enough?

Not always. Where that name does not make AI involvement obvious, state it explicitly. The obviousness exception must be assessed from the context and user’s perspective.

Must every text written with ChatGPT be labelled?

No. The specific deployer rule concerns AI-generated or manipulated text published to inform the public on matters of public interest. Substantive human control and editorial responsibility may support an exception.

Is a human spelling check sufficient?

The Commission distinguishes substantive review from superficial edits. Correcting typos without checking content, sources and claims does not demonstrate genuine editorial control.

Are metadata and watermarks enough to inform the public?

Not automatically. Machine-readable marking concerns the provider’s technical layer; where the deployer owes a disclosure, it must be clear and perceivable by people.

Is a decorative AI image a deepfake?

Not necessarily. A deepfake resembles existing persons, objects, places, entities or events and may appear authentic or truthful. Provenance, context and deception risk should still be assessed.

Does an AI chatbot always require a cookie banner?

No. The banner depends on cookies, tracking, identifiers and purposes. Inspect the widget because telemetry, analytics or third-party services may introduce additional processing.

Can the privacy policy replace the notice in the chat?

No. The policy documents personal-data processing; the Article 50 notice helps a person understand, at the right moment, that they are interacting with an AI system.

Does the chatbot need to be accessible?

Article 50 information must meet applicable accessibility requirements. The component should also address keyboard use, focus, accessible names, states, errors and alternatives in line with the website’s scope.

Can you make my website AI Act compliant?

I can analyse and implement the technical scope: interfaces, notices, accessibility, minimisation, permissions, logs and documentation. Legal qualification and confirmation of compliance require the appropriate legal professional.

Did you find this guide useful? Share it.

No social tracker loads before you choose an action.

Next step

Does your website use a chatbot or publish AI content?

I map the technical flow, design accessible notices and controls, reduce data and permissions and prepare a verifiable implementation to connect with the legal assessment.

Test evidence

Mobile PageSpeed Insights: 100 in every category

PageSpeed Insights result from 28 July 2026: 100 for Performance, Accessibility, Best Practices and SEO on mobile.
Google PageSpeed Insights · Lighthouse mobile · verified 28 July 2026 Open the verifiable report
© 1995–2026 Gian Luca Partengo · All rights reserved.

GLP AI

GLP AI assistant

Answers based on the public content of this website.

Tell me what you need from your website. I will look through GLP services and Articles and point you towards the most relevant route.

Ready

You are interacting with an AI system, which can make mistakes: its answers are not binding quotations. Do not enter personal, sensitive or confidential data. Questions are sent to OpenAI to generate the answer and are not saved by this website. Read the Privacy Policy.

Search