What Does the EU AI Act Mean for Your Website's AI Features?
What does the EU AI Act mean for your website's AI features?
As of September 2026, the transparency rules are live. Article 50 of the EU AI Act became applicable on 2 August 2026. If your site has an AI chatbot, publishes AI generated text, or uses AI generated images, some disclosure duties now apply to you, with a short grace period for one of them.
We are a web studio, not a law firm, and nothing here is legal advice. What we can do is tell you which parts of this land on the website itself, because that is the part our clients keep asking about and the part that gets missed until someone's counsel sends an email.
The good news is that most of it is smaller than the panic suggests. The bad news is that one exemption everyone is relying on is narrower than they think.
What does Article 50 actually cover?
Four situations, according to the European Commission's own guidance. Systems that interact directly with people. Marking of AI generated audio, image, video and text. Emotion recognition and biometric categorisation systems. And labelling of deepfakes and AI generated text published on matters of public interest.
For a normal B2B website, the first two are the ones that matter. The third is unlikely unless you are doing something unusual with cameras. The fourth catches you only if you publish on matters of public interest, which most product blogs do not, though the boundary is not as obvious as it sounds.
The Commission splits the duties between providers, meaning those developing or placing AI systems on the market, and deployers, meaning those using a system under their own authority. If you bought a chatbot and put it on your site, you are usually a deployer. If you built one, you may be both.
Does your site chatbot need a disclosure?
Yes, unless the fact that it is AI is already obvious. The Commission's guidance says systems that interact directly with people must inform users they are engaging with AI unless this is obvious. That is a low bar to clear and most teams clear it accidentally, but it is worth checking rather than assuming.
In practice, a widget labelled AI Assistant with an opening message that says it is an automated assistant is fine. A widget that shows a stock photo of a person called Sarah and an opening line written to sound human is the case this rule exists for. We have built the second kind for clients in the past and would not do it now.
The fix is a design decision, not an engineering one. Say what it is in the header, say it again in the first message, and make the route to a human visible. Our piece on putting an AI chatbot on your website covers the pattern we use.
Do you have to label AI written blog posts?
Only in specific circumstances, and this is where the detail matters. The deployer duty covers AI generated text published to inform the public on matters of public interest, and it applies where that text has not had human review or editorial control. Product marketing copy is generally not that. News style commentary can be closer to it than teams expect.
The exemption people lean on is the human review one, and the Commission is specific about what counts. It says human review requires deliberate examination by qualified persons, and that superficial, solely formal or procedural checks do not qualify. Skimming a draft and pressing publish is a procedural check.
That is the sentence we would put in front of any content team running an AI assisted pipeline. If your review step is a person glancing at a draft for thirty seconds, you may not have the editorial control you are relying on. Our article on fact checking AI written content describes what a real review step looks like.
What about machine readable marking?
That duty sits with providers rather than with you as a site owner. The Commission describes it as marking synthetic audio, image, video or text with machine readable marks that enable the outputs to be detected as generated or manipulated by AI systems. It is a job for the company that built the model, not for the company that used it.
There is a timing wrinkle worth knowing. The Commission's guidance notes that systems placed on the market before 2 August 2026 have until 2 December 2026 for marking compliance only. So through the rest of this year, some tools you use will not yet be emitting those marks.
It also confirms that content generated before 2 August 2026 does not require retroactive labelling. Nobody has to go back through four years of blog images. That is the single most reassuring line in the whole guidance and it is not widely known.
Which uses are explicitly exempt?
Several, and they cover a lot of everyday work. The Commission's guidance lists outputs that are a short sequence of numbers, symbols or letters, source code, machine to machine communications, standard editing assistance functions, and deepfakes in evidently artistic, creative, satirical or fictional works.
Standard editing assistance is the one most marketing teams live under. Using a model to tighten a sentence you wrote is editing assistance. Using a model to write the piece from a one line brief is not, whatever you call it internally.
The source code and machine to machine exemptions are useful for anyone building automations. An agent that classifies form submissions and writes rows to your database is machine to machine. You are not labelling database rows.
How does this interact with what you already do for privacy?
It is a separate regime with a familiar shape. Teams that built a real cookie consent and privacy process already have the muscle for this: find where the thing happens, write down what it does, disclose it in plain language, keep a record. The mechanics of compliance are not new even though the rules are.
What is different is that a lot of this lands in the interface rather than in a policy page. A privacy policy nobody reads can absorb a paragraph. A chatbot disclosure has to be visible in the moment someone starts typing. That makes it a design problem for the website team.
We would treat it the same way we treat consent. Build it into the component once, in the design system, rather than bolting it onto each page. That is the difference between a change you make now and a change you keep making forever. Our guide to cookie consent on websites makes the same argument for the same reason.
What should a marketing team actually do this quarter?
Inventory first. List every place AI touches your public site: the chatbot, the search box if it is AI powered, generated images, AI drafted articles, any personalisation. Most teams cannot produce this list from memory, which is itself the finding.
Then sort each item into interacts with people, generates content, or neither. The first group needs a disclosure. The second group needs you to be honest about whether your review process is deliberate examination or a rubber stamp. The third group you can stop worrying about.
Then take it to your counsel with the inventory in hand rather than as an open question. A lawyer given a list of eleven specific things will give you a useful answer far faster than one asked whether the AI Act applies to you.
Is this going to keep moving?
Some of it will. The AI Act has already been amended, and the Commission adopted its guidelines on these transparency obligations on 20 July 2026, shortly before the rules applied. Guidance arriving weeks before a deadline is a sign that interpretation is still settling.
Our read is that the direction is stable even if the detail moves. Disclose that a machine is talking. Be able to show a person genuinely reviewed what you published. Do not pass off generated media as captured media. Those principles are unlikely to reverse, and building to them now is cheaper than retrofitting later.
We would not rebuild anything on the assumption of future rules, though. Build to what is written, keep the inventory current, and revisit when the next amendment lands.
Where does this leave AI on marketing sites?
In a better place than the headlines suggest. Nothing here bans AI features on a website. It asks you to say when a machine is involved and to mean it when you say a person reviewed something. Most of the sites we build would pass with a label change and a paragraph.
The teams that will struggle are the ones whose AI content pipeline has no genuine review step, because the honest fix is a process change rather than a disclosure. That is uncomfortable, and it is also the right outcome.
If you want help taking the inventory, or building the disclosure into a design system rather than page by page, we are happy to walk through it. Find us at phoenix.studio.
Want a site that performs like this?
Tell us about your project. We will come back with a clear next step, no pressure.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Have a project like this?
Tell us where you want to go. We'll tell you how we'd get you there.