The AI Act took effect on 2 August: what your website must do now

On 2 August 2026 the transparency rules of the European AI regulation took effect — and with them the power to impose fines. French newsletters have been full of 15-million-euro headlines ever since. Let us go through the official text and see what actually applies to the owner of a small website: the answer is shorter than the scare.

This is a news article. It explains what is changing and by when, and is not legal advice. Interpretations of the regulation are still being refined — check the official sources linked in the text before acting.

What exactly took effect

As of 2 August 2026, the transparency obligations (Article 50 of the regulation), the rules for general-purpose models, the bans on certain practices and — more importantly — the power of supervisory authorities to impose penalties all apply. Before that date the requirements formally existed, but nothing enforced them.

The regulation sets two further dates after this one, and they are constantly confused with it. Here is the full timeline.

Already in force 2 August 2026

Transparency duties, the bans, the rules for general-purpose models and — above all — the authorities’ power to impose penalties. The AI literacy requirement for staff has applied since February 2025.

Grace period 2 December 2026

End of the limited grace period on marking for systems that were already running before the rules took effect.

Postponed 2 December 2027 and 2 August 2028

Deadlines for high-risk systems — recruitment screening, scoring, medical devices. Those are what the amendment package pushed back, not transparency.

Most of the duties are not yours

The regulation splits everyone into two roles, and which one you are in decides everything.

A provider develops an AI system or places it on the market under its own name: OpenAI, Mistral, the company behind the chat widget you installed. A deployer uses someone else’s system in their professional activity. That is you, if you put that widget on your café’s website.

And here is the point: paragraphs 1 and 2 of Article 50 are addressed to the provider. The duty to make sure a person understands they are talking to a machine sits with whoever built the machine. So does the duty to mark generated content in a machine-readable format. A site owner has to neither design a marking method nor embed invisible watermarks in images.

One caveat worth knowing: the European Commission’s guidance states that a legal person remains the deployer even when a third party operates the system on its behalf, and that it must ensure compliance in its own specific context of use. “It is not my software” will not protect you — but you are not expected to do someone else’s job either. In practice this means one thing: check that the chat you bought actually introduces itself as a chat.

What genuinely is yours: four points

1. A chatbot must be recognisable. If there is an assistant on your site, the visitor must understand they are dealing with a program, at the latest at the first interaction. There is an explicit exemption: if this is obvious to a “reasonably well-informed, observant and circumspect” person, no separate warning is required. A widget labelled “Chatbot” or “Automated assistant” falls under that exemption. A widget with a first name, an avatar and “hello, my name is Claire” does not.

2. Deepfakes must be disclosed. If you publish an image, audio or video showing a real person, place or event in a way that did not happen, you must disclose it. For artistic, satirical and fictional works the exemption is softer: it is enough to note the fact without spoiling the work.

3. AI-generated text must be labelled — but only on matters of public interest. This is the point most often reported wrongly. It is not about any text, but about material published to inform the public on matters of public interest: the Commission names politics, justice, public health and environmental protection. A café menu, a salon’s list of services or the story of your workshop do not qualify. And even where they do, there is an exemption — see the next section.

4. Emotion recognition and biometric categorisation must always be disclosed. This one is a deployer duty, with no softening: if a system on your premises detects emotions or sorts people into categories by biometrics, you must inform the people exposed to it and comply with data protection rules on top. For most readers this is not their situation — but if someone is selling you a “smart display that analyses customer reactions”, know what you are signing up for.

Why a blog a human actually reads needs no label

The duty to label AI-generated text does not apply where the material has undergone human review or editorial control and a person holds editorial responsibility for the publication.

Importantly, the Commission has spelled out what counts as that review: deliberate examination by one or more natural persons with relevant expertise — not spell-checking or grammar correction. Running a text through a spellchecker and calling it edited will not do. Reading it, judging it on substance, sending it back for revision and standing behind the result under your own name will.

This is not a loophole; it is a rule written down in plain terms. And it describes exactly the kind of work you should be doing on your texts anyway.

The postponement does not cover these rules

A package of amendments discussed in the spring pushes part of the requirements back: Annex III systems to 2 December 2027, Annex II systems to 2 August 2028. Many articles concluded from this that “everything has been postponed, no rush”.

Something else was postponed. Transparency, the AI literacy requirement, the bans, the rules for general-purpose models and the power to impose penalties all stayed at 2 August 2026. The delay covers high-risk systems — which is not the chat on a café website, but recruitment screening, credit scoring, medical devices and the like.

One more duty almost nobody writes about

Article 4 of the regulation has applied since February 2025 and requires both providers and deployers to ensure a sufficient level of AI literacy among the people working with these systems. Company size makes no difference.

If you work alone, the “staff” is you. There is no formal exam and nobody will ask for a certificate. The point of the requirement lies elsewhere: if you use a tool in your work with clients, you must understand where it gets things wrong. Which is, incidentally, the best practical reason to understand the tool rather than merely use it.

Fines, enforcement and the grace period

The ceiling is 15 million euros or 3% of worldwide turnover. For small and medium-sized enterprises the lower of the two applies, so for a micro-business this means a figure tied to its own turnover, not the millions in the headlines.

Enforcement rests with national authorities. In France, the scheme presented in September 2025 is a distributed one: the DGCCRF handles operational coordination and general market surveillance, the DGE handles strategic coordination, and actual checks are spread across roughly fifteen existing sector regulators, with technical support from ANSSI and PEReN. The formal designation of some authorities is still being settled — treat it as something to verify rather than as finally decided.

Separately: for systems already in service before the rules took effect, a limited grace period on marking runs until 2 December 2026.

What to do this week

  1. Open your site and look at the chat, if you have one. Is it clear within three seconds that this is a program? If not, rename the widget and add one line to the greeting.
  2. Check which tool you installed and who provides it. If it is an assistant built into a booking service or your site builder, the marking duty is theirs — but making sure they meet it is on you.
  3. If you publish texts made with AI, arrange genuine editing. Not spell-checking: a reading on substance by someone who knows the subject and answers for the publication. Then no label is needed.
  4. If someone is selling you emotion analysis, facial recognition or “smart” video analytics — stop and look into it separately. It is the one item on this list where deployer duties are strict and admit no exemption.
  5. Everything else is not your concern. Machine-readable marks, technical model documentation and conformity assessments all sit with providers.

In short

The rules apply, penalties back them, and none of this is cause for panic. For the owner of a small website in France the new duties come down to three things: do not pass a bot off as a human, do not pass generated video off as footage, and genuinely read what you publish under your own name. Everything else the regulation addresses to those who build the tools, not to those who use them.

If you do not have a website yet, or yours was thrown together in a hurry, start with the foundations: the guide “A website for a micro-entrepreneur” covers which pages French law requires, why you need a consent banner, and what changes when you add a chat or analytics.

Information is current as of 17 August 2026 and matches the official text of the regulation and the European Commission’s guidance, both linked in the text. Webinkub accepts no responsibility for changes in legislation or for decisions taken on the basis of this article. If you use biometrics or systems that screen people, consult an avocat.

Get in touch

Not sure whether this applies to you?

Tell me who you work with — businesses or private individuals. I’ll tell you what to do and by when.

Want your whole situation looked at?

Mentoring covers the whole path: from registration to reporting and choosing your tools.