Cybersecurity

The AI Act: what it requires from your website and marketing from 2 August 2026

The ScaleLab teamPublished 8 min read

In short: From 2 August 2026 the transparency obligations in Article 50 of the EU AI Act apply. For your website and marketing that means three things: a chatbot must clearly say it is AI, realistic AI-generated or manipulated images, video and audio (deepfakes) must be labelled, and AI text published to inform the public on matters of public interest must be disclosed unless a person has reviewed it and takes editorial responsibility. The Digital Omnibus on AI postponed the rules for high-risk systems, but Article 50 still applies.

What actually took effect on 2 August 2026?

The AI Act is an EU regulation (Regulation (EU) 2024/1689) that applies in stages. From 2 August 2026, Article 50 applies. It deals with transparency: people should know when they are talking to AI or looking at content created or altered by AI.

The regulation distinguishes two roles, and for marketing the difference matters:

  • Provider: whoever develops an AI system, or places it on the market or puts it into service under their own name or trademark.
  • Deployer: whoever uses an AI system in their professional activity. A company that creates ad visuals with an off-the-shelf tool is, as a rule, a deployer.

The duty for a chatbot to say it is AI formally sits with the provider. The duties on deepfakes and on public-interest text sit with the deployer, which is often the company publishing the content. The information has to be clear and distinguishable and given no later than the first interaction or first exposure to the content.

What did the Digital Omnibus on AI postpone, and what not?

In 2026 the EU adopted amendments to the AI Act known as the Digital Omnibus on AI. The political agreement came on 6 and 7 May 2026, the European Parliament voted on 16 June, the Council approved it on 29 June, it was signed on 8 July and it has been in force since 27 July 2026.

What changed:

  • High-risk systems in Annex III: the rules are postponed to 2 December 2027.
  • AI in regulated products: the rules are postponed to 2 August 2028.
  • The AI literacy duty in Article 4: softened.

What did not change: Article 50 applies from 2 August 2026. The only relief concerns machine-readable marking of generated content under Article 50(2): systems placed on the market before 2 August 2026 have until 2 December 2026. That duty falls on the providers of the tools, not on the companies using them.

In short for marketing: the postponement barely touches day-to-day work on your website and advertising. The transparency rules apply now.

Who needs to act, and on what?

A chatbot on your website

If your website has a chat assistant that answers visitors, they must be able to tell they are talking to AI, unless that is obvious from the context. Where the bot was built for you but runs under your brand, check with a lawyer whether you may count as the provider. Our recommendation is that, whatever the role, the bot introduces itself clearly in its very first message. How to build such an assistant without losing enquiries is covered in our article on an AI chat assistant for enquiries.

Deepfakes and synthetic images and video in advertising

The regulation defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places or events and would falsely appear to be authentic. A video made with AI using the face or voice of a real person falls into this category. An ad with a realistic generated person presented as a genuine customer may also fall into it, so our recommendation is to label it. How to work with such visuals on social media is covered in our article on AI creative in Meta ads. For evidently artistic, satirical or fictional work the duty is lighter: it is enough to disclose that such content exists, in a way that does not spoil the work.

AI text on matters of public interest

Text generated or altered by AI and published to inform the public on matters of public interest must be disclosed as such. The exception is where the text has gone through human review or editorial control and someone holds editorial responsibility. According to the European Commission, a superficial check such as fixing spelling and grammar is not enough. If your company publishes material on topics such as health, finance or the environment, this concerns you directly.

Situation Company’s role What to do
Chatbot on the website Often deployer, sometimes provider Clear AI notice in the first message
Realistic AI person in an ad Deployer Visible label in the ad itself
AI article on a public-interest topic Deployer Accountable human review, or a label
Generated product banner Deployer Check whether it looks like a real event or person

ScaleLab tip: When you are not sure whether a visual is a deepfake, ask whether a viewer would believe it is a photo of something real. If the answer is yes, label it.

What should you do now? A practical checklist

1. Make an inventory of AI tools

Put every AI tool your company uses in public-facing work in one place: chatbots, image and video generators, writing tools, voice assistants, generation features in advertising platforms. For each one, note what it is used for, who is responsible for it and whether its output reaches customers.

2. Prepare disclosure texts

Write short, clear texts the team can use consistently: for the chatbot (“I am an AI assistant for …”), for visuals and video (“This image was created with AI”), for articles (“This text was prepared with the help of AI”). Think about accessibility too: the label has to be visible and readable on a phone.

3. Introduce internal approval of AI content

Decide who reviews AI content before it is published and what exactly they check: facts, tone, whether an image could mislead. Keep a record of the review. If you rely on the human review exception for public-interest text, this process is your evidence that the review is genuine.

4. Ask your suppliers the right questions

Ask the suppliers of your chatbot and generation tools:

  • Disclosure: how does the system tell users it is AI, and can you change the wording?
  • Marking: does the tool mark generated content in a machine-readable way, and from when?
  • Data: where are conversations and the data you enter processed, and are they used for training?
  • Roles: who is the provider under the AI Act, and what does the supplier take on under the contract?

ScaleLab tip: Add the AI Act questions to your annual review of supplier contracts. That way you will not have to chase them separately every time you change a tool.

What does this mean for your business?

The good news is that for most companies Article 50 does not call for expensive systems. It calls for clarity: knowing which AI tools you use, telling people when they are looking at AI, and having someone accountable for what gets published.

Remember that AI tools work with data: chatbot conversations, forms, files the team uploads. So the AI Act and data protection go hand in hand, and the security of these tools is part of your company’s overall security. We explain the cybersecurity requirements for mid-sized companies in our article on NIS2 requirements.

This article is general information, not legal advice. How the AI Act applies to a particular case depends on the facts, and the European Commission’s guidance continues to develop, so check the current texts and consult a lawyer. Our recommendation is to start with an inventory of systems and data, then set rules, texts and accountable people. To see how we protect websites and help with GDPR requirements, visit cybersecurity and data protection.

Frequently asked questions

Did the Digital Omnibus on AI postpone the chatbot and deepfake rules?

No. The Digital Omnibus on AI postponed the high-risk rules to 2 December 2027 and 2 August 2028. Article 50 on transparency applies from 2 August 2026. Only providers of systems placed on the market before that date have until 2 December 2026 for machine-readable marking.

Do I have to label every visual made with AI?

The deployer’s duty covers deepfakes: realistic content that resembles existing persons, objects, places or events and would appear authentic. In our view, a stylised illustration nobody would mistake for a photo usually does not qualify. When in doubt, labelling is the safer choice.

Who is responsible for the website chatbot, the company or the supplier?

The duty for a chatbot to say it is AI sits with the provider, meaning whoever developed the system or places it on the market under their own name or trademark. If the bot runs under your brand, check your role with a lawyer. In practice, the bot should introduce itself clearly either way.

Do I have to disclose that a blog article was written with AI?

The duty covers text published to inform the public on matters of public interest. If the text has been reviewed by a person who holds editorial responsibility, the exception may apply. A superficial spelling check is not enough.

Sources

Related articles

  • Paid advertising

    Advertising healthcare, finance and other regulated services: how to get past the review

    In healthcare, pharma, finance and insurance, advertising platforms add their own rules: certification, advertiser verification, restricted targeting and required information on the landing page. Rejected ads often come down to a missed step rather than the message itself. Plan the checks, the sign-off and the approval time before the campaign, and take legal questions to a lawyer.

    9 min read

  • Email and automation

    How do you advertise and measure without relying on third-party cookies?

    Third-party cookies are becoming less reliable because of consent rules, browsers and people who decline tracking, even though Chrome is not removing them. A company can advertise and measure steadily by relying on its own data: enquiries, orders and an email list of people who signed up themselves. Add clearly requested consent, contextual advertising and tracking tied to real sales.

    9 min read