Since August 2, 2026, the next stage of the EU AI Act has been in force. If you have googled the topic in recent days, chances are high that you have been reading outdated information: most articles you will find date from 2024 or 2025 and describe a timeline that no longer exists.
In the summer of 2026, the EU postponed key deadlines with the Digital Omnibus, its omnibus amendment package (Parliament on June 16, Council on June 29, 2026). What has actually applied to your website since August 2, what was postponed, and what you as a small or mid-size business can safely ignore: here is the verified state of play, with sources. Two Austrian institutions come up repeatedly, relevant if you operate in Austria or the DACH region: the RTR, whose KI-Servicestelle is Austria's official AI service desk, and the WKO, the Austrian Economic Chamber.
What actually applies since August 2, 2026
What was NOT postponed are the transparency obligations under Article 50. They have applied since August 2, 2026 and cover exactly the AI features found on ordinary business websites: chatbots, AI-generated content and deceptively real AI images. On top of that comes an obligation many overlook because it has already applied since February 2025: the AI literacy requirement for businesses that use AI (Article 4).
What was postponed
The heavy artillery of the AI Act, meaning the obligations for high-risk systems (risk management, conformity assessment, logging), was originally due to take effect on August 2, 2026 as well. The Digital Omnibus postponed it: to December 2, 2027 for standalone high-risk systems (such as AI in recruitment or credit decisions) and to August 2, 2028 for AI in regulated products. Anyone trying to sell you an expensive high-risk compliance program today is arguing with a deadline that no longer exists. These obligations also primarily target the manufacturers of the systems, not their users.
Chatbots must identify themselves as AI
Does your chatbot have to say that it is an AI? Yes, since August 2, 2026. Users must be told clearly, and at the latest at the first interaction, that they are communicating with an AI, unless it is obvious from the context. According to the WKO (in German), a notice at the start of the chat or on the input field is usually sufficient. The technical implementation is primarily the chatbot vendor's job, but as the operator you must make sure the notice is actually displayed on your website. This is a ten-minute task, not a compliance megaproject.
When AI texts and AI images must be labeled
Does AI-generated content have to be labeled? It depends, and it is less dramatic than often claimed. Deceptively real AI images, videos or audio (deepfakes) must be disclosed as AI-generated; a plain "Image: AI-generated" is sufficient according to the WKO. For texts, the labeling obligation only applies if they are published on topics of public interest AND no human editorial review takes place. A blog post that you create with AI assistance and then edit and take responsibility for yourself needs no label. For systems that were already on the market before August 2, 2026, a transition period for the machine-readable labeling additionally runs until December 2, 2026.
The quiet obligation since February 2025: AI literacy
Article 4 also obliges pure AI users, in practice every business where employees work with AI tools, to ensure sufficient AI literacy. No specific minimum content is prescribed; Austria's AI service desk at the RTR (KI-Servicestelle) (in German) recommends covering the basics, legal and ethical aspects, and internal guidelines. There is no direct AI Act fine for violations, but the RTR points to the civil-liability angle: if you let unqualified employees work with AI, damage they cause can be attributed to you as negligence. A documented short training session is the cheapest insurance here.
What does NOT affect you as a website operator
By its own account, the EU Commission classifies the large majority of AI systems used in the EU as minimal risk, with no specific obligations. For webshops, according to the assessment of specialist lawyers, that concretely means: product recommendations, AI-powered search and filters, spam filters and the usual marketing tools trigger no new AI Act obligations. Things only change when AI makes decisions in sensitive areas, for example applicant screening or creditworthiness, and even there the obligations only apply from December 2027.
Fines put in honest perspective
Yes, the ranges are high: violations of the transparency obligations can cost up to 15 million euros or 3 percent of worldwide turnover. But panic articles tend to leave out two things. First: for SMEs, the LOWER of the two values explicitly applies, and the authorities must take proportionality, severity and cooperation into account (Article 99). Second: according to the RTR, Austria has not even named its national market surveillance authority yet. The obligations still apply directly, but the realistic scenario for a missing chatbot notice is a request to fix it, not a multi-million fine. Labeling is mandatory and costs almost nothing. Panic is unfounded.
Do not forget the GDPR
The AI Act does not replace the GDPR; both apply in parallel. If your chatbot processes personal data, you need, as before, a legal basis, a data processing agreement with the vendor, an updated privacy policy and clarity on whether chat data is used to train the model (without a legal basis: no). EU hosting or properly secured third-country transfers remain on the agenda. If you set this up cleanly, you take care of AI Act transparency and the GDPR in one pass.
Checklist: what you should do now
- AI inventory: list where AI is in use on your website, in your shop and in your tools, including hidden AI features in standard software.
- Clarify your role: if you merely use third-party AI, you are a deployer and have far fewer obligations than the provider.
- Label your chatbot: a clear AI notice at the start of the chat or on the input field.
- Label deceptively real AI images: "Image: AI-generated" is enough.
- Document your editorial process: human review of AI texts makes labeling for texts unnecessary.
- Run and document a short training session: the literacy obligation has applied since February 2025.
- Vet your chatbot vendor: data processing agreement, EU hosting, training use of the data, update your privacy policy.
Clarity instead of guesswork: the free AI check before December 2, 2026
No reason to panic, but a concrete timeline: the transparency obligations under Article 50 have applied since August 2, 2026, and on December 2, 2026 the transition period for the machine-readable labeling of existing systems ends. Instead of ploughing through legal texts yourself, let us take a look: in our free AI check we review your chatbot disclosure, the labeling of AI content and the GDPR side of your AI features, plus a quick look at performance and accessibility. You receive a written assessment with clear priorities, free of charge and without obligation. We get back to you within one business day.
Afterwards you know exactly what needs to be done, in what order, and what can wait. If you want support with the implementation, we discuss it in a free initial consultation.
Important: this article is not legal advice but a technical, practical assessment based on the sources linked below. For binding questions, your legal counsel belongs at the table; we implement the technical side. If you are planning an AI feature on your website or want to integrate an existing one cleanly and in line with the GDPR, from chatbot disclosure to the architecture behind it: book a free initial consultation. For regulated industries, we have summarized the legal framework for webshops here.
Sources
- RTR KI-Servicestelle (Austria's AI service desk): FAQ on the AI Act (in German)
- WKO: AI in business, what additionally applies from August 2, 2026 (in German)
- WKO: The EU AI Act, obligations for companies (in German)
- EU Commission: Regulatory framework for AI (current timeline)
- European Parliament: Digital Omnibus on AI (legislative history)
- AI Act Explorer: Article 99 (penalties, SME rule)
- Dr. Datenschutz: Chatbots and data protection (German-language analysis)
