Regulation · 14 August 2026

Since 2 August 2026, Article 50 of the European regulation on artificial intelligence applies. A chatbot or AI agent that talks to people must disclose that the counterpart is not a human, unless that is obvious. For a French VSE or SME that has put an assistant on its website, extranet or switchboard, this is no longer a watch item: it is a deployer obligation, with fines of up to €15 million or 3% of worldwide turnover.

What actually changed on 2 August

Article 50 targets transparency of interactions and of content. Three points concern a director who already has an agent in production.

First: systems that interact with people must disclose that the user is talking to AI, unless it is obvious. An “assistant” widget on a contact page is not obvious. A discreet banner at the foot of the chat is not either, if it appears only after three messages. The information must be given in time, in an understandable form, before the customer takes a decision on the strength of the reply.

Second: synthetic content (audio, image, video, text) must carry a machine-readable marking. Systems already placed on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking under Article 50(2). That is not a free pass for user information: the duty to inform about the interaction is already in force.

Third: deepfakes used in a professional setting must be labelled visibly. AI-generated text of public interest must indicate the use of AI if it has had only limited human review. An SME that publishes press releases, product pages or automated replies on social networks is not off-topic.

What this means for a VSE or SME director

The regulation distinguishes the provider (the one who places the model or system on the market) from the deployer (the one who uses it under their authority). An SME that installs a chatbot on its site is a deployer. It must inform users. It cannot shift that onto the model vendor, American or European, nor onto the integrator that delivered the widget.

Prohibited practices (manipulation, social scoring, and so on) fall under another regime, already applicable, with higher caps: up to €35 million or 7% of worldwide turnover. Article 50 is the transparency strand. It is the one your customers, your staff and a controller will see first: the screen, the banner, the generated file.

Patrick Dajan Mouelle, director of Cybernecs, puts it this way: compliance is decided on the real journey. If a prospect asks a price question without ever reading that they are talking to a machine, you are not compliant, even if your AI policy runs to twenty pages.

Deployer checklist: six actions to handle now

  • Map the contact points. List every chatbot, voice agent, assisted form, internal bot (HR, support, sales) and every flow that generates text, image or audio intended for a third party. Without an inventory, there is no compliance.
  • Display the information from the first exchange. A clear sentence at the top of the conversation, not only in the legal notices. Example: “You are speaking with an automated assistant. A human can take over on request.”
  • Provide a human hand-off. The transparency duty does not require a human 24 hours a day. It requires honesty. A “talk to an adviser” button and a stated delay beat a fake first name and a stock photo.
  • Handle generated content. If you publish visuals, voice-overs or texts produced by AI, plan for machine-readable marking (watermark, metadata) and, for deepfakes in professional use, the visible label. Systems predating 2 August 2026 have until 2 December 2026 for the machine-readable marking under Article 50(2).
  • Align GDPR and the AI Act. Telling someone they are talking to AI does not replace information on personal data. Legal basis, retention of conversations, transfers outside the EU: a GDPR compliance audit and an AI Act review overlap on the same customer journey.
  • Train the people who deploy. Article 4 on AI literacy has applied to providers and deployers since 2 February 2025. A salesperson who “plugs in” an agent without knowing what must be displayed is an operational risk, not an HR detail. See our AI and cybersecurity training.

What you do not have to rush

High-risk systems under Annex III are postponed to 2 December 2027. Embedded systems under Annex I are postponed to 2 August 2028 (Digital Omnibus, Regulation EU 2026/1744, in force since 27 July 2026). An appointment-booking chatbot is not, by that fact alone, a high-risk system. Do not confuse transparency (already due) with a conformity assessment file (not yet required for most VSE/SME uses).

Do not, however, postpone the disclosure. The transparency sanctions are already in the text. For an SME, the most immediate risk remains the unhappy customer, or an inspection that starts from the homepage.

Where Cybernecs steps in

We design AI agent solutions for VSEs and SMEs with user information built into the journey. For a review (wording, logs, marking), write to us via the contact page. The aim is not to stack disclaimers. It is honest use, readable, tenable in front of a customer as in front of a regulator.

Sources: Artificial Intelligence Regulation (AI Act), Regulation EU 2026/1744 (Digital Omnibus), Touteleurope, L’Express.

Articles de la même catégorie