This is not legal advice. JNET.support is an AI implementation consultancy, not a law firm. Everything below quotes the official text and the European Commission’s own guidance so you can check it yourself, and the points where a business genuinely needs a lawyer are marked. If you have real EU exposure, take advice.

The direct answer

The EU AI Act can apply to a UK business even though the UK left the EU, and it does not depend on having an EU office. Article 2(1)(c) catches providers and deployers established in a third country

“where the output produced by the AI system is used in the Union”

So the test is where your AI’s output lands.

From 2 August 2026, the transparency obligations in Article 50 apply. In practice, for a typical UK small or medium business, that means two things:

  1. If you run a chatbot or AI assistant that talks to people, those people must be told they are dealing with AI, unless it is genuinely obvious.
  2. If you publish AI-generated or AI-manipulated content in certain categories, you must disclose that.

Most SMEs are deployers, and deployers carry the lighter half of Article 50. The expensive mistake is drifting from deployer to provider without noticing.

If your AI use is entirely internal, entirely UK-facing, and produces no output that reaches an EU audience, Article 50 does not reach you. But the “reaches an EU audience” test is broader than most people expect.

What changes on 2 August 2026

Under Article 113, 2 August 2026 is the Regulation’s general application date. Every other date is an exception to it:

DateWhat applies
1 August 2024The Act entered into force
2 February 2025Chapters I and II (definitions, Article 4 AI literacy, Article 5 prohibited practices)
2 August 2025GPAI model rules, governance, and the penalty chapter
2 August 2026General application, including Article 50 transparency
2 August 2027High-risk AI embedded in regulated products (Article 6(1))

Note the second row. Article 4 has applied since February 2025, eighteen months before the date everyone is planning around. If your use falls within Article 2(1)(c), that obligation has been live on you the whole time.

The amendment that has not been published yet

The Digital Omnibus on AI (procedure 2025/0359(COD)) was signed on 8 July 2026. Its status on the European Parliament’s Legislative Observatory is “Procedure completed, awaiting publication in Official Journal.”

It is therefore not yet law. The AI Act’s EUR-Lex record carries no amendment, and no consolidated version exists. The Omnibus defers parts of the high-risk regime. It does not delay Article 50. Commission Communication C(2026) 5054 final states plainly that

“the transparency obligations are directly applicable as from 2 August 2026.”

The Omnibus does introduce one narrow grace period relevant here: for generative systems already on the market before 2 August 2026, the Article 50(2) marking obligation gets a transitional period to 2 December 2026. The Commission is already describing that as operative, but it cannot take effect until the Omnibus is published in the Official Journal. If you are relying on that grace period, check whether it has been published before you do.

And the guidance is still in draft

The Commission’s Article 50 guidelines were approved on 20 July 2026, in draft only. The governing document says:

“The Guidelines will be formally adopted by the Commission at a later date, when all language versions are available. It is only from that moment that these Guidelines will be applicable.”

The accompanying Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026 and assessed as adequate by the Commission on 8 July 2026. It is voluntary, it has not been approved by implementing act, and both the Code and the Commission’s opinion state that adherence “does not constitute conclusive evidence of compliance.” That is weaker than the equivalent regime for general-purpose AI models, which does confer a presumption of conformity.

There is also no technical standard. The Code says so itself:

“At the time of publication of this Code, relevant interoperability standards and/or best practices are yet to be developed, except for digitally signed metadata.”

That leaves a hard obligation date, an amendment in transit, guidelines in draft, and no harmonised standard. It is the state of play eleven days out, and it is why the practical advice below is about records and defensible decisions rather than certification.

The provider or deployer distinction decides everything

Article 50 splits its duties, so getting your category right decides what you owe.

Article 3(4) defines a deployer:

“‘deployer’ means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”

Article 3(3) defines a provider as someone who develops an AI system, or has one developed, and

“places it on the market or puts the AI system into service under its own name or trademark”

If you buy ChatGPT, Copilot, a Claude subscription or an off-the-shelf chatbot and use it in your business, you are a deployer. You did not build it and you are not selling it under your name.

That matters because the duties divide like this:

ObligationFalls on
50(1) Tell people they are interacting with AIProvider (built into the system’s design)
50(2) Mark synthetic output as machine-readableProvider
50(3) Disclose emotion recognition / biometric categorisationDeployer
50(4) Disclose deepfakes, and certain published AI textDeployer

A deployer’s direct Article 50 duties are 50(3) and 50(4). The marking obligation in 50(2) belongs to the vendor whose model you are using.

How a deployer accidentally becomes a provider

This is the highest-value risk in the whole article, and it is commonly explained wrongly.

You will find commentary claiming Article 25 turns you into a provider if you put your name on a system or substantially modify it. Article 25 applies only to high-risk AI systems. Every limb of it is scoped to high-risk, and its consequence is expressly the high-risk provider obligations in Article 16. Citing it as a general rule about transparency would be a plainly wrong statement of law.

The correct route is Article 3(3). You become a provider by developing or commissioning a system and putting it into service under your own name or trademark. The Commission’s guidelines give the concrete case:

“If a company takes an already existing generative AI system placed on the market by another provider and modifies that system (e.g. with new training data), which it afterwards puts into service under its own name or trade market, then that company becomes a provider of the new system”

So the line runs roughly here:

  • Configuring, prompting, or connecting a bought-in tool to your data → still a deployer
  • Taking that tool, modifying it, and offering it to your customers under your brand → now a provider, and 50(2) marking becomes yours

Worth taking advice on. If you white-label an AI chatbot to your own customers, this is the transition that changes your legal category. Get advice before launch.

Decision tree

Does Article 50 reach you, and as what?

  1. Does any output of your AI reach people in the EU? No, and it is not foreseeable. Article 50 does not apply to you. Stop here, but keep a note of why you concluded that. Yes, or you direct it there. Continue.
  2. Did you build the system, or put it into service under your own name or trademark? Yes. You are a provider. Duties 50(1) and 50(2) apply, so design the AI disclosure in and mark synthetic output machine-readably. No, you are using someone else's tool. You are a deployer. Continue.
  3. Does it do emotion recognition or biometric categorisation? Yes. 50(3) applies. Inform the people exposed to it, and handle the personal data under UK GDPR / GDPR. No. Continue.
  4. Do you generate or manipulate image, audio or video that resembles real people, places or events? Yes. That is a deep fake under Article 3(60). 50(4) applies, so disclose it. Reduced disclosure if the work is evidently artistic or satirical. No. Continue.
  5. Do you publish AI-generated text to inform the public on a matter of public interest? Yes, and nobody reviewed it. 50(4) applies, so disclose it. Yes, but a person reviewed it and holds editorial responsibility. Exempt. This is the practical answer for most marketing teams.

Simplified for orientation. The exemptions have conditions, and the tree does not replace reading Article 50 or taking advice.

When a person must be told they are interacting with AI

Article 50(1), verbatim:

“Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.”

Two practical points.

This obligation is on the provider. If you deploy a bought-in chatbot, the disclosure should be built into the product. That does not mean you can ignore it. If the vendor has not done it, you are running a system on your site that does not comply, and your customers will hold you responsible regardless of where the legal duty formally sits.

Do not rely on “everyone knows it’s a bot.” The Commission reads the exemption narrowly:

“The exception should be interpreted restrictively given that it deprives natural persons from the protection and the right to be informed… The general awareness of consumers and other natural persons that AI systems (including chatbots and agents) exist does not imply that they recognise them in interactions.”

Article 50(5) sets the timing: the information must be given

“in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”

and must “conform to the applicable accessibility requirements.” A disclosure buried in a terms page does not satisfy that. A line in the chat window’s opening message does.

When AI-generated content needs disclosure or marking

Two separate duties that get conflated.

Marking (50(2)) is the provider’s job. Output of generative systems must be

“marked in a machine-readable format and detectable as artificially generated or manipulated”

with technical solutions that are “effective, interoperable, robust and reliable as far as this is technically feasible”. There is an exemption where the system “performs an assistive function for standard editing” or does not substantially alter the input data or its semantics. That is why grammar and spell-checking tools are not caught.

The voluntary Code asks for a multi-layered approach, minimum two layers: digitally signed, time-stamped, tamper-evident metadata where the format supports it, plus imperceptible watermarking, still expected for free-form text over 200 tokens. Signatories also commit to watermark-detection interoperability by 2 February 2027.

Disclosure (50(4)) is the deployer’s job, and covers two things:

Deepfakes. Article 3(60) defines a deep fake as AI-generated or manipulated image, audio or video content “that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”. If you generate that and publish it, disclose it. Where the content is part of an “evidently artistic, creative, satirical, fictional or analogous work”, the duty reduces to disclosing existence “in an appropriate manner that does not hamper the display or enjoyment of the work”.

Text published to inform the public on matters of public interest. This one has an exemption most businesses will fall inside:

“This obligation shall not apply… where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.”

If a person reviews your AI-drafted content and someone holds editorial responsibility, the disclosure duty does not bite. That is a strong argument for having a named editorial owner anyway.

Four worked examples

1. A customer-support chatbot on your website

You are a deployer of a bought-in tool. The 50(1) disclosure duty formally sits with the provider, but the disclosure has to be present in what your customers see. Check your vendor has it; if not, add an opening line. If the bot reaches EU customers, you are within scope via Article 2(1)(c).

What to do: confirm the disclosure appears at first interaction. Record who checked and when.

2. An internal AI assistant over your own documents

You are a deployer. If it is genuinely internal, meaning staff only and no EU-facing output, Article 50’s disclosure duties largely do not engage, because 50(1) is a provider duty and 50(3)/50(4) turn on emotion recognition, deepfakes or published public-interest text.

If this assistant genuinely produces no output used in the EU, the Act does not reach it, and that includes Article 4. If anything else you run puts you in scope under Article 2(1)(c), Article 4 has applied to you since February 2025, and it is the obligation nobody diarised.

What to do: treat this as a training and record-keeping question. Scoping an internal assistant properly, with approved sources, permissions and review points, is the same work that makes an Article 4 position defensible.

3. A marketing content workflow

You draft blog posts, social copy and email with AI, and a person edits before publication.

For most marketing content, 50(4) does not engage at all. It is not a deepfake, and ordinary commercial marketing is not “informing the public on matters of public interest”. Where it might edge into that category, say a piece on a public health or policy topic, the human review and editorial responsibility exemption is the answer.

What to do: make the review real and name who holds editorial responsibility. If you generate images that depict real people or real events, you are into deepfake territory and disclosure applies.

4. Content published to inform the public on a matter of public interest

The narrowest and most misunderstood category. If you publish AI-generated text whose purpose is to inform the public about a matter of public interest, and no person has reviewed it under editorial responsibility, you must disclose that it was artificially generated.

What to do: if you are publishing unreviewed AI text on public-interest topics, review it. That does more for you than adding a disclosure label.

What Article 50 does not do

Worth stating clearly, because it is over-read in both directions.

  • It does not make your AI use lawful. Recital 137 is explicit: compliance with the transparency obligations “should not be interpreted as indicating that the use of the AI system or its output is lawful under this Regulation or other Union and Member State law”. UK GDPR, consumer law and the Article 5 prohibitions still apply on top.
  • It is not the high-risk regime. Article 50 is about telling people what they are dealing with. Conformity assessments, technical documentation and CE marking belong to a different chapter.
  • It does not cover accuracy. Nothing in Article 50 requires AI output to be correct.
  • Open source does not exempt you. Article 2(12) excludes free and open-source systems, “unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50”. The carve-out specifically does not rescue you from Article 50.
  • It is not a UK law. It reaches you through EU-facing output.

Where the UK sits

There is no UK AI Act, and none in the current legislative programme. The King’s Speech of 13 May 2026 contained no AI bill. The 2023 white paper approach still stands. Five cross-sectoral principles (safety and robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress) are applied by existing regulators within their existing remits, with no statutory duty attached. The current ministerial position, stated in June 2026, is that “most AI systems should be regulated at the point of use.”

The change that has landed for UK businesses is in data protection law. The Data (Use and Access) Act 2025 replaced Article 22 UK GDPR with new Articles 22A–22D, commenced 5 February 2026. Solely automated significant decisions on non-special-category data are now permitted on a wider range of lawful bases, subject to safeguards: information, the ability to make representations, human intervention, and contestability. Special category data keeps the stricter position.

The ICO’s headline AI guidance still reflects the old Article 22 framing. Its draft guidance on automated decision-making and profiling from March 2026 is the better reference, but it is draft.

One gap worth knowing about: as of this verification date, neither GOV.UK nor the ICO publishes guidance helping UK businesses assess their EU AI Act exposure, even though DSIT has acknowledged in a January 2026 explanatory memorandum that the Act “has extraterritorial effect”.

What the penalties come to for an SME

Article 50 breaches sit in the middle tier. Article 99(4) sets fines of up to €15,000,000 or 3% of total worldwide annual turnover, and paragraph (g) of that list is “transparency obligations for providers and deployers pursuant to Article 50”.

The part almost everyone reports backwards is Article 99(6):

“In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.”

For an SME it is the lower of the two. For a small UK company, 3% of turnover is the effective ceiling, and it sits well below the €15m headline. Article 99(1) also requires penalties to take into account “the interests of SMEs, including start-ups, and their economic viability.”

A preparation checklist

Practical, and doable before 2 August 2026.

  1. List every AI system in use, including the ones bought on a corporate card by one team.
  2. Classify each as provider or deployer. Bought-in and used as supplied is deployer. Modified and offered under your brand is provider.
  3. Establish EU exposure for each. Does the output reach people in the EU, and do you foresee or direct that? Write down the answer and the reasoning.
  4. Check every customer-facing bot discloses at first interaction, not in a policy page.
  5. Identify anything generating images, audio or video of real people or events. That is deepfake territory.
  6. Name an editorial owner for AI-assisted published content. This is what engages the 50(4) text exemption.
  7. Address Article 4 for every system with EU exposure. It has applied since February 2025. Proportionate training for the people using these tools, recorded.
  8. Ask your vendors, in writing, whether their output is marked machine-readably under 50(2) and whether they have signed the Code of Practice.
  9. Diarise a re-check for when the Digital Omnibus is published, because it changes the grandfathering position.

Records and ownership

You will not be able to prove much after the fact without a record made at the time. What is worth keeping:

  • The AI inventory, with owner, vendor, purpose and EU-exposure conclusion for each system.
  • The reasoning behind each provider/deployer classification, dated.
  • Evidence of the disclosures shown to users. A screenshot with a date is fine.
  • Training records for Article 4, covering who, when, and what.
  • Vendor correspondence about 50(2) marking.
  • A named owner for the whole picture. This is the one that decides whether any of the rest stays current.

None of that requires a compliance platform. A spreadsheet with dates and named owners will do more for you than a tool nobody updates.

Not rhetorical. These are the ones where an article cannot responsibly give you the answer.

  1. Given how our output reaches people, are we caught by Article 2(1)(c) at all?
  2. We white-label an AI tool to our customers. Are we a provider under Article 3(3)?
  3. Can we rely on the “obvious” exemption in 50(1) for our particular interface?
  4. Is our content “evidently artistic or satirical”, and is our editorial review sufficient to disengage the 50(4) text obligation?
  5. Which Member State’s market surveillance authority would have competence over us?
  6. How would “total worldwide annual turnover” be computed across our group?

The practical next step

If you are reading this eleven days before the date, start with an inventory rather than a compliance project. Every AI system in use, who owns it, whether its output reaches the EU, and whether anyone has been told what they are dealing with. Expect that exercise to show Article 50 exposure narrower than feared, and the Article 4 position on whatever is in scope weaker than assumed.

That inventory is part of what an AI readiness assessment produces anyway, because you cannot sensibly decide what to automate without knowing what is already running and who owns it. Where the answer is that staff need to understand these tools properly, role-specific training is the Article 4 answer. Where the Act reaches you, that obligation has been live since February 2025, eighteen months before the date everyone is watching. Training the people who use these tools is worth doing on its own merits either way.