• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar
OpenTechTips

OpenTechTips

Practical IT Guides, Expert Tips, and Real-World Solutions

MENUMENU
  • HOME
  • ALL TOPICS
    • Exchange
    • InfoSec
    • Linux
    • Networking
    • Scripting
      • PowerShell
    • SSL
    • Tools
    • Virtualization
    • Web
    • Windows
  • ABOUT
  • SUBSCRIBE
Home » EU AI Act Explained for Website Owners and Small Businesses

EU AI Act Explained for Website Owners and Small Businesses

August 5, 2026 - by Zsolt Agoston - last edited on August 5, 2026

The EU AI Act entered into force on August 1, 2024 and applies in stages. Prohibited-practice and AI-literacy rules started in 2025. Many provisions, including Article 50 transparency obligations, apply from August 2, 2026, while certain high-risk-system requirements follow later dates.

Saying “the AI Act starts in 2026” is therefore an oversimplification. A small website may have straightforward disclosure and staff-training tasks, while recruitment, credit, biometric, or safety uses can require a much deeper assessment.

Policy snapshot: July 26, 2026. This article provides general technical and compliance information and is not legal advice. The law, guidance, national enforcement arrangements, and your obligations may change or depend on specific facts.

What is the EU AI Act?

The Act is a risk-based legal framework. It prohibits certain uses, imposes obligations for high-risk systems and general-purpose AI models, requires AI literacy, and creates transparency rules for some interactive and synthetic-content systems. Many limited- or minimal-risk uses receive no special high-risk regime.

  • Prohibited practices: uses the law does not permit.
  • AI literacy: measures to ensure staff and operators understand appropriate use and risk.
  • Transparency: disclosures for specified interactive systems and generated or manipulated content.
  • High-risk systems: regulated uses affecting areas such as employment, education, essential services, biometrics, or product safety.
  • GPAI obligations: duties primarily directed at providers of general-purpose AI models.

Current application timeline

EU AI Act Explained for Website Owners and Small Businesses
High-risk dates differ from the broad August 2026 application date.
  • August 1, 2024: the Act entered into force.
  • February 2, 2025: prohibited practices, definitions, and AI-literacy provisions began applying.
  • August 2, 2025: governance and general-purpose AI obligations began applying.
  • August 2, 2026: broad application and Article 50 transparency rules.
  • December 2, 2027: current Commission information identifies this as the latest date for certain Annex III high-risk areas.
  • August 2, 2028: current information identifies this date for high-risk systems embedded in regulated products.

The final AI Omnibus changes entered into force in July 2026. Confirm the consolidated legal text before relying on a high-risk deadline.

Does the Act apply to a small website?

It depends on what the organization does and its legal role. A provider develops or places a system on the market under its name. A deployer uses an AI system under its authority. Importers, distributors, and product manufacturers have other roles. Simply using a general-purpose service does not automatically make a blogger the provider of the underlying model.

Small organizations are not universally exempt. Proportionality and some simplified measures exist, but role, risk, affected people, and intended purpose remain important.

Chatbots and disclosure

Article 50 generally requires people to be informed when they are interacting directly with an AI system unless this is obvious to a reasonably informed, observant person, with additional legal details and exceptions. Place disclosure before or at the start of the interaction, make human assistance easy to find, and avoid presenting the bot as a human employee.

Example for discussion: “This chat is handled by an AI system. Responses may be incorrect. Contact our staff for human assistance.”

This example is not guaranteed legal wording. Adapt it to the service, language, audience, and professional advice.

AI-generated and manipulated content

Article 50 separates duties. Providers of systems that generate synthetic audio, image, video, or text may need machine-readable marking. Deployers may need to disclose deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. Exceptions and treatment differ where content receives human review or editorial control and a person holds editorial responsibility.

Do not reduce this to “label everything made with AI.” Spelling correction, brainstorming, a human-written article based on an outline, mostly generated public-interest text, and a realistic synthetic video present different facts. Document the human review, editorial responsibility, and reason for the chosen disclosure.

AI literacy for employees

Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf, considering knowledge, experience, context, and affected people. The law does not prescribe one universal certificate or course length.

  • Define approved tools and prohibited data.
  • Teach verification of factual outputs and escalation of consequential decisions.
  • Cover hallucinations, bias, privacy, security, and prompt injection.
  • Record basic training, audience, date, and material.

Common uses and risk signals

  • Customer-service chatbot: assess Article 50 disclosure, privacy, accuracy, and human handoff.
  • Marketing text and product images: assess misleading claims, consumer law, copyright, and synthetic-content rules.
  • Office productivity: set data and verification rules; usually not high-risk merely because AI is used.
  • CV ranking, employee monitoring, credit, insurance, and biometrics: obtain specialist review because these may fall into sensitive or high-risk categories.

Ten practical actions

  1. Inventory every AI tool and embedded feature.
  2. Identify your provider, deployer, or other role.
  3. Remove prohibited uses.
  4. Train staff and record the training.
  5. Document data sources, recipients, decisions, and affected people.
  6. Add appropriate chatbot disclosures and human handoff.
  7. Review synthetic-media and public-interest labeling.
  8. Maintain meaningful human review.
  9. Review vendor contracts, instructions, logs, and documentation.
  10. Obtain legal advice for high-risk or ambiguous uses.

Frequently asked questions

Does the AI Act apply outside the EU?

It can have extraterritorial reach, including where a system is placed in the EU market or its output is used in the EU. Get advice for cross-border cases.

Must every AI-written blog post be labeled?

No blanket rule says every AI-assisted sentence must be labeled. Article 50’s public-interest text rule, human review, editorial responsibility, deepfake provisions, and other laws must be assessed.

Does GDPR still apply?

Yes. The AI Act does not replace GDPR, consumer-protection, employment, intellectual-property, or sector-specific rules.

What are the fines?

Maximums depend on the violation. Article 50 enforcement information cites up to €15 million or 3% of preceding worldwide annual turnover, with proportionality for smaller organizations. Do not treat a maximum as the likely outcome in every case.

Verify your role and current consolidated law through EUR-Lex, the European Commission’s AI Act pages, and the AI Act Service Desk. Seek qualified legal advice for sensitive or high-risk uses.

Reader Interactions

Comments Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Tools

Secondary Sidebar

CONTENTS

  • What is the EU AI Act?
  • Current application timeline
  • Does the Act apply to a small website?
  • Chatbots and disclosure
  • AI-generated and manipulated content
  • AI literacy for employees
  • Common uses and risk signals
  • Ten practical actions
  • Frequently asked questions
  • Does the AI Act apply outside the EU?
  • Must every AI-written blog post be labeled?
  • Does GDPR still apply?
  • What are the fines?

  • Terms of Use
  • Disclaimer
  • Privacy Policy
Manage your privacy
We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}