← Back to the blog

The EU AI Act just went live. Here is what a UK SME actually has to do this month.

Toby Remond5 August 20266 min read
The EU AI Act just went live. Here is what a UK SME actually has to do this month.

The EU AI Act transparency rules went live on 2 August. Cue the scary posts about lawyers, compliance officers and six figure fines.

The boring truth is most UK SMEs need about twenty minutes and a two line disclosure.

This is not legal advice. If your business is regulated, or you sell into healthcare, finance, HR screening, or law enforcement, treat this as a nudge to go and read the actual text, or pay someone who has. For everyone else, here is what changed and what to ignore.

What the rules actually say

The bit that went live is Article 50. It covers transparency, not the scary stuff. Five obligations, in plain English:

  1. If a user is talking to a bot, tell them it is a bot.
  2. If you generate synthetic audio, video, images or text, mark it as AI generated in a machine readable way.
  3. If you publish a deepfake, say it is a deepfake.
  4. If you use emotion recognition or biometric categorisation on people, tell them.
  5. If you publish AI generated text on a matter of public interest, say so, unless a human has reviewed it and taken editorial responsibility for the piece.

That is it to be honest - no approvals, no registers to file, no auditor turning up. Just disclosure.

The high risk stuff, the bit people are actually scared of, sits in a separate regime with its own timeline. That is where credit scoring, CV screening, medical devices and critical infrastructure live. Most SMEs are nowhere near it, and if you are, you already know.

Are you even in scope

The Act reaches you if you put an AI system on the EU market, or if the output of your system is used in the EU. That covers a lot of UK businesses by default. If you have EU customers using your chatbot or reading your AI generated content, assume you are in scope.

Being in scope is not the same as having a problem. For the transparency article, being in scope just means you owe your users the disclosure above. That is a copy job, not a compliance project.

The nothingburgers

Most of the panic on LinkedIn last week is misplaced. You can safely ignore all of the following.

"You need an AI policy." You don't, not for Article 50. Having one is fine, some clients will ask for it on procurement forms, but the Act does not demand a document.

"You need to register your AI." No. Article 50 has no registration requirement. That is a different, later obligation that only applies to specific high risk systems.

"You need to watermark every AI image you post on LinkedIn." The obligation to build in machine readable marking sits with the provider of the generation tool, not with you as the person who used Nano Banana to make a header image. You still have to say when a piece of content is synthetic if it is a deepfake of a real person or a realistic scene passed off as real. A stylised illustration is not a deepfake. One nuance worth flagging: under the Omnibus, generation systems already on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking requirement, so tool vendors have a short grace period to catch up.

"Fines are massive so it is urgent." The headline 7% of global turnover, or 35 million euros, figure is for the worst category of breach under Article 99, using a prohibited system like real time public biometric surveillance. Transparency breaches under Article 50 sit in a lower tier, capped at 3% of turnover or 15 million euros, and several member states are still standing up their enforcement bodies. Nobody is knocking on an SME door in August for a missing chatbot label. Get it right this quarter and you are ahead of the pack.

The two line disclosure most people can ship in an afternoon

Here is the actual work. Four small jobs, all doable in a morning.

Add a one liner to your chatbot or AI assistant. Something like:

You are chatting with an AI assistant. It can make mistakes. For anything important, ask for a human.

Put it in the greeting, or in the widget footer, or both. Do not bury it. That is your Article 50 chatbot obligation done.

On any page where you publish AI generated audio, images or video that a reasonable person might mistake for real, label it. A small caption is enough. "Image generated with AI." "Voice generated with AI, script by us." You do not need to label every icon or every stylised graphic. You need to label the stuff that could be mistaken for a photo, a recording, or a real person.

In your privacy notice, add a paragraph on how you use AI. What tools, on what data, why. If you use a chatbot, name it. If you generate content, say so. This is not strictly an Article 50 requirement but it lines up with GDPR obligations you already have, and it is the question your enterprise customers are about to start asking on procurement forms.

If you publish AI assisted articles on anything a reader would treat as public interest, add a byline note. Something like "Written with AI assistance, reviewed and edited by [name]" at the top or bottom of the post is enough. The rule is really asking who is willing to stand behind the piece. If a named human has read it and takes editorial responsibility, that is the disclosure done. If nobody has, either get someone to review it or ship it labelled as AI generated.

That is the whole job for a typical UK SME. Four small edits. Twenty minutes if you know where your website copy lives, an afternoon if you have to chase your web person.

What to actually watch

The transparency stuff is the easy bit. The parts of the Act worth actually reading, in order of how likely they are to affect a normal business:

  1. The high risk annex. Skim the list. If your product is on it, you have real work to do and a real deadline. The AI Omnibus, in force since late July 2026, pushed standalone Annex III high risk obligations (credit scoring, CV screening and the like) out to 2 December 2027, and Annex I embedded systems to 2 August 2028. Most SME products are not on either list.
  2. The general purpose AI rules. These land on the model providers (OpenAI, Anthropic, Google), not you. But they will change the terms and the pricing of the tools you use. Expect vendor emails.
  3. The codes of practice. These are still being written. They will define what "reasonable" looks like for a lot of the fuzzy bits. Worth checking again in Q4.

The pattern

Every big regulation has the same shape. A small bit that actually applies to most businesses, wrapped in a lot of noise from people who want to sell you something.

The Article 50 obligations for a normal UK SME are real, but small. Ship the disclosures this month, put a note in your privacy policy, and get back to work. The lawyer conversation is for a different tier of the Act, and probably a different kind of business than yours.

Not sure which of this applies to you? We built a free two minute self-check that asks seven questions and hands you the exact disclosure lines for your answers: optibee.ai/ai-act-check

If in doubt, read the actual text. It is dry, but it is short, and it is free.

Written with AI assistance, reviewed and edited by Toby Remond.

Explore an AI audit · Talk through your process