AI labeling: what applies to your business since August 2
Published on August 24, 2026
AI labeling has applied since August 2
A little over three weeks ago, a new obligation took effect in Germany, and in most businesses nobody noticed. Since August 2, 2026, the transparency obligations of the EU AI Act have been applicable — the part of the rulebook that covers exactly the applications small and mid-sized businesses typically start with: chatbots, phone assistants, AI-generated images and text.
The good news first: the effort is far smaller than the term “transparency obligation” suggests. For most businesses, it comes down to two or three sentences in the right place.
The bad news: alongside it, there’s a rule that isn’t a labeling issue at all but a prohibition — and it gets overlooked regularly.
What the EU AI Act requires since August 2
The relevant provision is Article 50 of the AI Act. It distinguishes cleanly between whom each obligation applies to — and this distinction gets flattened almost everywhere in general reporting.
| Paragraph | Obligation applies to | What it’s about |
|---|---|---|
| 50(1) | Providers | Anyone talking or chatting with an AI system must be able to recognize it |
| 50(2) | Providers | AI-generated content must be marked in machine-readable form |
| 50(3) | Deployers | Emotion recognition and biometric categorization must be disclosed |
| 50(4) | Deployers | Deepfakes must be disclosed; likewise AI texts on matters of public interest |
| 50(5) | Both | The notice must be clear and distinguishable, at the latest at the first interaction |
For the daily life of a small business, two rows of this table are truly relevant: the first and the fourth.
Provider or deployer: why this distinction matters to you
A provider is whoever develops an AI system and puts it on the market or into service under their own name. A deployer is whoever uses such a system under their own responsibility. A trade business that has a phone assistant set up for it is, as a rule, a deployer.
That sounds like one worry fewer, because the labeling obligation for talking and writing systems sits in paragraph 1 — and that one addresses the provider. Still, you shouldn’t retreat to that reading, for three reasons.
First, the line blurs as soon as a system runs under your name. Whoever has an assistant built, calls it “your appointment assistant,” and operates it under their own number is not far from the provider role anymore.
Second, in practice the notice is your job anyway: the greeting on the phone and the first sentence in the chat window belong to your configuration, not to the software.
Third, whoever faces the public is liable anyway. An annoyed caller complains to you, not to the manufacturer.
Practical consequence: Don’t ask your service provider whether they’ll handle the labeling — get it from them in writing that their system meets the requirements of Article 50, and write the notice texts yourself.
AI labeling in practice
Here’s the entire effort we’re talking about.
On the phone. The notice belongs in the greeting, not in fine print at the end:
“Hello, this is the digital assistant of Muster & Co. I can book appointments and take callback requests — if you’d rather talk to a person, just say so.”
That meets two requirements at once: it makes the AI recognizable, and it shows the way to a human. The law doesn’t expressly require the latter, but it’s the difference between a caller who plays along and one who hangs up.
In the chat window. One sentence at the start of the dialog, visible before the first question is typed:
“You’re chatting with an AI assistant. For personal advice, I’m happy to connect you.”
For AI-generated images and videos. If you artificially create or alter a real person, a real place, or a real event, that must be disclosed. A generated mood image for a social media post doesn’t fall under this; a deceptively real image of your store with a person who never existed very much does.
For AI-generated text. Here the obligation only applies to texts published to inform the public about matters of public interest. Your proposal email and your services page don’t fall under it.
When AI labeling isn’t required
The regulation carves out three cases, and all three are useful in daily life.
- When it’s obvious. No notice needed if it would be clear anyway to a reasonably informed person. Better not to rely on this: a voice assistant sounds so good today that “obvious” is hard to argue.
- Under editorial control. For texts, disclosure isn’t required if a human has reviewed the content and someone carries editorial responsibility. This exception is relevant for everyone who uses AI in their writing.
- For recognizably artistic or satirical works. Here a notice that doesn’t disrupt the presentation is enough.
What does not apply: the high-risk obligations were postponed
The most demanding part of the AI Act was originally supposed to take effect on August 2, 2026 as well: the requirements for high-risk systems — AI in hiring, in credit decisions, or in critical infrastructure. With the so-called Digital Omnibus, in force since late July 2026, these obligations were postponed — to December 2027 for standalone systems, to August 2028 for AI built into regulated products.
Two further reliefs from the same package are worth mentioning:
- The machine-readable marking under paragraph 2 applies to systems that were on the market before August 2, 2026 only from December 2026.
- The AI-literacy obligation under Article 4 was softened. It still requires you to take measures so that the people operating AI in your business understand what they’re doing — but no specific level, no proof, no certificate.
What was not postponed is the labeling obligation. It has applied since August 2, unchanged.
The real trap: emotion recognition in the workplace
And that brings us to the point missing from most overviews.
AI systems that infer people’s emotions in the workplace aren’t subject to labeling — under Article 5(1)(f) they are simply prohibited. The only exceptions are medical and safety reasons. This ban has been in force since February 2025.
That’s not a theoretical rule. It gets triggered the moment someone has the idea of analyzing employee conversations or service calls for mood, stress, or motivation. What may, depending on the setup, still be disclosable for customer calls is a prohibited practice toward your own staff.
The difference is substantial: violations of the labeling obligation sit in the middle fine bracket; prohibited practices sit in the highest.
Who enforces the AI rules in Germany
Since June 2026, the German side of jurisdiction is settled too. On June 11, 2026, the Bundestag (Germany’s federal parliament) passed the act implementing the AI Act. The central market-surveillance authority is the Bundesnetzagentur (Germany’s Federal Network Agency); for certain sectors, the respective specialist authorities remain in charge.
For you, this mostly means: there’s now an address. Whoever wants to complain knows where to go — and whoever has questions does too.
Fines: what really applies to small businesses
The numbers circulating in the press come from Article 99: up to €15 million or 3 percent of worldwide annual revenue for violations of the transparency obligations — whichever is higher.
That headline is incomplete for small and mid-sized businesses. Article 99(6) expressly flips the rule for SMBs and startups: for them, the lower of the two values applies.
For a business with €2 million in annual revenue, the cap is therefore not the million-euro figure from the headline but the percentage. That’s still to be taken seriously — but it’s a different order of magnitude than the one this topic is usually sold with.
Why I still think this rule is wrong
Up to here, this was about what applies. To close, what I think of it — this is my opinion, not the legal text.
The people responsible in businesses were overwhelmed even before August 2. Not because of the rules, but because of the sheer range of possibilities and the speed at which everything changes. Add to that a basic attitude you can feel everywhere in Germany: the fear of doing something wrong. That fear is the real brake, not the technology.
Into exactly this situation, more rules are being pushed that add to businesses’ uncertainty. That every new development here gets pelted with regulation first sets back companies that already operate under a crushing load of rules.
And the annoying part: on the substance, I have nothing against the labeling. It’s perfectly fine to say in a phone call that an AI is on the line. I just doubt it takes a law. Why can’t businesses decide that for themselves? If customers find it opaque and annoying, they’ll say so — faster and more effectively than any authority ever could.
What you should do this week
- Take stock: Where in your business does AI already talk or write to customers? Phone, chat window, automatic replies.
- Check your greeting texts: Is the notice at the beginning and is it understandable? Two sentences are enough.
- Path to a human: Is there a recognizable way to reach a person at every point?
- Put your service provider on the record: Does the system in use meet the requirements of Article 50? Get it in writing.
- Check your workforce: Is anyone’s mood or emotion being automatically analyzed anywhere? If so: stop it immediately.
- Give a short briefing: Whoever works with the systems should know what they can do and where their limits are. Article 4 demands nothing more.
My takeaway
The labeling obligation is not a project. It’s one sentence in the greeting, one sentence in the chat window, and one question to your service provider. Whoever starts today is done by the afternoon.
What truly demands care sits elsewhere: with the data that leaves your business, and with the question of what you let AI find out about your own people. The first is solvable; the second is, at one specific point, simply prohibited.
My view: The people responsible in businesses were already overwhelmed before — not only because of the flood of tools and possibilities and the insanely exponential pace of development. In Germany there’s simply a default skepticism and worry about doing something wrong. Pushing out yet more rules right now, which only make it harder again for businesses to use AI without constantly breaking laws, I consider completely wrong. It sets German businesses — already bureaucratized to death by an unbelievable number of regulations — even further back. That said, I do think it’s fine to say transparently in a phone call that an AI is on the line — I just don’t know whether that immediately has to be a law again. Why can’t businesses simply decide that for themselves?
Don’t let the rule stop you. It’s done in an afternoon — and the value a well-configured assistant delivers remains, every single day after.