Back to Articles

What's Actually Changed in AI Disclosure Law, and What It Means for Your Business

Kim Taylor
August 28, 2026
3 mins

Real, sourced updates on EU and US AI transparency law as of August 2026, what's confirmed, what's still changing, and what to actually check for your business.

A note before anything else: this article is general information, not legal advice. AI regulation is moving quickly, provisions referenced here are explicitly under active amendment even as this is being written, and requirements depend heavily on your specific business, your customers' locations, and the scale of the AI systems involved. Confirm your specific obligations with qualified legal counsel before making compliance decisions.

TL;DR

  • As of 2 August 2026, the EU began actively enforcing new AI transparency rules under Article 50 of the AI Act, requiring AI systems that interact directly with people, chatbots included, to disclose that they're AI. Penalties can reach €15 million or 3% of global turnover.
  • Article 50 itself is currently subject to an unresolved amendment, the EU's Digital Omnibus on AI, and the published legal text hasn't yet been updated to reflect it. The substance could shift.
  • In the US, there's no single federal standard. California's SB 942 is confirmed and real, but it specifically targets large generative AI developers with over one million monthly California users, not most businesses using a third-party AI tool. Other state rules exist and vary.

Most content about AI disclosure law either oversimplifies into "you must disclose AI use" without specifying where or to whom, or goes untouched because the details are genuinely hard to pin down while they're still moving. This piece tries to do neither: here's what's actually confirmed, sourced directly from primary legal and government material, what's still unsettled, and what that means practically.

What's confirmed in the EU, as of 2 August 2026

On 2 August 2026, the European Commission's AI Office and national authorities began actively enforcing the EU AI Act's transparency rules. According to the Commission's own announcement, chatbots and other interactive AI systems must now tell users they're dealing with AI, not a human. Deepfakes must be labelled, and AI-generated or altered content must carry machine-readable marks so it can be detected.

This isn't a symbolic rule. The Commission has already published a list of more than 180 organizations that signed a Code of Practice operationalizing these transparency requirements, and enforcement is split across three bodies depending on the type of provider: 

  1. The AI Office
  2. National competent authorities 
  3. European Data Protection Supervisor for EU institutions. 

Penalties for companies can reach up to €15 million or 3% of global annual turnover, whichever is higher, with proportionality considered for small and medium-sized businesses.

The specific legal basis for the chatbot disclosure requirement is Article 50 of the AI Act, which requires that AI systems designed to interact directly with people be built so those people are informed they're interacting with an AI system, unless that would already be obvious to a reasonably well-informed, observant, and circumspect person.

The important caveat: this provision is currently being amended

Here's something worth taking seriously rather than glossing over. The official published text of Article 50 currently carries a notice stating it has been amended by something referred to as the Digital Omnibus on AI, and that the displayed text has not yet been updated to reflect those amendments. 

In plain terms: the rule is in force and being enforced, but the exact wording of what it requires is in the middle of being changed, and the public-facing legal text doesn't yet show the update.

This matters practically. If you're making a specific compliance decision based on the precise wording of Article 50, that wording could already be out of date. The safest approach is treating the general principle, disclose clearly when an AI system is interacting directly with someone, as solid, while confirming the specific legal language directly and recently before treating any detail as final.

It's also worth separating this from a related but distinct piece of news, a broader "AI Omnibus" has postponed rules specifically for high-risk AI systems, pushing that timeline to 2 December 2027, and further to 2 August 2028 for high-risk systems integrated into regulated products. That postponement applies to a different category of rules than the transparency and disclosure requirements discussed here, which remain in force from 2 August 2026. It's easy to conflate these, so it’s worth keeping them separate when reading other sources on this topic.

What's confirmed in the US, and what isn't

There is no single US federal equivalent to the EU's approach. What exists is a growing, uneven patchwork of state laws, and the details matter considerably.

California's AI Transparency Act, SB 942, is confirmed directly from the bill's primary text. It became operative January 1, 2026, and applies specifically to "covered providers," defined as generative AI system developers with over one million monthly visitors or users within California. Covered providers must offer a free AI detection tool, support optional visible disclosures on AI-generated image, video, or audio content, and embed hidden disclosure metadata in that content. Violations carry a $5,000 penalty per violation, with each day of continued violation counted separately.

It's worth being clear about who this actually applies to, the one-million-monthly-user threshold means SB 942 is aimed at large AI platform providers, not most small or mid-sized businesses using a third-party AI tool to talk to their own customers. If your business isn't itself building and operating a generative AI system at that scale, this specific law likely isn't the one governing your situation directly, though the vendor whose tool you're using might be in scope.

A companion law, AB 2013, requires generative AI developers to publish documentation about their training data. Beyond this general description, further specifics aren't independently confirmed here against primary bill text.

Other states have moved in different directions, some, including reported activity in Utah, have leaned toward disclosure requirements that read as more directly applicable to businesses using AI in customer-facing interactions, including chatbots, without the scale threshold California's law includes. 

What this actually means practically for your business

Given a genuinely unsettled, multi-jurisdiction picture, a few practical steps hold up regardless of exactly where the details land:

  • Check where your customers actually are, since obligations in most of these frameworks depend on exposure to people in a specific jurisdiction, not just where your business is headquartered. 
  • Check the scale and role of any AI vendor you use, since several of these laws draw a real distinction between a large platform provider and a business deploying a third-party tool. 
  • Build clear, upfront AI disclosure into your customer interactions regardless of which specific law technically applies to you, since separately from any legal requirement, the data on customer reactions to disclosure is consistently positive when it happens upfront, and negative specifically when it doesn't.

Worth a look

If you're evaluating an AI tool for customer interactions and want one that's built with clear disclosure as a standard part of how it operates, that's worth asking about directly. SalesAPE offers a free demo if you'd like to see how that works in practice, no pressure either way.

FAQs

Is it now legally required for a chatbot to tell customers it's AI? 

In the EU, yes, under Article 50 of the AI Act, in force since 2 August 2026, though that provision is currently being amended and the published text hasn't been fully updated to reflect the changes. In the US, it depends on the specific state and the scale of the AI provider involved, there's no single federal requirement.

Does California's AI Transparency Act apply to most small businesses using AI chatbots? 

Generally, no. SB 942 specifically applies to "covered providers," generative AI developers with over one million monthly California users. Most small and mid-sized businesses using a third-party AI tool fall outside this definition, though the vendor providing that tool might be in scope.

What are the penalties for non-compliance with these AI transparency rules? 

In the EU, penalties under the AI Act's transparency rules can reach up to €15 million or 3% of global annual turnover for companies, with proportionality considered for smaller businesses. In California, SB 942 violations carry a $5,000 penalty per violation, with each day of continued violation counted separately.

Why does the exact wording of these laws matter if the general principle is clear? 

Because compliance decisions often hinge on specific definitions, thresholds, and exemptions written into the text, not just the general idea. Article 50 of the EU AI Act, for example, is currently being amended, and relying on outdated specific wording could lead to an inaccurate compliance decision even though the underlying principle, disclose AI use, remains stable.

{ "@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "Is it now legally required for a chatbot to tell customers it's AI?", "acceptedAnswer": { "@type": "Answer", "text": "In the EU, yes, under Article 50 of the AI Act, in force since 2 August 2026, though that provision is currently being amended and the published text hasn't been fully updated to reflect the changes. In the US, it depends on the specific state and the scale of the AI provider involved, there's no single federal requirement." } }, { "@type": "Question", "name": "Does California's AI Transparency Act apply to most small businesses using AI chatbots?", "acceptedAnswer": { "@type": "Answer", "text": "Generally, no. SB 942 specifically applies to \"covered providers,\" generative AI developers with over one million monthly California users. Most small and mid-sized businesses using a third-party AI tool fall outside this definition, though the vendor providing that tool might be in scope." } }, { "@type": "Question", "name": "What are the penalties for non-compliance with these AI transparency rules?", "acceptedAnswer": { "@type": "Answer", "text": "In the EU, penalties under the AI Act's transparency rules can reach up to \u20ac15 million or 3% of global annual turnover for companies, with proportionality considered for smaller businesses. In California, SB 942 violations carry a $5,000 penalty per violation, with each day of continued violation counted separately." } }, { "@type": "Question", "name": "Why does the exact wording of these laws matter if the general principle is clear?", "acceptedAnswer": { "@type": "Answer", "text": "Because compliance decisions often hinge on specific definitions, thresholds, and exemptions written into the text, not just the general idea. Article 50 of the EU AI Act, for example, is currently being amended, and relying on outdated specific wording could lead to an inaccurate compliance decision even though the underlying principle, disclose AI use, remains stable." } } ] }