What Happened
On July 20, the European Commission published detailed guidance on the AI Law. The most important: transparency obligations take effect on August 2, 2026 — two days from now.
This is the date that matters for SMBs. It's not a soft transition date. Once that day arrives, the law is in effect, and obligations are mandatory.
What Are These Obligations?
The European AI law (focused on Article 50) requires any organization using significant-risk AI systems to be transparent about it.
In practical terms, this means:
If you use AI to make decisions about people:
- Customers need to know an AI was involved (example: algorithm that decides if credit is approved).
- There must be a way for the customer to challenge the decision.
- Records of how the AI worked must be kept.
If you use AI for automated communication:
- You must disclose when you're talking to a bot, not a person.
- This includes customer service, chatbots, virtual assistants.
If you train AI systems with personal data:
- You need clear documentation on how data is used.
- You must respect data consent.
Who Is Affected?
This sounds like it's for big companies, but SMBs are included too.
SMBs clearly affected:
- E-commerce with recommendations: If you show products based on past behavior using AI, you're covered.
- Accounting/Services with automatic analysis: If you use AI to classify expenses or analyze customer risk.
- Hospitality with dynamic pricing: If you automatically change prices based on AI patterns.
- Logistics with routing: If you use AI to plan deliveries.
- Customer service with chatbots: If you use bots to respond, you need transparency.
SMBs less affected at first:
- Using generic tools like ChatGPT for internal analysis (doesn't involve critical decisions about others).
- Document support like summaries (low risk).
The Fines: What's at Stake
This is not a recommendation. These are legal obligations.
Fines for non-compliance with Article 50 can be:
- Up to €15 million, or
- 3% of global annual turnover, whichever is higher.
For an SMB with €2 million in revenue, 3% means a fine of €60,000 for any identified violation.
You need to take this seriously.
How to Stay Compliant
Today (before August 2):
- Do a quick inventory: where do you use AI in your business? List each system.
- For each system, ask: "Does this make decisions about people or communicate with customers?"
- Yes = needs transparency
- No = lower risk (for now)
- If the answer is yes:
- Review your website, app, or process. Do customers know AI is involved?
- If not, add a clear statement.
- Example: "Recommendations on this website are generated by artificial intelligence."
Starting August 2:
- Keep records: how each AI system works, what data it uses, how it was tested.
- Train your team: anyone who speaks with customers needs to know how to respond "I'm a bot. If you prefer, I can connect you with someone.".
- Monitor: check that your AI is working as expected. If there are systematic errors, document and fix them.
Our Advice
The European AI Law is not an obstacle — it's a protection. It protects your customers, and therefore it protects you too.
The most important thing right now is to act quickly. You don't need to be perfect on August 2, but you do need to be compliant. Start with basic transparency — tell customers where you use AI.
A company that suddenly reveals it's been using AI without warning seems dishonest. A company that anticipates and communicates seems careful with customer data.
Be the second.