The EU's AI Transparency Law Is Live Today. It Reaches US Chatbots Too.
Article 50 of the EU AI Act took effect today, requiring every chatbot to disclose it's AI, with fines up to €15 million. Here's what it means for US SaaS founders.

News Breakdown · FiscEdge Academy
Starting today, August 2, any AI system talking to a user in the European Union has to say so. Article 50 of the EU AI Act took effect, requiring every chatbot and interactive AI system to disclose, clearly and at the first interaction, that the user is talking to a machine, not a person. Deepfakes, images, video or audio that have been AI-generated or edited to look real, must be labeled even when there's no intent to deceive. Fines for getting this wrong reach €15 million or 3% of a company's worldwide annual turnover, whichever is higher.
Here's the detail most coverage is glossing over: this isn't limited to EU companies. The Act reaches any provider or deployer whose AI system is used by people in the EU, regardless of where the company is headquartered. If your SaaS has a support chatbot, a sales assistant, or AI-generated marketing content that a single user in Germany or France can reach, you are in scope today, not in some future compliance cycle.
The delay that isn't a delay
Some of the confusion is understandable. In late June, the Council of the EU gave final approval to a "Digital Omnibus" package that pushed back the Act's toughest obligations, the ones covering standalone high-risk AI systems under Annex III, to December 2, 2027, and obligations for AI embedded in regulated products to August 2, 2028. That's a real, meaningful delay, and it's fueled a narrative that the whole AI Act timeline just slipped.
It didn't. Article 50's transparency rules, the chatbot-disclosure and deepfake-labeling requirements, stayed exactly where they were: enforceable from today. The one piece that did move is narrower than it sounds: the machine-readable watermarking requirement for AI-generated content under Article 50(2) gets a four-month grace period, until December 2, and only for systems that were already on the market before today. Everything else on the transparency side is live now.
Why this is a US story, not just a Brussels one
The Act's enforcement structure puts obligations on both providers (the companies that build the AI system) and deployers (the companies that put it in front of users). A US startup running someone else's foundation model inside a customer-facing chatbot is a deployer under this rule, and deployer obligations don't disappear because the model came from OpenAI or Anthropic. If you sell into Europe at all, even as a secondary market, "we'll deal with it when we open an EU office" is no longer a viable answer. The obligation attaches to the interaction with an EU user, not to where your company is incorporated.
What to actually check this week
- Audit every AI-facing surface for EU traffic. Support chat, onboarding assistants, AI-written landing page copy, personalized email generation, anything a user in the EU might touch. If you don't currently track EU-origin traffic, that's the first gap to close.
- Add a disclosure, not a disclaimer buried in your terms. The requirement is "clear and distinguishable... at the latest at the time of first interaction." A line in your ToS doesn't satisfy that; the bot needs to say it's a bot, inside the conversation itself.
- Label anything AI-generated that could pass as real. Product photography, testimonial-style video, synthetic voiceovers. The deepfake rule applies without intent to deceive, so "we weren't trying to trick anyone" isn't a defense.
- Don't assume the Digital Omnibus bought you time. If your read of the news was "the AI Act got delayed," go back and separate the Annex III high-risk delay from Article 50. They're different obligations on different clocks, and only one of them moved.
If you remember one thing
The EU AI Act's headline deadline shifted to 2027 for high-risk systems, but the disclosure rule for chatbots and deepfakes did not move: it's enforceable today, and it reaches any company whose AI talks to a user physically in the EU, no matter where that company is based. If you have EU users and an undisclosed chatbot, you're out of compliance as of this morning.
We cover regulatory and compliance planning for AI products in FiscEdge's AI for entrepreneurs course, and how to structure a SaaS business for multiple markets in business fundamentals. For the governance side of building compliant AI products while you raise, startup strategy has the playbook. Browse the full blog for more daily breakdowns. Follow @fiscedge for daily Business & AI analysis.
How interesting did you find this article?
The week's breakdowns, every Sunday.
Business & AI news decoded for founders. One email a week, no fluff.
Stay connected with FiscEdge Academy
Want more breakdowns like this one? Follow us and keep learning.