Back to Blog
EU AI Act compliance guide for anyone using AI - transparency and disclosure rules, live 2 August 2026
August 6, 2026 HadesFlow Team AI & Automation

The EU AI Act: A Compliance Guide for Anyone Using AI

If you use AI in your work in any real way, whether that's a customer-service chatbot, an AI writing assistant, a tool that helps sift job applications, or an image generator, there's a new set of European rules you should know about. Part of it took effect this month. Since 2 August 2026 the transparency obligations of the EU AI Act have been enforceable. This isn't a deadline sitting off in the future somewhere. It's live now.

The reassuring part is that for most people and businesses the actual work is small. You're almost certainly not building high-risk medical AI. Mostly you just need to be honest about where you use AI, in a way people can actually notice. Below we go through what the law is, what it expects of you, the practical steps, and the mistakes people keep making. No legalese. And we finish on the one thing almost anyone running a chatbot should sort out first, because it's exactly what we fixed on our own site not long ago.

One honest caveat before we start: we build AI automation for a living and we've read these rules closely, but we're not lawyers. Treat this as a clear map of the terrain rather than legal advice. If something is genuinely high-stakes for you, have a professional look at your specific setup.

What the EU AI Act actually is

The EU AI Act is the first serious attempt anywhere to regulate artificial intelligence in a comprehensive way. It came into force in 2024 and is arriving in stages through 2027. The idea at its centre is worth holding onto, because it tells you roughly how much of it lands on you: the law sorts AI by risk, not by hype. The more a system can affect people's rights, their safety, or their money, the more it asks of you.

Two things tend to catch people off guard. The first is that the reach goes beyond Europe. If people in the EU are affected by your AI, the rules can apply even if you sit somewhere else entirely. The second is that they land on the organisations and people who use AI, not only the big labs that build the models. In the law's language you're a "deployer"; they're the "provider". Buying a tool off the shelf doesn't hand the whole obligation to the vendor. How you use it, and how you present it to the people it touches, is still on you.

Here's the risk picture at a glance, and where most everyday AI use tends to land:

Risk tier What it covers What you must do
Unacceptable Banned uses, such as social scoring or manipulative and exploitative AI. Prohibited. Don't build or use it.
High AI used for things like hiring, credit scoring, education, or medical decisions. Strict duties: risk management, documentation, human oversight, registration.
Limited Chatbots, AI-generated text and images, deepfakes. Most everyday AI use is here. Transparency: tell people clearly when they're dealing with AI.
Minimal Spam filters, recommendation engines, most everyday AI. No specific obligations.

Look at where the crowd sits. A business running a support chatbot, a team drafting content with AI, a shop generating its own product images: almost all of it falls into the limited-risk band. And that band has basically one job, transparency, which is why most of this article lives there.

The obligations that matter for most AI users

Set aside the parts written for banks and hospitals and you're left with three duties for the average person or business using AI.

1. Transparency: tell people they're dealing with AI

This is the big one, and it sits in Article 50. When someone interacts directly with an AI system, a chatbot being the obvious case, they have to be told clearly, and right at the start, that they're dealing with a machine rather than a person. There's an exception for when it's genuinely obvious to a reasonable person, but regulators read that one narrowly. A friendly name and a little robot icon don't cover it on their own.

2. Disclosure: label AI-generated content

If you put out AI-generated or AI-altered content that could pass for the real thing, synthetic images, deepfake-style media, and in some cases AI-written text published as information to the public, you generally have to say so. Content that's clearly fictional or obviously stylised is treated more gently, and text that a human editor has actually reviewed and stands behind gets some slack too.

3. Risk management: know what your AI does

Even below the high-risk tier, it's simply good practice to understand your own AI: what data it sees, where it tends to go wrong, and how a human can step in when it does. For most people this is light work, a short internal note of what AI you use, from which vendor, and how you handle the data it touches. It also lines up neatly with what GDPR already asks of you.

Practical steps to take if you use AI

None of this needs a legal team to begin. Here's the short version you can start on today.

  1. Make a list of your AI. Every place it shows up: customer-facing chatbots, AI-written content, hiring or support tools, image generation, coding assistants, analytics. You can't disclose what you haven't mapped.
  2. Sort out your chatbot disclosure. If you run any chat or voice assistant, make sure it says up front that it's AI. Visibly, before the conversation starts, not tucked away on a policy page.
  3. Label AI-generated content. Where you publish synthetic images or media, mark them. If AI drafts your text, have a human review it and take ownership.
  4. Update your public notices. Your privacy policy, and any terms, should explain that your AI features process what users type, often through a third-party model, and how that data is handled. This is where the AI Act and GDPR meet.
  5. See what your vendors already do. If you use a third-party tool, check what disclosure it builds in, then fill the gaps yourself. How you use and present it is still your responsibility.
  6. Leave people a way to reach a human. It's good service, and it strengthens your position under the rules.
  7. Write it down. Keep a one-page record of the AI you use and the steps you've taken. If anyone ever asks, you can show your working.

Common mistakes to avoid

  • Assuming none of it applies to you. "We're small", "we're not in the EU", "we only use an off-the-shelf tool": none of those get you out automatically. The reach, and the deployer duties, are broad.
  • Hiding the disclosure. Tucking "this is an AI" into your terms, or setting it in tiny grey footer text, is exactly the sort of thing regulators single out. It has to be clear and easy to spot.
  • Leaning on a clever name. A bot called "Aria" with a smiling avatar can make things worse by implying a human. The name isn't the disclosure.
  • Disclosing too late. Telling someone it was AI after they've had a full conversation defeats the point. It goes up front, at first contact.
  • Overlooking the privacy angle. An AI tool usually sends what users type to a model somewhere. If your privacy notice says nothing about that, you've got a GDPR gap sitting right next to the AI Act one.
  • Treating it as a one-off. The Act is still rolling out, the guidance keeps shifting, and your own AI use will change. This is a habit, not a box to tick.

A concrete example: the chatbot disclosure

Let me make this concrete with the most common case of all, and the one we dealt with ourselves not long ago. HadesFlow runs an AI chatbot on every page. For a while, the only clues that it was AI were the assistant's name and a small robot icon. Article 50 says that isn't enough: the "it's obvious" exception is read narrowly, and our own cheerful copy ("we typically respond right away", a "typing" indicator) actually nudged people towards assuming a human was on the other end. So we changed it. Here's what a compliant chatbot disclosure looks like in practice:

  • Say it plainly, before the chat starts. We added a clear notice on the widget's welcome screen: a short line telling visitors they're talking to an AI assistant, not a person, visible before they type anything.
  • Keep it in view during the chat. A small "AI chatbot, not a human" subtitle now sits under the assistant's name for the whole conversation, so the context doesn't vanish once you start.
  • Make it readable. The notice is a distinct, legible callout, not faint microtext. Regulators specifically dislike "tiny footer" disclosures.
  • Be honest about the limits. We note that the assistant can get things wrong and that anything important is worth double-checking, and we point people to a human by email.
  • Back it up in the privacy policy. A new section explains that chat messages are handled by an automated system using a third-party model, and asks people not to share sensitive details in the chat.
The one-line test

Open your own chatbot as if you'd never seen it before. In the first second, without clicking anything, is it unmistakable that you're talking to AI? If you have to squint, guess, or read the small print, that's your gap. The same test works for any AI feature: could someone tell it's AI without being told?

The whole thing took an afternoon, because the fix is really about honesty rather than engineering. That's the quietly reassuring bit underneath all the regulatory language. Transparency is mostly a matter of design and wording, and it tends to make for a better, more trustworthy experience anyway. People who know they're talking to a bot ask sharper questions and get frustrated less often.

Compliance is a moving target, and that's fine

A closing point worth stating plainly: the EU AI Act hasn't finished settling. More of it comes into force through 2027, official guidance is still landing, and enforcement will sharpen with time. The penalties for the transparency rules are real, up to 15 million euros or 3% of worldwide annual turnover, but staying on the right side of them isn't about a one-off scramble. It's a light, repeatable habit: know what AI you use, be honest about it where people can see, and revisit it when your tools or the rules change.

If you've got a chatbot, get its disclosure right first. It's the highest-impact, lowest-effort move you can make. Then work down the list. You'll be most of the way there, and you'll have earned a little trust along the way.

And if a question about the EU AI Act comes up along the way, or you run into an issue getting compliant, HadesFlow is glad to help - reach us any time at contact@hadesflow.com.

Not sure whether the AI you use is disclosed the way it needs to be? That's exactly the kind of audit we do - and we just ran it on ourselves. Get in touch and we'll take an honest look at where you stand.