Expert orientation, as of end of May 2026. This is not legal advice.

Between headline and reality lies half a year of work you can skip

Search for the AI Act today and you will find two kinds of text. Some warn of million-euro fines and a wall of bureaucracy. Others sell you a compliance package against the fear the first text just created. Both have an interest in making the whole thing look complicated.

It is not. At least not for a normal SME.

The AI Act is an EU regulation that classifies AI by risk. The higher the risk to people, the stricter the obligations. A business that has a chat window on its website and occasionally has ChatGPT draft a text sits at the very bottom of that scale. Precisely there, a modest adjustment takes effect in August, nothing more.

What actually comes into force on 2 August

From that date, Article 50 applies: the transparency article. It requires businesses to disclose when people are interacting with AI. For a typical SME with a website, this produces three things, and only the first one affects almost everyone.

  • The chatbot must identify itself. If AI responds in a chat on your site, the visitor must know that before typing the first message. A visible notice on the chat window is enough. A hidden footnote is not.
  • Genuine deepfakes and news-style texts must be labelled. Anyone publishing artificially generated images, audio recordings, or videos with a deceptively real character, or AI-generated texts on topics of public interest, must disclose the artificial origin. Marketing texts and product descriptions are explicitly excluded.
  • Machine-readable marking is the providers’ responsibility. Ensuring an AI text remains technically identifiable as such is for OpenAI, Google and the like to solve in their software. The obligation falls on the model maker. It does not extend to companies that merely deploy the model.

That is the complete list for the lower risk tier. No external certification, no ongoing reporting obligation. Adding the chatbot notice takes one to two hours. Everything else depends on whether you publish content on the topics the article actually addresses.

Why the strict rules have just been pushed back

In early May 2026, the Council and Parliament agreed on a reform package called the Digital Omnibus. It moves the genuinely demanding obligations for high-risk AI systems considerably later: systems such as automated applicant screening or credit scoring must meet their requirements only from December 2027, and AI embedded in regulated products not until August 2028.

The reason is unspectacular. The technical standards and guidelines that businesses were supposed to follow simply were not ready in time. What matters for you: the transparency obligations from Article 50, the three points above, are unaffected and apply from August as planned.

One caveat belongs here. At the end of May, this agreement had not yet been published in the Official Journal and was therefore not formally in force. That it will come is considered certain. Until then, you should plan for the new deadlines while not yet treating them as settled law.

A number you should ignore

Several articles circulate a supposed fine from an Austrian authority, six figures, for AI-assisted applicant screening. The number sounds dramatic, which is exactly why it keeps getting shared.

I am not repeating it here. While researching this article, I could find no credible source for that decision, not at the authority, not in a legal database, not in a reliable report. A number no one can substantiate has no place in a factual overview, no matter how well it works as a hook.

Three everyday situations, three clear answers

You have a chatbot on your website. A visitor types a question into the chat window, an AI responds. From August, the visitor must be able to tell beforehand that no human is on the other end. A short, visible notice handles that. As long as the chat does not simultaneously decide on job applications or credit, it stays in the harmless risk tier.

You have AI write or translate texts. Nothing changes for your service pages, product texts, and SEO articles. The labelling obligation targets content intended to inform the public on socially relevant questions, not advertising. Anyone who does publish on such topics has a straightforward alternative: a person reviews the text substantively and takes responsibility for it. That removes the obligation.

You are considering an AI tool for applicant screening. This is where it gets serious, because that is high-risk. The specific AI Act obligations for it do not start until late 2027. Data protection law applies already today, though: introducing such software without a data protection impact assessment, and without applicants’ right to human review, is a problem independent of the AI Act.

And who enforces all this in Austria?

Honest answer: that was not yet definitively settled at the end of May 2026. Austria had not formally designated a supervisory authority for the AI Act. The AI Service Office at Rundfunk und Telekom Regulierungs-GmbH (RTR) has been the practical point of contact since 2024, providing information and advice, but does not hold the full supervisory role.

Beyond that, the existing authorities remain responsible within their subject areas: the data protection authority for anything involving personal data, the financial market authority for AI in finance, and so on. In practice, this means: where personal data is involved, the route still runs through the data protection authority, and the AI Service Office’s advice is free.

What to do before August

If you run a website with the usual building blocks, a short, honest inventory is all it takes. Four steps, the first one takes a quarter of an hour.

  • Write down where AI is actually being used. Chatbot, writing tools, translation, possibly an applicant tool. Only that list shows what affects you and what does not.
  • Add the chatbot notice. Visible, clear, before the first exchange. This is the one obligation that affects almost everyone with a chat window.
  • Document how you handle AI-generated texts. Who reviews, who takes responsibility. A brief internal note is sufficient and relieves you of the burden of proof if it comes to it.
  • Catch up on basic AI training. An often-overlooked obligation has been in place since February 2025: anyone in the business who works with AI needs demonstrable basic knowledge. A certificate is not required; brief internal documentation is enough.

The technical side is not something you need to solve alone

The chatbot notice, a cleanly labelled page, documented handling of AI-generated texts: these are adjustments to your website, not a matter for a legal department. That is exactly the part I can take care of, while the legal fine-tuning stays where it belongs. If you want this sorted before August, let’s talk.

Frequently asked questions

Do I have to label every text written with ChatGPT as AI-generated?

No. The labelling obligation from Article 50 targets artificially generated content intended to inform the public on matters of public interest. Marketing texts, product descriptions, and ordinary advisory articles are not covered. Labelling, or documented human review, only becomes relevant for editorial content on socially significant questions.

Does this also apply to AI-translated website pages?

Nothing changes for ordinary business pages. An AI translation of your service or product pages does not trigger a labelling obligation, because that content does not inform the public on matters of public interest. The question only becomes relevant for journalistic texts on such topics.

I have a chatbot. What exactly do I need to do?

Your visitors must be able to tell that they are writing to an AI system, before they send their first message. In practice, a clearly visible notice directly on the chat window is sufficient. The effort is usually one to two hours, with no external certification required.

How high are the fines really?

For violations of the transparency obligations, the AI Act provides for fines of up to 15 million euros or 3 percent of annual turnover. These ceilings are aimed at large providers. For a small business, the actual risk is well below that, though a reputational and cease-and-desist risk remains.

When does the AI Act apply to AI-assisted applicant screening?

The specific high-risk obligations for that were moved to December 2027 by the May 2026 reform package. That is not an all-clear: such software already touches data protection law today and requires, among other things, a data protection impact assessment and applicants’ right to human review.

Who enforces compliance in Austria?

A formal supervisory authority had not been definitively designated as of end of May 2026. The AI Service Office at RTR is the practical point of contact and advises free of charge. The existing authorities remain responsible within their subject areas, in particular the data protection authority once personal data is involved.

Is the delayed entry into force already settled law?

The agreement on the deadline extension dates from early May 2026 but had not yet been published in the EU Official Journal and was therefore not formally in force. You should plan for the new deadlines while not treating them as final until publication.


This article provides expert orientation and does not replace legal advice in individual cases.

All posts