Your website chatbot now has to say it is a chatbot. Here is who that actually binds.
The EU AI Act's transparency rules went live on August 2, 2026. Chatbots have to identify themselves, AI-generated content has to carry a machine-readable mark, and the penalty ceiling is 15 million euro or 3 percent of global turnover. The high-risk rules everyone was bracing for got pushed to 2027. Here is what applies, whether it reaches a Canadian business, and the Ontario rule that already binds you today.
On August 2, 2026, the transparency rules in the EU AI Act started applying. The headline version is easy to summarize: if a person is talking to a machine, the machine has to say so.
That sounds like somebody else’s problem if your business is in Toronto. It mostly is. But “mostly” is doing real work in that sentence, and the parts that reach across the Atlantic are worth ten minutes, because the fix is a line of copy above a chat widget and the ceiling on getting it wrong is 15 million euro or 3 percent of worldwide turnover, whichever is higher.
There is also a second story here that got much less coverage: six days before the transparency rules landed, the EU quietly pushed its high-risk AI obligations back by more than a year. So the thing most compliance emails were warning you about all spring is not happening until December 2027, and the thing nobody mentioned is live right now.
What actually turned on
Article 50 of the AI Act contains four obligations, split between the people who build AI systems (providers) and the people who use them (deployers). If you bought your chatbot rather than trained it, you are usually a deployer, and only some of this is yours.
1. Tell people they are talking to a machine. Any AI system designed to interact directly with a person has to be built so that the person is informed they are dealing with AI. The disclosure has to arrive at the latest at the time of the first interaction, so before or at the very start of a conversation, not in a footer and not in your terms of service. This one is a provider obligation, meaning the vendor has to build the capability. In practice, the vendor builds the banner and you are the one who decides whether to switch it off, which is why it lands on your desk anyway.
There is an exemption where AI involvement is obvious to a reasonably well-informed, observant person. A widget labelled “AI assistant” with a robot icon is probably obvious. A support agent named “Sarah” with a human-sounding voice and a stock photo is not, and the more human-like you make it, the more clearly you need to say it.
The Commission’s final guidance, published July 20, 2026, goes a step further for agents that act on your behalf: it expects an agent to identify both that it is artificial and who it is acting for. If you are deploying something that emails suppliers or books appointments in your name, “I am an AI assistant for AuraByt” is the shape of the answer, not just “I am an AI assistant.”
2. Mark AI-generated content so machines can detect it. Providers of generative systems have to embed a machine-readable mark in synthetic audio, images, video, and text, so the output is detectable as AI-generated downstream. This is a watermarking and metadata obligation, and it sits with whoever built the model, not with you for using it. There is a carve-out for assistive editing that does not substantially change the input, so a grammar checker is not caught. Systems already on the EU market before August 2 have until December 2, 2026 to get the marking in place.
3. Tell people when you are reading their emotions or sorting them biometrically. A deployer obligation, and one that almost no small business touches. If you did, you would also need a GDPR basis for it, which is the harder problem.
4. Label deepfakes and AI-written text on matters of public interest. If you publish AI-generated or manipulated content that resembles real people, places, or events and could pass as authentic, you have to disclose it. Same for text published to inform the public on matters of public interest. The important carve-out for anyone running a blog: if a person actually reviewed and edited the text and somebody holds editorial responsibility for it, the disclosure obligation does not apply. The review has to be substantive. A glance is not editorial control.
The Commission also released three optional icons for labelling AI-generated content, folded into its voluntary Code of Practice on Transparency of AI-Generated Content, which it confirmed as an adequate compliance route in July. Signing the code is not required. Following Article 50 is.
The part that got deferred
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026, six days before the August 2 deadline it was amending.
It moved the compliance date for standalone high-risk systems in Annex III (the hiring, credit, education, and essential-services category) from August 2, 2026 to December 2, 2027. High-risk AI embedded in regulated products under Annex I moved to August 2, 2028.
It did not touch the transparency rules. Those went live on schedule.
That inversion is worth noting if you were following the compliance chatter earlier this year. The obligations with the heavy paperwork, the conformity assessments and risk-management systems and technical documentation, are now more than a year out. The obligation that actually reaches a small business with a website, which is “say it is a bot,” is the one in force.
Does this reach a business in Ontario?
Honestly: for most of our clients, no. But the test is not where you are, it is where the system or its output lands.
Article 2 of the AI Act applies to providers placing AI systems on the Union market “irrespective of whether those providers are established or located within the Union or in a third country,” and to providers and deployers located in a third country “where the output produced by the AI system is used in the Union.”
Read at its widest, that second clause catches any chatbot on any public website, because someone in Dublin can open it. That reading is not how this is generally understood, and it is not how the equivalent question resolved under GDPR, where deliberately offering goods or services to people in the EU is what matters rather than mere accessibility. The practical line most advisers are drawing is targeting: do you sell into the EU, price in euro, ship there, run campaigns there, support customers there in their language.
So the honest breakdown:
- A Toronto dental clinic with a booking chatbot. Not in scope in any serious reading. Your patients are in Ontario.
- A GTA retailer with a Shopify store that ships to the EU and an AI support widget. Arguably in scope, and cheap enough to comply with that arguing about it costs more than fixing it.
- A SaaS product with EU customers. In scope, and you should be treating this as a product requirement, not a marketing footnote.
- An agency or studio building AI features for clients who sell into the EU. Your contract should say who owns this. Ours now does.
One more wrinkle worth knowing before you panic or relax: enforcement runs through national market surveillance authorities that each member state has to designate, and as of mid-June 2026 only 9 of the 27 had fully designated both their market surveillance and notifying authorities, with 12 more in progress and 6 with nothing appointed. The original deadline for that was August 2025. So the first year of Article 50 enforcement is going to be uneven, and the fines with the scary numbers are a ceiling reserved for the serious cases, with explicit proportionality for SMEs written into the framework.
Uneven enforcement is a bad reason to skip a fix that takes ten minutes. It is a good reason not to buy a compliance platform this quarter.
What already binds you in Ontario, today
This is the part that gets left out of the EU coverage, and it is more likely to matter to you than anything in Brussels.
Since January 1, 2026, Ontario employers with 25 or more employees have to disclose AI use in publicly advertised job postings. Under the Employment Standards Act, a publicly advertised posting must include a statement disclosing the employer’s use, if any, of artificial intelligence to screen, assess, or select applicants. The definition of AI in the regulation is broad: a machine-based system that infers from its input to generate predictions, content, recommendations, or decisions.
Two things owners keep getting wrong on this one. First, it applies whether you run the screening yourself or a recruiter does it for you. Using a third party does not move the obligation off you. Second, you do not have to explain the system. The Ministry’s own guidance says it is enough to state that AI is used to screen, assess, or select applicants. A sentence in the posting clears it.
If your applicant tracking system ranks or filters resumes, and most of them now do something along those lines, you are probably in scope and may not know it.
Federally, there is no AI statute. The Artificial Intelligence and Data Act died on the order paper when Parliament was prorogued in January 2025 and has not come back. What governs AI in Canada today is the general law: PIPEDA, Quebec’s Law 25, sector regulators, and the Competition Act if an AI system is used to mislead consumers. Bill C-36, which we wrote about this week, would add a disclosure duty of its own, but a narrower one: it covers automated systems making predictions or decisions with a legal or similarly significant effect on a person, not chatbots generally. It is also still at second reading and may not pass.
So the Canadian picture is: nothing requires you to label a chatbot, one Ontario rule requires you to label AI in hiring, and the direction of travel everywhere is toward disclosure.
What we would actually do
For a typical small business website, in order of effort:
-
Put a visible line at the top of the chat widget saying it is an AI assistant, and name who it works for. If it is a support bot on a clinic site, “AI assistant for Bloor Street Dental. I can help with booking and general questions.” One line. If you ever end up in scope, you are done, and if you never do, you have a clearer widget.
-
Check what your vendor turned on by default. Most chat vendors ship an AI disclosure toggle now. Some ship it off, or bury it behind a persona setting that lets you give the bot a human name and photo. Look at what your widget actually says on first message, from a fresh browser, not from your admin preview.
-
Decide whether you actually sell into the EU, and write the answer down. Not a legal memo. One line in whatever document holds your operational decisions. If the answer is yes, the AI Act is now one of your product requirements and it is worth twenty minutes with a lawyer who does this.
-
Fix your job postings if you have 25 or more employees. This is the one with a real, current, local obligation attached. Check whether your ATS does any automated ranking or filtering, and if it does, add the sentence.
-
Keep human editorial control over anything you publish. If a person genuinely reviews and takes responsibility for the writing on your site, the deepfake and public-interest-text labelling obligation does not reach it. That is also just how you should be publishing.
Notice what is not on the list: watermarking your own content, buying an AI governance tool, or auditing your model. The marking obligation belongs to whoever built the model. The heavy compliance machinery got deferred to December 2027. Between now and then the useful work is knowing which systems you run, what they do to people, and whether you are honest about it.
The reason we think this is worth reading anyway
Disclosure requirements are the cheapest kind of regulation to comply with and the easiest to get quietly wrong, because the failure mode is not a decision anyone makes. It is a vendor default, a persona setting somebody picked because it tested better, an ATS feature nobody knew was on.
The underlying trend does not depend on the AI Act passing anyone’s approval. Europe has it now, Ontario has a narrow version in hiring, Bill C-36 would add another, and several US states have their own. All of them converge on the same instruction, which is a reasonable one to follow regardless of what any legislature does: when a machine is talking to your customer, or deciding something about them, say so.
That was good practice before August 2, 2026. It is now the law in one large market, and the cost of doing it is a sentence.
If you run a chatbot, an AI feature, or an automated screening step and you want a straight answer about whether any of this reaches you, send us a note. We build these systems, including for regulated clients, and we would rather tell you it is fine than sell you a compliance project.