If your website uses a chatbot, publishes AI-generated images, or serves AI-written copy, you may now have a legal duty to say so. The new EU guidelines on AI labelling clarify a rule that was always coming under the AI Act: people have a right to know when they are talking to a machine or looking at synthetic content. The good news is that the duty is narrower than the headlines suggest, and a well-worded label costs you nothing and rarely spooks anyone.
Here is the short version. Two things trigger disclosure: interacting with an AI system (a chatbot), and generating or manipulating content that looks real (images, audio, video, and in some cases text). Purely decorative or obviously artificial AI output is largely exempt. Below is a practical map of what applies to a normal small business site, with label wording you can paste in today.
What the EU actually requires
The AI Act requires transparency in two situations relevant to almost every website: when users interact with an AI system, and when AI produces or alters realistic content. The recent guidelines exist to explain the edges — what counts as "realistic", who carries the duty, and how the label should look.
The obligation sits in Article 50 of the AI Act. It splits neatly:
- Chatbots and virtual agents: if a person could reasonably think they are talking to a human, you must make clear they are not — unless it is already obvious from context.
- Synthetic media (deepfakes and generated images/audio/video): must be disclosed as artificially generated or manipulated.
- AI-generated text published to inform the public on matters of public interest: must be labelled, unless a human reviewed it and takes editorial responsibility.
The disclosure has to be clear, at the latest at the first interaction or exposure. It does not have to be a giant warning banner. It has to be honest and easy to notice. That distinction matters, because a subtle label reads as professional, while an alarmist one makes people distrust content that is perfectly fine.
Which of your features trigger a duty (and which don't)
Most small business sites have three AI touchpoints — a chatbot, generated images, and AI-assisted copy — and only some of them need a label. Run through this table before you start adding disclaimers everywhere.
| Feature | Disclosure needed? | Why |
|---|---|---|
| Support chatbot answering customers | Yes | Users could mistake it for a human agent. |
| Chatbot clearly styled as a bot (robot avatar, "AI assistant" name) | Borderline — label anyway | Context may make it obvious, but a one-line note removes doubt. |
| Photorealistic AI hero/product image | Yes | It looks like a real photo; that is exactly what the rule targets. |
| Obviously artistic or abstract AI illustration | No | Nobody would take it for real footage or a real person. |
| AI-drafted blog post reviewed and edited by you | No | Human editorial responsibility exempts it. |
| Fully automated AI news/article feed on public-interest topics | Yes | Published to inform the public with no human sign-off. |
| AI-generated product descriptions you checked before publishing | No | Not public-interest content, and human-reviewed. |
The pattern is simple. Realism plus the risk of being fooled equals a label. If a reasonable person would not be misled — because the content is clearly stylised, or because a human stands behind it — you are generally fine. When in doubt, a quiet label is cheaper than an argument with a regulator.
Copy-paste label patterns that don't scare customers
A good AI label is short, factual, placed where the content is, and free of apology or alarm. The worst thing you can do is bury it in the footer or dress it up as a legal warning.
For a chatbot, disclose in the very first message or in the widget header:
- "Hi, I'm an AI assistant. I can help with orders and common questions — type agent any time to reach a person."
- Widget label: "AI chat" or "Automated assistant".
For a generated image, a small caption near the image does the job:
- "Image generated with AI."
- "Illustration created using AI tools."
For text that needs it (the rarer case), a single line under the byline works:
- "This article was produced with AI assistance and reviewed by our team." (use only if a human genuinely reviewed it)
- "Automatically generated summary — not edited by a person." (for unreviewed automated feeds)
Notice the tone. You are informing, not confessing. Customers care far more about whether they can reach a human than about the fact that a bot answered first. Pair every chatbot disclosure with a clear route to a real person, and the label stops being a liability and starts being a trust signal.
The technical bit: machine-readable marking
Beyond the visible label, the guidelines expect synthetic media to carry a machine-readable marker so platforms and browsers can detect it, and the obligation falls first on whoever generated the content. For most site owners this is handled by your tools, but it is worth checking.
Practical steps you can take this week:
- Keep the metadata. Tools like DALL·E, Adobe Firefly and others now embed C2PA "Content Credentials" in the file. Don't strip EXIF/metadata on upload — some image optimisers do this by default, so check your pipeline.
- Don't re-export needlessly. Running a generated PNG through a lossy converter can wipe the embedded provenance. Optimise in a way that preserves metadata.
- Log what you generated. Keep a simple record — file, tool, date — so you can prove provenance if asked. A spreadsheet is enough for a small site.
- Add a visible caption anyway. Machine-readable marking and a human-readable label are separate requirements; you generally need both for realistic media.
If you host with us at TPC Hosting, your image files and metadata sit on EU servers, which keeps this whole provenance question inside EU jurisdiction — one less cross-border headache when you are trying to demonstrate compliance.
A 20-minute compliance pass for your site
You can get a normal small business site compliant in under half an hour by auditing three things and fixing only what actually triggers the rule. Skip the panic — most sites need one or two small changes.
- Chatbot: Does the first message say it's AI? Is there a visible way to reach a human? Fix both if not.
- Images: List any photorealistic AI images. Add a small "Image generated with AI" caption. Leave clearly artistic ones alone.
- Content: Identify any fully automated, unreviewed published text on public-interest topics. Either add a human review step or label it. Reviewed marketing copy needs nothing.
- Metadata: Confirm your upload/optimisation flow isn't stripping Content Credentials.
- Records: Start a short log of generated assets.
Keep a dated note of the pass. If a customer or authority ever queries it, "we reviewed our AI features on this date and labelled X, Y, Z" is a far stronger position than scrambling after the fact. And if you are moving to EU hosting to keep your data and provenance in-region, our engineers handle the migration for free and you have 30 days to back out — so you can sort the compliance and the hosting in one go.
The rule is not out to punish small businesses using AI sensibly. It exists so people are not deceived. Label the things that could fool someone, keep a human in the loop where it counts, and you are done.
FAQ
Do I need to label AI-written blog posts?
Usually no, as long as a human reviewed the post and takes editorial responsibility for it. The labelling duty for text targets fully automated content published to inform the public on matters of public interest with no human sign-off, so ordinary reviewed marketing and blog copy is exempt.
Does my customer support chatbot need a disclosure?
Yes, if a visitor could reasonably think they are talking to a human. Say it's an AI assistant in the first message or the widget header and give a clear route to a real person — that single line satisfies the rule and actually builds trust.
Do I have to label AI illustrations that clearly look artificial?
No, obviously stylised or abstract AI illustrations generally don't require a label. The requirement applies to realistic images, audio and video that could be mistaken for genuine footage or real people; when in doubt, add a small caption anyway.
What happens if I ignore the AI labelling rules?
Non-compliance with the AI Act's transparency duties can lead to enforcement and fines under national supervisory authorities. For a small business the bigger day-to-day risk is losing customer trust, so a quiet, honest label is the cheaper option by far.
Does where I host affect AI compliance?
Hosting location doesn't change the labelling duty, but keeping your files and metadata on EU servers keeps provenance and any data questions inside EU jurisdiction. TPC Hosting is EU-hosted and GDPR-friendly, which simplifies demonstrating where your generated content lives.

