August 9, 2026
Automation & AI Strategy & value
The AI Act applies now: What must ordinary Danish businesses actually do?
The AI Act transparency rules apply now. See concretely what businesses must do about AI chatbots, AI agents, content and how employees use AI.

The EU AI Act is no longer just something businesses can note is coming at some point in the future. A significant part of the rules applies now.
On 2 August 2026, the transparency requirements in Article 50 of the AI Act, among others, began to apply. In concrete terms, that means businesses must, in a number of situations, make it clear when people communicate directly with an AI system, or when certain types of content have been generated or manipulated with AI.
It sounds simple at first. But as with so much other EU regulation, it quickly becomes less simple when you ask the practical questions:
- Do you have an AI chatbot on your website?
- Have you built a phone agent that answers customer enquiries?
- Does customer service use AI to reply to emails automatically?
- Does marketing use ChatGPT for articles?
- Do you create images with generative AI?
- Do employees use Copilot or other AI tools in their daily work?
And do you now have to put a big “THIS TEXT WAS WRITTEN WITH AI” on everything the business publishes?
The short answer to that last question is: No.
The AI Act does not contain a general requirement that all texts, images or emails that AI has helped with in some way must be visibly labelled as AI-generated. There are, however, some fairly concrete situations where transparency is now a requirement. And for many ordinary businesses they are actually reasonably manageable once you separate the rules.
This article is therefore not meant as a legal review of the entire AI Act. The purpose is far more practical: What should an ordinary Danish business concretely examine and do?
The AI Act is relevant even if you do not develop AI
One of the misunderstandings I regularly encounter around AI regulation is that the rules primarily concern businesses that develop their own AI models. They do not.
The AI Act distinguishes, among other things, between a provider of an AI system and a business that uses an AI system professionally.
A business that uses an AI system under its own responsibility will typically be what the AI Act calls a deployer. That could be, for example, a business that uses an external AI service in its customer service, marketing or internal administration.
A business can, on the other hand, be considered a provider if it develops – or has developed – an AI system and places it on the market or puts it into use under its own name or trademark.
That is an important difference. If your business simply uses an ordinary AI service internally, that is not the same as developing an AI product. But if you build, for example, an AI-based customer portal, chatbot, phone agent or SaaS solution under the business's own name, the role should be assessed more specifically.
So it is not enough to say: “We're just using an API from another AI supplier.” What matters can be the overall solution and the role the business has in the value chain.
The key new requirement: People must know when they are communicating with AI
Article 50 contains a very concrete principle: When an AI system is designed to communicate directly with people, the person must as a rule be informed that they are communicating with AI, unless it is already obvious.
The European Commission's guidance describes four central elements. There must be an AI system, the system must be designed for genuine two-way communication, the AI must communicate directly with the person without a human intermediary, and the communication must be with a human. Pure machine-to-machine processes and AI that works solely in the background therefore do not fall under this particular requirement. That makes the rule easier to translate into practice.
Do you have an AI chatbot on your website?

Then this is one of the obvious places to look first. If visitors to the business's website can open a chat and hold a conversation directly with AI, it should be clear from the start that the chatbot is AI.
You do not necessarily have to meet the customer with half a page of legal text. On the contrary. The information must be clear and plain no later than at the first interaction. A practical wording could, for example, be:
“You are chatting with our AI assistant. It can help with common questions. You can always ask to be transferred to a human.”
That tells the customer the essentials without making the dialogue cumbersome.
At the same time, I would recommend that the business decides what the chatbot may and may not do:
- May it give concrete prices?
- May it promise delivery times?
- May it advise on contractual matters?
- Can it create an order?
- Can it change customer data?
- Can it pass information on to employees?
- And what happens when it does not know the answer?
That last point is not only about the AI Act. It is also about building a solution you actually dare to put in front of your customers.
What about an AI phone agent?

The same basic principle is relevant. If a customer calls the business and is met by a voice-based AI agent that can hold a real conversation, the customer should know that it is AI.
Here I would keep it very simple and mention it as one of the first things in the conversation. For example:
“Hi, you're talking to our AI assistant. I can help you with…”
The conversation can then continue naturally. In my assessment, it is also better for the customer experience.
A phone agent does not become worse because the customer knows it is AI. The problems arise rather if, after several minutes of conversation, the customer discovers that they thought there was a human at the other end. Transparency can therefore be an advantage rather than a limitation. And a well-implemented AI agent should in any case have clear rules for when a human must take over.
What if AI only helps the employee?
Here the distinction becomes important. Imagine that a customer sends an email. AI analyses the email and drafts a suggested reply. An employee then reads the reply, edits it and sends it to the customer.
In that situation, the customer is not necessarily communicating directly with AI. The European Commission's guidance emphasises precisely that Article 50's direct-interaction requirement concerns situations where the AI system itself communicates with the person and does not do so through a human intermediary.
That does not mean all other rules disappear. But it does mean you should not make the AI Act simpler than it is by concluding: “If AI has been involved somewhere, the customer must always be informed.” That is not how Article 50 is worded. It is the specific use that is decisive.
Do AI-generated articles have to be labelled?

Here I expect a fair amount of confusion in the coming months. Because no: the AI Act does not say that every business using ChatGPT as a writing aid automatically has to put an AI label on all its articles.
Article 50 has a more specific requirement. If a business uses AI to generate or manipulate text that is published for the purpose of informing the public about matters of public interest, the use of AI must as a rule be disclosed. But there is an important exception where the content has been subject to genuine human review or editorial control, and a natural or legal person holds editorial responsibility for the publication.
The European Commission mentions, among other things, politics and democratic processes, public administration, the justice system, fundamental rights, public safety, public health, environmental protection, consumer safety, as well as economic, political, scientific or cultural developments that may be part of public debate.
What is interesting is therefore not only: “Did AI write some of the text?” What is interesting is also: “What is the text about, how was it produced, and who has actually taken editorial responsibility for it?”
Human review has to be genuine
Here is a detail worth noting. The European Commission clarifies that a superficial check is not necessarily enough to be called human or editorial review.
Running the text through a spell checker or correcting a few grammatical errors does not in itself count as real editorial control. There must be a deliberate review of the content's substance by a person with relevant competence and professional judgement. In the case of editorial control, the responsible person must genuinely be able to approve, change or reject the content of the text, including, for example, checking facts and sources.
I actually think that is a quite sensible dividing line. If AI functions as a tool in an ordinary editorial process, where a human researches the topic, assesses the information, edits the text and takes responsibility for the finished result, the situation is something other than a fully automatic article machine that generates and publishes a hundred articles without human control.
That is also how I believe businesses should work with AI-generated content. AI may well make the work faster. It just should not remove the human responsibility.
An automatic AI news site is something else
Imagine instead this workflow: A system finds current news by itself. AI generates an article. AI creates the headline and image. The article is published automatically. No one has read it first.
If the content is at the same time about matters of public interest, we are much closer to precisely the situation that Article 50's disclosure requirement concerns. Here the business should therefore not only think about SEO, quality and fact-checking. It should also build transparency into the publishing flow itself.
It is a good example of why compliance works best when it is built into the automation flow from the beginning – rather than being added afterwards as yet another manual step.
What about AI images?
There are two rules that often get mixed up.
Providers of generative AI systems that generate synthetic text, images, audio or video must as a rule ensure that the output can be marked in a machine-readable way and identified as artificially generated or manipulated. There are, among other things, exceptions for standard editing and situations where the input is not substantially altered.
This is first and foremost a provider obligation. It is therefore not the same as a general requirement that an ordinary business must write “AI-generated image” under every decorative AI image on its website.
But there are separate rules about deepfakes.
Deepfakes must as a rule be disclosed
The AI Act defines a deepfake in relation to AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events in a way where the content may falsely appear authentic or true.
If the business uses such content professionally, it must as a rule be made clear that the content is artificially generated or manipulated. It has to be something a human can actually perceive. A hidden technical metadata marking is not in itself sufficient for the deployer's disclosure obligation regarding deepfakes.
A milder approach applies to clearly artistic, creative, satirical or fictional works, where the disclosure can be given in a way that does not spoil the experience.
It is yet another reason not to reduce the rules to: “All AI must be labelled.” Context matters.
Machine-readable marking – does your business have to build it?
For many ordinary businesses: probably not. The requirement that synthetic text, audio, images and video must be markable in a machine-readable way and detectable as AI-generated or AI-manipulated lies in Article 50(2) with the provider of the generative AI system.
If your business simply uses an existing AI tool, you are not automatically the party that has to develop the watermarking or metadata technology itself. If, on the other hand, you develop or have developed a generative AI system and put it into operation under your own name, the situation may be different. Here it is again crucial to establish the business's role.
The EU has at the same time drawn up a voluntary Code of Practice on the transparency of AI-generated content, and there are optional EU icons that can be used for certain labelling situations. The icons are voluntary; the disclosure requirement itself is not voluntary when you fall within the rules.
There is a limited transition period – but only in one area
There is a transition period until 2 December 2026 for certain generative AI systems that were already on the market before 2 August 2026. But the transition period concerns the technical marking and detection obligation in Article 50(2).
So it is not a general four-month grace period during which businesses can simply ignore the other transparency rules. That is an important detail, because the opposite conclusion can quickly spread when the new rules are boiled down to short social media posts.
What about ChatGPT and Copilot on employees' computers?

Here Article 50 is not necessarily the most interesting part. There is another part of the AI Act that many businesses should be at least as interested in: AI literacy.
Article 4 requires businesses that develop or use AI systems to take relevant measures regarding AI competence among employees and other people who work with the systems on the business's behalf. The requirement has actually applied since 2 February 2025. Following changes in 2026, no particular certified competence level is required, but AI literacy remains an obligation.
The European Commission recommends, among other things, that the business considers which AI systems the organisation uses, employees' existing knowledge, the systems' risks and the specific context in which they are used.
There is no requirement for a particular AI certificate, and the AI Act also does not require every business to appoint a special “AI Officer”. An internal record of training, guidelines and other measures can, on the other hand, be used as documentation.
For an ordinary smaller business, it therefore does not have to develop into a huge project. But “employees just use whatever AI they feel like” is not a very durable strategy either.
A simple internal AI policy can solve a lot
At a minimum, I would get some clear internal frameworks written down. Not a 47-page document that no one reads. But concrete answers to the questions employees actually face:
- Which AI tools may we use?
- May we enter customer data?
- May we insert internal documents?
- May we use AI for code?
- May AI write directly to customers?
- Which answers must always be reviewed by a human?
- Who is responsible for fact-checking?
- When may AI perform actions automatically?
- How do we handle confidential information?
- And what do we do if we are in doubt?
That provides both more secure use and far more peace of mind around AI in the organisation.
GDPR does not disappear because the AI Act has arrived
The AI Act does not replace GDPR. If the business sends personal data into an AI system, the data protection rules still have to be complied with. The AI Act itself also clarifies that the rules apply alongside, among other things, the EU's data protection rules.
The Danish Data Protection Agency (Datatilsynet) has warned several times that employees may end up entering personal data into generative AI tools without the workplace having taken a position on it. The agency therefore recommends organisational frameworks and guidelines for employees' use of generative AI.
In practice, that means a business should not settle for asking: “Is our AI chatbot labelled correctly?” You should also ask: “What data are we actually sending through it?” The most significant risk may lie somewhere entirely other than in the AI labelling itself.
Using AI for recruitment and employees requires extra attention
Some AI uses go far beyond Article 50. AI systems used for certain tasks within recruitment and workforce management can, for example, be classified as high-risk. The Commission mentions, among other things, AI for targeted job advertisements, analysis and filtering of job applications and evaluation of candidates. Other high-risk areas include parts of education, credit scoring, critical infrastructure, biometric systems and certain public areas.
If the business uses AI in that type of decision, you should therefore not settle for this article. Here the solution must be assessed more specifically.
A chatbot is one thing. A decision engine is something else.
It is also a useful way to think about the AI Act. A chatbot that tells the customer the business's opening hours is one type of risk. An AI system that assesses whether a person should be hired, granted credit or receive a particular benefit is something entirely different.
The AI Act is built precisely around a risk-based approach. It therefore does not make much sense to have one general rule like: “We use AI.” The interesting question is: “Where do we use AI, what does the system do, which data does it get, and what significance does the result have for people?” Once you can answer that, the rest of the work becomes much easier.
What should ordinary businesses concretely do now?
If I were to review a smaller or medium-sized business's AI use tomorrow, I would begin quite down to earth.
| Situation | What you should examine |
|---|---|
| AI chatbot on the website | Is it clear from the first interaction that the customer is communicating with AI? |
| AI phone agent | Is the customer informed about AI at the start of the conversation, and can a human take over? |
| Automatic AI customer service | Does AI communicate directly with the customer, or does an employee review the replies first? |
| AI-generated articles | Are they about public interest, and is there genuine human/editorial review? |
| AI images, audio or video | Could the content be a deepfake that falsely appears authentic? |
| Own AI solutions | Is the business only a deployer, or could it also be a provider of the system? |
| ChatGPT, Copilot, etc. internally | Are there frameworks, instructions and relevant AI competence among employees? |
| Customer or employee data in AI | Are GDPR, data processing arrangements, security and purpose clarified? |
| AI in recruitment or significant decisions | Could the system be high-risk and require a separate assessment? |
It is not necessarily complicated. But it does require that someone actually does the mapping.
Start with an AI register – even if you only have five employees
I think businesses can benefit from making a small internal register of their AI use. It does not have to be a new enterprise system. A spreadsheet can be plenty. For each system, the business can note:
- which AI tool or system is used
- what it is used for
- who uses it
- whether it communicates directly with external people
- which data it receives
- whether output is published automatically or performs actions
- who quality-assures the result
- who internally owns the process
Once that exists, the business has a far better foundation for the AI Act, GDPR, security and ordinary operations alike. And not least, it becomes visible if there is “shadow AI” – that is, tools employees have started using without any actual decision or risk assessment.
Transparency does not have to make AI worse
I actually take a positive view of many of the transparency requirements. A good AI solution does not need to pretend to be a human to be useful. If a customer gets their problem solved in 30 seconds by an AI agent, the solution does not become less valuable because the customer knows it is AI.
On the contrary, you can set expectations correctly from the beginning: The AI can solve standard tasks quickly. Humans take over when the situation requires judgement, empathy or decision-making authority. In my assessment, that combination is far more interesting than trying to hide where AI is involved.
Compliance should be built into the solution – not stuck on afterwards
If you develop an AI chatbot, phone agent or an automated workflow, it is far easier to build the requirements in while the system is being built:
- An information field in the chatbot.
- A short disclosure at the start of the phone call.
- Logging of when a human has approved an article.
- A rule that certain output may not be published automatically.
- A system for escalation to an employee.
- Access control around personal data.
- Documentation of models, prompts and integrations.
That is ordinary good system design. And it is typically cheaper than discovering six months later that the system's architecture makes it hard to document who did what.
What can the fines be?
Breaches of Article 50 can, in the most extreme case, be subject to administrative fines of up to 15 million euros or up to 3 percent of the business's total global annual turnover from the preceding financial year.
For SMEs, special proportionality principles apply, and when imposing sanctions, factors such as the nature and gravity of the breach, the size of the business, its responsibility, cooperation with the authorities and whether the act was intentional or negligent must be taken into account.
It is therefore not very helpful to present the AI Act as: “Forget an AI icon and you get a million-euro fine.” That is not how the rules work. But the very high maximum amounts naturally show that businesses should not ignore the requirements either.
My recommendation: Do it pragmatically
For most ordinary Danish businesses, I would not begin by buying a large AI compliance system. I would begin by creating an overview:
- Find out where AI is already used.
- Find the systems that talk directly with customers or other people.
- Find the processes where AI publishes something automatically.
- Find the places where personal data is involved.
- Find the uses where AI affects significant decisions.
- And make sure employees know what they may do.
For many businesses, after that exercise you will discover that the necessary changes are fairly concrete. For others, the review may show that an AI solution is more critical than expected. Both are valuable to know.
The AI Act should not be a reason to stop using AI
I think that is an important closing point. The goal should not be for employees to become so nervous about rules that they stop experimenting.
AI can already automate large amounts of trivial work, improve customer service, help with documentation, analyse data, support employees and make entirely new products possible. But it has to happen with open eyes:
- When the customer talks to AI, we say so.
- When AI is used for something sensitive, we examine the risk.
- When the employee uses AI, we provide sensible frameworks.
- When AI creates content, a human takes responsibility where necessary.
- And when we build automations, we make sure we can also explain how they work.
That is not necessarily bureaucracy. To a large extent it is simply good digital practice.
Are you unsure how the AI Act affects your solution?
If you already work with an AI chatbot, phone agent, automated customer service, generative content or other AI workflows, it can be a good idea to have the solution mapped before you start changing everything.
I help businesses with both the technical and practical side of AI solutions: how the systems are built, which data flows between them, where humans are involved, which processes are automated, and where it makes sense to build in transparency and control.
I do not provide legal advice, but I can help with the technical mapping and implementation – and work together with the business's legal adviser where an actual legal assessment is needed.
Have your business's AI use reviewed
Have you already started using ChatGPT, Copilot, AI agents or automated AI workflows? I help map the solutions and translate requirements and risks into concrete technical measures.
Sources and further reading
The article is based on the applicable AI Act as well as the European Commission's final guidance on the transparency requirements in Article 50, the Commission's current Q&A on Article 50 and AI literacy, and Danish guidance from the Data Protection Agency (Datatilsynet). Article 50 applies from 2 August 2026, while the AI literacy obligation has applied since February 2025.
Note: This article is general information about the AI Act and the practical use of AI and does not constitute legal advice. For high-risk AI, larger implementations or doubt about the business's specific legal obligations, relevant legal advice should be obtained.