Skip to content

You use AI.From 2 August, you have to say so.

From 2 August 2026 the AI Act's transparency obligations (Article 50) apply — to any company using AI, including through off-the-shelf tools. We inventory where you use it, put the disclosures and markings where they belong, and leave your internal rules in writing, so none of it depends on anyone's memory.

See the AI Act calendar
01 · Calendar

What applies and when — no interpretation needed.

The AI Act phases in. The simplification package adopted in June 2026 (the “Digital Omnibus”) deferred the obligations for high-risk systems, but deliberately left Article 50 transparency untouched. That is the date that concerns you now.

  1. 2 February 2025

    Prohibited practices + AI literacy

    The prohibitions took effect (social scoring, manipulation, emotion recognition at work) along with the duty to ensure a sufficient level of AI literacy for the people using it on the company's behalf (Article 4).

  2. 2 August 2025

    General-purpose models + governance

    Obligations for providers of foundation models (OpenAI, Google, Anthropic, Meta) and national supervisory authorities taking up their role.

  3. 2 August 2026

    Transparency — Article 50

    You state clearly when someone is talking to an AI. You disclose AI-generated or manipulated content that could be mistaken for reality. You disclose AI-generated text published to inform the public on matters of public interest — or you take editorial responsibility for it through a documented human review.

    In force now
  4. 2 December 2026

    Machine-readable marking

    The deadline by which providers of generative AI must have technical, machine-readable marking on systems already placed on the market — four months later than the rest of Article 50.

  5. 2 December 2027

    High risk — stand-alone systems

    Obligations for Annex III systems: recruitment, credit scoring, education, access to essential services. Deferred from the original schedule by the simplification package.

  6. 2 August 2028

    High risk — embedded in products

    AI systems embedded in already-regulated products (Annex I): medical devices, vehicles, toys, lifts.

Basis: Regulation (EU) 2024/1689 (the AI Act), Articles 50 and 113, plus the simplification package adopted by the European Parliament on 16 June 2026 and the Council on 29 June 2026. We re-read the calendar at every quarterly review and update it here.

What we cover, specifically.

What the law requires (Article 50)

The AI inventory

Where you actually use AI: chatbot on the site or WhatsApp, images in ads and social, text on the blog and newsletter, internal tools, AI features that appeared inside platforms you already run. Most companies find twice as many places as they expected.

Art. 50Inventar

Disclosing the chatbot

People must know from the first interaction that they are talking to an AI, unless it is obvious from context. We write the wording, place it in the first message and in the widget, and keep it accurate after a handover to a colleague.

ChatbotArt. 50(1)

Marking images and video

AI-generated or manipulated content resembling real people, places or events must be visibly disclosed. We build the badge in your brand identity (RO/EN), settle where it applies and where it does not, and leave the template for future material.

DeepfakeArt. 50(3)

AI text and the editorial exception

For text published on matters of public interest you have two options: disclose it as AI-generated, or run a human review in which a named person takes editorial responsibility. The second is usually better for the brand — but it has to exist on paper, with a name and a date.

Text AIArt. 50(4)

The internal rules that make it stick

Internal AI policy

One page, not a manual: which tools are approved, which data never goes into a public AI, what passes through human review before publication, who approves exceptions.

Politică internă1 pagină

Register of AI systems

A living list of every AI system in the company, with its purpose, the data it touches, the vendor and the person responsible. It is the first document you open if anyone asks.

RegistruResponsabil

AI literacy for the team

Article 4 requires a sufficient level of AI literacy for people using AI on the company's behalf. A short session on your actual roles, with examples from your own workflows — and a written trace that it happened.

Art. 4Instruire

Vendors and data

Which AI tools you use, what contracts you have with them, where the data goes and what gets trained on it. This is where it connects to GDPR and your privacy policy.

FurnizoriDate

What keeps it true a quarter from now

Quarterly re-check

Sites, chatbots and campaigns change. We re-run the check every quarter, mark new material as it ships, and tell you when the deadlines move.

TrimestrialAlerte

The evidence file

Screenshots, text versions, the signed procedure, the training log. Compliance is not what you did — it is what you can show you did.

DosarDovezi

How we work — four steps.

01 / Inventory

What AI you actually use

1 day

We go through the site, chatbots, live campaigns, social and internal tools. We come out with a complete list of the places where AI touches your public or your data.

02 / Diagnosis

What is compliant, what is not

included

We check every item in the inventory against the three transparency obligations. A 2–3 page report: compliant / non-compliant / to be decided, prioritised by risk and effort.

03 / Remediation

We put it right

3–10 days

Disclosure wording in the chatbot, the badge on material, the human review procedure, policy updates. We implement it — we don't hand you homework.

04 / Governance

Still true a year from now

quarterly

Internal policy, register of systems, team training and a re-check every quarter — plus an alert when something in the legislation moves.

Three levels. Pick how far you go.

01
Compliance audit

Where you stand against Article 50, in black and white.


  • Full inventory: where you use AI
  • Check against the three transparency obligations
  • 2–3 page report: compliant / non-compliant
  • Prioritised remediation list
Start with the audit
02 · Most chosen
Audit + Remediation

The audit, plus the actual implementation.


  • Everything in the Audit
  • Chatbot disclosure — wording and implementation
  • “Generated with AI” badge in your identity (RO/EN)
  • Human review procedure, with a named owner
  • Privacy policy and terms updates where needed
Book the remediation
03 · Ongoing
Ongoing governance

Stay compliant as the company changes.


  • Everything in Remediation
  • Internal AI policy + register of systems
  • Quarterly re-check and marking of new material
  • Legislative-change alerts + a briefing for management
Discuss the retainer

2 August 2026

The deadline is already here. An audit plus the basic remediation fits inside one working week.

We built your site

For the sites, chatbots and campaigns we already run, remediation needs no coordination with anyone else.

You leave with evidence

Report, signed procedure, register and a file of screenshots — not just a verbal all-clear.

Proportionate to your company

The Regulation requires proportionality for SMEs. We won't sell you a corporate compliance system if you have twelve people.

What we don't do.

×

We don't give legal opinions

We cover the technical and operational side. Documents with legal standing stay with your lawyer — we work with them, not instead of them.

×

We don't issue certifications

There is no “AI Act certificate” we could hand you. There is evidence you can show, and that is what we build.

×

We don't ban your AI

The goal isn't to use less AI, it's to use it declared. Almost nothing you do today needs to stop — it needs to be stated.

×

We don't produce paper for its own sake

A one-page policy someone actually reads beats a forty-page manual nobody opens.

Every week we brief our clients' managers on what's changing in AI and what it means for the company. The archive is public.

See the AI Briefing

Frequently asked questions

We only use ChatGPT and Canva. Does this apply to us?

Yes. The transparency obligations follow how you use AI, not who built it. If you publish AI-generated images that look real, or run a chatbot on your site, you are in scope even if you never wrote a line of code.

Who is responsible — us or the tool vendor?

It's split. The model provider is responsible for technically marking generated content. You, as a professional user, are responsible for disclosing deepfake-type content and AI-generated text published on matters of public interest. In practice: the part your audience sees is yours.

Is the chatbot on our site “ours” or the platform's?

It depends on the setup, and it's exactly the question we put to your lawyer. The working rule we apply: if the bot carries your name and brand and you configure it, treat the disclosure obligation as yours. It costs one sentence in the first message and takes the argument off the table.

How big are the fines, realistically?

For breaching the transparency obligations, the Regulation's ceiling runs up to €15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs and start-ups the lower of the two applies, and authorities must take company size into account. The realistic risk for a small Romanian company isn't the maximum fine — it's a complaint, an inspection and the time it eats.

Are we a “high-risk” system?

Most likely not, if you do marketing, retail or ordinary services. High risk mainly means recruitment, credit scoring, education, access to essential services, or AI embedded in regulated products. We tell you in the audit — and if you are, your deadlines are in 2027–2028, not August 2026.

We already have a lawyer or DPO. Do you overlap?

No. They cover the legal basis and the documents; we cover what shows up in the product — the chatbot wording, the marking on material, the review procedure, the register. We send them what we did, so they can validate it.

How long does all of it take?

The audit: one working day for an ordinary company. Remediation: from a few hours to a week, depending on how many channels you run. If we already manage your site and campaigns, it's visibly faster.

The information on this page is indicative and reflects the text of Regulation (EU) 2024/1689 and the amendments adopted in June 2026. It is not legal advice. For classifications and documents with legal standing we work together with your lawyer or DPO.

See where you stand, before someone else asks.

A compliance audit on your company: where you use AI, what is compliant, what is not, and what gets fixed in what order. One working day.

The compliance audit includes

  • An inventory of where you use AI, channel by channel
  • A check against the three Article 50 transparency obligations
  • A short report: compliant, non-compliant, to be decided
  • A prioritised remediation list with estimated effort
  • Half an hour with management to walk through the findings
Call now

B-dul Unirii 25–27, București · office@websem.ro · 0760.60.48.49