Does the EU AI Act Apply to Your Website? A Quick Self-Check

SEO & GEO for WordPress websites

The EU AI Act is now enforcing its first major transparency obligations, and many small business website owners are genuinely unsure whether the regulation touches them at all. The short answer is: it probably does, at least in part. Whether you run a WordPress site with a customer-facing chatbot, publish AI-assisted blog content, or use a third-party recommendation engine, understanding where you stand is not optional. Fines for transparency violations reach up to €15 million or 3% of global annual turnover, whichever is higher.

This guide walks you through the key concepts, a practical five-question self-check, and the compliance steps that matter most for SMB website owners right now. It is not legal advice, but it will give you a clear-eyed picture of your exposure and what to do about it.

Who the EU AI Act actually targets

The EU AI Act (Regulation 2024/1689) applies to four groups: providers who develop and place AI systems on the EU market, deployers who use AI systems professionally within the EU, and both groups outside the EU when their AI system’s output reaches EU users. That last point carries real weight. A US-based business running an AI-powered chatbot accessible to European customers falls within scope, even without a single EU office.

The distinction between a provider and a deployer determines which obligations apply to you. A provider is any person or company that develops an AI system and makes it available under their own name or trademark. A deployer is any professional entity that uses a third-party AI system in its own operations. Most SMB website owners who embed tools like a GPT-based chatbot via API, without rebranding or substantially modifying it, are classified as deployers. That matters because deployers carry fewer obligations than providers, though they are not off the hook entirely.

The reclassification rule is worth knowing. Under Article 25, if you white-label a third-party AI system, significantly change its intended purpose, or modify it substantially, you automatically inherit full provider obligations. Embedding a chatbot and calling it your own branded assistant is a common trigger. The Act also explicitly excludes AI used solely for scientific research, personal non-professional use, and certain open-source systems, but those carve-outs are narrower than many assume. The regulation only governs systems that qualify as AI under Article 3(1), covering machine learning models, logic-based systems, and statistical models, not every piece of software on your site.

AI risk tiers and where websites typically land

The EU AI Act organizes AI systems into four risk tiers, and your compliance obligations depend almost entirely on which tier your tools fall into. The four tiers are: Prohibited (banned outright), High-Risk (strict requirements), Limited-Risk (transparency obligations), and Minimal-Risk (no mandatory requirements). The EU AI Office estimates that roughly 80% of all AI systems fall into the minimal- or limited-risk categories, which is broadly good news for standard SMB websites.

Minimal-risk AI: the most common tier for SMBs

Spam filters, product recommendation engines, inventory management tools, and AI-enabled analytics fall into the minimal-risk tier. The Act imposes no mandatory compliance obligations here. If your website uses a basic “people also viewed” recommendation widget, you are almost certainly in this tier and can move on.

Limited-risk AI and transparency obligations

Customer-facing chatbots, conversational AI for support, AI-generated marketing content, and synthetic media used in advertising fall under what is widely called the limited-risk tier. The Act’s Article 50 transparency obligations apply here, requiring you to clearly disclose to users that they are interacting with AI. These obligations became enforceable on August 2, 2026. The penalty ceiling for violating them is the same as for high-risk system failures, up to €15 million or 3% of global turnover, so treating transparency as a minor formality is a genuine financial risk.

One important nuance: Article 50 is technically a parallel track that runs across all risk levels, not a separate tier in the legislative text. A high-risk chatbot is subject to both high-risk system requirements and Article 50 transparency obligations simultaneously. The obligations stack rather than replace each other.

High-risk AI: unlikely but not impossible on SMB sites

High-risk AI systems fall into eight Annex III domains: biometric identification, critical infrastructure, education, employment and recruitment, access to essential services such as credit and insurance, law enforcement, migration, and administration of justice. Most standard SMB websites do not touch these domains. However, if your site uses AI to filter job applicants, score creditworthiness, or make decisions that affect access to services, you are in high-risk territory. The compliance deadline for Annex III standalone systems, updated by the Digital Omnibus approved by the Council of the EU in June 2026, is now December 2, 2027.

The self-check: 5 questions to assess your exposure

A structured self-assessment takes less than an hour and prevents most compliance failures. Work through these five questions top-down: rule out the most serious issues first, then address transparency obligations, and treat everything remaining as minimal-risk.

Question 1: Does the Act apply to you at all? If your AI system’s output is used by anyone in the EU, the Act applies. This includes websites, apps, or tools accessible to EU users, regardless of where your business is registered. If your answer is yes, continue.

Question 2: Are you a provider or a deployer? If you built the AI system, commissioned it to your specification, or rebranded a third-party system under your own name, you are a provider. If you use a third-party tool via API without modification, you are a deployer. Providers carry heavier obligations. Deployers still have duties around use, monitoring, and transparency to affected users.

Question 3: Do any of your AI tools involve prohibited practices? Article 5 has been enforceable since February 2, 2025. Prohibited practices include social scoring, real-time biometric identification in public spaces, subliminal manipulation, exploitation of vulnerable groups, and untargeted facial image scraping. If any tool on your site touches these areas, it must be removed immediately.

Question 4: Do any of your AI tools fall into Annex III high-risk domains? Check whether your site uses AI to filter resumes, assess creditworthiness, make insurance-related decisions, or perform biometric identification. If yes, your compliance deadline is December 2, 2027, but preparation should start now given the documentation and conformity assessment requirements involved.

Question 5: Do you use a customer-facing chatbot or publish AI-generated content? If your site has a chatbot, it must disclose its AI nature clearly at the first interaction, not buried in terms and conditions or a footer. If you publish AI-generated text, images, audio, or video, labeling obligations may apply depending on the content’s purpose and whether genuine human editorial oversight was applied. These obligations are live now. The European Commission published final Article 50 guidelines on July 20, 2026, confirming that disclosure must be clear, distinguishable, and provided no later than the first interaction.

A practical starting point is to inventory every AI tool your site uses. Most SMBs discover they have accumulated more tools than they realized across content, support, analytics, and email, and the inventory itself resolves most classification questions.

Practical compliance steps for SMB website owners

For most SMB website owners, the immediate compliance priorities as of August 2026 are three things: chatbot disclosure, AI literacy documentation, and an AI tool inventory. The heaviest high-risk obligations are deferred to December 2027, giving you time to plan, but the transparency and literacy requirements are active now.

Chatbot and AI content disclosure

If your site has a chatbot, add a clear disclosure at the start of every conversation. The disclosure must be explicit, not implied by a name like “AI Assistant.” The European Commission’s guidelines confirm that a business chatbot named “AI Assistant” on a landing page that also features human agents is not obviously AI to every user, so the “obvious from context” exemption is narrower than it sounds.

For AI-generated content, the obligation depends on purpose and oversight. If a marketing team reviews, edits, and takes genuine editorial responsibility for AI-drafted text, labeling may not be required for that content. Cursory approval does not qualify. The Cooley analysis of Article 50 published on August 3, 2026, notes that the AI Office has published a voluntary Code of Practice on Transparency of AI-Generated Content, including a set of recognized icons for labeling. Signatories benefit from a presumption of conformity and a more favorable enforcement posture.

AI literacy under Article 4

Article 4 has applied since February 2, 2025, with no grace period. Every provider and deployer must ensure that staff and contractors operating AI systems have a sufficient level of AI literacy, and that training is documented. A single onboarding video does not satisfy the requirement. The depth of literacy required scales with what the AI is doing, who it affects, and the consequences of errors.

Supplier conversations and documentation

If you use third-party AI tools via SaaS or external APIs, ask your suppliers what compliance documentation they provide and whether it covers Article 50 transparency requirements for your specific deployment. If an AI solution was built to your specification, you may be classified as the provider even if a third party did the technical building. For SMBs that do fall into high-risk territory, a two-to-three-page memo per system using the EU’s Annex IV template as a guide is typically sufficient technical documentation to start.

The Act includes several SMB-friendly provisions worth knowing: priority access to regulatory sandboxes free of charge, simplified documentation forms, proportional conformity assessment fees, and dedicated communication channels through member state authorities.

Common misconceptions that create compliance blind spots

Several widespread misunderstandings about the EU AI Act lead organizations to either over-invest in unnecessary compliance work or miss obligations that are already active. Clearing up the most common ones saves time and reduces real risk.

The Act only applies to EU-based companies. This is false. The Act applies to any organization whose AI output is used in the EU, regardless of headquarters location. A US business serving European customers through an AI-powered website is in scope.

There is a two-year grace period and everything applies from August 2026. The Act has a staggered implementation. Prohibited practices have been enforceable since February 2025. GPAI model obligations applied from August 2025. Article 50 transparency obligations are live now. High-risk Annex III obligations are deferred to December 2027 following the Digital Omnibus. Treating August 2026 as the single start date misses obligations that were already active and misrepresents the current state of enforcement.

All open-source AI is exempt. Open-source exemptions do not apply to prohibited practices, high-risk systems, or Article 50 transparency obligations. An open-source chatbot deployed on your website still requires disclosure.

If you use a third-party AI tool, the vendor handles compliance. As a deployer, you carry your own obligations regarding use, monitoring, and transparency to affected individuals. There is no automatic transfer of responsibility to the tool provider. Verifying that a vendor’s disclosure mechanism meets the standard for your specific deployment is your responsibility.

The Digital Omnibus delay applies to everything. The delay applied only to Annex III and Annex I high-risk system obligations. Article 4 (AI literacy), Article 5 (prohibitions), and Article 50 (transparency) were not postponed. Organizations that assumed the Omnibus bought them time across the board may already be out of compliance with active requirements.

Minimal risk means zero regulatory risk. Minimal-risk AI systems still must comply with GDPR, national data protection legislation, and any applicable sector-specific regulations. The EU AI Act classification does not override other legal obligations.

How AI-driven SEO tools fit into the EU AI Act

AI-assisted SEO tools occupy a well-defined position in the EU AI Act framework. Keyword research platforms, content optimization tools, technical audit tools, and rank trackers are generally classified as minimal-risk AI and face no mandatory compliance obligations under the Act. Standard grammar checkers, translation tools, and non-public internal content do not require AI-generated content labeling under Article 50 either.

The picture changes when AI-generated content moves from internal use to public-facing publication. Fully AI-generated blog posts on matters of public interest, synthetic media that could mislead viewers, and AI-generated images or videos created from scratch must be labeled. Routine marketing content for a product or service does not typically fall into the “matters of public interest” category, so the labeling obligation is not automatically triggered by subject matter alone. The publisher’s purpose and the presence of genuine human editorial oversight are the deciding factors.

Tools like Semrush, Ahrefs, and Surfer SEO are widely used by marketing teams and, based on general risk-tier criteria, fall into the minimal-risk classification as assistive SEO and analytics tools. No official EU AI Office ruling exists for these specific platforms, so that classification is an informed interpretation rather than a definitive legal determination. The Conformitas legal analysis on AI and marketing confirms that SEO optimization tools do not require AI-generated content labeling under Article 50.

For businesses scaling content output with AI assistance, the practical question is whether a human with genuine editorial accountability reviews and takes responsibility for what gets published. If that process is real and documented, the transparency obligation for text content is typically satisfied. If AI drafts content and it goes live with only cursory review, the picture is less clear, and the conservative approach is to label it. WP SEO AI’s content scaling service pairs AI-generated drafts with specialist review precisely because quality, accuracy, and editorial accountability matter both for search performance and for regulatory positioning.

The broader trend is worth watching. The Act’s emphasis on data quality, data governance, and bias mitigation is already influencing how AI search models are trained and evaluated. Organizations that build content practices grounded in genuine expertise and human oversight are better positioned not just for compliance, but for visibility in the AI-powered search environment that Google AI Mode, ChatGPT, and generative engines represent. Compliance and content quality are pulling in the same direction.

This content was generated with the help of AI — it may contain mistakes

Your customers are asking AI. Are you part of the answer?

In a quick demo, we show how WP SEO AI tracks your AI visibility, finds content gaps, and helps your website appear in ChatGPT, Google AI Overviews and more.

Dive deeper in