New transparency obligations under Europe's AI Act took a further step forward this summer. The European Commission published guidance clarifying what providers and deployers of certain AI systems must disclose, and when. The rules target familiar territory: chatbots that must identify themselves as automated, and AI-generated or manipulated content that could otherwise be mistaken for authentic material. What has changed is enforcement clarity, and with it, exposure for businesses that assumed the requirement did not reach them.
The obligation does not attach to company headquarters. It attaches to the market a product or service touches. A small business operating a website chatbot, generating marketing content with AI tools, or publishing AI-assisted media that reaches European users may fall inside scope even without a European office, a European employee, or a deliberate decision to comply with European law. Many companies never asked the question because the product felt domestic and the audience felt local.
The Commission's July guidance on Article 50 transparency obligations describes the disclosure requirement in practical terms: users interacting with an AI system should be able to tell that they are doing so, unless the interaction is obvious from context. Deepfakes and certain synthetic content require labeling regardless of whether the content is persuasive, decorative, or incidental to the business's core offering. The standard is not whether the company intended to deceive. It is whether a disclosure exists.
Enforcement authority has followed the guidance. The AI Act Service Desk, now operating as a coordination point for national authorities, gives regulators a functioning channel to identify noncompliant systems and act on complaints. A rule with no enforcement mechanism behaves differently than a rule with one. Businesses that treated the AI Act as aspirational compliance now have reason to treat it as operational risk.
The practical response does not require a legal department. It requires an inventory. Which customer-facing systems use AI to generate, personalize, translate, or respond to content? Do any of those systems reach users outside the country where the business is based? Does the interface disclose, in a way a reasonable user would notice, that AI is involved? Most businesses can answer these questions in an afternoon. Few have been asked to.
Regulatory uncertainty tends to reward the businesses that treat compliance as a design question rather than a legal afterthought. A disclosure notice added after a system ships costs more, in both engineering time and reputational risk, than a disclosure built into the interface from the beginning. The AI Act's transparency requirement is not unusually burdensome. It is unusually easy to miss until a regulator, a customer complaint, or a competitor points it out.
Stottly Enterprises sees this as a preview of a broader pattern: AI-specific disclosure and governance requirements are arriving faster than most companies are updating their compliance checklists. A business that reaches customers outside its home country through any AI-enabled product should confirm what it is required to say, not assume the requirement was written for someone else.