Home/Insights/AI Regulation

Why your AI tools are a liability right now

By Ani BjörkströmPublished 1 September 2026Reviewed 20 September 20267 min video + articleAI Regulation

Why your AI tools are a liability right now
▶ Watch the full 7-minute tutorial · free on YouTube

AI TOOLS

Does Your Chatbot or AI Content Already Break the EU AI Act?

In short: Article 50 of the EU AI Act took effect on 2 August 2026 — before the high-risk rules, which were pushed back to 2 December 2027.

Key takeaways

  • Article 50 of the EU AI Act took effect on 2 August 2026 — before the high-risk rules, which were pushed back to 2 December 2027.
  • Fines reach €15 million or 3% of global annual turnover, whichever figure is larger — for a €1 billion company, that is €30 million, not €15 million.
  • AI systems already running before 2 August 2026 have until 2 December 2026 to build in machine-readable labelling; content published before that date does not need retroactive marking.

In this video, Ani Björkström, the Stockholm-based AI consultant behind the YouTube channel "Ani Björkström | AI for Finance," walks through Article 50 of the EU AI Act — the transparency provision that quietly went live on 2 August 2026 while most attention was fixed on the high-risk AI rules now delayed to December 2027. The video is aimed at anyone running a chatbot, publishing AI-generated content, or using AI on customer faces and voices, and it distils the law into four practical rules plus a five-question self-audit.

What does Article 50 actually require?

Article 50 is not a safety or paperwork rule — it is a honesty rule. It covers four distinct situations: AI chatbots talking to people, AI-generated media (images, video, audio, text), emotion-recognition and biometric-categorisation systems, and deepfakes of real people, places or events. Each situation carries its own disclosure requirement, and the video stresses that the disclosure must be visible where people actually see it — not buried in a caption, a description, or hidden metadata inside a file.

The rule most companies are already breaking, according to the video, is the chatbot rule: if a customer could reasonably believe they are talking to a human, the AI must say otherwise at the start of the conversation, in clear and easy-to-notice language — a single sentence such as "You are chatting with an AI assistant" is enough.

What is the deadline for labelling AI-generated content?

The video draws a sharp line between the system and the content it produces. If an AI system was already running before 2 August 2026, the operator has until 2 December 2026 to build machine-readable marking into that tool. That deadline applies to the tool, not to past posts — content made and published before 2 December 2026 does not need to be labelled retroactively. Once the tool passes that deadline, everything it publishes afterward must carry the mark. A small logo in the corner of an image is described as not sufficient on its own; the label must be readable by a machine, not just visible to a human eye.

Who is liable if something goes wrong — the AI vendor or the company using it?

The video highlights a liability split that catches people off guard. For the chatbot disclosure rule, the company that built the AI system carries the responsibility. But for emotion-recognition, biometric categorisation, and deepfakes, it is the user of the AI — the company deploying it in a call centre, a shop, or a marketing campaign — that carries the legal responsibility. "We just bought the tool" is explicitly called out as not a valid defence.

RuleWho it applies toWhat to do
Rule 1 — ChatbotsWebsite chat, phone support, booking assistantsState clearly at the start of the conversation that the user is talking to AI
Rule 2 — AI-generated contentAI images, video, audio, textMachine-readable mark; systems running before 2 Aug 2026 have until 2 Dec 2026 to comply
Rule 3 — Emotion/biometric AICall centres, shops, interview-scoring toolsDisclose at the moment the AI is used, not in a policy document
Rule 4 — DeepfakesMarketing, AI avatars of real people, AI-written news textDisclose the content is synthetic; softer disclosure allowed for art/satire; human editor can substitute for disclosure on news text

How can a business check its own exposure quickly?

The video closes with five self-check questions companies are told to answer this week: does every AI chat clearly say it is AI at the start; does every AI-generated output carry a machine-readable mark; does the company use anything that reads emotion or sorts people by appearance; does it publish AI images, video or voice of real people; and does it publish AI-written text about news or public affairs without a human editor taking responsibility. A "yes" to the fourth or fifth question without an existing disclosure is flagged as something to fix immediately, while the 2 December 2026 date is the one deadline every operator of a pre-existing AI system should already have in their calendar.

FAQ

When did Article 50 of the EU AI Act take effect?

On 2 August 2026. The high-risk AI rules that most coverage expected on that date were separately delayed to 2 December 2027.

What are the fines for non-compliance?

Up to €15 million or 3% of global annual turnover, whichever is larger. For a company earning €1 billion a year, that means a €30 million exposure, not €15 million.

Do I need to label AI content I published before the deadline?

No. If your AI system was already running before 2 August 2026, its labelling deadline is 2 December 2026, and that applies only to the tool going forward — content published before that date does not need to be retroactively marked.

Full transcript of the video (1,053 words, 10 sections)

0:00 A lot of what you see on YouTube, Instagram, and TikTok right now breaks a new European law. Not next year, today. Why? Because on the 2nd of August, a new part of EU AI Act switched on. It is called Article 50. It is about telling people the truth. If you make a picture, a video, or a voice with AI, you have to mark it. If it could look real, you have to say so. Not in the caption, not in the description, not hidden inside the file, where people actually see it. Get this wrong, and the fine is 15 million euros. Or 3% of everything your company earns in a year. The strange part, almost nobody is talking about this. Here are four rules in plain English.

0:51 The law is called the EU AI Act. It does not arrive all at once, it arrives in steps. On the 2nd of August 2026, one step went live. It is called Article 50. It is about being honest. Not about safety, not about paperwork, about telling people the truth. Here is the part most news got wrong. Everyone expected the big rules for high-risk AI on these dates. Those were moved. They now come on the 2nd of December 2027. So, if someone told you high-risk rules are live today, they are wrong. What is live today is honesty. Rule one.

1:36 If a person talks to your AI, the person must know it is AI. That is it. That is the whole rule. Think about your website chat, your phone support, your booking assistant. If a customer could think they are talking to a human, you have a problem. The message must come at the start, not after 5 minutes, and it must be easy to see. You cannot hide it in a small gray text at the bottom of the page. The law says, "Clear and easy to notice." So, here is your fix. One sentence at the top of the chat. You are chatting with an AI assistant. That sentence costs you nothing. Missing it can cost you millions. Rule two.

2:24 If your AI creates content, that content must be marked. Pictures, video, audio, text. The mark must be machine readable. That means a computer must be able to read it, not only a human eye. A small logo in the corner is not enough on its own. Now, stop. There are two different things here, and people mix them up. One is your system. One is your content. Different rules. First, your system, the tool itself. If your AI system was already running before the 2nd of August, you get extra time to build the marketing in. Your deadline is 2nd of December, 2026. That date is about the tool, not about your old posts.

3:11 Second, your content. What the tool makes. Anything made and published before that December date does not need a label. You do not go back and add marks to old work. You are not fixing 5 years of posts. So, simply, the tool must be ready by December. What you publish after December must carry the mark. Everything before that stays as it is. Rule three. This one surprises people. Some AI reads faces and voices. It guesses how you feel. Are you angry? Are you stressed? Are you happy? Other AI sorts people into groups by how they look. If your company uses this, you must tell people it is used on.

3:58 And you must tell them at the moment it happens, not in a policy nobody reads. Where does this shows up in real life? Call centers that measures customer mood, shops that count who talks in and guesses their age, job interview tools that score a candidate's face. If that is you, you'll need a notice today. Rule four, deep fakes. If you make a video, a photo, or a voice that looks like a real person and it is not real, you must say so. Same for real place or real event. This is not only for bad actors, this is for marketing schemes, too. Use an AI version of your CEO in an ad, say it.

4:46 There is one softer case, art, comedy, and satire. There you still disclose, but in a way that does not ruin the work. And one more, AI-written text about news or public matters. If you publish that, you must say it is AI, unless a real human checked it and takes responsibility for it. So, what happens if you ignore this? 15 million euros or 3% of your global turnover. Whichever number is bigger. If your company earns 1 billion a year, 3% is 30 million. So, you do not pay 15, you pay 30. The percentage is the dangerous part for big companies.

5:36 Now, who pays? This is where people get it wrong. It is not only the company that built the AI. If you only use the AI, you can still be responsible. For chatbots, the builder carries it. For emotional AI and deep fakes, the user carries it. So, we just bought the tool is not the defense. Let us make this simple. Five questions, answer them today. One, does every AI chat we run say it is AI at the start clearly? Two, does everything our AI generates carry a machine-readable mark? Three, do we use anything that reads emotion or sorts people by how they look? Four, do we publish AI images, video, or voice of real people?

6:28 Five, do we publish AI-written text about news about a human editor? If you answered yes to four or five and you have no notice, fix this week. If your AI system is older than August, your deadline is the 2nd of December. This is your date. Put it in your calendar now. Four rules, one deadline, one number to remember. This is not the hard part of the AI Act. The hard part comes in 2027, but this part is live now and it is the easy one to fail. If you want the checklist as a file, the link is in the description. You can find it in my free school community. And tell me in the comments which of four rules is your company breaking.

7:16 Bye.

Want this working inside your finance team?

Ani Björkström

Ani Björkström — founder of QvantX Sweden AB, a Stockholm consultancy building AI solutions for banks, asset managers and finance teams. Anthropic partner. Every article starts from a real client build, minus the confidential parts. LinkedIn →