Since 2 August 2026, the EU AI Act’s transparency rules apply. If you’re a Belgian SME with a chatbot on your website or an AI agent answering your phone, they already concern you: people must be told they are talking to an AI. The good news: most small business AI use cases still fall into low-risk categories, and the transparency duty is easy to meet.
This post gives you a plain-language walkthrough of the regulation, a practical compliance checklist, and specific resources for Belgian companies. We build AI-powered automation for SMEs every day at Flowful, and we design our systems with compliance in mind from day one. Here’s what we’ve learned. We updated this guide on 14 September 2026, after the Digital Omnibus on AI became law and Article 50 started to apply.
Disclaimer. Flowful builds AI automation, we are not lawyers or compliance consultants. This post is general information, not legal advice. It shares what we learned compiling our own AI Act posture, so SMEs can ask informed questions of their legal counsel. It reflects the AI Act as amended by the Digital Omnibus, and the Commission’s Article 50 guidelines, as of 14 September 2026. Verify with a specialist before acting on any specific obligation.
What Is the EU AI Act?
The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive AI law. Published in the Official Journal on 12 July 2024, in force since 1 August 2024. It classifies AI systems by risk: higher risk, stricter rules. The Commission’s full AI regulatory framework page has the detail.
Key dates, as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, published on 24 July 2026, in force since 27 July 2026):
- 2 Feb 2025: Prohibited practices banned. AI literacy (Article 4) applies.
- 2 Aug 2025: GPAI rules apply, together with the governance and penalty chapters. Code of Practice published 10 July 2025.
- 2 Aug 2026: The AI Act applies in general. The Article 50 transparency obligations (chatbots, voice agents, deepfakes, generated content) are live.
- 2 Dec 2026: Deadline for machine-readable marking by generative AI systems already on the market before 2 August 2026.
- 2 Dec 2027: Annex III high-risk obligations apply (postponed from August 2026).
- 2 Aug 2028: Annex I high-risk obligations apply (postponed from August 2027).
For a Belgian SME running a chatbot or a voice agent, the date that matters has already passed: the disclosure duty has applied since 2 August 2026. High-risk obligations land late 2027, but if they concern you, do not wait.
What Changed on 2 August 2026
Two things happened this summer. The Digital Omnibus on AI stopped being a proposal: the Council gave its final approval on 29 June 2026 and the regulation entered into force on 27 July. Then, on 2 August, Article 50 started to apply. The Commission adopted its Article 50 guidelines on 20 July 2026, next to a Code of Practice on marking and labelling AI-generated content.
- AI that talks to people must say so. Chatbots, voice agents and AI agents must inform people that they are dealing with an AI, clearly and at the latest at the first interaction (Article 50, paragraphs 1 and 5). The exception for cases where this is “obvious” is narrow: the guidelines name helpdesk chatbots as a case where it does not apply.
- Generated content must be marked. Providers of systems that generate audio, images, video or text must mark the output in a machine-readable way. Systems already on the market before 2 August 2026 have until 2 December 2026. That grace period covers marking only: disclosure in conversations had to be in place on 2 August.
- Deepfakes and unreviewed public-interest text need a visible label. This duty sits with the business that publishes them. Content published before 2 August 2026 does not need retroactive labels, but content generated earlier and published after that date does.
- High-risk dates moved. Annex III systems (hiring, credit scoring, education and others) now apply from 2 December 2027, AI in products covered by Annex I from 2 August 2028.
- Lighter rules for smaller companies. Some simplifications reserved for SMEs now extend to small mid-caps, and the Article 4 AI literacy duty was softened: businesses must take measures to support their staff’s AI literacy, without guaranteeing a set level, with the Commission and Member States taking a stronger role in promoting it (Commission summary).
- Fines. A breach of Article 50 falls in the tier of up to 15M EUR or 3% of worldwide annual turnover (Article 99). For SMEs, the lower of the two is the ceiling.
What a Chatbot or Voice Agent Deployer Should Do Now
On paper, Article 50(1) is a design duty for the provider: whoever builds the system or puts it into service under their own name. That is us when you run a Flowful package, and it is you if your team built the bot in-house. Either way, your customers see your brand, so check these six points yourself.
- Disclose in the first message. Not only in the terms and conditions or a linked document: the guidelines call that insufficient on its own. For example: “Hello, I’m the AI assistant of [Company]. I can answer questions about quotes and opening hours, or put you through to a colleague.” A bare “Assistant” label, or a line like “this service uses LLMs”, does not count.
- Say it at the start of every call. A voice agent should state that it is an AI in its greeting, before the caller explains anything: “Hello, you’ve reached [Company]. You’re speaking with an AI assistant. I can book an appointment or take a message.” On longer calls, the guidelines recommend reminders. A tone or jingle alone is not enough.
- Answer honestly when asked. If someone asks “am I talking to a real person?”, the system has to say it is an AI. The same applies when the conversation shows the person is confused about it.
- Keep the disclosure accessible. Plain words, readable by screen readers, simpler still if children or elderly people are likely users. In sensitive flows such as complaints, insurance, health, legal or financial questions, repeat it during the conversation.
- Label what you publish. AI images or video of realistic-looking people, cloned voices, and AI-written texts on matters of public interest that nobody reviewed editorially need a visible label.
- Ask your vendors about marking. If a tool generates images, audio, video or text for you, its provider must mark that output in a machine-readable way, by 2 December 2026 for tools already on the market before 2 August. Get that confirmed in writing.
A route to a human is not an Article 50 requirement. We still build one in by default, because a disclosure that leads nowhere frustrates customers.
The Four Risk Categories
The AI Act sorts systems into four tiers, shown in the pyramid above. The higher up, the stricter the rules. Below, what each tier means for an SME.
Unacceptable Risk (Banned)
Social scoring, subliminal manipulation, real-time biometric identification in public spaces (with narrow law-enforcement exceptions), emotion recognition at work or school, untargeted facial-image scraping. For SMEs: very unlikely you are doing any of this. But verify any tool that claims emotion detection, trustworthiness scoring or facial recognition, and get legal advice if it does.
High Risk (Heavy Obligations)
Listed in Annex III: HR/recruitment screening, credit scoring, life or health insurance risk and pricing, education access, essential public services, law enforcement, migration, non-real-time biometrics. Plus AI safety components in regulated products under Annex I (medical devices, vehicles, machinery). For SMEs: if you screen job applicants, assess loan eligibility, or take consequential decisions about individuals, you are likely here. Chapter III obligations (risk management, data governance, technical docs, human oversight, conformity assessment, EU database registration) apply by 2 Dec 2027 for Annex III and 2 Aug 2028 for Annex I.
Limited Risk (Transparency Obligations)
Customer-facing chatbots, virtual assistants, deepfakes and certain AI-generated text on matters of public interest, plus emotion recognition or biometric categorisation where not banned. For SMEs: since 2 August 2026, tell users from the start that they are talking to an AI, and label deepfakes or unreviewed AI-generated text published to inform the public. Article 50 obligation, straightforward to implement.
Minimal Risk (No Specific Obligations)
Spam filters, AI-assisted email drafting, workflow automation, product recommendations, inventory forecasting, document classification, AI-assisted translation. For SMEs: almost everything you use daily. No mandatory steps. Document what you run and why.
A Separate Track: General-Purpose AI (ChatGPT, Claude, Gemini)
General-purpose AI models (GPAI) sit alongside the four risk tiers under their own regime, applicable since 2 August 2025. Providers of these models must publish a summary of training data, respect EU copyright (notably the Article 4(3) text-and-data-mining opt-out), and supply technical documentation to downstream users. The largest models (above 10²⁵ FLOPs of training compute) face additional systemic-risk obligations. For SME deployers using ChatGPT, Claude or Gemini in a workflow: the practical impact is light. Keep using them, apply the Article 50 transparency rules (disclose AI to users, label deepfakes and unreviewed public-interest text), and record which model handles what in your AI inventory.
What This Means for Belgian SMEs
If you use AI chatbots for support, email automation, workflow tools or document processing, your use cases are almost certainly minimal or limited risk. You are probably fine. But “probably” is not a strategy. Four reasons to still pay attention:
-
You might be high-risk without realising it. HR screening CVs, sales scoring leads feeding into credit decisions, anything consequential about individuals: the classification depends on the use case, not the technology.
-
Provider or deployer, the role decides the obligations. The AI Act splits responsibility between providers (who develop or place an AI system on the market) and deployers (who use it under their own authority in a professional context). Most SMEs are deployers, sometimes both at once. Providers carry the bulk of high-risk and GPAI obligations; deployers must follow the provider’s instructions for use, monitor operation, keep logs, and in high-risk contexts run a fundamental-rights impact assessment under Article 27. Deploy a general-purpose tool in a high-risk context and the burden lands on you.
-
Belgian enforcement is still being set up. The federal government agreement names BIPT as the main market surveillance authority, SPF Economie coordinates implementation, and the CSA is one of twenty-one Article 77 fundamental-rights bodies (audiovisual media in the French-speaking community). Belgium missed the August 2025 deadline to designate its authorities, and as of mid-September 2026 we could not find a Belgian law that formally does so. The regulation applies directly all the same. In France, the bill giving the CNIL supervisory powers under the AI Act passed the Senate on 18 February 2026 and was still pending before the Assemblée nationale when we updated this post. Fines under Article 99: up to 35M EUR or 7% of global turnover (prohibited practices), 15M / 3% (most other obligations, including Article 50 transparency), 7.5M / 1% (false information). SMEs and start-ups pay up to the lower of the two figures, still significant.
-
Clients will start asking. B2B buyers, especially larger companies and public sector, will ask about your AI compliance posture. Being prepared is an edge, and a written answer helps: ours is our security and data page.
A Practical Compliance Checklist
Seven steps you can start today. These are baseline good practices we follow ourselves, not a substitute for a formal conformity assessment. No law firm on retainer required.
- Inventory your AI systems. List every tool you run, including third-party SaaS. Note what it does, what data it processes, who is affected, and who provides it. Count the personal ChatGPT accounts your staff use for work too: that shadow AI is part of your inventory. You cannot assess risk on what you do not know.
- Classify each system. Three questions: does it influence consequential decisions about people, does it interact with users who may not know they are dealing with AI, can it manipulate or exploit vulnerabilities? Three “no” puts you in minimal or limited risk. One “yes”, check Annex III and dig deeper.
- Implement transparency. Disclose AI to users at the first interaction: in the chatbot’s first message, in the phone greeting. Label deepfakes, and AI-generated text published to inform the public without editorial review. Article 50 obligation, in force since 2 August 2026 and detailed above. A route to a human is not required, but it is good practice. Illustrative visuals that do not resemble real people, places or events need no visible label.
- Keep humans in the loop. Review AI output before it is sent or used for decisions. Build escalation paths. Let employees override. Mandatory and technical for high-risk; good practice everywhere else. For the engineering side of making AI outputs trustworthy enough to act on, see our note on building reliable AI systems.
- Document everything. Inventory, risk classification, justification, transparency and oversight measures, incidents, GDPR data-processing records. Documentation is the backbone of compliance. The Future of Life Institute compliance checker is a useful free starting point.
- Review vendor contracts. Does the provider classify their system’s risk level? Do they provide the AI Act technical documentation? Who owns the conformity assessment? What happens to your data? Where is it processed? A vendor that cannot answer is a red flag.
- Train your team. The Article 4 AI literacy obligation has applied since 2 Feb 2025. Since the Digital Omnibus, it asks you to take measures that support your staff’s AI literacy rather than guarantee a level. In practice: make sure staff know what AI they use, how it works at a basic level, its limits, and your internal policy. PhD-level not required. It is far easier with one approved tool than with a dozen personal accounts, which is the case for an internal chatbot.
GDPR and the EU AI Act Work Together
If you are already GDPR-compliant, most of the analytical work maps over: DPIAs ≈ AI Act risk assessments. Data minimisation and purpose limitation ≈ AI Act data governance. Article 22 ≈ AI Act transparency obligations. GDPR right to human intervention ≈ AI Act human oversight.
Where the AI Act goes further: technical standards on the system itself (accuracy, robustness, cybersecurity, technical documentation). GDPR governs data; the AI Act governs the system. Do not run two parallel projects. Integrate AI Act work into your existing GDPR framework, same team, same docs.
How Flowful Approaches AI Compliance
At Flowful, we build web and internal chatbots, AI phone receptionists, and email automation for SMEs in Belgium and France, plus an AI-first helpdesk (TicketFlow) and AI-ready booking (Flowcal). We design our systems with compliance in mind from day one. We are not a law firm. What follows describes how we build, not legal advice.
- EU-first hosting. Workflow infrastructure runs on Hetzner (Germany). AI inference, voice, and transactional email route through a small set of carefully selected sub-processors under DPAs with appropriate transfer safeguards (SCCs or technical controls such as no-training, no-retention). On request, we restrict processing to EU-only providers or run open-source models on dedicated infrastructure. The current sub-processor list is in our DPA.
- No training on your data. Every sub-processor is configured to disable training on customer data; per-vendor settings are documented in our DPA.
- Human-in-the-loop where it matters. Email Automation can be configured with human approval before sending, and we recommend it for outbound or higher-stakes flows. Voice agents escalate to a person when out of scope.
- AI Act tier by package. Our Web Chatbot, AI Phone Receptionist and Internal Chatbot sit in Limited Risk. Each conversation opens with a clear AI disclosure, written in the chatbot’s first message and spoken in the receptionist’s greeting, which is what Article 50 asks for. Each also offers a route to a human, which Article 50 does not require but your customers will expect. Our Email Automation sits in Minimal Risk. We can add human approval before sending depending on the use case. We do not build Annex III high-risk systems (hiring, credit scoring, insurance pricing, education access) without a formal compliance plan.
- A DPA with every contract. Covers GDPR and AI-specific obligations including the no-training clause and the sub-processor list. Our security and data page sums up what it commits us to.
Belgian-Specific Resources
Regulatory and Government
- BIPT (IBPT): Belgium’s main market surveillance authority for the AI Act. This is where enforcement will happen for most providers and deployers, including a single point of contact for high-risk system operators.
- SPF Economie (FPS Economy): Coordinates Belgium’s implementation of the AI Act. The dedicated AI Act section has guidance for entrepreneurs, plus an SME-oriented campaign and a downloadable guide.
- Data Protection Authority (APD/GBA): Belgium’s GDPR supervisor. As AI compliance and data protection overlap significantly, the APD remains relevant for AI-related data processing questions.
- AI4Belgium Coalition: A multi-stakeholder initiative that published Belgium’s AI strategy. Their resources include practical guidelines and sectoral recommendations.
Regional Innovation Support
- Innoviris (Brussels): Brussels’ innovation funding body. Offers AI-specific vouchers and funding programs. If you’re a Brussels-based SME exploring AI, they can help fund a compliant implementation from the start.
- Digital Wallonia (Wallonia): Wallonia’s digital strategy hub. Runs the Start IA and Tremplin IA programs, and publishes practical AI adoption guides.
- VLAIO (Flanders): Flanders’ innovation and entrepreneurship agency. Offers R&D grants and SME support programs applicable to AI projects.
Practical Tools
- EU AI Act Explorer: An independent resource with a searchable, annotated version of the full regulation. Useful for looking up specific articles and requirements.
- Future of Life Institute AI Act Compliance Checker: A free self-assessment tool that helps you determine whether your AI system might be high-risk under the AI Act.
We’ve also published a guide to funding AI projects in Belgium, which covers subsidies and grants that can help offset the cost of building AI solutions that are compliant from the start.
What to Do Next
A realistic timeline for a Belgian SME:
- Now: check that every chatbot and voice agent says it is an AI from the first exchange, label deepfakes and unreviewed public-interest text, inventory your systems, verify no prohibited practice, review vendor contracts.
- By 2 December 2026: get confirmation from the providers of your generative tools that their output is marked in a machine-readable way.
- Before 2 December 2027: if a system falls under Annex III, finish classification and high-risk remediation.
- Ongoing: follow Commission guidance, the formal designation of Belgian authorities, and harmonised standards. Keep documentation current.
For most Belgian SMEs running standard business automation, the workload is manageable. Start with the disclosure, classify honestly, build the documentation habit.
This post is general information, not legal advice or a compliance assessment. For a formal conformity check, work with a legal or compliance specialist. If you want a web chatbot or an AI phone receptionist that discloses itself properly from the first message, both packages ship with it built in. Get in touch to set one up.
