01
Someone talks to your machine
The website bot, the switchboard assistant, the agent booking appointments. The person must know they are not talking to a human. Unless it is obvious, and obvious does not mean grey text in the terms.
// The audit · GDPR & AI Act
Since 2 August 2026, if it is not a human, you have to say so. The rule fits in one sentence. What it costs you, however, depends on a paragraph almost nobody quotes.
Half a day · 100 % remote · a written audit, not a certificate
Four situations, and nothing else. The rest of what you are told is commentary.
01
The website bot, the switchboard assistant, the agent booking appointments. The person must know they are not talking to a human. Unless it is obvious, and obvious does not mean grey text in the terms.
02
Image, sound, video, text. The content must carry machine-readable marking. This is the only point whose deadline moved, and only for systems already in service.
03
Emotion recognition, biometric categorisation. Exposed people must be informed, and it is the deployer who informs them, not the model provider.
04
Content imitating a real person, or a text published to inform the public, must be flagged. One exception exists: genuine human review, with an identifiable person taking editorial responsibility. A rubber stamp does not qualify.
Article 99 sets the fine at 15 million euros or 3 % of worldwide turnover, whichever is higher. That is the figure everyone waves around.
The same article has a paragraph 6. For SMEs and start-ups, the LOWER of the two applies. The exact opposite. This is not left to member states, it is mandatory.
A company with 2 million euros of turnover does not risk 15 million. It risks 3 % of 2 million, that is 60,000 €. Still very bad news. Not the same conversation with your board.
Regulation (EU) 2024/1689, art. 99(6). The 35 million tier targets the prohibited practices of article 5, not transparency.
It is the only genuinely hard question in the text, and the one dealt with fastest.
Provider: you develop the system, or place it on the market under your own name. Wiring an API into your product and selling it under your brand moves you here, with nobody warning you.
Deployer: you use the system in your business. Most companies are here, and their obligations are far lighter.
The answer is not a guess. It is written in the contract, and that is where an audit earns its keep.
An agent that keeps memory across sessions and reaches into several tools is not the same problem as a chatbot. The French CNIL wrote it on 20 July 2026: with agentic AI, the risk changes scale, not just degree.
Legal basis, retention, chained processors, transfers outside the EU: the same questions as in 2018, asked of a machine that no longer forgets.
A provider selling you compliance is selling you something they cannot deliver.
This audit describes your systems and what the regulation asks of them. It does not replace legal advice, and on edge cases I will tell you to get some.
Nobody issues one for article 50, and a European icon pasted on a site establishes nothing. What you get is a dated document you can hold yourself to.
If your systems are in order, the audit says so in one page and you will have paid half a day to sleep well. That is a result, not a failed sale.
Law as of 3 September 2026. Article 50 has applied since 2 August 2026. The postponement to 2 December 2026 covers only machine-readable marking of systems already in service, on the provider side: it waives nothing else.