On August 2, the transparency provisions of the EU AI Act — Article 50 — become enforceable. Almost no small business in Colorado has this on a calendar, and for most of them that's correct. For a meaningful minority, it isn't, and the tell is not where your office is.
What Article 50 actually requires
Three things matter for ordinary businesses. A chatbot has to identify itself as a machine at the first point of contact — not in a terms-of-service page, not in small grey text under the widget. AI-generated or AI-manipulated content that gets published has to be marked as such, in a machine-readable way and, where practical, visibly. And synthetic audio, image, and video carry the same marking duty.
Penalties top out around EUR 15 million or 3% of worldwide turnover. Enforcement against a ten-person firm is not the realistic risk. Being named in a customer complaint or getting a platform takedown is.
Why a Denver company can still be caught
The regulation follows the user, not the company. If you sell into the EU, market to EU customers, or run a website chatbot that EU visitors can reach, you're potentially in scope regardless of where you're incorporated. A brokerage courting overseas buyers, a manufacturer with European distributors, a consultancy with one client in Dublin — these are not exotic.
Conversely: if you use AI to draft internal emails, build proposals, or clean spreadsheets, and you don't publish AI-generated content into the EU or run a public chatbot, Article 50 does not reach you. Don't buy a compliance product to solve a problem you don't have.
This isn't only Europe
The same requirement shape is showing up domestically. California's privacy regulator finalized rules requiring notice before automated decision-making technology is used on people. Colorado's own AI Act rewrite lands January 1, 2027, and it removed the small-business exemption that used to protect firms under fifty employees. Disclose that AI is involved, allow human review, be able to explain the outcome — that pattern is hardening everywhere.
The honest caveat
Guidance on how content marking works in practice is still settling, and there's a transition window for generative systems already on the market. If you're genuinely in scope, this is a conversation with counsel, not a blog post. What follows is triage, not legal advice.
Do this in twenty minutes
Answer three questions in writing. Do we run a chatbot the public can reach? Do we publish AI-generated text, images, or audio? Do EU users touch either one? If all three are no, file this and move on. If any is yes, the cheapest fix is also the honest one: label the bot as AI in its first message, and note AI involvement where you publish. You were going to need that disclosure habit anyway.