The EU AI Act starts enforcing in 40 days. Here is what AI agent builders actually need to do.

I have been building AI marketing agents in production for over a year. Not one client has asked me about the EU AI Act. Not one founder I talk to has read it. The general sentiment is "that is for big tech" or "that is for Europe" or "we will deal with it later."
Later is August 2, 2026. That is 40 days from now.
The transparency rules of the AI Act come into full effect that day. If your agent generates content a human sees, or makes decisions that affect a person, or operates anywhere a European customer might touch it, the rules apply. The fines can reach 7 percent of global annual turnover.
I read through the relevant sections. Here is what actually matters if you are building AI agents, not what the compliance consultants want to sell you.
The one rule that applies to almost every AI agent
Article 50 is the transparency article. It says, in plain terms: if a person interacts with an AI system, they must be informed they are interacting with AI.
This is not about model cards or risk assessments. This is about telling people the truth.
If your marketing agent writes emails to customers, those customers need to know an AI wrote them. If your support agent chats with users, they need to know it is not a human. If your content agent publishes blog posts, readers need to know.
The law does not say you need a banner on every email. It does not prescribe a format. What it requires is that the person is informed "in a clear and distinguishable manner" at the time of interaction. Reasonable people can disagree on what that means. The principle is not complicated.
What most agent builders are getting wrong
The mistake I see everywhere is assuming that if you are a small company, or your agent is not "high-risk," the Act does not apply. That is wrong in two directions.
First, the transparency rules apply to almost all AI systems that interact with people. Not just high-risk ones. Not just large platforms. If your agent generates text, images, or audio that a person sees or hears, Article 50 applies. The only exceptions are systems used for personal, non-professional activity, and systems where it would be "obvious" to a reasonable person that they are interacting with AI.
Second, "high-risk" is not as narrow as most builders assume. The Act designates certain categories: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and democratic processes. A marketing agent that screens job applicants or determines credit eligibility crosses into high-risk territory. Most marketing agents do not. But the transparency rules still apply.
Three things to do in the next 40 days
This is not a compliance checklist. This is what I am doing for the systems I operate, and what I would recommend to any builder who wants to handle this seriously without over-engineering it.
First, disclose. Add a line to agent-generated emails that says something like "This email was generated by an AI agent and reviewed for accuracy." Add a small indicator to agent-powered chat interfaces. If your blog posts are AI-assisted, say so. This is not marketing. This is the law, and it is also the right thing to do.
Second, log. Article 50 requires that AI-generated content be "marked in a machine-readable format." For text, this means metadata. For images, watermarking. In practice, if you are generating content through a pipeline, add a metadata flag. It does not need to be complex. A simple ai-generated: true in your content management system meets the spirit of the requirement.
Third, document your decision. Write down which of your systems fall under Article 50 and why others do not. The Act requires deployers of AI systems to maintain documentation. For a small team, this can be a single page. The point is that you thought about it and made a deliberate decision, rather than ignoring it.
What the EU AI Act does not require
Some of the advice circulating right now is nonsense.
You do not need a dedicated compliance officer. You do not need to register your marketing agent in an EU database unless it is genuinely high-risk. You do not need to run a fundamental rights impact assessment for a subject line optimizer. You do not need to hire a law firm.
What you need is honesty about what your system does and transparency with the people it affects. If you are already building responsible systems, you are probably 80 percent of the way there.
The real risk is not fines
The first wave of enforcement will not be 7 percent fines. It will be scrutiny. Journalists will test whether AI systems disclose themselves. Competitors will file complaints. Regulators will make examples of obvious violations.
The builders who handle this well will not be the ones with the biggest compliance budgets. They will be the ones who treat transparency as a feature, not a burden. The same way the best email marketers treated GDPR as an opportunity to clean their lists and earn trust, the best agent builders will treat the AI Act as a chance to differentiate on honesty.
August 2 is coming. If your agents touch customers, take the 40 days to add disclosure, add logging, and write down what you decided. That is the work.