A customer opens the chat at a Norwegian online store for a normal evening. ‘What bike fits the commuting road?’ The answer comes after two seconds, polite and well-formed. The customer has no idea if it was written by a human or machine.
Until now, there has been an uninterested question. From 2. August 2026, it is a legal one.
In that case, transparency requirements of EU AI law enter into force. Chatbots must be told that they are machines. Images, video and audio made with AI that appear real should be marked. And EU surveillance can remedy those who break the rules.
And here's the few people have brought: the law was changed at the end of July. EU adopted a major amending package which entered into force on 27. July 2026So let's say that this is the same thing as that. The changes are big. Much of what is written about 'AI Act 2026' — reports, LinkedIn articles, lunch seminars — describes rules that no longer exist.
This article describes those that apply.
Conclusion first
- From 2. August, customers will know when they talk to AI. What has been good, now becomes legal requirements — with fines for breaches.
- AI Act is not the most about OpenAI. It's about you. The law distinguishes the person who creates AI from the person who uses it. If you use AI against the customers, you have a responsibility. The supplier cannot be moved.
- What the law requires of you is order — not technology. Know which AI tools you use, who is responsible, and how to capture errors. None of this requires anyone to program. Everything requires some leader.
- ‘This does not apply in Norway’ does not help you. The law is not yet Norwegian. But you sell to customers in Sweden or Denmark, it hits you from 2. August however — and a Norwegian AI law is on its way.
The rest of the article explains the four points, one for one.
You bought a tool. The law says you made a decision.
The most common objection first: ‘We only use ChatGPT’.
The idea is understandable. OpenAI has created the model, the chatbot provider has created the solution. The online store has only put it into use. Then must the responsibility lie with those who made the technology?
The AI law answers no. It distinguishes between two roles: the one which: storage AI, and the one that activates itSo let's say that this is the same thing as that. Both have duties. The supplier is responsible for the correct creation of the tool. You are responsible for how it is used in you.
And you take AI into use more often than you think. If you have a chatbot, you will use AI against customers. If you are conducting machine learning, you will do so again. Writing market department Copilot promotional texts, a third time.
You bought a tool. The law says you made a decision. And with decisions, responsibility is in the hands of the people.
It's not as unfair as it sounds. OpenAI cannot know that your chatbed provides bicycle advice to teenagers, or that customer service glues AI responses right into complaintsSo let's say that this is the same thing as that. The use is yours. Therefore, your responsibility for use is also yours.

What's actually going on is 2. August — and what has been deferred
The confusion occurred in July. Take it in the right order.
The plan was that 2. August would be the big day. The most severe requirements would then also enter into force — the rules on high-risk AI, such as recruitment tools and credit ratings. These are the requirements that have filled the advisory reports.
It doesn't happen. The EU recognised that neither the standards nor the supervisions were clear and exposed the heavy requirements until December 2027 and August 2028.
Two things happen anyway. August. And they hit a lot more:
Customers should know when they meet AI. Chatbots, speech assistants and AI agents must say they're machines. The exception for the ‘open-ended’ is narrow: a fine that writes as a human being does not escape the fact that ‘all people realize it is a robot’. The provider shall build the notification — you must make sure it is turned on.
The supervision is given power. The rules have been in place for a while. From 2. the authorities of the EU may examine and pay fines on August. Now, power is behind it.
One more thing: The demand for AI competence among employees was softened in July — the EU realized that it was too heavy for small businesses. It is worth noting: the EU adjusts its course when something does not work.

We tested 25 Norwegian online stores
So how's it going out there? On 31st. July 2026 — just before the deadline — we tested the chat at 25 Norwegian online shops. We acted as an initial visitor and did not send any personal data.
Eleven of the stores had an AI-based chat. And here comes the surprise: nine of the eleven told the user at the opening that they talked to an AI. The planting says you meet two AI assistants — and they may be wrong. ARK writes 'Knut gives you AI generated answers' right above the edit field. Belakkers Rosie presents himself as chatbot with error-free. Electricity purchase, Jernia, Kid, Kitchen, Table and Get Inspirad make variations of the same. Five shops had a human-man-maned chat, and you had no chatbot at all.
The last two exceptions are: Both Holzweiler and Villoid clearly lacked AI information when the chat was opened 31. July. At Holzweiler's assistant said it was AI only after direct questions. At Villoid, the Villoid-Vera presents herself with her own name and personality — without saying she is a machine. It's hardly random. A fine with names, greetings and chats must be felt human — and then labelling is both the most tempting to drop and the most necessary to have.

Two reservations: the sample assesses the user — not the contracts, the role distribution and the procedures behind. And chat solutions change quickly, so the picture can look different all over the next month.
But notice what the find says: the marking — the visible part of the law — is largely in place. It will arrange the supplier in a set. The overview, responsibility and procedures behind you have to take care of yourself. Norwegian online stores have made the simple part. The rest of the article is about the difficult one.
The myth of the product texts
Now that many online stores have been unspoken.
The claim is repeated everywhere: AI generated content must be marked — i.e. product descriptions written with ChatGPT must be given an AI label. For a online store with ten thousand goods, it sounds like a nightmare.
The claim is wrong. The labelling obligation concerns text to inform the public about issues of public interest — typical news, policies, health and economics. And even there, the duty falls when a person has actually checked the text and someone is editorially responsible.
A product description of a off-road bike is not a matter of public interest. It must be true and not misleading — it has the marketing law required all the time — but it does not need an AI label. Write product texts with AISo let's say that this is the same thing as that. Read them before publishing. You should have done that anyway.
The same applies to the images. An AI generated product image of a bike does not need a label. The label first takes content that looks like real people, places or events and can be taken to be real — like a photorealistic AI model or a cloned voice. For such content it does not hold with a separate page that the store uses AI. The marking shall be visible where the contents are displayed, for each person who sees it. A statement hidden under the terms of the terms does not count. Remember: the marking should reach the customer in the meeting with the contents — not require any searching.
Here is the logic of the law: The text about the bike does not need any labelling. Chatboten As seller The bike, must say it's a machine. The content may be worded the same. The difference is the relationship — a text you read, a chatbot you trust. The law regulates trust, not the text.
The myth of the fines
The second myth is pulling in the opposite direction: fear.
The numbers are real enough. The maximum fines are up to EUR 35 million or 7% of global turnover. These are the numbers that adorn the message headlines.
But the law has a rule most of the references that jump over: for small and medium-sized enterprises it is minimum the amount and percentage — not the highest, as for the groups.
- Yeah. - Yeah. A webshop with 25 million on the market risks a maximum of around 750 000 kroner at the level of the fine in question — not tens of millions of euros. Two reservations, because honesty is cheaper than retreat: 750 000 swiss for any online store. And the rule does not remove the obligation, just the disaster scenario.
The conclusion on both myths is the same: AI Act is neither the bagel nor the monster it is made as. The most dangerous thing you can do is not to break it on purpose. It's based on the representation of others of what it requires.
‘This does not apply in Norway’ — true and to zero help
So to the objection any Norwegian reader is sitting with: EU law, yes well. However, Norway is not part of the EU.
That's right. AI Act is not yet Norwegian law. The EEA process is ongoing, a Norwegian AI law has been consulted and the Ministry is working on the bill. The aim is to enter into force as soon as possible after the EEA integration. No Norwegian authority can currently fine a Norwegian online store for AI Act breaches.
If it felt like a relief, read on.
First, the law is to hit AI use where the result is used in the EU. The chatbot serving customers in Sweden and Denmark is within 2. August — regardless of where the server is located and the company is registered. If you sell against EU countries, ‘law does not apply in Norway’ you nothing.
Second, your suppliers are already following the law. OpenAI, Microsoft, Google and Chatbot platforms are built for the EU market, and requirements are downwards in contractual terms and settings. You will meet AI Act in the supplier agreements long before you will meet it in Norwegian law.
Thirdly, the Norwegian law comes. If you wait until it comes into effect, you start right after you have finished.
The EEA supply is not a derogation. It's a deadline. And the deadline is a gift to those who use it.
A technology annex management code
Here are the actual points of the article, and it's not about paragraphs.
AI Act is referred to as technology regulation. But look at what compliance is actually about for a normal business: knowing which AI systems you use. Make sure the customers know when they meet them. Support the AI skills of staff. Control when something goes wrong.
None of this is about technology. Everything's about order.
AI Act is not a technology code with management annex. It is a governance code with a technology annex.
Norwegian companies have done this exercise before — with HMS in the nineties, with privacy at GDPRSo let's say that this is the same thing as that. AI is lucky, and the pattern is the same: first experimentes everyone, then requires some overview, and finally the overview is a self-explanatory.
The test on whether your online store is ready is therefore not technical. It consists of questions which any manager can ask tomorrow morning: What AI tools do we use — also the employees have put into service on their own? Who approved them? Do they process personal data? Our customers meet AI without knowing? Who is responsible for wrongness?

If the management group responds, the new legal requirements are formality. If it doesn't, the problem is older than AI Act — the law made it just visible.
The overview is also not something you obtain for supervision. It's the prerequisite for using AI. moreNot less. Anyone who knows what is in operation can say yes to the next tool quickly and safely. Whoever doesn't know, has to say no or gamble.
Start before you need to
One last thing, since legislation is always presented as cost.
Online shops compete on trust. The price and selection can be copied; the confidence that the store treats you properly, cannot. A chatbot that opens up saying it's an AI assistant — and offers a person when the matter requires it — builds more trust than one who pretends to be called Kari. From 2. August is the first legal requirement in the EU. It's been a good business all the time.
In a few years, nobody's gonna ask if your online store is using AI. Everybody does. The question will be whether you can show that you use it in a way that customers can trust.
It starts with a list of which AI tools your company uses.
Write it this week.
Sources
- Regulation (EU) 2026/1744 — ‘Digital Omnibus on AI’ (EUR-Lex). The amending Regulation adopted 8. July 2026, in force 27. July 2026. The primary source of the suspensions and the new deadlines.
- KI Regulation — Regulation (EU) 2024/1689 (EUR-Lex). The AI Act itself, with its role distribution, the transparency requirements of Article 50 and the fines provided for in Article 99.
- EU Commission guidelines on transparency requirements in Article 50 (final version, 20. July 2026). How to practice the chatbot warning and the marking requirements.
- Akin Gump: ‘EU AI Act Extensions Defer and Clarify Debreligations’ (July 2026). Legal analysis written after the changes were published in the Official Journal.
- NicFab: ‘Digital Omnibus on AI: Regulation (EU) 2026/1744 Is Published in the Official Journal’ (July 2026). Detailed review of what was exposed — and what is not touched.
- Government: Hearing — Draft new law on artificial intelligence (KI law)So let's say that this is the same thing as that. The proposal implementing the KI Regulation in Norwegian law, with EEA status and timetable.
