The AI Act in Denmark: what it means for your website
Short answer: the AI rules apply to you if your website has a chatbot, AI-generated images or video, or content made by an AI model. Most of what you write and edit yourself is not covered. That means most small businesses don't have a task tomorrow — but they do have one today, because they need to be able to answer what their supplier has made.
I work in Denmark, so this article looks at the rules from a Danish perspective. The EU regulation is the same across the EU; the national details differ.
What the new rules actually are
Two things have come into force, and they are often mixed up.
The AI literacy requirement (Article 4 of the AI Act) has applied since 2 February 2025. It says that employers and others who use AI tools must make sure their staff know what the tools can and can't do. It is a requirement to know, not a requirement to label anything.
The transparency requirement (Article 50) applies from 2 August 2026. This is the one that changes things, because it requires users to be able to see when something is AI.
The basis is the AI Act, Regulation (EU) 2024/1689. In Denmark it is implemented through the Danish act on artificial intelligence (Lov om kunstig intelligens) — always read the current Danish version, because that is the one that applies to you if you are a Danish business.
What the requirement covers — and what it doesn't
This is the part I am asked about in every conversation, so it is worth being precise.
Not covered: a text you have written yourself and edited with help from an AI. It is your text, and you are responsible for it. There is no labelling obligation for it.
Covered: content that is synthetically generated — i.e. made by a model — and published as if it were real recordings, images or audio. Here the content must be labelled, and the labelling must be machine-readable so platforms can detect it.
Covered: a chatbot, an assistant or a voice feature that a customer interacts with. Here the user must be told that they are talking to an AI — unless that is obvious from the context in advance.
Covered: deepfake images and video, i.e. realistic fake material that resembles a real person or event. This must be labelled explicitly.
The first two lines are the practical news: your own text is free. Anything AI-made that looks like reality is not.
A chatbot on the website: the most common mistake
The mistake I see most often isn't missing labelling. It is a chatbot that looks like a human without saying what it is.
That isn't only a legal problem. It is a trust problem, because the customer writes a message they think is going to an employee, and then gets a generated answer with no caveat. When it later comes to light, it isn't the chatbot the customer remembers — it is the feeling of having been misled.
The simple fix is one visible line that appears before the first message, not in a footer: what the user is talking to, what it can help with, and what it can't. It also needs to be there when the solution is an assistant built into your own system — not only when it is a visible chat window.
AI images on the website: where most people get it wrong
An AI-generated photo of a large Danish office looks convincing, and that is exactly the problem. It looks like a picture of an office, as if it were a picture of your office.
This is where the second rule comes into the picture: the Danish Marketing Practices Act (markedsføringsloven) prohibits marketing that misleads consumers. That rule applies regardless of how the image was made. It doesn't ask whether you paid for an AI tool; it asks whether the image makes a customer believe something that isn't true.
So my rule of thumb after these jobs: AI images are for illustration, never for documentation. Illustrate a concept with them. Don't show a person, a place or a product that the customer is meant to believe is you.
The same goes for voices. For example, an AI voice on an answering machine that sounds like an employee, without that being disclosed.
The checklist: six things you need to have in place
- Which parts of the site are AI-generated? Write it down, including the parts that have since been replaced. That is the list you will be asked for in a year.
- Which chatbots or assistants are customers in contact with, and does the site say that they are AI?
- Are there AI images showing people, places or products? Then they must be labelled, or removed.
- Do your supplier agreements mention AI tools, and are they allowed to write to your code, your files or your customer data?
- Who takes the blame when an AI solution makes a mistake — you, the supplier or the tool? That has to be in the agreement, not in an email reply.
- Can the access be switched off again if the collaboration ends, and who owns the accounts that have been created?
Points 1 and 6 are the two that cost the most when they are missing. The rest is an afternoon's work.
What it means for a small business
The honest answer: most small businesses have no urgent task. If your website was written by you, edited by you, and your images are your own, you are covered by what you have done.
But you do have a task today, and it is a cheap one: you need to be able to say what has been made with AI on your website. That is what a supplier, an insurance company, an auditor or a customer will ask you. If you can't answer, the problem isn't the rules — it is that nobody has control of the system.
And that is exactly what separates a website from a product. A website can sit on a server and look respectable while nothing in it is documented. It has been built, but it hasn't been handed over for operation.
The five questions to ask any supplier
- Which part of what we have had made was generated by a model? Not "AI has been used" — which part.
- Have images been used that show a person or a place that doesn't exist?
- Which of our systems do AI tools have access to, and what permissions do they have?
- What is the agreement about errors, and where is it in writing?
- Can we switch the access off again, and who owns the accounts?
The first question is the one that matters most. A supplier who can answer concretely has things under control. One who answers "we use AI to be efficient" doesn't.
What I do myself when I build with AI
I use AI to write code, find bugs and produce text drafts. That isn't a secret, and it isn't something that makes a site unlawful.
What I do is three things that keep it clean:
I mark what is AI-generated, and I mark it for you, so it can go in your own documentation, not just in my head.
I review what is going to be published, because published content is my responsibility, whatever wrote the first draft.
I keep two things separate: the tool you use yourself, and the one that writes into your system on your behalf. The first requires nothing of you. The second requires an agreement, access that can be switched off, and clarity about who cleans up after an error.
That is the difference the AI solutions article is about, and it is also why it sits in the maintenance packages and not in the tool list. You can buy the assistant yourself. What you can't do yourself is the agreement about responsibility — and that is exactly what a technical partner collaboration is.
Where to read the rules
- The AI Act, Articles 4 and 50 — Regulation (EU) 2024/1689. The full text is on EUR-Lex, and it is the binding text. English version: Regulation (EU) 2024/1689 on EUR-Lex.
- The Danish act — Lov om kunstig intelligens, in its current version, is available from Retsinformation, the official Danish legal database (in Danish). The Danish text carries the most weight in the parts that differ from the EU regulation, so read it when you need to apply it in practice.
- Marketing — the Danish Consumer Ombudsman's (Forbrugerombudsmanden) guidance on misleading marketing (in Danish). It applies whether or not the image is AI-generated.
Always read the current version. The rules are new, which means the interpretation is still moving — especially about what "clearly labelled" means in practice.
Conclusion
The question to ask yourself isn't "is my website lawful?". It is: who made what in it, and can you answer that?
You can find the first part quickly if you know it. The second part — having a supplier who can answer it, and who has an agreement about what happens when a model makes a mistake in your name — is the part that is a technical partner.
If you need it reviewed, that is part of maintenance. If you just want it looked at for an hour, you can get an overview of your setup first, and the prices are here.

