Our Blog

Blog Index

EU AI Act Transparency Rules Take Effect: Chatbots Must Reveal Themselves, Deepfakes Must Be Labelled

Posted on 3rd Aug 2026 06:04:31 in Artificial Intelligence, Machine Learning

Tagged as: EU AI Act, AI regulation, artificial intelligence, deepfakes, transparency

On 2 August 2026, the European Union switched on the enforcement phase of the Artificial Intelligence Act, its landmark law for governing artificial intelligence. From this date, the EU AI Office and national authorities across the bloc began enforcing the AI Act's rules, while a new set of transparency obligations took effect for chatbots, deepfakes, and AI-generated content. The measures are designed to help people recognise when they are interacting with a machine rather than a human, and to make it far harder for manipulated or synthetic content to be passed off as genuine.

The AI Act entered into force on 1 August 2024, but its provisions were always designed to apply in stages. Different obligations switch on at different times, giving providers, deployers, and regulators time to prepare. The 2 August 2026 milestone is one of the most significant so far: it marks the start of active enforcement and the application of the transparency rules under Article 50 of the Act, which touch a far wider range of systems than many businesses expect.

What the New Transparency Rules Require

Under the new rules, any interactive AI system such as a chatbot, virtual assistant, AI agent, or avatar must clearly tell users that they are dealing with AI and not a real person. This applies at the moment of first contact and covers systems used across the EU, regardless of where the provider is based.

AI-generated or manipulated content must also be clearly identified. Specifically, the obligations cover:

  • Images, audio, and video that resemble existing persons, objects, places, entities, or events, commonly known as deepfakes, which must be visibly labelled;
  • Emotion recognition and biometric categorisation tools, where exposed individuals must be informed;
  • Text published to inform the public on matters of public interest, where there has been no human review or editorial control, which must be disclosed as AI-generated;
  • Synthetic content generally, which must carry machine-readable marks or watermarks so it can be detected automatically at scale.

The European Commission has published a set of icons that companies can use for labelling AI-generated content, along with detailed guidelines explaining how compliance can be demonstrated. These obligations apply to all AI systems used in the covered situations, not just systems classified as high-risk, and providers of open-source AI systems are not exempt. Content created by individuals for purely personal use, as well as artworks and satire, falls outside the labelling requirements.

Enforcement Begins: Who Polices the AI Act

Responsibility for enforcing the transparency rules is shared across three bodies. The EU AI Office enforces the rules for AI systems offered by the same provider as the underlying general-purpose AI model, and for systems integrated into very large online platforms and search engines designated under the Digital Services Act. National competent authorities enforce the rules for all other AI systems, while the European Data Protection Supervisor covers AI systems used by EU institutions, bodies, and agencies.

The fines are substantial. Companies can face penalties of up to EUR 15 million or 3% of global annual turnover, whichever is higher, for violations of the transparency rules. EU institutions, bodies, and agencies face fines of up to EUR 750,000, and proportionality must be taken into account for small and medium-sized enterprises and small mid-cap companies. Member states are responsible for setting and enforcing penalties in their own jurisdictions, and several have already moved: Spain and Ireland have introduced national fines, while Greece has proposed an amendment that would introduce prison sentences for people who remove AI label watermarks.

To support enforcement, the AI Office has launched a Complaint Tool for reporting alleged infringements, a Whistleblower Tool for people working with AI providers, and a dedicated channel for downstream providers building systems on general-purpose models. The AI Office is also backed by a Scientific Panel of 60 independent AI experts, which recently held its first meeting, and has appointed Professor Alessandro Abate of the University of Oxford as its Lead Scientific Adviser.

Obligations for General-Purpose AI Models

Enforcement now also extends to providers of general-purpose AI (GPAI) models, the large foundation models that power a wide range of tools and services, including AI agents. All GPAI providers must document key information about their models and provide it to competent authorities or downstream providers on request. They must also put in place a copyright policy and publish a sufficiently detailed summary of the content used to train their models.

The most advanced GPAI models that may pose systemic risks face additional obligations. Their providers must address risks of large-scale harm, including risks linked to chemical, biological, radiological, and nuclear incidents, loss of control, cyber offence, harmful manipulation, and threats to fundamental rights. The Commission has specifically highlighted risks that have recently drawn public attention, including threats to European cybersecurity and AI acting outside human control.

Enforcement also begins for the AI Act's prohibited practices, which ban particularly harmful systems, including systems that manipulate people, exploit vulnerabilities in harmful ways, or unfairly score people in ways that threaten their rights. Separately, the AI Omnibus regulation has adjusted the overall timeline: rules for high-risk AI systems are postponed to 2 December 2027, and for high-risk systems integrated into regulated products to 2 August 2028. New prohibitions on AI systems that generate non-consensual sexually explicit content and child sexual abuse material will apply from 2 December 2026. Generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement.

The Code of Practice and Industry Response

The Commission has endorsed a voluntary Code of Practice on the transparency of AI-generated content that operationalises the labelling rules, and more than 180 organisations have already signed it. Providers and deployers that sign the code can rely on its measures to demonstrate compliance with the AI Act's labelling and detection rules, making it a practical route to compliance. Participation is optional, but legal compliance itself remains mandatory for everyone operating in the EU market.

"As enforcement begins, we are taking an important step towards AI that people and businesses can understand and trust, and whose benefits are shared widely across our society," said Henna Virkkunen, the EU's tech sovereignty chief, as the rules took effect.

The EU's move comes at a moment when the debate over AI governance has shifted worldwide. In the United States, the chief executives of Google DeepMind, OpenAI, and Anthropic have all publicly called for frontier AI to be regulated, proposing frameworks ranging from an independent testing body to a US-led international certification forum. While the US approach remains largely voluntary and industry-driven, the EU has now crossed the line from writing rules to enforcing them, giving it a head start in shaping what transparency means in practice for the global AI industry.

What It Means for Businesses and Users

For businesses, the practical takeaway is that transparency obligations are not limited to high-risk AI. Any company that runs a customer-facing chatbot, uses generative AI to produce marketing content, publishes AI-written text on matters of public interest, or deploys tools that create synthetic imagery now has obligations under Article 50. New AI systems entering the EU market must comply immediately, while systems already on the market have until 2 December 2026 to meet the machine-readable marking requirement. There is no mandatory requirement to label content produced with AI before the rules came into force, although companies are encouraged to do so.

For users, the change is intended to be visible and practical: chatbots will identify themselves as AI, deepfakes will carry clear labels and watermarks, and synthetic content will be traceable through machine-readable marks. The Commission has also published guidelines and an FAQ for the transparency obligations, and the AI Act Service Desk is available to answer questions from businesses.

With enforcement now live and fines of up to EUR 15 million or 3% of global turnover on the table, the era of voluntary disclosure in the EU is over. For the rest of the world, the EU's approach will be closely watched as the first large-scale test of whether transparency rules can keep pace with generative AI.

Sources

whatsapp me