EU AI transparency rules now cover deepfakes and chatbots
The EU's AI Act transparency obligations now require disclosures for AI interactions, synthetic content and deepfakes, with fines up to €15 million or 3% of global turnover.
The EU's AI Act has moved from a future compliance deadline to an operating requirement for certain AI systems. On August 2, 2026, new transparency obligations began applying to AI interactions, synthetic content and deepfakes. The change matters to businesses that build or deploy customer-facing AI because disclosure is now part of the product experience, not just a policy document.
Definition: The EU AI Act's Article 50 transparency obligations require certain AI providers and deployers to disclose AI interactions and label specified AI-generated or manipulated content.
Example: A customer-facing AI agent may need to identify itself as AI, while an AI-generated video that appears to show a real person must carry a disclosure and machine-readable provenance mark.
Key takeaway: The EU's standard is not one universal badge; it is a set of obligations tied to who provides or deploys the system and what the system does.
Business impact: Teams shipping chatbots, generative-content features or realistic synthetic media should inventory those uses now and assign an owner for disclosure, marking and evidence of compliance.
What changed on August 2, 2026?
The European Commission says the new rules are intended to help people recognise when they are interacting with AI or seeing AI-generated content, reducing the risk of deception and manipulation. The Commission's enforcement announcement confirms that the AI Office and national authorities began enforcing the AI Act on the same date that the transparency rules started to apply. For an operator, the immediate action is to map each AI use to its provider or deployer role instead of treating “AI compliance” as one undifferentiated checklist.
The European Commission says the EU AI Act separates providers, which develop and market AI systems, from deployers, which use those systems in products and services; that provider/deployer distinction matters when a business builds a chatbot on another company's model because the business may still be the deployer. Operators should record both roles in their AI inventory before deciding who owns the interaction disclosure, output marking or deepfake label.
Which AI interactions need disclosure?
A chatbot or AI agent that directly interacts with people must make its AI nature clear unless that fact is obvious in context. The requirement covers more than a chat window: the same operating question applies to virtual assistants, automated phone systems and other interactive experiences. Businesses already linking AI agents to support or sales workflows should add the disclosure to the interaction itself and test it with the intended audience, as readers of the AI agent explainer can distinguish from a simple text-only chatbot.
The disclosure obligation is separate from the rules for generated media. The European Commission's enforcement summary describes both user-facing AI disclosure and marking of generated or altered content; a provider may need to tell a person that an AI system is responding, while a deployer may separately need to label the image, audio or video that the system creates. Teams should therefore keep interaction notices and content labels as separate controls instead of relying on one generic “AI-generated” badge.
How must AI-generated content and deepfakes be marked?
Providers of generative AI systems must make synthetic audio, images, video and text carry machine-readable marks that identify the content as artificially generated or manipulated, as far as technically feasible. Deployers must visibly disclose AI-generated or manipulated deepfake images, audio and video that resemble existing people, objects, places, entities or events and could appear authentic. The European Commission's Code of Practice on Transparency of AI-generated Content separates these provider marking duties from deployer labelling duties, so an organisation should check both sides before releasing a feature.
The rules also cover machine-readable marks for AI-generated text outputs, alongside audio, image and video. The European Commission's Code of Practice explains that providers must make synthetic content detectable, so teams shipping generated text should preserve the marking path and verify that downstream systems do not strip it before publication.
Are the EU's labels mandatory?
The European Commission's AI disclosure icons are optional, but the underlying transparency requirements are not. The Commission's Code of Practice presents the icons as a consistent visual aid rather than a replacement for the legal duties; businesses should choose a label that is clear in the relevant medium and document how it satisfies the applicable requirement.
What happens to existing AI models and services?
The Verge reports that new AI systems face the transparency requirements immediately, while models and services launched before August 2 have a four-month transition period until December 2. That timing makes migration work part of the news: companies cannot assume that an existing chatbot, media generator or AI-powered platform is permanently outside the new regime. Operators should use the transition window to inventory deployed systems, identify whether each system is a provider or deployer use case, and schedule the needed product and documentation changes.
The European Commission says companies can face fines of up to €15 million or 3% of global annual turnover for non-compliance. The same Commission summary assigns enforcement across the AI Office, national market-surveillance authorities and the European Data Protection Supervisor for EU institutions, so operators should create a traceable control for every in-scope AI use and assign it to a named owner.
What should AI operators do now?
A practical first pass is to inventory every customer-facing chatbot, AI agent, content-generation feature and synthetic-media workflow; record the provider and deployer for each; and map the required notice, visible label, machine-readable mark or human-review exception. The Article 50 practical guide also recommends checking carve-outs and contractualising compliance with AI vendors. Businesses that already use AI agents can start with the same narrow, workflow-by-workflow scoping approach described in how to get started with AI agents instead of attempting a vague audit of every AI reference in the company.
The European Commission's August 2 summary and The Verge's report establish the same baseline: people should know when they are dealing with AI, synthetic outputs should be detectable, and realistic AI-generated or manipulated content should not pass as authentic without disclosure. Operators should make the next milestone a production check that each required notice or mark is visible, machine-readable where required, and assigned to a real owner.
Frequently asked questions
What changed under the EU AI Act on August 2, 2026?
The EU began applying new transparency obligations under Article 50 of the AI Act. Certain providers must tell people when they are interacting with an AI system, and generative AI providers must make synthetic outputs detectable through machine-readable marks. Deployers must disclose AI-generated or manipulated deepfake images, audio and video. The rules apply to specific uses of AI rather than only to systems classified as high risk.
Do EU companies have to use the European Commission's AI icons?
No. The European Commission's icon set is an optional implementation aid, not the legal obligation itself. Companies may use the icons to make labels more consistent, but they still need to meet the underlying transparency requirements through adequate methods. Providers and deployers that follow the voluntary Code of Practice can use its measures to demonstrate compliance; organisations that use another approach must be able to show that the approach is adequate.
What must a chatbot or AI agent tell users?
A chatbot, voice assistant or other interactive AI system covered by the rules must make clear that the user is interacting with AI rather than a human, unless the AI nature is obvious in context. The practical requirement is a clear disclosure at the point of interaction, not a hidden statement in a privacy policy. Businesses should check each customer-facing workflow, including AI agents connected to support, sales or internal service channels, and document how the disclosure is shown.
What is the maximum fine for breaking the new AI transparency rules?
Companies can face fines of up to €15 million or 3% of their global annual turnover. The exact enforcement route depends on the AI system and the responsible authority, including the AI Office, national market-surveillance authorities or the European Data Protection Supervisor for EU institutions. A business should treat the fine ceiling as a reason to map its AI uses and controls, not as a substitute for checking the rules that apply to its specific deployment.
Alex
Founder & Lead AI Writer
Alex is the founder of Yowox and lead AI writer since 2024, breaking down complex information into clear, actionable insights for thousands of readers every day. Alex has built AI automation systems for businesses since 2024, focusing on AI agents, workflow automation, and business process optimization.
Save hours. Save thousands.
Practical guides, real workflows, and the latest AI and automation news that matters — straight to your inbox.