EU AI Act transparency rules become enforceable tomorrow: every AI interaction must now be disclosed, every deepfake labeled
On August 2, 2026, Article 50 of the EU AI Act takes effect, requiring providers and deployers to disclose when users are interacting with AI, label AI-generated synthetic content, and clearly identify deepfakes. The rules apply to all AI systems in scope regardless of when they were built, with fines reaching EUR 15 million or 3 percent of worldwide annual turnover. Text published to inform the public on matters of public interest must now carry AI-generated content labels, and providers must design systems that ensure individuals are explicitly informed they are engaging with AI.

EU AI Act transparency rules take effect Sunday, catching systems built before the law existed
A chatbot built in 2022, before the EU AI Act existed as a final text, faces the same August 2 deadline as a system shipped last week. Article 50 of the regulation requires providers and deployers to disclose when users are interacting with AI, mark AI-generated content so it can be detected as synthetic, and label deepfakes and AI-generated text published on matters of public interest. The European Commission adopted its guidelines explaining how to comply on July 20, thirteen days before the obligations take effect, and the technical standards for machine-readable content marking remain unfinished. 1
The rules cover four situations: AI systems that interact directly with people (chatbots, voice assistants, automated phone systems), AI systems that generate synthetic content (text, images, audio, video), emotion recognition or biometric categorization systems, and deepfakes or AI-generated text published on matters of public interest. 2
3 Law firm Stibbe describes the obligations as "by far the most widely applicable section" of the AI Act because they bind not only providers but also deployers: the companies, public authorities, and organizations that use AI systems in their own operations.
1
The scope is broader than most organizations assume. The obligations apply to any AI system used in the four covered situations, not just those classified as high-risk. An organization with no high-risk systems may still face significant obligations because it operates a customer-facing chatbot, uses generative AI to produce news content, or relies on software that generates deepfake imagery. 2 Open-source AI systems are not exempt.
2
Stibbe identifies OpenAI, Anthropic, Canva, Grammarly, and Spotify, whose AI-powered recommendations fall within the scope, as examples of providers subject to the rules. 1 On the deployer side, the obligations reach a bank running a third-party chatbot on its customer-service portal, a media company using generative AI to produce news articles, or a recruitment firm using AI-powered CV-screening software.
1
Non-compliance can attract fines of up to EUR 15 million or 3% of worldwide annual turnover. 1 Enforcement falls to national market surveillance authorities, the EU AI Office, and the European Data Protection Supervisor when EU institutions are providers or deployers.
3
The retroactive reach is what makes preparation difficult. The obligations apply from August 2 regardless of when a system was built or first deployed. 2 One narrow exception exists: the AI Omnibus provisional agreement of May 2026 grants generative AI systems already on the market before August 2 an additional four months, until December 2, 2026, to meet the machine-readable marking requirement for synthetic content under Article 50(2).
2 That extension covers only the technical obligation to embed provenance marks in AI-generated content. It does not delay the requirements to disclose AI interactions, label deepfakes, or inform people about emotion recognition systems.
The timeline adds to the pressure. The Commission's guidelines, adopted July 20, are non-binding, and the specific technical standards for machine-readable marking are still being finalized through a Code of Practice and complementary EU standardization work. 2 The AI Office has indicated that signatories to the voluntary Code of Practice on Transparency of AI-Generated Content will benefit from a degree of presumption of conformity with the marking requirements.
1 Providers and deployers that choose not to sign must demonstrate compliance through alternative equivalently adequate means.
3
For AI agents specifically, the guidelines confirm they fall within the interaction disclosure obligation. Where a provider cannot reliably predict whether an agent will interact with a person, the system should be designed to disclose its AI nature in every such situation. 2
These obligations also stack alongside existing instruments. The GDPR, the Digital Services Act, the Digital Markets Act, consumer protection laws, and accessibility legislation all continue to apply in parallel and will need to be reconciled with the AI Act. 1
National authorities can investigate and impose fines from day one. The systems built before anyone imagined this regulation are the ones that will be hardest to bring into compliance.
References
Cite this story
ProvenBrief (2026). "EU AI Act transparency rules become enforceable tomorrow: every AI interaction must now be disclosed, every deepfake labeled." ProvenBrief. https://provenbrief.com/story/eu-ai-act-transparency-rules-become-enforceable-tomorrow-every-ai-interaction-mu
Free to quote and link with attribution. Republishing in full or AI-training use requires a license.
Get the next brief in your inbox
One weekly email. Every claim verified against primary sources before we hit send.
This story
WordsProduced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.