On 2 August 2026, the EU AI Act's transparency obligations under Article 50 took effect — the first continent-wide rules requiring AI systems to identify themselves to the people interacting with them. If any part of your business touches EU users, this is worth understanding now rather than after a complaint lands.
What the rules actually require
- Chatbots and virtual assistants must disclose they're AI. Users need to be clearly informed they're interacting with an automated system, not a person.
- Deepfakes need a label. AI-generated or manipulated audio, image, or video content depicting real people or events must be marked as such.
- Machine-generated content needs machine-readable marks. Synthetic text, audio, image, and video output from AI systems — including general-purpose AI — must carry marks that let it be detected automatically, not just a visible watermark.
Why this matters even outside the EU
Regulatory patterns like this tend to travel — GDPR set the template for privacy law well beyond Europe's borders, and AI transparency requirements are likely to follow a similar path. Building disclosure and content-labelling into your AI systems now is cheaper than retrofitting it under multiple jurisdictions later.
A practical checklist
- Audit every customer-facing AI touchpoint (chat, voice, email) for clear "you're talking to AI" disclosure.
- Confirm your content generation tools support machine-readable provenance marking, not just visible watermarks.
- Review any AI-generated marketing, support, or media content for deepfake-adjacent risk — synthetic voice or likeness use needs explicit labelling.
- Assign clear ownership for AI compliance — this shouldn't sit solely with legal or solely with engineering.
Transparency rules like this are a natural extension of the guardrails conversation — see my earlier post on AI Guardrails for the operational side of catching AI mistakes before they reach a customer or a regulator.