Skip to main content
EU AI Act · 7 min read

EU AI Act Transparency Rules Start August 2: What Must Be Disclosed

The EU AI Act’s transparency rules begin applying on August 2, 2026. The European Commission says its AI Office and national authorities will begin enforcement on the same date.

This deadline was not displaced by the Digital Omnibus changes to parts of the high-risk AI calendar. Article 50 follows its own schedule. It covers several familiar products and practices: systems that interact directly with people, generators of synthetic audio, images, video, or text, emotion-recognition and biometric-categorization systems, deepfakes, and certain AI-generated public-interest text.

The compliance mistake now would be to treat “AI disclosure” as one small badge added by the marketing team. Article 50 divides duties between providers and deployers, uses different rules for different outputs, and includes exceptions that need to be documented rather than assumed.

First, Know Whether You Are the Provider or Deployer

The transparency duty depends partly on the organization’s role. A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority, subject to the Act’s definitions and exclusions.

A company can be a customer in one relationship and still take on provider-like responsibilities in another if it substantially modifies, rebrands, or puts a system into service under its own name. Do not assign the role based only on who trained the underlying model. Record the role for the specific system and deployment.

Direct AI Interaction: Tell People When They Are Dealing With a Machine

Providers must design systems intended to interact directly with natural persons so that people are informed they are interacting with AI. The notice is not required when that fact is obvious to a reasonably well-informed, observant, and circumspect person in the circumstances.

For most public-facing chatbots, voice agents, virtual assistants, and AI intake tools, the safest operational question is simple: would a normal user understand at the beginning of the interaction that this is AI? If not, add a clear notice at or before the first interaction. Do not bury it in terms of service.

Synthetic Outputs: Providers Need Machine-Readable Marking

Providers of AI systems—including general-purpose AI systems—that generate synthetic audio, images, video, or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.

The technical solution must be effective, interoperable, robust, and reliable as far as technically feasible, taking into account the content type, implementation cost, system limitations, and state of the art. Article 50 includes an exception where a system performs an assistive function for standard editing or does not substantially alter the input or its meaning.

This is not just a visible “made with AI” label. It is a product and engineering requirement. Providers should be able to identify the marking method, test whether it survives ordinary processing, document known limits, and explain how changes are controlled.

Deepfakes and Public-Interest Text: Deployers Have Disclosure Duties

Deployers must disclose when an AI system generates or manipulates image, audio, or video content that constitutes a deepfake. Artistic, creative, satirical, fictional, and analogous works receive a narrower treatment: disclosure may be made in an appropriate way that does not hamper the display or enjoyment of the work.

Deployers also must disclose AI-generated or manipulated text published to inform the public on matters of public interest. That duty does not apply when the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.

That exception is not “a person glanced at it.” A business relying on human review should define who has editorial responsibility, what review occurred, what the reviewer could change or reject, and where the approval record is kept.

Emotion Recognition and Biometric Categorization Require Notice

Deployers of emotion-recognition or biometric-categorization systems must inform the people exposed to the operation of the system and must process personal data consistently with applicable EU data-protection law.

This reaches beyond chatbots and generative content. Workplace monitoring, customer analytics, access systems, education tools, and event technologies may use features described as sentiment, affect, attention, engagement, identity, or audience classification. Inventory what the system actually does, not just the vendor’s product category.

The Code Is Voluntary; Article 50 Is Not

The EU Code of Practice on Transparency of AI-Generated Content is a voluntary compliance tool. The Commission and AI Board have said the code is an adequate voluntary way to demonstrate compliance with the relevant transparency duties.

The underlying Article 50 requirements are legal obligations. A team may choose another compliant method, but “we did not sign the code” is not an exemption. The practical decision is whether to follow the code, use another documented approach, or explain why a particular duty does not apply.

A Last-Mile Transparency Checklist

Before treating the August 2 deadline as complete, verify the implementation rather than the policy statement:

  • System inventory: identify direct-interaction AI, synthetic-content generators, deepfake tools, public-interest publishing workflows, emotion recognition, and biometric categorization.
  • Role record: document whether the organization is provider, deployer, or both for each system.
  • User notice: confirm chatbot and voice-agent notices appear clearly at the first interaction unless the AI nature is genuinely obvious.
  • Technical marking: identify the machine-readable method for generated outputs, test it, record limitations, and assign an engineering owner.
  • Content disclosure: define labels for deepfakes and covered public-interest text, including where and when the disclosure appears.
  • Editorial-control evidence: if relying on the human-review exception for public-interest text, name the responsible editor and retain an approval record.
  • Biometric notice: confirm exposed people receive notice for covered emotion-recognition or biometric-categorization systems.
  • Accessibility: provide disclosures clearly, distinguishably, accessibly, and no later than the first interaction or exposure.
  • Vendor terms: establish who supplies markings, notices, documentation, change alerts, and technical support across the value chain.

The Bottom Line

August 2 is not merely another date on the EU AI Act timeline. It is the point when several visible, testable transparency duties move from planning into operation.

If a person talks to your AI, sees a deepfake you deployed, encounters covered biometric analysis, or receives certain AI-generated public-interest content, the disclosure path should already exist. If your system generates synthetic content, the machine-readable marking path should already exist.

The high-risk calendar may have moved. The transparency deadline did not.

Key Takeaways

  • EU AI Act Article 50 transparency obligations begin applying August 2, 2026, and the Commission says the AI Office and national authorities will begin enforcement on that date.
  • Providers must address direct-interaction notices and machine-readable marking of synthetic content; deployers have separate duties for deepfakes, certain public-interest text, emotion recognition, and biometric categorization.
  • The human-review exception for certain public-interest text should be supported by real editorial control, a responsible person or organization, and an approval record.
  • The Code of Practice is voluntary, but the relevant Article 50 transparency duties are legal obligations.
  • Compliance should be verified in product behavior, technical marking, accessible disclosures, vendor responsibilities, and retained evidence—not only in an AI policy.

Related Regulations

Sources & References

Disclaimer: Content on AIRegReady is educational and does not constitute legal advice. Regulatory summaries are simplified for clarity and may not capture every nuance of the underlying law or guidance. Consult qualified legal counsel for specific compliance obligations. Information was accurate as of the date noted but regulations change frequently.

Related Resources