The EU AI Act's transparency rules apply from today. A checklist for chatbots, AI-written text and deepfakes
From 2 August 2026, Article 50 of the EU AI Act applies to anyone whose AI systems talk to people, generate content, or read emotions, wherever the company is based, if the output is used in the EU. The high-risk rules were pushed to December 2027 by the AI Omnibus last week. This part was not. Here is what to check, system by system.
Two things happened to the EU AI Act in the last week of July, and companies are confusing them.
On 27 July the AI Omnibus entered into force. It delays the obligations for high-risk AI systems, the ones in employment, education, credit, biometrics and critical infrastructure, to 2 December 2027, and the rules for AI embedded in regulated products to 2 August 2028. If you read a headline that said the AI Act was postponed, that was the story.
Today, 2 August, the transparency obligations in Article 50 apply. So do the AI Office's enforcement powers. The Commission published its guidelines on Article 50 on 20 July, and the fines for getting it wrong run to €15 million or 3 per cent of worldwide annual turnover, whichever is higher. The Act applies to any provider or deployer whose AI output is used in the EU, which includes a company in Bangalore or Boston with European customers.
Treat what follows as a practitioner's checklist rather than legal advice. It is the one we walk through with clients, arranged by the kind of system you run. Most companies will find they are in scope for at least two of the four.
If your AI talks to people
Chatbots, voice agents, AI assistants inside a product, anything that interacts directly with a natural person. The provider must make clear that the person is dealing with an AI, unless that is already obvious from the context.
Check that every conversational surface says so at the start, in the language of the conversation, and that the disclosure survives the design refresh. A voice agent needs to say it out loud. A chat widget needs it above the first message rather than in a footer. "Obvious from context" is narrower than product teams assume, and an assistant with a human name and a photo is the opposite of obvious.
Check the handover. When the conversation moves to a person, the person should be identifiable as one, or the disclosure is being undone.
If your AI generates images, audio, video or text
Providers of systems that produce synthetic content must embed machine-readable markings in the output and provide a way to detect that it was generated. The Commission's guidelines allow limited exceptions for standard editing and non-substantial changes.
If you built the generation system, this is yours to do. If you use a vendor's model to generate content inside your product, you are relying on their marking and you should confirm in writing that it is there, what standard it follows, and that your pipeline does not strip it. Image processing that re-encodes a file can remove a watermark without anyone intending to.
Systems already on the market before today have until 2 December 2026 to comply with the marking and detection requirement. New systems are in scope now.
The AI Office has published a voluntary Code of Practice on transparency of AI-generated content, including a set of icons, and several major providers have signed. Signing brings a presumption of conformity. Companies that do not sign have to demonstrate compliance another way and can expect closer attention.
If you publish AI-generated text about matters of public interest, or any deepfake
This is the obligation most companies miss, because it falls on deployers rather than builders. If you use an AI system to generate or manipulate an image, audio or video that constitutes a deep fake, you must disclose that. If you publish AI-generated text to inform the public on matters of public interest, you must disclose that too.
The exception matters. AI-generated public-interest text does not need the label where it has had substantive human review or editorial control and a natural or legal person takes editorial responsibility. A news desk that edits and signs off is covered by the exception. A content farm that publishes model output unread is not, and neither, arguably, is a corporate communications team that pastes a generated statement about a product recall straight onto a website.
Check every place your organisation publishes text to the public about anything that could be a matter of public interest: health, safety, finance, elections, public services. For each, either a named person reviews and takes responsibility, and the process shows it, or the content carries a disclosure.
Content generated and published before today does not need to be labelled retrospectively.
If your AI reads emotions or sorts people by biometrics
Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Contact-centre sentiment analysis on a live call, retail analytics that infers mood from a face, recruitment tools that score expression in a video interview: all in scope, and all needing a disclosure to the person before the system runs. Note that several of these uses are also on the high-risk list for December 2027, and some emotion-recognition uses in workplaces and education were prohibited outright in February 2025.
Who is the provider and who is the deployer
The obligations split by role, and the split is where compliance goes wrong. The provider develops the system and places it on the market. The deployer uses it under their own authority. A company that buys a chatbot platform, gives it a name and puts it on their website is a deployer of that platform and, depending on how much they changed it, may also be a provider of the resulting system.
Agencies and contractors complicate it further. If a marketing agency generates campaign imagery with an AI tool on your behalf, the guidelines look at whose authority the system operated under. Write it into the contract.
A one-week plan
Day one: list every AI system you provide or deploy that talks to people, generates content, or reads emotion or biometrics. The agent registry we described in June is the same list with three extra columns.
Day two: for each, decide whether you are provider, deployer or both, and who is on the other side of that line.
Days three and four: for every conversational surface, verify the disclosure is present and audible or visible at the start. For every generation system, confirm marking with the vendor in writing. For every public-facing text workflow, name the editorial owner or add the label.
Day five: write down what you found, what you changed and what remains, dated. When a regulator asks, the record of a good-faith review on the week the rules applied is worth a great deal.
The governance work we do covers this as part of the wider AI Act mapping, and the transparency review is the quickest piece of it, which is one reason there is no excuse for skipping it.
Frequently asked
What EU AI Act obligations apply from 2 August 2026? The transparency obligations in Article 50: providers must tell people when they are interacting with an AI system and must mark synthetic audio, image, video and text in a machine-readable way; deployers must disclose deep fakes and AI-generated text published on matters of public interest (unless substantively reviewed by a person who takes editorial responsibility), and must inform people exposed to emotion recognition or biometric categorisation. The AI Office's enforcement powers also begin on this date.
Did the AI Omnibus delay the EU AI Act? Partly. The AI Omnibus, in force since 27 July 2026, delays the obligations for high-risk AI systems under Annex III to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. It did not delay the Article 50 transparency obligations, the prohibited practices, or the general-purpose model rules already in force since August 2025.
Do the EU AI Act transparency rules apply to companies outside the EU? Yes. The Act applies to providers, deployers, importers and distributors who place AI systems on the EU market or whose AI outputs are used within the EU, regardless of where the company is established. Fines for breaching Article 50 can reach €15 million or 3 per cent of worldwide annual turnover.
Related reading
- The AI governance checklist for enterprise teams
- Governance is a feature, not an appendix
- Microsoft wants an inventory of your agents
The rules that apply today are the easy ones: say when it is an AI, mark what it made, label what you published. A company that cannot do those three by the end of the month is not ready for the harder rules in 2027 either.