Sign up for free for our Privacy & Security event on 28 May

New transparency obligations AI Act

August 12, 2026
AI has become an integral part of our daily lives. A customer service chatbot assists you, you ask ‘Chat’ a question, or you scroll through a timeline full of content without knowing exactly who or what created it. This raises the question: do people even realise when they are interacting with AI? The European Commission is stepping in with new transparency obligations under the AI Act. These rules will come into force on 2 August 2026 and represent the next step in the AI Act’s implementation timeline. In this blog, we summarize the key information about the new obligations for you.

Who do the transparency obligations apply to?

The new transparency obligations of article 50 of the AI Act apply to both providers and deployers of certain AI systems. A provider is an organisation that develops an AI system or a general-purpose AI model and places it on the market or puts the AI system into service under its own name or trademark (e.g. Anthropic (Claude), Open AI (ChatGPT) or Google (Gemini)). A deployer is an organisationusing an AI system under its authority. Both need to take various measures. We explain them below.  

What do the transparency obligations entail?

Transparency for interactive AI systems

Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system. Think of things like voice assistants, AI companions, or chatbots. From the very first interaction, it must be clear that this is an AI system. This notice can consist of text, sound, or symbols. The guidelines of the European Commission give us a few examples: a chatbot that starts a conversation by mentioning that it is based on AI technology, an email generated by an AI agent sent to a natural person that features an AI label at the top or a voice assistant that says at the beginning of a session that it is powered by AI.

Marking and detection of AI-generated or manipulated content

Providers of AI systems that generate audio, image, video or text, must mark the output as AI-generated or AI-manipulated in a machine-readable format. This can be done, for example, throughwatermarks, metadata identifications or fingerprints. This obligation does not apply to the extent the AI systems perform an assistive function for standard editing, such as a grammar check, or do not substantially alter the input data. Providers of generative AI systems that have been placed on the market before August 2, 2026 have until December 2, 2026 to comply with this obligation. The other obligations, however, already apply to these providers immediately.

Informing when an AI system is used for emotion recognition or biometric categorization

Deployers of AI systems for emotion recognition or biometric categorization must inform individuals exposed to these systems. This can be done, for example, through a clear pop-up on a screen, or a clearly visible notice before entering a room where such AI systems are used. Note: AI systems for emotion recognition and biometric categorization are at least high-risk AI systems under the AI Act. This means that this transparency obligation exists alongside other obligations that apply to high-risk AI systems. In some cases, the use of AI for emotion recognition is even prohibited, for example if an organization deploys emotion recognition in the workplace or in education.

Labelling of deep fakes

Deployers must clearly mark deepfakes as AI-generated or AI-manipulated. A deepfake is more than just a video of a person saying something they never actually said. The AI Act defines a AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

The definition of a deepfake is therefore very broad. It can also involve places or buildings, and even fictional objects can fall under it. When assessing whether something qualifies as a deepfake, the degree of resemblance, the message, the context, and the intended audience are all relevant. An AI-generated image of a dragon flying over the Eiffel Tower, for example, is not a deepfake. People would generally not consider this to be truthful.

In some cases, this obligation is limited, for example when it concerns an artistic, creative, satirical, fictional, or analogous work. The previously mentioned guidelines use the example of a deepfake of a deceased actor appearing in a new film. In that case, the marking must still be present, but it may not hamper the display or enjoyment of the work.

Informing the public of AI-text publications on matters of public interest

Deployers of AI systems that generate or edit text informing the public about matters of public interest must mark this text as AI-generated or AI-manipulated. Think of topics such as political elections, public health, or the justice system. This obligation does not apply when the text has undergone human or editorial review, and someone bears editorial responsibility for the publication. Superficial, purely formal, or procedural checks (for example, spell checking or grammatical correction) are not sufficient to qualify for this exemption.

Code of practice  

Organizations that fail to comply with the transparency obligations risk a fine of up to 15 million euros or three percent of global annual turnover. To help organizations comply with the transparency obligations, the European Commission has published a code of practice that supplements the guidelines. This code is voluntary but offers practical guidance on the technical and organizational steps you can take. Organizations can sign the entire code of practice, or only parts of it.

In addition, the Commission is also introducing a set of EU icons for labelling AI-generated content, so that marking will soon be recognizable and consistent across different platforms and services. The use of these icons is optional; labelling AI-generated content is not.

Getting started

It's important to assess how you mark your AI content and what processes you need to comply with the new European rules. Transparency isn't just a legal obligation; it's also a way to build trust with users at a time when the distinction between human and AI is becoming increasingly blurred. Whether you publish AI-generated images, deploy a chatbot, or draft texts with the help of AI: it's wise to think about how you build in transparency.

Would you like to find out more about the timeline for the AI Act? If so, read our blog ‘Timeline of the AI Act and the impact of the Digital Omnibus on AI’ for a comprehensive overview.

Do you have any questions about the AI Act and the obligations that may apply to your organisation? The legal advisers at Privacy Company will be happy to help. Please contact info@privacycompany.nl.

Download
Fleur
Consultant