New EU rules for AI content, chatbots and deepfakes from August 2026

Aug 14, 202612 min read
  1. SmithySoft
  2. Blog
  3. AI

Related service

AI solutions Standards compliance

From 2 August 2026, companies providing or deploying certain AI systems in the EU face new transparency requirements. Providers of interactive AI systems must ensure users know when they are interacting with AI, while businesses deploying AI may have disclosure obligations for deepfakes and certain AI-generated public-interest content.

This is not a new standalone law, but the next stage in the implementation of the EU AI Act, which entered into force in August 2024. The latest phase brings Article 50 transparency requirements into effect.

What exactly has changed, which businesses are affected, and what the new rules mean for AI products, content workflows and compliance – we break down below.

EU AI Act: what changed in August 2026?

The EU AI Act (Regulation (EU) 2024/1689) is the EU’s common legal framework for the development, deployment and use of artificial intelligence. It entered into force on 1 August 2024, but its requirements were designed to apply in stages rather than all at once.

One of those stages arrived on 2 August 2026, when the transparency obligations under Article 50 started to apply. They cover several AI uses that are already common in digital products: systems that interact directly with people, generative AI that produces or modifies content, and deepfakes or certain AI-generated materials published in the public interest.

The practical change is that AI can no longer always operate invisibly. Depending on the use case, people must be informed when they are interacting with an AI system; generative AI outputs must be technically identifiable as AI-generated or manipulated; and deepfakes and certain other synthetic content require disclosure to the people who see or hear them.

So, the main changes are:

Providers must:

  • Design AI systems in a way that ensures individuals are explicitly informed whenever they interact with an AI system directly.
  • Add machine-readable marks to enable the detection of AI-generated or manipulated content.

Deployers of AI systems must inform individuals when they are exposed to:

  • Emotion recognition and biometric categorisation tools.
  • Deepfakes.
  • Text publications on matters of public interest without human review or editorial control.

Who is a provider of an AI system? 

According to Article 3(3) of the AI Act, providers of AI systems are natural or legal persons, public authorities, agencies or other bodies that develop AI systems, or have them developed, and place them on the EU market or put them into service under their own name or trademark. 

This is irrespective of whether those providers are established or located within the EU or in a third country. Providers of AI systems established or located outside the EU are also subject to the provisions of the AI Act if the output of their AI system is used in the EU.  

Providers must ensure that their AI systems meet the relevant transparency obligations laid down in Articles 50(1), (2) and (5) of the AI Act before placing those systems on the market or putting them into service.  

According to Article 50(2) of the AI Act, providers must design and develop AI systems that interact directly with natural persons – such as chatbots, AI agents, and avatars – to ensure that people are informed they are interacting with AI. 

Providers must also ensure that the outputs of their generative AI systems are marked with effective, reliable, robust and interoperable machine-readable marks that enable the outputs to be detected as generated or manipulated by AI systems.

Who is a deployer? 

Deployers of AI systems are natural or legal persons, public authorities, agencies or other bodies that use AI systems under their authority, excluding use for personal, non-professional activities.

When a natural person uses an AI system in a personal capacity – for example, to generate a deepfake and share it on social media – this is considered a personal activity and falls outside the scope of the AI Act.

However, if AI is used as part of an activity that regularly generates economic benefit, or within a business, trade, occupation or freelance activity, it is considered a professional activity. In that case, the natural person can be considered a deployer of the AI system.

The distinction is particularly important when AI is used within a company. If an AI system is used under the authority and responsibility of a legal person, such as an advertising company, the company is the deployer. Employees who operate the system under the company’s instructions and control – including designers, content creators or journalists – are not treated as separate deployers.

The same principle applies when external parties are involved. If a company hires a freelancer or contractor to operate an AI system on its behalf and under its responsibility and control, the company remains the deployer. The freelancer or contractor does not become a separate deployer simply because they operate the system.

In practical terms:

  • A company uses an AI system under its own authority and responsibility → the company is the deployer.
  • Employees use the system under the company’s instructions and control → they are not separate deployers.
  • A freelancer or contractor operates the system on behalf of the company and under its control → the company remains the deployer.
  • A freelancer uses AI independently as part of their own professional activity → the freelancer may be the deployer.

Under the AI Act, deployers have specific transparency obligations. They must inform people when using emotion recognition or biometric categorisation systems under Article 50(3), and clearly disclose deepfakes and certain AI-generated or manipulated texts on matters of public interest where the conditions of Article 50(4) apply.

Which AI interactions require disclosure?

According to Article 50(1) of the AI Act, Providers of AI systems that directly interact with people must design and develop those systems in such a way that the individuals concerned are informed that they are interacting with an AI system, unless this is obvious.  

The Guidelines on Transparency of AI-Generated Content clarify the 4 cumulative criteria in which this obligation applies: 

  • the system must qualify as an AI system;  
  • it must be designed for a genuine two-way exchange with people, rather than merely collecting data or providing automated responses;  
  • the interaction must be direct, meaning the AI itself communicates with the person rather than through a human intermediary;  
  • the interaction must be with natural persons, whether consumers, professionals or other users.  

AI systems operating solely in the background, through machine-to-machine communication, or without direct contact with people, fall outside the scope of this obligation.

People must be notified when they are interacting with an AI system from the start of the first interaction in a clear and distinguishable manner and in accordance with accessibility requirements. This will enable them to take informed decisions regarding their interaction with the system and calibrate their trust in the content accordingly.

How exactly must people be informed?

The AI Act does not prescribe one universal label for every AI use. The form of disclosure depends on what the system does and whether the obligation falls on the provider or the deployer.

For chatbots, AI agents and other systems that interact directly with people, users must be informed that they are dealing with AI from the start of the first interaction. The disclosure must be clear, distinguishable and accessible. In practice, this can be a straightforward message such as “You are interacting with an AI assistant.” No separate notice is required where it is already obvious to an average person that the interaction is with AI, although the Commission says this exception should be interpreted narrowly.

For AI-generated or AI-manipulated text, images, audio and video, the obligation on providers is different. The content must carry an effective, reliable and interoperable machine-readable mark that allows its AI origin to be detected. This is primarily a technical provenance requirement and does not mean that every AI-generated image or text must display a visible “Made with AI” label.

Deepfakes face a stricter standard. A deployer must disclose their artificial nature by the time a person is first exposed to the content. The notice must be understandable and perceivable without special software or additional actions – for example, through a visible label on an image or video or an audible notice in audio content. A hidden machine-readable marker alone is not enough. Artistic, fictional or satirical works have more flexibility, provided the disclosure does not interfere with the experience of the work.

For AI-generated or manipulated text published to inform the public on matters of public interest, the deployer must clearly label the content where the Article 50 conditions are met. However, the label is not required if the text has undergone substantive human review or editorial control and someone holds editorial responsibility for its publication. Simple proofreading or grammar correction does not qualify.

EU Icons for labelling AI-generated content

The EU has developed a set of icons that creators, publishers and other deployers of generative AI systems may use to label their AI-generated content. These icons are freely available. 

The Icons have 4 variations: black, white, black with 50% transparency and white with 50% transparency. You can download zip files with all the icons in all variations in SVG and PNG formats.

These icons are made publicly available for everyone to use freely, without the need for attribution to the Commission or the AI Office. The use of these EU icons is optional, but the labelling requirements under Article 50 AI Act are not.

How to display the EU icons

  • The icon should be clearly perceivable and distinguishable at the latest at the time of first exposure of a natural person to the deepfake or published text.
  • The icon should be placed where no intervening overlay elements exist.
  • The icon should be directly embedded into the deepfake or published text (except for creative works), unless equivalent alternatives are available such as a user interface overlay. The icon must be visible when content is reshared or downloaded.
  • The icon should be in a clearly visible size.
  • Any accompanying label should use plain language and avoid jargon, confusing wording and abbreviations other than “AI”.
  • If possible, the icon should be readable by assistive technologies using alt text or ARIA labels indicating that the content is AI-generated or manipulated.
  • If the disclosure appears for a limited time, it should remain visible long enough to be read and understood by users with cognitive or processing difficulties.
  • If additional information is provided through a second interactive layer, the icon should clearly indicate that further information is available and the second layer content shall be navigable using assistive technologies.

Chatbots 

For chatbots and other AI systems that communicate directly with people, the practical requirement is simple: the user must be told they are interacting with AI at the start of the first interaction.

The disclosure should be clear and visible within the interface – for example, “You are interacting with an AI assistant.” Hiding this information in terms of service or privacy policies is not sufficient.

An additional notice is not required when it is already obvious to a reasonably informed user that the system is AI. The requirement therefore mainly affects products where an AI assistant could reasonably be mistaken for a human – such as customer support, sales, booking or service interfaces.

AI-generated content 

Providers of generative AI systems that create or manipulate text, images, audio or video must ensure that the output can be identified as AI-generated or AI-modified. The requirement applies at the system level: providers must add an effective, reliable and interoperable machine-readable mark and support mechanisms that allow synthetic content to be detected.

This does not mean that every AI-generated image, article or video must carry a visible “AI-generated” label. For Article 50(2), the core requirement is technical marking – information embedded in or attached to the content so that platforms and other systems can detect its AI origin. Visible disclosure is required separately in specific cases, particularly for deepfakes and certain public-interest content.

Manipulated text

According to Article 50(4) of the AI Act, deployers of generative AI systems must clearly label AI-generated or manipulated text published with the purpose of informing the public on matters of public interest. For text to fall within this obligation, 3 criteria must be fulfilled. The text needs to be:

  • Published
  • Informative to the public 
  • On matters of public interest, such as: politics and democratic processes, public administration and services, administration of justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety and any economic, financial, political, scientific, or cultural developments that may be relevant subject of public debate.

Deepfake 

Deepfakes are defined in Article 3(60) of the AI Act as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. 

Three cumulative criteria need to be met for content to constitute a ‘deepfake’:  

  • Resemblance: a high level of similarity between the deepfake content and the simulated subject. 
  • Existing: simulated persons, objects, places, entities or events need to resemble someone or something that exists, can plausibly exist or could have plausibly existed in reality. 
  • False appearance to be authentic or truthful: this relates to the essential characteristic of deepfake content and its capacity to potentially deceive or mislead a person regarding the content’s authenticity or truthfulness 

Unlike the machine-readable marking required from generative AI providers, deepfake disclosure must be clear to the person seeing or hearing the content. A hidden metadata tag alone is not enough. The label must be clear and distinguishable, for example through a visible notice on an image or video or an audible disclosure in audio content.

The rule covers synthetic media that closely resembles real people, objects, places, entities or events and could falsely appear authentic. For clearly artistic, fictional, satirical or similar content, the disclosure requirement is more flexible: the AI-generated or manipulated nature still has to be disclosed, but in a way that does not unnecessarily interfere with the experience of the work.

Responsibility sits with the deployer. So if an advertising company creates an AI-generated video under its authority, the company is responsible for the disclosure – not the individual designer or content creator operating the AI tool.

Which AI-generated text does not need to be labelled? 

The marking obligation does not apply where AI performs only an assistive function for standard editing or does not substantially alter the input data or its meaning. In other words, routine AI-assisted editing is treated differently from generating or materially transforming content.

Published text that has undergone human review or editorial control – does not need to be labelled.

Human review refers to the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement pertaining to the subject matter under scrutiny (e.g. academic peer review or professional validation chains). 

Editorial control refers to the control exercised in practice by a responsible editorial entity (e.g. an editor-in-chief) over the content having the authority to approve, alter or reject the substance of the text based on substantive grounds (incl. factchecking of information and ensuring the trustworthiness of sources).

Superficial, solely formal, or procedural checks (e.g. spell-checking or grammatical correction) are not considered to be human review or editorial control.

Editorial responsibility means that a person must hold the ultimate legal responsibility over the publication of the content, including the human review or editorial control.

When does Article 50 start to apply and is there a grace period?

Article 50 of the AI Act applies as from 2 August 2026. From that date onwards, providers and deployers of AI systems must comply with the transparency obligations laid down in that provision.

A limited grace period is envisaged only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation for AI-generated content (Article 50(2) of the AI Act). Providers of such systems must comply with those obligations only as from 2 December 2026. 

Content generated prior to 2 August 2026 does not need to be labelled retroactively. Nonetheless, the Commission encourages relevant deployers to do so, where possible, since it contributes to the goals pursued by Article 50 of the AI Act.

The cost of non-compliance

Compliance with the rules will mainly be enforced by national competent market surveillance authorities. 

The AI Office has a limited role in monitoring and enforcement, since it is only competent for AI systems that are built on general-purpose AI models, if the same entity provides the system and the model, or if the AI system is integrated into a very large online search engine or very large online platform designated under the Digital Services Act. 

The European Data Protection Supervisor will enforce the rules vis-a-vis AI systems used by the EU institutions, bodies and agencies. 

Fines can reach up to 15 million euros or 3% of total worldwide turnover for the preceding financial year, while proportionality can be taken into account in the case of small and medium sized enterprises (SMEs) and small mid-cap companies (SMCs).

So, what now?

The immediate priority is to map where AI is already used across customer interactions and content workflows and clarify whether the company acts as a provider, a deployer, or both. Chatbot disclosures, deepfake labelling, editorial review of public-interest content, and the technical marking of generated content should then be checked against Article 50. For certain AI systems placed on the market before 2 August 2026, the transitional period runs until 2 December 2026.

This is not the end of the AI Act rollout. The next major compliance phase concerns high-risk AI systems: rules for areas such as employment, education, biometrics, critical infrastructure and migration will apply from 2 December 2027, while high-risk AI embedded in regulated physical products will follow from 2 August 2028.

For many businesses, the work is therefore shifting from interpreting the regulation to changing the product itself. 

SmithySoft can help with the technical side of that transition – auditing existing AI-enabled products and workflows, implementing user-facing disclosures, integrating content-marking and traceability mechanisms, and adapting software architecture where new transparency controls are required. Legal interpretation remains a separate responsibility, but the compliance requirements increasingly have to be implemented in software, not just documented in policy.

Schedule a consultation with our team

Choose a time that works for you

Galina Berezina photo
Galina Berezina
COO
Schedule a consultation
Schedule with Galina

Prefer to share details first?

Our team will review your request and follow up to schedule a call.

0 / 10000
By submitting this form, you agree to our processing of your personal data in accordance with our Privacy Policy.