New EU AI Transparency Rules Take Effect Today
Chatbots must tell users they are AI under new EU transparency rules applying from today. Companies face fines of up to €15 million or 3% of global turnover.
New European Union rules requiring chatbots to tell you that you are talking to a machine, and requiring deepfakes to be clearly labelled, apply from today. Companies that fail to comply face fines of up to €15 million or 3% of global annual turnover.
From 2 August 2026, the European Commission's AI Office, together with national authorities, begins enforcing the Artificial Intelligence Act. On the same date, new transparency rules start to apply, requiring certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it.
In practice, that means three main things. Chatbots and other interactive AI systems must tell users they are dealing with AI, not a human. Deepfakes, meaning images, videos or audio that have been edited or generated using AI, must be labelled. AI-generated or altered content must also carry machine-readable marks so it can be detected more easily.
The EU has produced a set of icons that can be used for labelling. Where a deepfake forms part of an evidently artistic, creative, satirical, fictional or analogous work, the transparency obligation is limited to disclosing it in an appropriate manner that does not hamper the display or enjoyment of the work.
There is one exception on chatbots. People do not need to be informed when it is obvious they are interacting with an AI system, judged by reference to an average person who is reasonably well-informed, circumspect and observant. The Commission's guidance says that exception should be read restrictively, because it deprives people of transparency.
The rules also cover written content. Deployers of generative AI systems must clearly label AI-generated or manipulated text published with the purpose of informing the public on matters of public interest, such as politics, public administration and services, public health, public security or consumer safety. Text that has undergone human review or editorial control does not need to be labelled. Superficial checks such as spell-checking or grammatical correction do not count.
Ordinary users posting in a personal capacity are not caught by the Act. Where a person uses an AI system in their personal capacity, for example to generate deepfakes and disseminate them on social media, that is considered a personal activity and is excluded from the scope of the Act. If someone gains an economic benefit on a regular basis, or is otherwise involved in a business, trade, occupational or freelance activity, they are considered a deployer and the obligations apply.
Enforcement is shared across three bodies. National competent authorities enforce the rules for other AI systems. The AI Office covers systems offered by the same provider as the underlying general-purpose AI model, along with systems integrated into very large online platforms or very large online search engines designated under the Digital Services Act. The European Data Protection Supervisor covers AI systems used by European Union institutions, bodies and agencies.
Fines can reach up to €15 million or 3% of total worldwide turnover for the preceding financial year, with proportionality taken into account for small and medium-sized enterprises and small mid-cap companies. EU institutions, bodies and agencies face fines of up to €750,000.
There is limited breathing room for existing products. AI systems placed on the market before 2 August 2026 must comply with the marking and detection obligation from 2 December 2026. Content generated before that date does not need to be labelled retroactively, although the Commission encourages relevant deployers to do so where possible.
The Commission has published guidelines to assist providers and deployers in meeting the obligations, along with a voluntary code of practice that signatories can rely on to demonstrate compliance. A first list of more than 180 organisations that have signed the code was published today.
Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy:
"AI is a transformative technology that can bring extraordinary benefits to our people and businesses. But we are also seeing that harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale… As enforcement begins, we are taking an important step towards AI that people and businesses can understand and trust, and whose benefits are shared widely across our society."
Further changes are already scheduled. The AI Omnibus introduces new prohibitions on AI systems that generate non-consensual sexually explicit content and child sexual abuse material, applying from 2 December 2026. It also postponed the rules on high-risk AI systems to 2 December 2027, and to 2 August 2028 for high-risk systems integrated into regulated products.
Individuals and organisations can report alleged infringements by providers supervised by the AI Office using its complaint tool, and people working with providers of AI systems or general-purpose AI models can use a separate whistleblower tool. The AI Office will treat information received through these tools confidentially. Further detail is available in the Commission's frequently asked questions on the transparency obligations.