New transparency rules for Artificial Intelligence
Update 01.09.2026
The transparency obligations of the AI Act are now in effect.
Artificial Intelligence
AI
Transparency Obligations
European Union
In Detail
The transparency obligations set out in Article 50 of Regulation (EU) 2024/1689 have applied since 2 August 2026.
From this date onwards, certain uses of artificial intelligence (AI) have been subject to rules designed to enable people to recognise when they are interacting with an AI system, and to identify content that has been artificially generated or manipulated.
The introduction of these rules marks a new stage in the implementation of the AI Act, introducing specific obligations for providers and users of systems covered by Article 50.
What is required now?
These obligations cover situations involving direct interaction with people, content generation and manipulation, emotion recognition, and biometric categorisation.
When a person interacts with an AI system: Systems designed to interact directly with people, such as chatbots and virtual assistants, must inform users that they are communicating with AI.
However, this requirement does not apply if it is obvious to a reasonably well-informed person, taking into account the circumstances and context of use, that they are interacting with AI.
When AI generates or manipulates content: Providers of generative AI systems must ensure that outputs produced by their systems, including text, images, audio and video, can be identified as having been generated or manipulated by AI through machine-readable marking.
For systems placed on the market before 2 August 2026, a transitional period applies. In these cases, the requirement for machine-readable marking will apply from 2 December 2026.
When emotion recognition or biometric categorisation systems are used: Organisations using AI systems designed for emotion recognition or categorising people based on biometric data must inform those exposed to these systems.
This information must make it clear that such systems are being used in the context in question.
When deepfakes are disclosed: Content constituting deepfakes must be identified as having been artificially generated or manipulated. The same requirement applies to AI-generated or AI-manipulated text published to inform the public on matters of public interest.
Specific conditions apply in the latter case, including instances where the content has undergone human review or editorial control, and where a person or organisation assumes editorial responsibility for its publication.
Who is responsible for compliance?
The obligations vary depending on the role played in developing and using AI systems.
Providers, for example, have obligations relating to the design of their systems to ensure that users can be appropriately informed and that AI-generated content can be identified where required.
Deployers and organisations that use AI systems in the course of their activities, have specific obligations relating to certain uses, including emotion recognition, biometric categorisation, and the disclosure of AI-generated or AI-manipulated content.
Exceptions
The AI Act provides for a number of exceptions. For example, the transparency obligations do not apply to the use of AI systems by natural persons in the course of a purely personal and non-professional activity. Specific provisions also apply to systems developed exclusively for scientific research and development.
Under certain conditions, content does not have to be identified if AI is used solely to assist with editing, without substantially altering the content.
The AI Act also provides for specific situations involving the authorised use of AI for the prevention, detection and investigation of criminal offences.
What organisations need to do
Now that the new rules are in place, organisations using systems covered by Article 50 should review their existing procedures to ensure they comply with their obligations. In particular, organisations should:
- Identify the AI systems used when interacting with citizens, customers or other users;
- Check whether people need to be informed that they are interacting with an AI system;
- Confirm how AI-generated or AI-manipulated content is identified;
- Work with the providers of the tools they use to ensure that the relevant technical requirements are met;
- Assess the use of emotion recognition and biometric categorisation systems;
- Establish procedures for identifying deepfakes and certain content relating to matters of public interest.
What happens if the rules are not followed?
Failure to comply with the obligations set out in the AI Act may result in fines of up to €15 million or 3% of a company's worldwide annual turnover, whichever is higher.
This is the maximum fine for these infringements. When determining the amount of a fine, the relevant authorities must consider the nature, severity and duration of the infringement, as well as the circumstances of the case.