The EU AI Act launches its transparency rules: chatbots and deepfakes will have to identify themselves
This Sunday, 2 August 2026, one of the most anticipated milestones of the European Union’s Artificial Intelligence Act comes into force: the transparency obligations for AI systems. From that date, the providers and deployers of tools such as chatbots, virtual assistants, or content generators will have to clearly inform users that they are interacting with a machine, and synthetic content — including the famous deepfakes — will have to be visibly labelled. It is the first major package of obligations activated since the Community regulation entered into force in August 2024, and it marks the start of a phase in which European regulation stops being a theoretical framework and becomes a concrete requirement for thousands of companies.
What exactly changes on 2 August
The AI Act (EU Regulation 2024/1689) organizes artificial intelligence systems into four risk levels: unacceptable, high, limited, and minimal or none. The rules now being activated affect the transparency level, that is, the relationship between AI and people. In practice, this translates into three major obligations.
The first affects chatbots and conversational assistants: if a person converses with an AI system, they must know it. The second targets content generators, which will have to make the texts, images, or videos produced synthetically identifiable. The third, perhaps the most visible, requires clearly and prominently labelling deepfakes and AI-generated content published with the aim of informing the public about matters of general interest. The logic is simple: preserving trust requires that no one be able to pass off what is artificial as real, especially when public opinion is at stake.
A phased timetable that started a year ago
The application of the AI Act has not been immediate, but staggered. The prohibitions on practices considered unacceptable risk — such as social scoring, emotion recognition in the workplace, or the non-selective scraping of images for facial recognition databases — already came into force in February 2025. Now, in August 2026, it is transparency’s turn. And milestones still lie ahead: in December 2026 the prohibition on systems that generate non-consensual sexually explicit and intimate content will be activated, the so-called prohibited practice number nine, incorporated by the AI Omnibus package.
As for high-risk systems — those that can affect health, safety, or fundamental rights, such as those used in education, employment, critical infrastructure, or border management — the strict obligations (risk assessment, data quality, traceability, human oversight, and robustness) will apply from 2 December 2027. That deadline was extended by 16 months compared to the initial timetable, a decision by the European Commission in autumn 2025 that drew criticism from digital rights organizations, but which Brussels defended as necessary to publish the pending technical standards first.
Who is affected
The scope of application is broad. It affects both providers of AI systems operating on the European market and those who deploy them, regardless of whether the company is headquartered inside or outside the EU. American tech giants, European startups, and SMEs that integrate AI into their products are equally obliged to comply. In addition, general-purpose AI models, such as those powering the large assistants, have specific documentation and systemic risk management rules, supervised by the European Commission’s AI Office.
To ease the transition, the Commission has promoted the AI Pact, a voluntary initiative that encourages providers and deployers to get ahead on complying with the key obligations. It has also set up a dedicated helpdesk to resolve doubts about how to apply the regulation in each specific case. The intention is to avoid the legal uncertainty that usually accompanies major digital regulations.
A model setting a global trend
The European AI Act remains the world’s first comprehensive legal framework for this technology, and its phased rollout is being watched closely by other countries and blocs. Its philosophy is that of the preventive approach: regulate before risks materialize, rather than reacting once they have already caused harm. For companies operating in Europe, the message is that regulatory compliance is already part of product development, not a later formality. For citizens, the promise is that, from now on, when a machine speaks to them or a video surprises them, they will have the right to know it.
The coming into force this Sunday is not the end of the road, but the start of the most visible phase of a regulation that will continue to unfold over the coming years. With transparency as its first cornerstone, Europe is rehearsing in real time a question that the rest of the world will also have to answer: how to live with an increasingly powerful technology without giving up knowing what is real and what is not.






