Starting August 2, 2026, any company whose AI system talks to people in the EU, or whose AI-generated content reaches them, has been operating under a new legal requirement. The European Commission’s transparency rules under Article 50 of the AI Act took effect that day, and the Commission’s AI Office and national authorities became responsible for overseeing and enforcing the applicable transparency obligations in accordance with the AI Act.
The rules don’t restrict what AI can do. They restrict how quietly it can do it. Chatbots now need to identify themselves as AI, unless it is already obvious to a reasonably well-informed, observant, and circumspect person that they are interacting with AI. Deepfakes need a label. AI-generated text on public interest topics needs a disclosure, unless a human editor genuinely reviewed it. None of this required a vote or a headline-grabbing ban. It’s a disclosure regime, and disclosure regimes tend to be less visible than bans, right up until an AI company gets fined for skipping one.

What the EU AI Act’s transparency rules require
Provider transparency vs. deployer transparency: they’re not the same. One of the most common misunderstandings about Article 50 is that all transparency obligations are the same. They are not.
The AI Act distinguishes between providers (companies that develop or place AI systems on the EU market under their own name) and deployers (companies that use AI systems iin their business). Their transparency obligations are different.

This distinction is important because machine-readable marking and visible AI labeling are not the same thing.
Machine-readable marking is a technical obligation placed on providers of certain generative AI systems. It is intended to help detect AI-generated or AI-manipulated content through technical means, such as metadata or other provenance mechanisms.
Visible disclosures and AI labels, by contrast, are user-facing obligations. Their purpose is to ensure that individuals understand when they are interacting with AI or are exposed to certain AI-generated or AI-manipulated content.
In practice, many companies might act as both provider and deployer. For example, a company that develops its own AI chatbot and deploys it on its website may need to comply with both sets of obligations.

Two details matter more than the headline: disclosure must be “clear and distinguishable.” Buried terms-of-service language or a faint, flashing label isn’t enough. The information must also be provided at the latest at the time of the first interaction or first exposure and comply with applicable accessibility requirements. And content generated before August 2, 2026 doesn’t need retroactive labeling, which is important to keep in mind. Generative AI systems already on the market before that date also get until December 2, 2026 for the machine-readable marking piece specifically.
Examples of clear labels:
“AI-generated image”
“This video includes AI-generated or AI-altered content.”
“This text was generated using AI and has not undergone human editorial review.”
Transparency is broader than labeling. Depending on the AI system and its intended purpose, compliance may require informing users that they are interacting with AI, providing visible disclosures, embedding machine-readable markings in AI-generated content, or combining these measures. Companies should assess each AI use case individually rather than assuming that every AI-enabled feature requires the same type of disclosure.
Providers, deployers, and who should pay attention
The Act draws a real line between providers, companies that build an AI system or place it on the EU market under their own name, and deployers, companies using an AI system, under their own authority, for professional purposes. The same company is often both: a SaaS business that builds its own support chatbot is a provider of that chatbot and, if it also uses a third-party emotion-detection tool internally, a deployer of that tool too.
This affects a wider range of businesses than “AI company” implies. It reaches software providers embedding a chatbot or AI agent into a product, marketing teams publishing AI-generated or AI-modified content that falls within Article 50, media and content platforms publishing AI-assisted articles, and any business using AI-driven sentiment or biometric analysis on customers. It applies regardless of where a company is headquartered. If the AI system’s output or interaction reaches someone in the EU, the obligation can apply, in the same extraterritorial pattern GDPR set years earlier.
It’s also worth being precise about what it doesn’t reach: internal tools with no external user-facing interaction, machine-to-machine systems, standard editing that does not substantially change the initial content or its meaning, or public interest text that was reviewed meaningfully by a human. Not every AI feature needs a label. Only the categories above.
What this means for AI businesses
For companies selling AI-powered products into Europe, transparency has quietly joined a list that already includes tax handling, data protection, and payment localization: things you now have to get right operationally, not just build well technically. A chatbot that performs brilliantly but doesn’t disclose it’s AI is now a compliance gap.
That has a knock-on effect for anyone building for global markets rather than a single one. AI features designed for a US-only launch often assume no disclosure requirement at all. Shipping the same feature into the EU without adjustment creates exposure the moment a European user interacts with it. Companies that expand internationally already manage this kind of jurisdiction-by-jurisdiction variation for tax and payment methods. AI disclosure is becoming another line item in that same category: requirements that differ by market and should be handled correctly before launch, not after.
Here’s what companies should start doing now:
- Review every AI touchpoint that interacts with users or generates content reaching them, including chatbots, voice agents, image, video, and text generators, and embedded third-party AI features.
- Classify each one as a provider role, a deployer role, or both.
- Build transparency and labeling into the design and development process, not as a manual afterthought, especially before December 2, 2026 for systems already on the market.
- Review editorial workflows for any AI-assisted content touching public interest topics, and document who holds real editorial responsibility.
- Check the Code of Practice on Transparency of AI-Generated Content. Loop in legal and compliance before an EU launch, particularly for anything that touches emotion recognition, biometric categorization, or synthetic media.
The bigger picture: transparency becomes part of AI commerce
None of this changes what AI products can do. It changes what they have to say about themselves while doing it. For a while, “AI-powered” was a feature to advertise. Increasingly, in the EU at least, it’s also something that may need to be disclosed, depending on the AI system and the applicable transparency obligations: a small shift in wording with real operational consequences for anyone building, selling, or deploying AI at scale across borders.
Frequently asked questions
What is Article 50 of the EU AI Act?
Article 50 of the EU AI Act is the provision covering transparency for AI systems, requiring disclosure when someone interacts with AI, when content is a deepfake, and when text on public interest topics is AI-generated without human editorial review. It became applicable August 2, 2026.
Do all AI companies need to label AI-generated content under the EU AI Act?
No. Only specific transparency scenarios trigger disclosure, labeling, or machine-readable marking obligations: direct AI interaction, generative AI output (machine-readable marking), emotion or biometric tools, and deepfakes or AI-generated public-interest text. Whether it applies depends on the specific system and use case.
What’s the difference between a “provider” and a “deployer”?
A provider builds or places an AI system on the EU market under its own name. A deployer uses an AI system, under its own authority, for professional purposes. Many companies hold both roles for different systems.
What are the penalties for non-compliance with the EU AI Act?
If you don’t comply with the EU AI Act, you’re subject to up to €15 million or 3% of global annual turnover penalties, whichever is higher, for companies; up to €750,000 for EU institutions and bodies. The Act calls for proportionate treatment of SMEs, though the exact mechanics of that proportionality aren’t fully spelled out in public guidance yet.
Does the EU AI Act apply to companies outside the EU?
Yes, if the AI system’s output or interaction reaches people in the EU. The obligation isn’t limited to companies headquartered there.