
EU begins enforcing AI Act transparency rules: chatbots must identify themselves, deepfakes must be labelled
From 2 August, providers of chatbots and AI-generated media must clearly inform users they are interacting with a machine and label synthetic content, with fines of up to €15 million or 3% of global turnover for violations.
What changes on 2 August
From Sunday, any interactive AI system such as a chatbot or virtual assistant must clearly inform users they are conversing with a machine, unless the context makes it obvious (for example, when someone knowingly opens ChatGPT). The same rules require that images, audio and video generated or manipulated by AI, so-called deepfakes, carry visible or audible labels, plus technical markers in metadata so that search engines and other automated systems can detect them. Enforcement falls to the national market surveillance authorities designated by each member state, not to the Commission's AI Office, whose exclusive remit under Article 88 covers general-purpose AI models. In Poland the implementing law designating that authority was still missing as the rules took effect.
Enforcement and penalties
For violations of the transparency duties, Article 99(4) sets penalties of up to €15 million or 3 percent of global annual turnover, whichever is higher, imposed by national authorities or courts rather than by the Commission. The Commission's own power to fine, under Article 101, reaches providers of general-purpose AI models. The Commission published its Code of Practice on Transparency of AI-generated Content in June and said at the end of July that about 190 organisations had signed it.
What the rules do not cover
The obligation to label AI-generated content does not apply to private individuals, only to businesses and public bodies. Under Article 50(4) the disclosure duty does not apply to AI-generated text published to inform the public where the content has undergone human review or editorial control and a person or body holds editorial responsibility, a carve-out discussed by Dr Damian Flisak, an expert in new technology law. It covers text only: AI-generated or manipulated image, audio and video get no editorial exemption. Content depicting things that do not exist, a dragon for instance, does not require labelling, but Maciej Broniarz of the University of Warsaw's Centre for Forensic Sciences noted on Tok FM that this leaves room for interpretation: an illustration supporting a flat-earth theory might be considered non-existent by some but believed by others.
Expert scepticism
Dr Maria Dymitruk, a partner at the Lubasz i Wspólnicy law firm, warned that the rules may not curb the flood of deepfake disinformation.
It seems to me that as a result of these regulations we will be flooded with AI labels from business, for example in advertisements. And what has been our bane for a long time — filling the internet with a plague of deepfakes, including those used for disinformation — may unfortunately remain unchanged.
She added that a simple "AI" label may be ineffective if users do not understand what it means, and called for digital literacy efforts. Olga Zabolewicz, a legislative specialist at NASK, said a clear label such as "Content generated by artificial intelligence" would suffice in practice. Jarosław Śliżewski, a media market expert from Praktycy.eu, pointed to the imprecision in regulations regarding the extent of AI interference in journalistic materials.
Industry standards and the limits of labels
The Rzeczpospolita article recalls a March 2026 attack ad released by the National Republican Senatorial Committee, in which the Texas Democratic Senate candidate James Talarico appeared in a synthesized voice to read his own five-year-old posts, smiling and commenting. The video was AI-generated, revealed only by a small "AI GENERATED" caption in the corner. Major tech firms including Adobe, Google, Microsoft and Meta are developing the C2PA standard, which embeds provenance and edit history into digital files. However, the article notes that a certificate can show an image's history but cannot replace human judgment about what the image means.
The staggered rollout
Not all parts of the AI Act take effect today. A digital omnibus amendment, adopted by Parliament on 16 June and the Council on 29 June and in force since 27 July, postponed several deadlines. It also pushed the providers' duty under Article 50(2) to embed machine-readable markers in synthetic content to 2 December 2026, so part of the transparency package does not start today. National regulatory sandboxes for testing AI systems are now due by 2 August 2027. Obligations for certain high-risk systems used in recruitment or banking are pushed to 2 December 2027. New bans on AI systems that generate sexually explicit material without consent or child sexual abuse material will apply from 2 December 2026.
- Transparency rules for chatbots and deepfakes take effect; AI Office gains enforcement powers.
- Bans on AI-generated non-consensual sexual content and child abuse material apply.
- Deadline for national regulatory sandboxes for testing AI systems.
- Obligations for high-risk AI systems in recruitment, banking and other sectors begin.


