04/08/2026
The EU AI Act entered into force on 1 August 2024. Its transparency rules are now enforceable, while the European AI Office and national authorities begin exercising important enforcement powers.
So what changes when you open a chatbot, use AI at work or publish AI-generated content?
1. AI must introduce itself
When you interact directly with a chatbot, AI agent or avatar, you must be informed that you are dealing with AI, unless this is already obvious to a reasonably observant person.
This may make little difference when you deliberately open Claude, ChatGPT, Gemini et al. But it matters when AI is embedded less visibly in customer service, recruitment platforms or online services. The disclosure must come at the start of the interaction, not after you have been led to believe that you were dealing with a human.
2. AI-generated content must carry a digital trace
Providers of generative-AI systems must ensure that synthetic text, images, audio and video are marked in a machine-readable format, enabling them to be detected as artificially generated or manipulated.
This does not necessarily mean that every output will display a large “Made by AI” warning. The mark may be embedded in the file. Nor does the rule cover ordinary editing tools that do not substantially alter the original content. Systems already on the market before today have until 2 December 2026 to comply with this machine-marking requirement.
3. Deepfakes must be disclosed but not every AI image is a deepfake
A deepfake is an AI-generated or manipulated image, audio or video that resembles a real person, object, place, entity or event and could falsely appear authentic. A fantastical AI illustration is therefore not automatically a deepfake.
When a business, public authority, NGO or professional uses AI to produce or manipulate a deepfake, it must clearly disclose that the content was artificially generated or altered. A hidden digital mark is not enough: the audience must be able to see or hear the warning. Art, satire and fiction receive more flexible treatment so that disclosure does not spoil the work.
There is an important exception: people using AI in a purely personal, non-professional capacity are not treated as “deployers” under the Act. They therefore have no general AI Act duty to label their social-media posts. Other rules on privacy, defamation, copyright, harmful content and platform moderation still apply.
4. Public-interest texts must be labelled or genuinely edited by a human
Professionally published AI-generated text intended to inform the public about matters of public interest must be labelled as such.
There is no labelling requirement, however, if the text has undergone meaningful human review or editorial control and a person or organisation assumes legal responsibility for its publication. Running a spell-check or correcting the grammar is not enough. But using AI as a drafting assistant does not require a label when a real editor reviews, verifies and takes responsibility for the result (as with this article).
These distinctions and exceptions are explained in the Commission’s guidance on Article 50.
5. You must be told when AI analyses your emotions or biometrics
Organisations using emotion-recognition or biometric-categorisation systems must inform the people exposed to them. If a system is analysing facial expressions, voices or physical and behavioural characteristics, it should no longer operate invisibly.
This is a transparency right, not necessarily a right to refuse. Data-protection rules and the AI Act’s separate prohibitions may nevertheless restrict whether the system can lawfully be used at all.
6. You can complain
Any individual or organisation that suspects an infringement can complain to the relevant national market-surveillance authority. The Commission has also opened an AI Act complaints tool for systems falling within the AI Office’s remit. Transparency violations may result in fines of up to €15 million or 3% of a company’s worldwide annual turnover.
Conclusions
But do not mistake an AI label for a truth certificate. AI-generated content can be accurate, while entirely human content can be false. Labels can also be lost when material is copied or reposted.
Nor does every AI Act safeguard apply today. Following the recent AI Omnibus, the stricter regime for high-risk systems used in employment, education, migration and other sensitive areas has been postponed until 2 December 2027, while rules for high-risk AI embedded in regulated products follow in August 2028.
Today’s change is narrower, but still consequential: when AI speaks to us, assesses us or manufactures something that looks real, it should no longer be allowed to hide in plain sight.