Index
- What was included in the first part
- Chatbots and virtual assistants: declaring them to be AI
- Synthetically generated images, audio, video and text: technical labelling
- Deepfakes: when a visible declaration is required
- Public-interest texts and editorial responsibility
- Emotion recognition and biometric categorisation
- What companies must do in practice
- Penalties and liability
On 2 August 2026, a key part of the AI Act - the European Regulation on Artificial Intelligence - came into force. Among the most significant changes for businesses are the transparency obligations set out in Article 50: new rules for chatbots, artificially generated content, deepfakes, emotion recognition systems and biometric categorisation tools.
It is not simply a matter of adding the label ‘created with AI’ to any content. The obligations vary depending on the system used, the nature of the output and the role of the business. In some cases, the technology provider must take action; in others, it is the company, agency or publisher that uses and publishes the content.
The European Commission has confirmed that, as of 2 August 2026, the AI Office and national authorities have begun monitoring compliance with the applicable provisions. For businesses, therefore, AI transparency is no longer merely a matter of good reputational practice, but a compliance issue.
What was included in the first part
The first phase began on 2 February 2025. From that date, Article 4, which deals with AI literacy, and Article 5, which prohibits certain artificial intelligence practices deemed unacceptable, have applied.
Article 4: AI literacy
Article 4 requires providers and deployers – that is, those who supply AI systems and those who use them professionally – to take measures to develop the skills of the people working with such systems. There is no single compulsory course, but training must be appropriate to the tools, tasks and risks involved.
A copywriter using a generative model, for example, should be aware that the system may invent sources or product features. A social media manager should be aware of the risks associated with synthetic images, stereotypes and third-party rights. Anyone entering customer information into prompts should also be trained in privacy, trade secrets and the provider’s policies. The Commission’s FAQs on Article 4 specifically mention the use of ChatGPT for advertising copy and translations.
Article 5: Prohibited AI practices
(b) the placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation, with the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that group in a manner that causes or is reasonably likely to cause that person or another person significant harm;
(c) the placing on the market, the putting into service or the use of AI systems for the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, with the social score leading to either or both of the following:
(i) detrimental or unfavourable treatment of certain natural persons or groups of persons in social contexts that are unrelated to the contexts in which the data was originally generated or collected;
(ii) detrimental or unfavourable treatment of certain natural persons or groups of persons that is unjustified or disproportionate to their social behaviour or its gravity;
(d) the placing on the market, the putting into service for this specific purpose, or the use of an AI system for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics; this prohibition shall not apply to AI systems used to support the human assessment of the involvement of a person in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity;
(e) the placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage;(f) | the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons;
(g) the placing on the market, the putting into service for this specific purpose, or the use of biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation; this prohibition does not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data or categorizing of biometric data in the area of law enforcement;
(h) the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement, unless and in so far as such use is strictly necessary for one of the following objectives:
(i) the targeted search for specific victims of abduction, trafficking in human beings or sexual exploitation of human beings, as well as the search for missing persons;
(ii) the prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons or a genuine and present or genuine and foreseeable threat of a terrorist attack;
(iii) the localisation or identification of a person suspected of having committed a criminal offence, for the purpose of conducting a criminal investigation or prosecution or executing a criminal penalty for offences referred to in Annex II and punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years.
Point (h) of the first subparagraph is without prejudice to Article 9 of Regulation (EU) 2016/679 for the processing of biometric data for purposes other than law enforcement.
(b) the consequences of the use of the system for the rights and freedoms of all persons concerned, in particular the seriousness, probability and scale of those consequences.
In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, first subparagraph, point (h), of this Article shall comply with necessary and proportionate safeguards and conditions in relation to the use in accordance with the national law authorising the use thereof, in particular as regards the temporal, geographic and personal limitations. The use of the ‘real-time’ remote biometric identification system in publicly accessible spaces shall be authorised only if the law enforcement authority has completed a fundamental rights impact assessment as provided for in Article 27 and has registered the system in the EU database according to Article 49. However, in duly justified cases of urgency, the use of such systems may be commenced without the registration in the EU database, provided that such registration is completed without undue delay.
The competent judicial authority or an independent administrative authority whose decision is binding shall grant the authorisation only where it is satisfied, on the basis of objective evidence or clear indications presented to it, that the use of the ‘real-time’ remote biometric identification system concerned is necessary for, and proportionate to, achieving one of the objectives specified in paragraph 1, first subparagraph, point (h), as identified in the request and, in particular, remains limited to what is strictly necessary concerning the period of time as well as the geographic and personal scope. In deciding on the request, that authority shall take into account the elements referred to in paragraph 2. No decision that produces an adverse legal effect on a person may be taken based solely on the output of the ‘real-time’ remote biometric identification system.
5. A Member State may decide to provide for the possibility to fully or partially authorise the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement within the limits and under the conditions listed in paragraph 1, first subparagraph, point (h), and paragraphs 2 and 3. Member States concerned shall lay down in their national law the necessary detailed rules for the request, issuance and exercise of, as well as supervision and reporting relating to, the authorisations referred to in paragraph 3. Those rules shall also specify in respect of which of the objectives listed in paragraph 1, first subparagraph, point (h), including which of the criminal offences referred to in point (h)(iii) thereof, the competent authorities may be authorised to use those systems for the purposes of law enforcement. Member States shall notify those rules to the Commission at the latest 30 days following the adoption thereof. Member States may introduce, in accordance with Union law, more restrictive laws on the use of remote biometric identification systems.
7. The Commission shall publish annual reports on the use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, based on aggregated data in Member States on the basis of the annual reports referred to in paragraph 6. Those annual reports shall not include sensitive operational data of the related law enforcement activities.
Article 5, on the other hand, prohibits practices such as social scoring, the exploitation of the vulnerabilities of certain individuals, certain forms of harmful manipulation, certain applications of predictive policing and, subject to limited exceptions, the recognition of emotions in the workplace and in schools.
For example, a company may not use a system that analyses employees’ faces or voices to determine who is motivated, stressed or uncooperative. An e-commerce business must be mindful of systems that deliberately exploit a person’s vulnerability to influence their choices in a harmful way. The Commission has examined these cases in detail in its guidelines on prohibited practices.
Article 53: Obligations of providers of general-purpose AI models
(b) draw up, keep up-to-date and make available information and documentation to providers of AI systems who intend to integrate the general-purpose AI model into their AI systems. Without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law, the information and documentation shall:
(i) enable providers of AI systems to have a good understanding of the capabilities and limitations of the general-purpose AI model and to comply with their obligations pursuant to this Regulation; and
(ii) contain, at a minimum, the elements set out in Annex XII;
(c) put in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790;
(d) draw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office.
From 2 August 2025, the obligations set out in Article 53 came into force for providers of general-purpose AI models, or GPAIs. These include technical documentation, information for those integrating the model, a copyright policy and a summary of the content used for training. The second phase in 2025 therefore mainly concerned model developers; the 2026 phase has a much more direct impact on the way in which companies present these models and publish their outputs.
Chatbots and virtual assistants: declaring them to be AI
Transparency obligations for providers and deployers of certain AI systems
‘1. Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence.’
Article 50(1) stipulates that systems intended to interact directly with natural persons must be designed in such a way that those persons are informed that they are interacting with an AI system. This information is not required where the artificial nature of the interaction is apparent to a reasonably well-informed and attentive person.
Let’s imagine a mobile network operator’s chatbot. If the system introduces itself with a human name and writes ‘Hello, I’m Giulia from customer services’, the user might think they are speaking to a member of staff. A phrase such as ‘I’m Giulia, the AI-powered virtual assistant’ makes the nature of the service clear, however.
The same principle applies to telephone voicebots, avatars on websites, sales assistants, digital tutors and virtual characters within an app. This information should appear at the start of the interaction; it should not be hidden in the terms and conditions or only provided after numerous steps.
If a chat is transferred from a bot to a human operator, it is also advisable to notify the user of the change. This is not only useful for legal purposes: it prevents the user from attributing automatically generated statements to a person, or vice versa.
Synthetically generated images, audio, video and text: technical labelling
Transparency obligations for providers and deployers of certain AI systems
‘2. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.’
Article 50(2) concerns providers of systems that generate synthetic content. They must ensure that the outputs are labelled in a machine-readable format and are recognisable as having been artificially generated or manipulated.
The labelling may include metadata, watermarks or other provenance and detection techniques. It must be effective, interoperable, reliable and proportionate to the state of the art. This responsibility lies primarily with the system provider, not necessarily with the company using the output.
For example, the provider of an image generator must implement technical tagging that makes it possible to detect the artificial origin of the output. This does not mean, however, that every advertising image generated using AI must also bear a visible label such as ‘created with artificial intelligence’. Article 50(2) primarily governs the technical detectability of the content and places this obligation on the system provider. A further statement addressed to the public may become necessary where the content constitutes a deepfake within the meaning of Article 50(4), or where other rules, such as those on misleading advertising, require its nature to be clarified.
The provision exempts from the labelling obligation systems that perform standard editing functions or that do not substantially alter the input or its meaning. A simple adjustment of brightness, colour correction of a photograph or the reduction of background noise in a recording therefore do not automatically trigger the obligation. However, this exception must be interpreted with caution: modifying a video so that a person appears to be performing actions that never took place or uttering words that were never spoken may constitute a deepfake and give rise to the obligations set out in paragraph 4.
Deepfakes: when a visible declaration is required
Transparency obligations for providers and deployers of certain AI systems
‘4. Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.’
Article 50(4) imposes a specific obligation on content providers who generate or manipulate images, audio or video that qualify as deepfakes. In such cases, it must be stated that the content has been artificially created or manipulated.
A typical example is that of a company which publishes a video in which its chief executive appears to be presenting a product, whilst their face or voice has been artificially generated or manipulated and the speech was never actually recorded. If the footage resembles an authentic recording, it may fall within the definition of ‘deepfake’ set out in Article 3(60) (“‘deepfake’: an image, audio or video content generated or manipulated by AI that resembles existing persons, objects, places, entities or events and which would appear falsely authentic or truthful to a person;”), even where the executive has authorised the operation.
When it comes to voice cloning, a distinction must be made between two situations. A generic synthetic voice, which does not imitate an identifiable person and is not presented as an authentic recording, does not automatically constitute a deepfake. If, on the other hand, an advert artificially reproduces the recognisable voice of a brand ambassador, an executive or another person and leads the listener to believe that this person actually spoke the message, the audio may fall within the definition of a deepfake. In such cases, the publisher must provide a clear statement accompanying the content. A disclosure hidden solely in the credits or in the terms of service may not meet the requirements of clarity and timeliness set out in Article 50(4) and (5). Furthermore, the subject’s consent and respect for rights relating to the voice and personal identity remain necessary.
For works that are manifestly artistic, creative, satirical or fictional, Article 50 permits less intrusive disclosure methods, provided that they do not prevent the public from understanding the artificial nature of the content and do not unnecessarily compromise the enjoyment of the work.
There is no automatic solution to the issue of virtual influencers. A wholly fictional character is not necessarily a deepfake, particularly when it is clearly presented as an avatar or digital creation and does not depict an existing person, place or event. The assessment changes if the content imitates a real person, artificially reconstructs an event, or is presented in such a way as to appear to be an authentic testimony.
For example, an avatar that is explicitly stated to be virtual and is promoting a clothing collection should not automatically be classified as a deepfake. If the same avatar claims to have personally tried a product or attended a real event, the company must carefully assess the risk of deception. Even where Article 50 does not expressly require labelling, the rules on commercial communications, unfair practices and the recognisability of advertising may still apply. It is therefore prudent to make the virtual nature of the character clear, without presenting this as an automatic requirement under the AI Act in all cases.
Public-interest texts and editorial responsibility
A website that automatically publishes articles on economic trends, elections or a health crisis should therefore indicate the use of AI. It is not enough for the text to be accurate: the regulation also safeguards the reader’s awareness of the process by which the information was produced.
Article 50(4) provides for an exception where the text has undergone a process of human review or editorial oversight and a natural or legal person assumes editorial responsibility for the publication. The Regulation does not set out in detail how such review should be documented. It is, however, advisable to keep a record of the process followed, the person or function responsible for the review and the assumption of responsibility: not as a requirement expressly laid down in Article 50, but in order to be able to demonstrate that the exception has in fact been applied.
Not all marketing texts automatically fall under this provision. A product description or a promotional newsletter is not necessarily a text intended to inform the public on a matter of general interest. However, the rules on advertising, consumer protection, copyright and unfair commercial practices remain applicable. Fabricated claims regarding product performance, sustainability or certifications remain problematic even if generated by AI.
Emotion recognition and biometric categorisation
Transparency obligations for providers and deployers of certain AI systems
‘3. Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. This obligation shall not apply to AI systems used for biometric categorisation and emotion recognition, which are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law.’
Article 50(3) stipulates that anyone using an emotion recognition or biometric categorisation system must inform the individuals affected by its operation. The processing of data must also comply with the GDPR and EU Regulation 2018/1725.
Consider, for example, an installation at a trade fair that analyses visitors’ facial expressions to deduce their interest, surprise or other emotions. If the system falls within the definition of emotion recognition and its use is lawful, the controller must inform the data subjects in accordance with Article 50(3). A sign generically indicating the presence of cameras may not be sufficient: the notice must make it clear that an AI system is being used to infer emotions or intentions.
Providing information to the public, however, is only one of the requirements. The organisation must separately verify the lawfulness of the processing under the GDPR and whether the prohibitions set out in Article 5 apply. If the system also carries out biometric profiling based on sensitive characteristics, its use may be prohibited and would not become lawful simply by virtue of being disclosed.
It is also necessary to check whether such use is permitted. Transparency does not render lawful anything that is prohibited by Article 5 or incompatible with the GDPR. Informing employees that a webcam will analyse their emotional state, for example, does not override the prohibition on emotion recognition in the workplace.
What companies must do in practice
The second step involves distinguishing between roles and responsibilities. The provider develops the system or brings it to market; the deployer uses it under their own authority. An agency may act as a deployer when it uses an external generator, but could become a provider if it markets its own system or rebrands a solution developed by others.
In the tech and marketing sectors, it is advisable to put in place:
- standard wording for chatbots, deepfakes and synthetic content;
- rules on where and when to display disclosures;
- checks to ensure watermarks and metadata are retained;
- human review procedures and records of approvals;
- contractual clauses with suppliers, agencies, influencers and content creators;
- checks on privacy, copyright and image and voice rights;
- tailored training for developers, marketing, customer care and management;
- a procedure for quickly correcting or removing misleading content.
‘5. The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.’
European accessibility requirements must also be met: a purely visual disclosure might be inadequate for audio content, just as an audio-only warning might not be sufficient for all users.
Penalties and liability
Penalties
‘1. In accordance with the terms and conditions laid down in this Regulation, Member States shall lay down the rules on penalties and other enforcement measures, which may also include warnings and non-monetary measures, applicable to infringements of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented, thereby taking into account the guidelines issued by the Commission pursuant to Article 96. The penalties provided for shall be effective, proportionate and dissuasive. They shall take into account the interests of SMEs, including start-ups, and their economic viability.
2. The Member States shall, without delay and at the latest by the date of entry into application, notify the Commission of the rules on penalties and of other enforcement measures referred to in paragraph 1, and shall notify it, without delay, of any subsequent amendment to them.
3. Non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
4. Non-compliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher:
(a) obligations of providers pursuant to Article 16;
(b) obligations of authorised representatives pursuant to Article 22;
(c) obligations of importers pursuant to Article 23;
(d) obligations of distributors pursuant to Article 24;
(e) obligations of deployers pursuant to Article 26;
(f) requirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34;
(g) transparency obligations for providers and deployers pursuant to Article 50.
5. The supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request shall be subject to administrative fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
6. In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.
7. When deciding whether to impose an administrative fine and when deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and, as appropriate, regard shall be given to the following:
(a) the nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system, as well as, where appropriate, the number of affected persons and the level of damage suffered by them;
(b) whether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement;
(c) whether administrative fines have already been applied by other authorities to the same operator for infringements of other Union or national law, when such infringements result from the same activity or omission constituting a relevant infringement of this Regulation;
(d) the size, the annual turnover and market share of the operator committing the infringement;
(e) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement;
(f) the degree of cooperation with the national competent authorities, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
(g) the degree of responsibility of the operator taking into account the technical and organisational measures implemented by it;
(h) the manner in which the infringement became known to the national competent authorities, in particular whether, and if so to what extent, the operator notified the infringement;
(i) the intentional or negligent character of the infringement;
(j) any action taken by the operator to mitigate the harm suffered by the affected persons.
8. Each Member State shall lay down rules on to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.
9. Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or by other bodies, as applicable in those Member States. The application of such rules in those Member States shall have an equivalent effect.
10. The exercise of powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process.
11. Member States shall, on an annual basis, report to the Commission about the administrative fines they have issued during that year, in accordance with this Article, and about any related litigation or judicial proceedings.’
Article 99 sets out the system of penalties. For infringements of the practices prohibited by Article 5, the maximum fine may be up to 35 million euros or 7 per cent of the undertaking’s annual global turnover for the preceding financial year, whichever is higher. For other infringements of the Regulation, including those relating to transparency obligations, the maximum fine may be up to 15 million euros or 3 per cent of the undertaking’s global turnover.
The official AI Act timeline and the Commission’s guidelines on transparency must therefore become operational benchmarks for legal, marketing, IT, privacy, security and procurement departments.
The message for businesses is clear: it is not enough simply to know that content has been created using AI. It must be possible to trace which system was used, who checked the output, what metadata was retained, what information was provided to the public and who assumed ultimate responsibility. From 2 August 2026, transparency must be built into the process from the outset, not hastily added at the point of publication.