Aug 3, 2026
Startups

EU AI Act enforcement begins with transparency rules for chatbots and deepfakes

EU authorities began enforcing new AI Act transparency duties on Aug. 2, requiring disclosures for certain AI interactions and content.

Marcus Adeyemi

By Marcus Adeyemi · Startups Editor

· 3 min read

EU AI Act enforcement begins with transparency rules for chatbots and deepfakes
Photo: Sifted

EU AI Act enforcement entered a new phase on August 2, 2026, as the European Commission’s AI Office and national authorities began applying transparency requirements for certain AI systems. The move puts practical disclosure duties on companies selling or deploying covered AI in Europe, while leaving the Act’s major high-risk-system requirements for a later stage.

The new rules require chatbots and other interactive AI systems to tell users they are dealing with AI rather than a person, according to the Commission. Deepfakes, including AI-generated or AI-edited images, video and audio, must be labelled. Covered AI-generated or altered content must also carry machine-readable marks to make detection easier.

The transparency rules also cover AI-generated or AI-manipulated text published on matters of public interest, which must be clearly labelled, the Commission said. The obligations are aimed at reducing deception and manipulation, but their practical effect will fall on both model providers and companies that put generative features into customer-facing products.

What does EU AI Act enforcement require from companies now?

For covered products, the immediate issue is whether users receive the required notice and whether generated or manipulated outputs can be labelled and detected. The obligations do not mean every AI system or every AI output is subject to the same requirements. The AI Act uses a risk-based framework, and this enforcement phase focuses on transparency duties.

Enforcement is split between institutions. The AI Office oversees providers of general-purpose AI models, while national regulators enforce the rules for most other AI systems, according to Sifted. That division matters for startups that build on third-party models: their compliance work may depend on what their suppliers can provide, particularly for marking and labelling outputs.

The Commission has also published a voluntary Code of Practice on Transparency of AI-generated Content. It gives providers and deployers a practical EU-wide framework for demonstrating compliance with the transparency obligations. The underlying Article 50 requirements are legal obligations, while joining the code is optional. The Commission says organisations choosing another route must demonstrate that their measures are adequate, with assessment by market-surveillance authorities on an individual basis.

About 190 companies and organisations had signed the code by the end of July, according to the Commission. It has separate sections for providers, covering the marking and detection of generated or manipulated content, and deployers, covering labelling of deepfakes and certain generated or manipulated text.

This is one stage of a phased AI Act rollout

August 2 was not the first date on which the AI Act took effect. The Commission says bans on eight prohibited AI practices, including harmful AI-based manipulation, exploitation of vulnerabilities and social scoring, have applied since February 2025. A ninth prohibition concerning systems that generate non-consensual sexually explicit content or child sexual abuse material is due to apply in December 2026.

The more extensive obligations for high-risk AI systems are scheduled to begin on December 2, 2027. Those systems will face requirements involving risk management, data quality, logging, documentation, human oversight, accuracy and cybersecurity.

Sifted reported that breaches in this new phase could bring fines of up to 3% of annual global turnover. A&O Shearman partner Peter Van Dyck told the publication that enforcement was likely to build gradually, with companies initially expected to show they are working toward compliance. Regulators have started applying the rules; the early test will be whether they can turn disclosure requirements into consistent enforcement across the bloc.

This story draws on original reporting from Sifted.

More from Startups

All Startups →