Technology

New EU Rules Say Companies Must Tell You When AI Is Involved

Martin HollowayPublished 5d ago4 min readBased on 12 sources
Reading level
New EU Rules Say Companies Must Tell You When AI Is Involved
Photo by EmDee / CC BY-SA 4.0

The European Union started enforcing new rules on August 2, 2026 that require companies to tell people when they are interacting with AI and when content has been created or altered by AI. The rules apply immediately to new AI systems, while AI tools and services that were already running before that date have a four-month grace period until December 2, 2026 to comply. The Verge

The rules divide responsibilities between two types of companies. The first type is providers — the companies that build and sell AI systems. They must make sure their AI tells users they are talking to AI instead of a human, unless it is already obvious. They must also attach hidden digital marks to AI-generated audio, images, video, and text, so that other software can detect them later. The second type is deployers — the platforms and services that actually use AI. They must label AI-generated or manipulated images, audio, and video that are designed to look real, and let people know when they are seeing AI-generated content. Some companies will fall into both categories. The Verge · European Commission AI Act Service Desk

Companies that do not follow these rules face significant fines: up to 15 million euros (about $17.2 million) or 3 percent of their total yearly revenue worldwide, whichever is higher. The Verge

To help companies prepare, the European Commission published guidance materials. Guidelines on the transparency rules were released on July 20, 2026. European Commission A Code of Practice on Transparency of AI-generated Content followed, with its rules taking effect on August 2. European Commission The Commission also designed a set of optional labels — standardized icons that platforms can use to show that content is AI-generated. The requirement to label AI content is mandatory; only the specific icons designed by the Commission are optional. European Commission

The reason behind the rules is simple: as AI tools have gotten better and faster, it has become harder for people to tell whether they are talking to a human or an AI, and whether a photo, video, or piece of text was made by a person or generated by software. Chatbots and similar interactive AI systems must now inform users they are dealing with AI rather than a human. European Commission

Article 50 is part of the larger AI Act, which sorts AI systems into four risk levels: unacceptable risk, high risk, limited risk, and minimal or no risk. The transparency rules fall under the "limited risk" level, meaning these systems are allowed on the market but must include disclosure duties. The Act does not regulate AI considered minimal or no risk. European Commission

The enforcement follows a staggered timeline. Bans on eight categories of AI practices took effect in February 2025, including AI used for harmful manipulation and deception, social scoring, mass-scraping of internet or CCTV images to build facial recognition databases, emotion recognition in workplaces and schools, and real-time remote biometric identification by law enforcement in public spaces. A ninth ban, covering AI systems that produce non-consensual sexually explicit content or child sexual abuse material, takes effect in December 2026 and was introduced as part of the AI Omnibus. Starting December 2, 2027, high-risk AI systems will face strict requirements before they can be sold, including risk assessments, high-quality datasets, activity logging, detailed documentation, clear information for deployers, human oversight measures, and standards for robustness, cybersecurity, and accuracy. European Commission

The broader context here is that these transparency rules are the first part of the AI Act to directly affect generative AI tools — the chatbots, image generators, and synthetic media software that create content. The bans that took effect in early 2025 mainly targeted surveillance and social-control uses of AI. Article 50 reaches the output of every chatbot, image generator, and synthetic media tool serving EU users through two separate requirements: the companies that build AI must embed hidden detection marks when content is generated, and the platforms that show content to users must display visible labels.

In my view, the four-month grace period may be tighter than it sounds. Adding hidden detection marks to AI-generated content is not a simple switch for most systems; it requires changes to how the AI produces output, potentially including changes to the model itself or to the software layer that processes results after generation. Companies that waited until the enforcement date to start planning now have until December 2 to update systems that are already in use, which may be a narrow window for companies with many AI models deployed across different products.

The optional Commission-designed labels address a separate concern: consistency. Without standardized icons, every platform would create its own visual style for AI disclosure, and users would see a different badge or label on each service, which would undermine the point of a transparency rule. Whether major platforms adopt the Commission's labels or design their own versions will determine whether people see a consistent disclosure experience across services or a patchwork of different badges. That picture should become clearer in the coming months.