Summary
- The European Commission’s AI Office and national authorities begin enforcing AI Act rules from 2 August 2026.
- Transparency obligations now apply to chatbots, deepfakes, and AI generated or altered content.
- Compliance will require changes to product design, content pipelines, supplier contracts, and customer facing workflows.
The European Commission has moved the EU AI Act into a new enforcement phase, with its AI Office and national authorities beginning to apply the law from 2 August 2026 and transparency obligations taking effect for certain AI systems.
Chatbots and other interactive AI systems must tell users when they are dealing with AI rather than a human. Deepfakes must be labelled, while AI generated or altered content must carry machine readable marks so that it can be detected more easily. The Commission says the rules are intended to reduce deception and manipulation, while giving businesses clearer obligations and a practical route to compliance.
After years of legislative debate, the operational work now moves into product teams, legal departments, procurement functions, marketing systems, public services, and software supply chains. Companies deploying AI in Europe have to decide where disclosures appear, how visible they are, how long they persist, and what happens when AI generated material is edited, republished, reformatted, translated, or moved through multiple platforms.
The Commission has also pointed organisations towards the Code of Practice on transparency of AI generated content, which is intended to help providers and deployers operationalise marking and labelling obligations. More than 180 organisations have signed the code, creating a voluntary compliance pathway that will still need technical implementation inside real products and workflows.
In a simple chatbot, a disclosure can be placed near the user interface and tested for comprehension. In a larger organisation, AI involvement may appear in call centre scripts, HR systems, customer correspondence, claims processing, internal knowledge tools, software documentation, public communications, and marketing automation. A label that works in one channel may disappear or become meaningless in another.
Machine readable marking raises a harder technical problem because content rarely stays inside the system that created it. Images are compressed, videos are clipped, documents are exported, text is copied into emails, and material is pushed through content management systems, social platforms, productivity tools, and third party services. Compliance will depend on how well those markers survive the ordinary life of business content, not on whether a vendor can demonstrate the feature in a controlled demo.
Supplier management will also change. Buyers of AI enabled systems will need clearer contractual terms covering disclosure tools, metadata handling, audit logs, model capabilities, support for downstream obligations, and liability when generated content moves through a customer’s systems. Vendors selling into Europe will be expected to support EU-style transparency even when their product roadmap is global.
Public sector bodies face a sharper version of the same test because transparency failures can damage trust even where the underlying use of AI is lawful. A citizen using a benefits service, health triage tool, immigration support line, tax helpdesk, recruitment process, or police information service may not understand where AI is involved unless the disclosure is placed at the right point in the process. Poorly timed or confusing disclosure can satisfy a design checklist while failing the person affected by the decision or communication.
The law will also influence organisations outside the EU. UK companies selling services into Europe, global platforms with European users, and software providers with European enterprise customers will all have to support these obligations in practice. Europe is not creating a universal AI rulebook, but its market size and regulatory clarity mean its requirements will shape product defaults, procurement questions, and board level risk reviews elsewhere.
Enforcement will still depend on capacity and consistency across national authorities, and early cases will decide how regulators treat good faith implementation failures. The direction, however, is no longer speculative. AI transparency is becoming part of the operating architecture of digital products, rather than a disclosure line added after deployment.




