A label is useful only if people notice it, understand it, and trust the system behind it. Europe’s new AI transparency rules now put that test on every company shipping or using certain AI systems.

EU AI Act transparency rules illustration

From 2 August 2026, Article 50 of the EU AI Act applies transparency duties across four areas: direct AI interaction, synthetic content, emotion recognition or biometric categorisation, and deepfakes or AI-generated text published on matters of public interest. The rule is broader than the phrase “deepfake law” suggests. A customer-service bot, an automated phone line, a coding agent that talks to users, and a text generator used for public-interest reporting can all sit inside the same compliance conversation.

That breadth is the important part. The obligations do not depend on a system being classified as high risk. A small business with no high-risk AI may still need to tell customers that a chatbot is artificial, mark generated media, or disclose that it used AI to create a realistic video. The European Commission says the enforcement date is 2 August, while AI systems already on the market get until 2 December 2026 for the machine-readable marking requirement under Article 50(2). Content created before 2 August does not need a retroactive label, according to the Commission’s FAQ.

The rule reaches the people using the model

Article 50 splits responsibility between providers and deployers. Providers of interactive systems must design them so people know they are dealing with AI. Providers of generative systems must make synthetic audio, images, video, and text machine-readable and detectable as artificial. Deployers, meaning the organisations using those systems, carry the disclosure burden for deepfakes and AI-generated public-interest text.

That distinction matters for companies that assumed the model vendor would handle everything. If a marketing team generates a realistic person for an advert, the team still has an operational problem even if the model provider added provenance metadata. If a publisher uses an AI draft for a public-interest story, human editorial responsibility can change the disclosure analysis, but “a human glanced at it” is not the same as meaningful editorial control.

The exemptions are narrower than many casual summaries imply. Personal content is outside the main obligation. Clearly artistic, satirical, or fictional work gets a lighter disclosure requirement when a label would disrupt the work. Ordinary editing assistance, such as grammar correction that does not substantially alter the source, can also fall outside the marking duty. A realistic synthetic politician delivering a fake speech is a much harder case than a clearly impossible fantasy scene.

The Commission’s own guidance is not the final word from a court, but it gives companies the working interpretation national authorities are expected to use. It also creates an awkward technical dependency: the law sets the outcome, while the standards and voluntary Code of Practice fill in how marking and detection should work.

The watermark problem is harder than the label

A visible notice is easy to describe. A durable machine-readable mark is not. It has to survive common transformations such as compression, cropping, screenshots, transcoding, and reposting. It also has to be readable by detection tools without becoming a new privacy or tracking mechanism.

Google says its SynthID systems have put invisible watermarks on more than 100 billion images and 60,000 years of audio. TikTok says it has helped label more than 3 billion pieces of content. Those figures show that large platforms already operate at a scale where provenance systems are possible. They do not prove that the marks survive every workflow, that independent detectors agree, or that a label remains visible once content leaves a platform’s control.

This is where the policy gets practical. A provenance mark attached by a generator can disappear when a user records a screen, runs an image through another editor, or copies text into a new document. A detector can also produce false positives. If every image in an advert gets a warning, users may stop distinguishing a synthetic political video from a harmless AI-assisted background. The Computer and Communications Industry Association has already argued that the EU guidance expands the deepfake concept beyond deceptive content. Its policy lead compared the likely result to cookie banners: everywhere, technically present, and easy to ignore.

That criticism is not a reason to abandon disclosure. It is a reason to measure whether disclosure changes behaviour. A label that nobody reads is compliance theatre. A watermark that disappears after one screenshot is a brittle technical promise. The EU is asking providers and deployers to solve both problems at once.

What companies should do this week

First, inventory actual uses rather than buying another abstract AI governance subscription. List chatbots, voice assistants, image and video generators, document tools used for public communications, emotion-recognition features, and any workflow that can create a realistic person or event. Then record who provides the system and who publishes the output.

Second, separate three things that teams often bundle together: telling a person they are interacting with AI, adding a machine-readable mark to generated output, and placing a visible disclosure on content. They are different obligations with different owners. A provider may handle the first two while the deployer still owns the third.

Third, test the output after it leaves the demo environment. Compress it. Screenshot it. Translate it. Re-edit it. Upload it to another platform. If the provenance signal vanishes, document that failure and decide whether the workflow should be blocked or labelled more prominently.

The penalty ceiling is €15 million or 3% of worldwide annual turnover, with proportionality taken into account for smaller companies. That is large enough to get an executive’s attention, but fines are not the main reason to care. The more immediate risk is that companies will ship a flood of weak notices, train users to ignore them, and then discover that the one dangerous synthetic clip looks exactly like every harmless one.

Europe has made transparency a product requirement. The next question is whether the industry can make that transparency legible instead of merely legal.