Regulation (EU) 2024/1689, commonly known as the AI Act, entered into force on 1 August 2024 and provides for a phased implementation period. August 2026 was originally intended to mark the implementation of a significant share of the Regulation’s obligations, including those applicable to high-risk AI systems.
This is no longer the case. Following an amendment adopted in July 2026, the application dates for the obligations relating to high-risk AI systems have been postponed. However, the transparency obligations applicable to providers and deployers will continue to apply from 2 August 2026.
If your organisation uses AI systems such as generative AI tools, AI assistants, chatbots, or other AI-based solutions as part of its business operations, you will generally fall within the scope of the AI Act. The same applies if you develop AI solutions.
The Regulation identifies the following categories of actors:
Provider: Develops or has an AI system developed and places it on the market under its own name or trademark.
Deployer: Uses an AI system in the course of its activities, including business operations or the exercise of public authority.
Importer: A person or undertaking established in the EU that places an AI system from a third country on the EU market.
Distributor: A supply-chain actor that makes an AI system available on the market without being the provider or importer.
Authorised Representative: An EU-based representative appointed by a provider established outside the EU.
Product Manufacturer: A manufacturer of a physical product into which an AI system is integrated.
Affected Person: A natural person who is impacted by the use of an AI system.
Please note: The transparency obligations apply only to providers and deployers.
Article 50 of the AI Act introduces transparency obligations requiring providers and deployers of AI systems to ensure that individuals are informed when they interact with AI or are exposed to certain forms of AI-generated or AI-manipulated content.
The rules require deployers using AI systems that generate deepfakes—defined as AI-generated or AI-manipulated image, audio, or video content that materially resembles existing persons, objects, places, entities, or events and would falsely appear authentic or truthful—to clearly disclose that the content has been artificially generated or manipulated.
Where the content forms part of an artistic, creative, satirical, or fictional work, the transparency obligation is limited to providing the disclosure in an appropriate manner that does not interfere with the presentation of the work.
Where AI-generated text is published to inform the public on matters of public interest, a disclosure must be provided unless the content has undergone human review prior to publication or a natural person assumes editorial responsibility for the published content.
If an AI system is used for emotion recognition or biometric categorisation, affected individuals must be informed of the use of such systems. This may be particularly relevant for organisations using AI in connection with access control, behavioural analysis, customer data processing, HR processes, or other people-focused applications.
Providers placing AI systems on the market that are intended to interact directly with natural persons must ensure that users are informed that they are communicating with an AI system. Examples include chatbots, AI-powered customer service solutions, virtual assistants, and similar applications. This obligation does not apply where it is obvious from the circumstances that the interaction involves AI.
Providers making available AI systems capable of generating AI-generated or AI-manipulated text, images, audio, or video must ensure that the system’s outputs are marked in a machine-readable format, clearly indicating that the content has been artificially generated or manipulated.
For systems already placed on the market before 2 August 2026, a transitional period applies until 2 December 2026 to implement the required technical marking mechanisms. For newly placed systems, the obligation applies from 2 August 2026.
The European Commission has developed standardised labels for this purpose: EU Icons for labelling AI-generated content | Shaping Europe’s digital future
If your organisation uses AI systems, you should ensure the following:
Emotion recognition and biometric categorisation: Before deploying such systems, assess whether the intended use is prohibited under Article 5 of the AI Act. Where the use is lawful, affected individuals must be clearly informed.
Deepfakes: Identify all use cases where AI generates or manipulates image, audio, or video content that may constitute a deepfake and ensure appropriate disclosure.
AI-generated content on matters of public interest: Where AI-generated text is published, either disclose the use of AI or establish a process involving human review and editorial oversight.
If your organisation develops or markets AI systems, you should ensure the following:
Transparency in AI interactions: Users must be informed when they are interacting with an AI system unless this is obvious in the specific context.
Labelling of AI-generated content: AI-generated outputs, including text, images, audio, and video, must include appropriate machine-readable markers identifying the content as AI-generated or AI-manipulated.
The AI literacy obligation under Article 4 and the prohibitions on certain unacceptable AI practices under Article 5 have applied since February 2025. The rules governing general-purpose AI models under Chapter V have applied since August 2025.
The Regulation’s risk-based structure remains unchanged, but the application dates for high-risk AI obligations have been postponed. These obligations will apply from:
2 December 2027 for stand-alone high-risk AI systems listed in Annex III; and
2 August 2028 for high-risk AI systems embedded in products covered by sector-specific product legislation listed in Annex I.
Organisations should establish a clear overview of their use of AI and determine whether they qualify as a provider, deployer, or another relevant actor under the AI Act, as this will determine the obligations that apply.
As the transparency requirements under Article 50 apply from 2 August 2026, organisations should review their AI systems and assess whether they generate or manipulate content that must be labelled as AI-generated. This may include AI-generated text, images, audio, or video used in communications with customers, citizens, employees, or other stakeholders. Any disclosure and labelling requirements should be integrated into existing processes and workflows.
Organisations should also ensure compliance with the AI literacy obligations by providing employees who use AI systems with the knowledge necessary to use such technologies responsibly and in accordance with the Regulation.
Finally, internal AI policies should be reviewed and updated to align with wider compliance efforts, including data protection and information security requirements. Organisations may also wish to begin preparing for the forthcoming obligations relating to high-risk AI systems.
For further advice on the AI Act and organisational compliance, please contact CO:PLAY.