The AI Act entered into force on 1 August 2024, followed by a gradual implementation period. 2 August 2026 was originally the date on which the majority of the AI Act’s provisions, including the key requirements for high-risk AI systems, were to become applicable.
If you use AI systems such as generative AI tools, AI assistants, chatbots or other AI-based solutions as part of your business and day-to-day operations, you will generally be covered by the AI Act. If you develop AI solutions, you will also be covered. The specific obligations that apply will, however, depend on the company’s role, the function of the AI system and the specific use.
Companies will typically have one or more of the following four roles under the AI Act:
Provider: a person, company, public authority, etc. that develops, or has developed, an AI system or a general-purpose AI model and places it on the market or puts an AI system into service under its own name or trademark.
Deployer: a person, company, public authority, etc. that uses an AI system within its own organisation or in the exercise of public authority, unless the AI system is used in the course of a personal non-professional activity.
Importer: a person or company located or established in the EU that places on the market an AI system from a third country.
Distributor: a person or company in the supply chain, other than the provider or the importer, that makes an AI system available on the market.
Please note: The transparency obligations under Article 50 of the AI Act apply only to providers and deployers. Importers and distributors are subject to other obligations under the AI Act.
Gennemsigtighedskravene i artikel 50 indeholder forskellige gennemsigtighedsforpligtelser for udbydere og idriftsættere af bestemte AI-systemer.
The transparency requirements in Article 50 contain various transparency obligations for providers and deployers of certain AI systems.
Depending on the specific use of the AI system, deployers may be subject to the following transparency obligations:
Emotion recognition and biometric categorisation: Natural persons exposed to an emotion recognition system or a biometric categorisation system must be informed of the operation of the system. Any personal data must also be processed in accordance with applicable data protection rules.
Deep fakes: If an AI system is used to generate or manipulate image, audio or video content constituting a deep fake, it must be disclosed that the content has been artificially generated or manipulated. For content that forms part of an evidently artistic, creative, satirical or fictional work or programme, the disclosure may be made in a way that does not hamper the display or enjoyment of the work.
Deep fake means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to be authentic or truthful.
Text on matters of public interest: If AI systems are used to generate or manipulate text that is published for the purpose of informing the public on matters of public interest, it must be disclosed that the text has been artificially generated or manipulated. However, the disclosure obligation does not apply where the content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.
The European Commission has published a set of icons that deployers may choose to use to disclose certain forms of AI-generated or AI-manipulated content. You can read more about this here.
Depending on the specific use of the AI system, providers may be subject to the following transparency obligations:
AI systems intended to interact directly with natural persons: The system must be designed and developed in such a way that natural persons are informed that they are interacting with an AI system. This information may be omitted where this is obvious from the point of view of a reasonably well-informed, observant and circumspect natural person, taking into account the circumstances and the context of use.
Marking of synthetic content: AI systems that generate synthetic audio, image, video or text content must be designed so that their outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. However, the requirement for machine-readable marking does not apply where the AI system performs an assistive function for standard editing or does not substantially alter the input data provided by the deployer or the semantics thereof.
Requirements for technical marking: The technical solutions for marking and detection must be effective, interoperable, robust and reliable, as far as this is technically feasible. Account may be taken, among other things, of the specificities and limitations of the various types of content, the costs of implementation and the generally acknowledged state of the art.
The individual transparency obligations also contain specific exceptions for AI systems or uses authorised by law for the purpose of detecting, preventing, investigating or prosecuting criminal offences.
Companies that are providers or deployers of AI systems should:
Map the company’s AI systems: Establish an overview of the AI systems that the company develops or uses, and determine the company’s role in relation to each system.
Identify relevant uses: Assess whether the systems interact directly with natural persons or are used for emotion recognition, biometric categorisation or the generation of deep fakes or other AI-generated content.
Clarify marking and disclosure requirements: Assess whether the supplier’s solution supports the required machine-readable marking, and determine how and when affected persons must be informed.
Establish editorial processes: Document human review and editorial responsibility for AI-generated texts that are published on matters of public interest.
Update internal policies: Incorporate the transparency requirements into the company’s AI policies and broader compliance work, including in relation to data protection and information security.
The AI Act becomes applicable in stages. The key dates are:
Rules already applicable
2 February 2025: The requirement concerning sufficient AI literacy and the prohibitions of certain forms of unacceptable AI practices have applied since this date.
2 August 2025: The rules on general-purpose AI models have applied since this date.
New rules from 2 August 2026
The transparency requirements in Article 50: The requirements described above generally become applicable from 2 August 2026.
Transitional rule: For AI systems that were placed on the market before 2 August 2026, the requirement for machine-readable marking under Article 50(2) will, however, only become applicable from 2 December 2026.
Upcoming rules
2 December 2027: The requirements for stand-alone high-risk AI systems covered by Annex III become applicable.
2 August 2028: The requirements for high-risk AI systems integrated into products covered by the sector-specific product legislation in Annex I become applicable.
For further advice on the AI Act and your company’s compliance, please contact CO:PLAY.