Background
The EU Artificial Intelligence Act (“AI Act”), the first EU-wide and sector-neutral regulatory framework for artificial intelligence (“AI”), has been in force since August 2024, as previously reported. Its aim is to establish harmonised standards for AI products. Depending on the level of risk posed by an AI application, the AI Act provides for obligations of varying intensity, ranging from transparency and labelling requirements to risk management and information duties, as well as prohibitions on certain AI practices.
The provisions of the AI Act are becoming applicable in stages. The first rules, including the obligation to ensure a sufficient level of AI literacy under Article 4 and the prohibition of certain AI practices under Article 5, have applied since 2 February 2025. Further provisions followed in August 2025, including obligations for providers of general-purpose AI models, such as large language models like GPT and LLaMA.
New transparency rules from 2 August 2026
The next major wave of requirements will apply from 2 August 2026 and will primarily concern the transparency obligations set out in Article 50 of the AI Act.
These obligations apply both to providers—that is, organisations that develop an AI system, or have one developed, and place it on the market or put it into service under their own name or trademark and to deployers, meaning organisations that use an AI system under their own responsibility for professional purposes.
From that date, companies, associations and public authorities will need to comply with the following requirements:
Interaction with AI Systems
Where an AI system is intended to interact directly with individuals, the provider must ensure that the persons concerned are informed that they are interacting with an AI system.
Chat interfaces must therefore include a notice making clear that users are not communicating with a real person, but with an AI application. This obligation does not apply where the use of AI is obvious from the circumstances or where the system is used for law-enforcement purposes.
Emotion recognition and biometric categorisation
Deployers of emotion recognition systems—that is, systems that infer a person’s emotions or intentions on the basis of biometric data—or biometric categorisation systems must inform the individuals concerned that the system is being used.
This may apply, for example, to systems used in customer service to infer customer satisfaction from service calls.
Deepfakes
So-called deepfakes will also be subject to disclosure requirements. Deepfakes are artificially generated or manipulated images, audio or video content that resemble real persons, objects, places or events so closely that they may be mistaken for authentic content.
The disclosure obligation applies to the deployer. For example, where an association creates an advertising poster featuring realistic-looking, AI-generated persons, the content will have to be clearly identified as AI-generated.
The European Commission has published symbols on its website that may be used for this purpose.
Exception: In the case of artistic works, disclosure may be limited to indicating the existence of AI-generated or manipulated content in a manner that does not interfere with the enjoyment of the work. The obligation does not apply where the content is used for law-enforcement purposes.
Texts intended to inform the public
Synthetically generated texts published for the purpose of informing the public about matters of public interest must likewise be disclosed as AI-generated by the deployer.
This obligation does not apply where the text has undergone human review before publication and where a natural or legal person assumes editorial responsibility for it. An exception also applies to texts used for law-enforcement purposes.
Household exemption
Persons who create deepfakes or similar content exclusively for personal and non-professional purposes are not considered deployers within the meaning of the AI Act and are therefore not subject to these obligations.
An AI-generated Christmas card sent to family members, for example, does not have to be labelled.
Please note: Disclosure does not in itself establish that the content is lawful. Civil law, including section 78 of the Austrian Copyright Act and section 16 of the Austrian Civil Code, as well as criminal law, must still be observed.
In addition, non-consensual sexualised deepfakes will fall within the prohibited AI practices under Article 5 of the AI Act from 2 December 2026.
Further obligations and commission guidelines
A further obligation, which will apply from 2 December 2026, requires providers to ensure that AI-generated outputs are marked in a machine-readable format.
This may be achieved through measures such as watermarks, cryptographic methods, metadata-based identification or digital fingerprints.
In July 2025, major providers of widely used AI models signed a Code of Practice that includes a chapter on transparency and provides guidance on how providers may comply with these obligations.
In addition, on 10 June 2026, the European Commission published a Code of Practice on the labelling of AI-generated content. It is addressed to both providers and deployers and is intended to support compliance with Article 50 of the AI Act.
We strongly recommend addressing these obligations now in order to ensure timely compliance.