The EU AI Act transparency rules began to apply on 2 August 2026, and a great deal of the coverage explaining them is wrong. Some articles tell readers that the Act’s demanding high-risk obligations landed on that date. They did not — those were pushed back by more than a year. Others concluded that the deferral meant nothing happened at all. That is also wrong.

Something specific and enforceable did take effect. If your business runs a customer-facing chatbot, publishes AI-generated images or text, uses emotion-recognition software, or produces synthetic media, you are likely in scope right now.

This article sets out exactly what applied, who it applies to, what was delayed, what the penalties are, and the one deadline still ahead of you. It is written for the people who have to act on this, not for lawyers. It is not legal advice — see the note at the end.

What are the EU AI Act transparency rules?

The EU AI Act transparency rules are the disclosure obligations set out in Article 50 of the Artificial Intelligence Act, Regulation (EU) 2024/1689. They require that people be told when they are interacting with AI, when certain AI systems are being used on them, and when content has been artificially generated or manipulated.

The central point to understand is this: these obligations are not limited to high-risk AI systems. They attach to four specific situations regardless of how the underlying system is classified. An ordinary customer-service chatbot is nowhere near the Act’s high-risk category, and it is still covered.

The rules also reach beyond Europe’s borders. The Act applies to providers, deployers, importers and distributors that place AI systems on the EU market, or whose AI outputs are used within the European Union. A company with no EU office can still be in scope.

The 4 obligations that applied from 2 August 2026

Article 50 splits its duties between providers — those who develop an AI system and place it on the market — and deployers, meaning organisations that use an AI system under their own authority.

SituationWho is responsibleWhat is required
1. AI systems that interact directly with people
Chatbots, voice assistants, AI agents
ProviderTell users they are dealing with an AI system, unless it is already obvious to a reasonably observant person
2. Generative AI output
Synthetic audio, images, video or text
ProviderMark outputs in a machine-readable format so they are detectable as AI-generated
3. Emotion recognition and biometric categorisationDeployerInform the people exposed to the system that it is being used
4. Deepfakes and AI-generated public-interest textDeployerDisclose that the content has been artificially generated or manipulated

The European Commission adopted formal guidelines on these obligations on 20 July 2026, and the AI Office published a voluntary Code of Practice on transparency of AI-generated content, which gives providers a recognised route to demonstrate compliance with the marking requirement.

The one deadline still ahead: 2 December 2026

A limited four-month transition applies, and it is narrower than most summaries suggest.

It covers only the provider-side machine-readable marking and detection duty under Article 50(2), and only for generative AI systems that were already placed on the EEA market before 2 August 2026. Those providers have until 2 December 2026 to comply.

Everything else applied immediately. Systems placed on the market on or after 2 August must meet the marking requirement from the outset. The deployer-side duties covering emotion recognition, biometric categorisation, deepfakes and public-interest text have been in force since 2 August with no grace period at all.

One practical relief worth knowing: according to the Commission’s own guidance, content generated before 2 August 2026 does not need to be labelled retroactively, though the Commission encourages it where possible.

What was delayed — and why the confusion happened

This is where most competing articles go wrong.

The AI Act’s substantial high-risk obligations — the conformity assessments, risk management systems and documentation requirements in Chapter III — were not switched on in August 2026. Under the Digital Omnibus, adopted as Regulation (EU) 2026/1744, they were deferred to 2 December 2027 for stand-alone high-risk systems listed in Annex III, and 2 August 2028 for high-risk AI embedded in regulated products under Annex I.

Article 50 was deliberately left out of that deferral. Its transparency duties applied on the original schedule.

So the accurate summary is narrow and specific: transparency obligations arrived on time; high-risk obligations slipped by more than a year. Any article that collapses those two into a single answer is misleading you in one direction or the other.

TechyKnow analysis: The deferral is easy to read as the EU softening its position. We would read it differently. Transparency duties are cheap to comply with and highly visible to the public; high-risk conformity assessment is expensive and depends on technical standards that were not ready. Deferring the second while keeping the first is what a regulator does when it wants demonstrable progress without an unenforceable deadline. This is sequencing, not retreat.

What else changed on that date

2 August 2026 was an enforcement hinge as much as a transparency deadline. The Commission’s AI Office, working with national authorities, began enforcing the Act — including in relation to providers of general-purpose AI models.

It helps to see the full sequence, because the Act did not switch on all at once:

  • 2 February 2025 — the Article 5 prohibitions on unacceptable-risk practices began to apply
  • 2 August 2025 — obligations for providers of general-purpose AI models began to apply
  • 2 August 2026 — Article 50 transparency duties applied; enforcement powers became active, including the Commission’s power to investigate and fine general-purpose AI model providers
  • 2 December 2026 — transition ends for machine-readable marking on pre-existing generative systems
  • 2 December 2027 — Annex III high-risk obligations apply
  • 2 August 2028 — Annex I high-risk product-route obligations apply
EU AI Act transparency rules illustrated by a tablet interface in a European institutional setting

Who enforces this, and what are the fines?

Enforcement sits mainly with national market surveillance authorities in each member state, not with Brussels. That is a meaningful practical detail: the body that comes asking questions will usually be a domestic regulator.

The AI Office has a deliberately limited role here. It is competent for AI systems built on general-purpose AI models where the same entity provides both the model and the system, or where the system is integrated into a very large online platform or search engine designated under the Digital Services Act. The European Data Protection Supervisor enforces the rules against EU institutions and bodies.

Breaching the transparency obligations can attract a fine of up to €15 million or 3% of total worldwide annual turnover, whichever is higher.

Those figures deserve context rather than alarm. Maximum penalties are ceilings for serious, sustained breaches, not opening offers for a missing chatbot disclosure. But the turnover-based component means the exposure scales with company size rather than with the size of the AI deployment.

Does this apply to my business?

Work through these questions honestly.

  1. Do you operate a chatbot, voice assistant or AI agent that people interact with directly? If a user might not realise they are talking to software, you owe them a disclosure.
  2. Do you publish AI-generated or AI-edited images, audio, video or text? Deepfake and synthetic-media disclosure duties apply to deployers now.
  3. Do you use emotion recognition or biometric categorisation anywhere? Recruitment screening and customer analytics tools sometimes include these features without advertising them clearly. Check your vendor documentation.
  4. Do you build and distribute a generative AI system? Then the machine-readable marking obligation is yours, with the December deadline if your system predates August 2026.
  5. Do EU residents use your product, even if you are based elsewhere? Territorial scope follows the market and the output, not your registered address.

If you answered yes to any of these, the sensible next step is not a compliance programme. It is a short inventory: list every AI system your organisation provides or uses, note which of the four Article 50 situations it touches, and record who is responsible for the disclosure. Most organisations discover the gap is a handful of missing sentences in a user interface rather than an engineering project.

Practical steps that cost almost nothing

  • Add a visible AI disclosure to every chatbot entry point. A single line before the first message satisfies the interaction duty in most cases.
  • Label AI-generated media at the point of publication. Build it into your publishing checklist rather than retrofitting later.
  • Ask your AI vendors, in writing, whether their systems apply machine-readable marking. If you are a deployer, their compliance directly affects yours.
  • Audit tools you did not think of as AI. Analytics platforms, recruitment software and customer-experience tools frequently include emotion or biometric features.
  • Keep a dated record of what you changed and when. Demonstrating good-faith compliance is considerably easier with a paper trail.

The organisations most exposed here are not the ones building sophisticated AI. They are the ones who quietly added a chatbot to their website eighteen months ago and never thought about it again.

The bottom line

The EU AI Act transparency rules are the part of the Act most businesses will actually encounter, and they are already live. They are also, by the standards of EU technology regulation, unusually cheap to comply with — the core requirement is telling people the truth about what they are dealing with.

The high-risk obligations that generated most of the anxiety are now a 2027 and 2028 problem. That is genuine breathing room for the companies building serious AI systems. It is not breathing room for anyone running a chatbot, because that deadline has already passed.

Check your inventory. The fix is usually a sentence.

This article explains publicly available regulatory information and is not legal advice. Obligations depend on your specific systems and role under the Act. Consult a qualified adviser before making compliance decisions.

FAQs

What are the EU AI Act transparency rules? They are the disclosure obligations in Article 50 of Regulation (EU) 2024/1689, requiring that people be told when they are interacting with AI, when emotion-recognition or biometric-categorisation systems are used on them, and when content has been generated or manipulated by AI. They applied from 2 August 2026.

Do the transparency rules only apply to high-risk AI? No. They apply to any AI system used in the four situations Article 50 covers, regardless of risk classification. An ordinary customer-service chatbot is in scope.

Were the EU AI Act high-risk rules delayed? Yes. Under the Digital Omnibus, Regulation (EU) 2026/1744, high-risk obligations were deferred to 2 December 2027 for Annex III stand-alone systems and 2 August 2028 for Annex I product-route systems. Article 50 was not part of that deferral.

Do I need to label AI content published before August 2026? No. The Commission’s guidance states that content generated before 2 August 2026 does not need to be labelled retroactively, although the Commission encourages it where practical.

What is the 2 December 2026 deadline? It is the end of a four-month transition covering only the provider-side machine-readable marking obligation under Article 50(2), and only for generative AI systems already on the EEA market before 2 August 2026.

What are the fines for breaching the transparency rules? Up to €15 million or 3% of total worldwide annual turnover, whichever is higher.

Does the EU AI Act apply to companies outside the EU? It can. The Act applies to providers, deployers, importers and distributors placing AI systems on the EU market, or whose AI outputs are used within the European Union.

Who enforces the transparency obligations? Mainly national market surveillance authorities in each member state. The AI Office has a limited role, and the European Data Protection Supervisor covers EU institutions and bodies.