EU AI Act Is Now Live: Chatbots Must Disclose They're AI
| |

The EU AI Act Is Now Live: Chatbots Must Say They’re AI and Deepfakes Need Labels

Last Saturday, August 2, the European Union’s (EU) AI Act transparency rules officially came into force. From August 2, new transparency rules started to apply, requiring certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it.

This is the world’s first binding AI transparency law. And because it applies to any company serving EU users — not just EU-based ones — American, Asian, and global tech companies are all affected. Here’s what the rules actually say, what they mean in practice, and what still has more time to roll out.

What’s Required Right Now

Three things are mandatory as of August 2.

Chatbots must disclose they are AI. Chatbots must disclose they are AI, and AI-generated images, audio, video, and text must be marked. That means any AI assistant, customer service bot, or virtual agent interacting with users in the EU must make clear — upfront, in plain language — that the user is talking to a machine, not a person. The disclosure can’t be buried in terms and conditions. It has to be in the interaction itself.

Deepfakes must be labelled. Deepfakes — with certain concessions for personal, artistic, satirical and fictional use — must begin with a disclaimer stating in plain and simple natural language that the content is AI-generated. A photorealistic video of a public figure saying something they never said can no longer simply appear in a news feed without disclosure. Audio deepfakes must carry an audible warning. Visual deepfakes need an on-screen label.

Emotion recognition and biometric systems must inform people. Deployers of emotion recognition or biometric categorisation systems must inform exposed individuals. If you walk into a shop using AI to read your emotional state, or a venue scanning faces, the law now requires disclosure.

What’s Still Coming

Not everything arrived at once. Rules for high-risk AI systems embedded in regulated products have been pushed back to August 2028. High-risk use cases in sensitive areas including recruitment, credit scoring, and law enforcement now face a deadline of December 2027.

That means the AI making lending decisions, screening job applications, or helping police identify suspects gets more time. The systems most likely to affect people’s jobs, finances, or interactions with the state have more time to comply, while everyday consumer-facing tools face the rules now.

There’s also a grace period on machine-readable watermarking. The disclosure duty for chatbots and deepfakes applies now, while the machine-readable marking of AI-generated content has a grace period until December 2026 for tools already on the market before August 2. The invisible technical markers that let platforms automatically detect AI-generated content are still being standardised — the law is ahead of the technology in places.

Who Has to Comply

The rules reach any provider or deployer serving EU users, so many US companies must comply. The US has no equivalent federal law yet.

That’s a significant reach. If your chatbot, your AI writing tool, or your deepfake video generator is used by anyone in the EU, you fall within scope. The regulation distinguishes between providers — companies that build the AI systems — and deployers — companies that use those systems in their own products. Both carry obligations.

Penalties can reach 15 million euros — about $16 million — or 3% of worldwide annual revenue, whichever is higher. For large tech companies, that’s a number that concentrates minds considerably.

What This Looks Like in Practice

For most people using AI tools in the EU, the visible changes will be gradual. You’ll start seeing more explicit “You are talking to an AI” messages at the start of chat interactions. AI-generated images will carry labels — though the invisible machine-readable watermarks are the more important mechanism for detection at scale, and those are still being rolled out.

That makes sense in a field where last year’s cutting-edge watermark can quickly become this year’s easily defeated parlour trick. It also gives industry room to develop standards rather than locking in a single approach that might become obsolete quickly.

The practical effect on disinformation is the open question. Labels help — but they require enforcement, and enforcement requires detection. The AI Office, working with national authorities, now has the power to act. How aggressively they pursue non-compliant companies — particularly large US platforms — will define whether these rules have teeth or stay on paper. For a practical guide to spotting AI-generated content yourself, see our evergreen guide on how to identify AI-generated content online.

The Bottom Line

The EU AI Act’s transparency chapter is now law, and unlike many regulatory frameworks, it has a credible enforcement body behind it from day one. Chatbots that pretend to be human, deepfakes that circulate without disclosure, and AI systems that scan your face or emotions without telling you are all now operating outside the law in the EU.

The harder rules, the ones covering AI in hiring, lending, and law enforcement — are still coming. But the foundation is in place. And for any company building AI products that reach European users, ignoring it is no longer an option.

Read more tech related articles here.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *