EU AI Act – transparency obligations take affect
A significant milestone for AI regulation in Europe
Most of the general provisions under the EU AI Act took effect on 2nd August 2026, and this marks the date when enforcement of the law will begin to properly kick in. The key change is the commencement of transparency obligations under Article 50, which include clearly telling people when they’re interacting with an AI system.
AI transparency requirements
Differing transparency obligations apply depending on whether you’re acting as a provider or a deployer of an AI system. They apply regardless of whether the system is categorised as ‘high risk’ or not. To briefly summarise:
⏹ People must be told by providers when they’re directly interacting with the provider’s AI system, such as a chatbot or AI agent. Where AI systems generate or manipulate audio, images, video or text, providers are also obliged to make sure outputs are marked in a machine-readable format and can be detected as AI-generated.
AI providers are the companies which develop, build and train the AI system and launch the technology under their own brand.
⏹ Deployers of emotion recognition and biometric categorisation systems must inform affected individuals when those systems are in use They must also disclose the artificial origin of any AI manipulated content constituting a deep fake.
AI deployers are organisations which use an AI system for work or business purposes, but did not actually develop, build and train the AI system itself. For example, you use Microsoft’s Co-Pilot in the workplace. In other words, you are responsible for deciding how and for what purposes the AI system is used for, but do not have technical control over it.
Necessary transparency information must be provided at the time of a user’s first interaction or exposure to the AI system, and this must be given in a clear and obvious way.
Of course, it’s a little more convoluted than this, and the European Commission has published reams of detail on how to comply in its Transparency Guidelines for Providers and Deployers of AI systems and its corresponding Code of Practice on Transparency of AI-Generated Content.
Territorial scope
Like GDPR, the AI Act has extra-territorial scope, meaning it applies to organisations based outside the EU (as well as inside) where they place AI products on the market or deploy them in the EU, and/or where outputs produced by AI applications are used by people within the EU.
What’s next?
While 2nd August is an important milestone, it’s not the whole story, with further obligations under the AI Act set to continue rolling out over next two years. For example;
⏹ December 2026 – the prohibition of non-consensual intimate material and child sexual abuse material takes effect.
⏹ August 2027 – all members states will be required to have at least on national AI regulatory sandbox in operation.
⏹ December 2027 – requirements for stand-alone high-risk AI systems which meet specific use cases take effect.
What about AI in the UK?
To date the UK has resisted calls for it to follow the EU’s lead. The Government’s approach is described as ‘pro-innovation’ with a sector-specific framework relying on existing regulators, such as the ICO. It’s interesting AI has been singled out, with the new Prime Minister, Andy Burnham appointing the UK’s first cabinet-level Minister for AI and launching an ‘AI Taskforce’.
There are plenty in the UK demanding a stricter EU-style regulation, but in equal measure are those urging a balanced approach with doesn’t hold back innovation and drive tech developers overseas.
It’s fair to say there are those within the EU proud to have the world’s first comprehensive AI regulation; proud to be seen as putting the safety and protection of citizens first. But this approach is not without its critics who fear it will leave Europe languishing behind the rest of the world for AI innovation.