Final Guidelines Published for EU AI Act Transparency Requirements
On 28 July 2026
The European Commission has published guidelines on transparency obligations for AI providers (and deployers), ahead of new rules that start to roll out on 2 August 2026.
This will be relevant to any UK business that uses AI where the output ends up in the EU (intentionally or not).
The Scope of Article 50 of the EU AI Act
The transparency requirements are likely to be the most far-reaching obligation, due to the popularity of online chatbots and generative AI products, like ChatGPT.
From August, people in the EU will have to be informed when they are interacting with AI systems or exposed to certain AI-generated content. Article 50 of the EU AI Act introduces transparency obligations in four situations:
1. When AI interacts directly with people.
· When an AI system is intended to interact directly with people (such as chatbots or virtual assistants) its provider must design it so that users are informed they are interacting with AI.
· This does not apply where it is obvious to an individual who is “reasonably well informed, observant and circumspect”.
2. When AI generates synthetic content.
· Providers of AI systems that generate synthetic audio, image, video or text must ensure that outputs are labelled as artificially generated or manipulated.
· The Act requires providers to ensure that their technical solutions for achieving this are as effective, robust and reliable as possible.
· This does not apply where the AI system only helps with editing and does not substantially alter the input data (for example a standard video editor that uses AI as an assistive function).
3. When AI is used for biometric categorisation or emotion recognition.
· Deployers of an emotion recognition or biometric classification system must inform individuals that they are subject to its use. Personal data must also be processed in compliance with relevant data protection law.
· Emotional recognition systems are banned in the workplace or educational institutions under Article 5 of the EU AI Act but outside of those settings they are generally permitted, and these disclosure obligations apply.
4. When AI creates deepfakes or text published on matters of public interest.
· Deployers of an AI system that generates or manipulates image, audio or video content which is a deepfake* must disclose that the content has been artificially produced.
· This is relaxed when the content is obviously “artistic, creative, satirical or fictional”. In this situation, deployers still need to disclose, but they can do so in a manner that does not “hamper the display or enjoyment of the work”.
· Deployers of an AI system that generates text which is published with the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated.
· There is an exemption where the generated text has undergone review by an individual and that individual holds editorial responsibility for the publication.
In all four situations, there is an exception for AI systems authorised by law to detect, prevent, investigate and prosecute criminal offences.
The Code of Practice on Transparency of AI-Generated Content
The European Commission has also published a code of practice to support compliance with Article 50. It’s split into two sections:
1. Applies to providers and sets out rules for the marking and detection of AI generated and manipulated content.
2. Explains how deployers must label deepfakes and AI generated published text.
While the code of practice is voluntary, organisations that comply with it will be well positioned to demonstrate Article 50 compliance. It includes placement specifications and guidance on imperceptible watermarking.
The EU has also created a set of icons that deployers of generative AI systems may use to label their AI-generated content.
What next?
Providers – developers of AI systems
· For systems that interact directly with people, ensure clear AI disclosure at the time of first interaction, in a manner that meets accessibility requirements.
· For generative AI systems, implement machine-readable markings of all outputs (this is aimed at enabling AI detection tools to verify whether content is AI-generated). Section 1 of the code of practice provides machine-readable marking techniques.
Deployers – users of AI systems
· For emotion recognition or biometric categorisation, design notice mechanisms that inform exposed individuals clearly.
· For deepfake systems, map all content that may meet the deepfake definition* and design appropriate disclosure.
· For published text, either implement disclosure or establish a process for human review and editorial responsibility to rely on the exemption.
Get in Touch
If you would like to know more about the EU AI Act and how it may apply to your business, please get in touch at ian.grimley@roxburghmilkins.com.
* The EU AI Act defines a deepfake as “AI generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”