Policy

The EU’s New AI Transparency Rules Are Live. Every Chatbot and Deepfake in Europe Now Needs a Label.

5 min read

The European Union’s AI Act transparency obligations under Article 50 took effect on August 2, 2026, meaning every company offering an AI chatbot, voice assistant, or content-generation tool to users in the EU is now legally required to disclose when someone is interacting with, or looking at content produced by, artificial intelligence. The rules had been on the books since the AI Act’s original passage, but this is the date the European Commission set for actual enforcement to begin — and regulators moved quickly this year to publish detailed practical guidance clarifying exactly what compliance looks like, after companies spent much of the first half of 2026 asking for specifics.

The obligations break down into four distinct categories. First, any AI system designed to interact directly with people — chatbots, voice agents, AI avatars — must make clear to users that they’re talking to a machine, not a human, generally at the start of the interaction. Second, AI-generated audio, image, video, or text content must carry a machine-readable mark identifying it as artificially generated or manipulated, intended to let platforms and detection tools identify AI content even when a human viewer can’t. Third, systems that perform emotion recognition or biometric categorization — reading a user’s mood or sorting people into categories based on physical or behavioral characteristics — must inform the people being analyzed that this is happening. Fourth, and most consequential for how the rules will actually be felt day to day: deepfakes, and AI-generated text published to inform the public on matters of public interest, need a visible or audible label a person can actually understand without needing a separate detection tool — a hidden watermark alone doesn’t satisfy this requirement.

The Deepfake Rule Applies Even Without Any Intent to Deceive

The detail catching the most attention from compliance lawyers is that the deepfake labeling requirement is not conditioned on intent. Content that looks or sounds like a real, identifiable person has to be labeled as AI-generated even if nobody involved meant to deceive anyone, and even in cases where the depicted person doesn’t exist at all. That’s a meaningfully broader standard than most existing deepfake laws elsewhere in the world, which typically only kick in when there’s demonstrated intent to mislead or cause harm. Penalties for non-compliance reach €15 million or 3% of a company’s worldwide annual turnover, whichever is higher — the same tier of financial exposure the AI Act uses for its more serious violations, not a symbolic slap on the wrist.

Enforcement itself sits with national market surveillance authorities in each EU member state, coordinated by the European AI Office to keep interpretation consistent across the bloc. Companies didn’t get much lead time to prepare for specifics: the European Commission only published its own draft interpretive guidelines on Article 50 on May 8, 2026, opening a short consultation window that closed June 3, 2026 — meaning a worked-through definition of what counts as an adequate AI disclosure existed in anything close to final form for less than three months before enforcement actually began. The guidelines are formally non-binding, but national regulators and the AI Office are expected to follow them closely, with any authority choosing to diverge from the Commission’s interpretation expected to justify why.

It’s worth noting what didn’t take effect on this date. The AI Act’s rules for genuinely “high-risk” AI systems — things like AI used in hiring, credit scoring, or critical infrastructure — were pushed back separately: standalone high-risk systems now have until December 2, 2027, and high-risk AI embedded inside other products until August 2, 2028. Only the transparency obligations under Article 50 are live as of this month. That distinction matters, because it means a much broader set of ordinary AI products — any customer service chatbot, any AI writing assistant, any social app with an AI-image filter — is now squarely in scope, well before the heavier high-risk machinery of the law ever kicks in.

What This Means for Philippine Founders

Very few Philippine startups are headquartered in the EU, but a meaningful number sell software, run marketing, or serve users there — and the AI Act, like GDPR before it, applies based on where your users are, not where your company is registered. Any Philippine-built product with an AI chatbot, an AI customer-support widget, or an AI content-generation feature that has even a modest EU user base is now technically in scope for the disclosure requirements under Article 50, whether or not the founding team has ever thought about EU compliance at all. The practical bar for most startups is genuinely low — a visible “You’re chatting with an AI assistant” notice, or a clear label on AI-generated images and video, satisfies the core requirement — but it’s a real, dated legal obligation now, not a best practice to get to eventually. For founders building AI tools aimed at global markets from day one, this is also a useful preview of where transparency expectations are heading more broadly: labeling AI interactions and AI-generated content is quickly becoming baseline product hygiene that investors and enterprise customers outside the EU will start expecting too, not a Europe-only compliance cost to isolate and ignore.

Deepfakes EU AI Act Europe Policy Regulation Transparency

Share this article

Share on X Share on LinkedIn Share on Facebook

Related Articles

Newsletter

By subscribing, you agree to our Privacy Policy.