If you run anything that talks to customers with a model behind it, the rules changed on Sunday and most people did not notice. The transparency obligations in the EU's AI Act came into effect on August 2nd, 2026. The Verge reported it the next day, and the European Commission even published a set of ready-made AI icons so companies do not have to invent their own badge for "a machine wrote this."

I want to be careful here, because AI regulation coverage usually swings between "nothing burger" and "the sky is falling," and neither is true. So here is what the text actually says, what it means for a small operation, and what nobody can answer yet.

What the rules require

There are four obligations in Article 50, and they split between two kinds of company. Providers are the ones who build and sell the AI system. Deployers are the ones who use it in their product or service. Some companies, Meta for example, are both, which is where a lot of the confusion is going to come from.

Providers have to do two things. First, if an AI system is meant to interact directly with a person, it has to be designed so the person is told they are talking to an AI — unless, in the language of the law, "this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect." Second, if the system generates synthetic audio, image, video, or text, the output has to be marked in a machine-readable format and detectable as artificially generated or manipulated. That is watermarking and provenance metadata, in plain terms, and the text says the solution has to be "effective, interoperable, robust and reliable as far as this is technically feasible."

Deployers get the other two. If you deploy emotion recognition or biometric categorisation, you have to tell people it is running. And if you publish a deepfake — image, audio, or video made or altered to look real — you have to disclose that it was artificially generated.

All of this has to be told to the person clearly, at the latest at the time of first interaction. Not buried in a settings menu three taps deep.

Verdict: if your product speaks in a human voice or ships synthetic media into the EU, you now owe a disclosure.

The carve-outs matter more than the rules

This is the part the headlines skip. Article 50 is full of exceptions, and they are load-bearing.

Artistic, creative, satirical, or fictional work only has to disclose the existence of the generated content "in an appropriate manner that does not hamper the display or enjoyment of the work." So a film using a de-aged actor does not have to slap a warning across the frame.

AI-generated text published to inform the public on matters of public interest has to be disclosed — but not if it went through human review and a real person or company holds editorial responsibility for it. Read that twice if you publish anything. An editor in the loop takes you out of the text-labeling obligation.

Law enforcement uses are exempt across the board. And the marking obligation does not apply where the AI is doing "standard editing" that does not substantially alter the input or its meaning, which is a genuinely fuzzy line. Is generative fill on a background standard editing? I do not know, and I have not seen anyone who does.

Verdict: the exemptions are wide enough that a lot of real-world use is out of scope, and nobody has litigated where the edges are.

What this means if you are small

Most people reading this are not Meta. You have a website, maybe a support chatbot, maybe you generate images for posts. Three practical things.

If you run a chatbot that serves EU visitors, put a plain line at the top of the widget saying it is an AI assistant. That is cheap and it removes the whole question. Being coy about whether the bot is a person was never a good look anyway.

If you publish AI-generated images or video that a reader could reasonably mistake for a photograph, label it. Not in the alt text where nobody looks — in the caption. We do this on this site: if a hero image is machine-made, the alt text says what it is. It is also just honest, which is the same reason I wrote up the Billboard chart story the way I did instead of asserting something I could not prove.

If you use AI to draft written content, keep a human editor who owns the published result. That is both the exemption and the reason your writing does not read like everyone else's. The LinkedIn AI slop button exists because platforms already know unedited machine text is a problem.

Verdict: for a small operator this is a disclosure task, not an engineering project.

What is not settled

The machine-readable marking requirement is the weak point, and I say that as someone who wants provenance to work. Watermarking synthetic text is not a solved problem. Paraphrase it, run it through a second model, or just retype it, and the mark is gone. Image and audio provenance via C2PA-style metadata is further along, but metadata gets stripped every time a file passes through a platform that re-encodes it, which is most of them. The law's own language — "as far as this is technically feasible" — is an acknowledgement that the tech is not there yet.

Enforcement is the other open question. The Verge notes companies could face fines for missing the requirements, and the AI Act's penalty structure is real money for the biggest firms. But an obligation that came into force yesterday with no enforcement actions behind it tells you nothing about how aggressive regulators will actually be. Anyone telling you today how this gets enforced is guessing.

The EU's icon set is optional, not mandated. If enough companies adopt it, labels start looking consistent across platforms, which is the actual point — a label only works if people recognize it. If adoption is patchy, we get twenty different badges and the whole thing becomes noise.

The honest read

I like this rule more than most AI regulation, because it does not try to decide which models are allowed to exist. It says: tell people. That is a standard we already apply to advertising, to food, to financial products. Telling someone a machine is on the other end of the conversation is not a burden, it is a baseline.

Where I am skeptical is the enforcement gap between the small stuff and the big stuff. Labeling a chatbot is trivial. Making synthetic-content marks that survive contact with the real internet is not, and the companies best equipped to do it are also the ones with the most lawyers.

If you serve EU users: disclose the bot, caption the synthetic media, keep a human on the byline. That is most of your compliance, and it takes an afternoon. If you want the deeper compliance work, the process I use for tracing where AI actually touches your stack is in how to audit AI supply chain compliance, and the broader regulatory backdrop is in the EU and US incident-disclosure briefing.

All gravy. Just say it is a robot.

Sources: The Verge — Europe's AI labeling and transparency rules are now in effect · EU AI Act, Article 50: Transparency Obligations