I. Scope: providers and deployers of AI systems
From 2 August 2026, the transparency obligations provided in Article 50 of Regulation (EU) 2024/1689 (hereinafter the “AI Act”[1]), imposed on both providers and deployers of artificial intelligence systems (“AI systems”), will apply directly in all Member States of the European Union (“EU”).
1. Who qualifies as a provider of an AI system and what transparency obligations apply to them?
According to art. 3(3) of the AI Act, a provider of an AI system can be a natural or legal person, a public authority, an agency or another body that develops an AI system or that has an AI system developed and places it on the market or puts the AI system into service under its own name or trademark.
The AI Act also applies to providers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI systems is used in the EU.
For providers, the AI Act imposes two levels of transparency: (i) information regarding direct interaction with an AI system, and (ii) technical marking of synthetic content (watermarking).
2. Who qualifies as a deployer of an AI system and what transparency obligations apply to them?
According to art. 3(4) of the AI Act, a deployer is the one who uses an AI system under its authority, except for personal, non-professional use. For example, a deepfake created by a natural person for recreational purposes constitutes a personal activity and is excluded from the scope of the AI Act. However, where the same person generates deepfakes to obtain a regular economic benefit (e.g., as a freelancer), that person becomes a “deployer” and must comply with the applicable legal transparency obligations, such as content labelling.
For deployers, the AI Act adds the following transparency levels: (i) disclosure of deepfake materials (image, audio, video); (ii) information regarding biometric categorisation systems or emotion recognition systems; and (iii) marking of texts published on matters of public interest.
II. Direct interaction with AI: the golden rule of transparency and its exceptions
1. What are the criteria that trigger the information obligation?
Art. 50(1) of the AI Act establishes a fundamental rule: users need to know who they are talking to from the very first interaction. However, the information obligation applies only when four fundamental criteria clarified by the European Commission[2] are cumulatively met:
- The technology used must fall within the legal definition of an AI system: namely those machine-based systems designed to operate with varying levels of autonomy and adaptiveness, capable of inferring from the input received how to generate outputs, such as predictions, content, recommendations or decisions, which can have a direct impact on the physical or virtual environments.
- There is genuine bidirectional dialogue: the AI system is designed to engage in a genuine bidirectional dialogue with humans, going beyond mere background data processing or the provision of fixed responses.
- The interaction must have a direct character: the algorithm communicates directly with the user, without any filter or human intermediary.
- It exclusively targets interactions with natural persons: the interaction occurs with a natural person, regardless of whether that person acts as a consumer, employee, professional, or representative of a company.
2. When and how must the information be provided?
The information must be provided from the very beginning of the first interaction, in a clear, distinguishable, and easily accessible manner, ensuring that these requirements are also met in a manner that is accessible to persons with disabilities.
3. The exception to the rule: When is notification not required?
The provision of information is not mandatory where the interaction with an AI system is obvious from the context to a reasonably well-informed, observant and circumspect person. Nevertheless, the European Commission recommends a cautious approach, limiting this exception to unequivocal situations, such as when a chatbot is explicitly designated as "AI Assistant" or "Virtual Bot" in the chat window header.
III. From digital watermark to visible disclaimer: a Guide to the labelling of AI-generated content
With regard to synthetic content, the provisions of the AI Act draw a clear distinction between “background” technical marking obligations and direct information requirements. Each of these two levels implies a distinct spectrum of application, as will be analysed below.
1. Technical marking — the provider’s obligation regarding AI systems
Providers of generative AI systems (audio, image, video, or text) are required to design the systems' technical architecture so that the output is marked in a machine-readable format that attests to its synthetic origin. However, this requirement does not apply in the following cases:
- short sequences of numbers, symbols or source code;
- outputs intended exclusively for communication between systems (machine-to-machine) that are not visible to humans;
- testing environments, research and development (closed-loop) or intermediate processing stages in the entertainment/cinematography industry, with the exception of the finished product placed on the market.
The labelling obligation does not apply where AI systems merely perform an assistive function for standard editing (for example, spell-checking or minor optimisation of text/image), without substantially altering the input data or its semantics.
2. Visible labelling — the deployer’s obligation towards natural persons
Deployers of AI systems may not rely exclusively on the background technical marking (watermarking) performed by the provider, but must provide the following warnings/labels:
- Disclosure of deepfake content: Deepfake content must be disclosed to the natural persons exposed, at the latest upon first exposure, by means of a clearly visible or audible label, without requiring technical detection tools. For artistic, creative, satirical or fictional works, the obligation remains, but the disclosure must be done appropriately, without affecting the enjoyment of the work. For example, a movie featuring an AI-generated historical character may include the information at the beginning or at the end of the movie, without detracting from the viewing experience.
- Information regarding biometric categorisation system or emotion recognition system: Where an emotion recognition or biometric categorisation system is used, a simple notification informing the person that they are subject to such an AI system is both necessary and sufficient, irrespective of whether the analysis is carried out in real time or retrospectively. For example, a retail store using smart advertising displays equipped with cameras that categorise passers-by by gender and age (without identifying them) in order to display personalised advertisements must visibly inform individuals, before they enter the area covered by the system, by means of notices stating that an AI system for biometric categorisation is in operation for advertising purposes.
- Marking of text published on matters of public interest: AI-generated texts of public interest must be labelled if three conditions are cumulatively met: they are publicly available, serve an informational purpose, and address topics of public interest, with the exception of those that have undergone a process of human review or substantial editorial control. For example, fire prevention notices automatically generated by a public authority must be labelled as AI-generated when published without human verification.
3. The format of the disclaimer
For audio, video or image content intended for the public, the label must be visibly placed in the frame or provided as an audible disclosure before playback and must not be concealed in the Terms and Conditions (T&Cs) or in the metadata.
IV. The risk of requalification: when a deployer becomes a provider
A major risk under the AI Act is that a deployer may be requalified as a provider, thereby taking over all compliance responsibilities, including obtaining certifications, drafting complex technical documentation, conducting conformity testing, and registering in the EU database.
This transfer of liability takes place according to the AI Act in case the deployer:
- Affixes its own name or trademark to the AI system (white-labelling practice);
- Makes a substantial modification to the AI system (by changing the architecture, performance or technical functioning of the underlying model);
- Modifies the initial purpose (intended use) of the system as established by the provider, resulting in its classification in a higher risk category (for example, by transforming a simple technical support chatbot into a system that makes decisions with a significant impact on natural persons).
The modification of status from deployer to provider implies the entire burden of proving conformity for the company that has thus become a provider. To prevent such exposure, it is recommended that any project involving the adaptation, rebranding, or change in the intended use of AI systems undergo a prior impact assessment to determine the extent to which reclassification from deployer to provider is imminent or can be avoided.
V. Deepfake or marketing strategy? Where should the line be drawn in AI-generated campaigns?
Under Art. 50, the AI Act introduces transparency rules for deepfakes (AI-generated content that perfectly imitates reality). The AI Act requires providers to integrate technical marking solutions and deployers to publicly label the materials. The practical aspects were clarified by the European Commission on 20 July 2026 through the new Code of Practice on Transparency of AI-Generated Content (the "Code") [3]. The following sections explain how deepfakes are defined, how disclosure obligations are divided, what exceptions are permitted, and the risks of enforcement.
1. The notion of deep fake within the meaning of the AI Act
According to art. 3(60) of the AI Act, a deep fake is any AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. From a legal perspective, classifying a material in this category requires the cumulative fulfilment of three conditions:
- Significant resemblance – the content must resemble, to a relevant extent, an existing person, object, place, entity or event and be capable of creating the false impression that it is authentic or truthful (recital 134 of the AI Act);
- Realism – the AI Act does not require the content to reproduce a real, identifiable and verifiable event; it is sufficient for it to bear a sufficiently close resemblance to existing persons, objects, places, entities or events;
- Targeted categories – art. 3(60) limits the applicability of the notion of deepfake to five categories: persons, objects, places, entities, and events.
The definition of a deepfake is narrower than the general notion of AI-generated or AI-manipulated content: not every material created with the assistance of an AI system automatically falls within this category, but only content that creates a false impression of the authenticity of an existing person, object, place, entity, or event.
2. Technical marking of deep fakes by providers
The AI Act does not establish a separate technical marking requirement specifically for deep fakes. Pursuant to art. 50(2), providers are subject to the general obligation to mark and make all generated synthetic content (images, audio, and video) detectable. Therefore, deep fakes simply fall under this general rule, without a separate technical regime.
3. Disclosure of deep fakes by deployers
Disclosure intended for the public is distinct from the technical marking carried out by the provider. As a harmonised solution, the Code provides deployers with a series of publicly available EU icons that they can use freely, without attribution, or replace with an equivalent label that meets the same requirements. Specifically, regarding the marking of deep fakes, the Code sets out requirements relating to both design and placement, as follows:
- The label must be easily recognisable, visible for a sufficient duration and not be obscured by other elements; for video content, it must be repeated at regular intervals, while for text it must be placed next to the headline or in the colophon.
- Where visual disclosure is possible, the label may include, as the main element, the acronym "AI", unless the use of that acronym is incompatible with the applicable national legislation. It is recommended that the acronym be accompanied by a statement indicating that the content was "AI-generated" or "AI-manipulated".
- For audio content, where visual marking is not possible, the Code recommends a short audio warning, such as "This recording contains an AI-generated voice", repeated periodically in the case of long-form content.
- The Code also states that signatories are encouraged to indicate, in an additional interactive layer, what exactly has been modified by the AI system. For example, an ad in which a person's face has been modified using AI may be accompanied by the statement "Face modified using AI", while where a synthetic voice is used, the statement "AI-generated voice" may be used.
4. The standardised icons recommended by the European Commission
The Code provides, in Annex 1, EU icons created by the European AI Office for free use without attribution for the disclosure of AI content; their use is optional, and an equivalent label is equally valid.
Accordingly, three icons are available: "AI GENERATED" (fully AI-generated content), "AI MODIFIED" (partially AI-modified content), and a basic icon displaying only the acronym "AI", which may be complemented by an interactive layer or a textual label. Each icon is available in several graphical variations to ensure visibility against any background.



VI. Checklist for 2 August 2026: Key measures for companies to consider
An organised and cost-effective implementation involves going through the following steps:
- Inventory of AI systems, by mapping all AI systems used internally, developed in-house or acquired from third parties.
- Legal classification of AI systems and allocation of roles (provider vs. deployer), by determining, for each AI system, which transparency obligations apply: interaction with AI systems, AI-generated or AI-manipulated content (deep fakes), synthetic text intended for public information, emotion recognition systems and biometric categorisation systems.
- Reviewing the contractual relationships with AI providers, including verification of the documentation provided in order to ensure a clear allocation of responsibilities concerning compliance and transparency obligations.
- Reviewing internal policies and procedures, in order to incorporate rules governing the use of AI systems, the approval of use cases and compliance with transparency obligations.
- Integrating transparency notifications into the interfaces used: the public must be clearly informed, by means of a disclaimer, whenever they interact with an AI system or read synthetic texts of public interest.
- Conducting training sessions for employees operating AI systems, thereby ensuring a level of AI literacy appropriate to their skills and work context.
The significance of this implementation is not merely formal. Infringements of the transparency obligations laid down in art. 50 of the AI Act are subject to administrative fines of up to EUR 15 million or 3% of the total annual worldwide turnover, whichever of these values is higher. However, unlike the general rule, where the fine is calculated by reference to the higher value between the fixed sum and the percentage of the turnover, a protective mechanism has been established for SMEs and start-ups: the maximum fine is determined by reference to the lower of those two thresholds
———————
[1] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act);
[2] Code of Practice on Transparency of AI-Generated Content published by the European Commission, 20 July 2026, available at: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content.
[3] Code of Practice on Transparency of AI-Generated Content published by the European Commission, 20 July 2026, available at: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content.