The four transparency requirements for the use of AI effective August 2, 2026: a practical guide for businesses
A chatbot that does not identify itself as artificial intelligence, a manipulated video that appears real, or a public-interest text published without human review. As of August 2, 2026, situations like these will be subject to specific transparency obligations for companies. Article 50 of the European Artificial Intelligence Regulation, the AI Act, establishes four obligations to ensure that people know when they are interacting with AI or when they are receiving certain content created or manipulated using this technology.
However, this does not mean that all content created with the involvement of AI must be labeled. The obligation depends on the system used, the organization’s role, and how the result is used. This guide explains the four situations and what a company should review in each one.
Before analyzing the obligations, it is important to distinguish between the two roles established by the Regulation and determine who is responsible for acting in each case:
- The supplier develops or markets the system under its own name or brand.
- The deployment manager is the company, government agency, or professional that uses the system under its own authority.
Although business terminology refers to an implementer, the AI Act does not recognize this as a separate legal entity. Therefore, whoever implements a tool for use in their operations typically acts as the party responsible for deployment. If the tool is operated by employees or contractors acting on behalf of and under the control of a company, responsibility continues to rest with the organization.
Table of Contents
Requirement to provide information when a person interacts with an AI
Providers of systems designed to interact directly with people must ensure that users are aware they are communicating with an AI. This requirement applies to customer service chatbots, virtual agents, voice assistants, and conversational avatars.
Specifically, the notice must appear at the start of the first interaction in a clear, distinct, and accessible manner. It may be omitted when it is evident that the user is interacting with an AI, although the European Commission recommends interpreting this exception narrowly.
What should the company check? If a company incorporates a third-party solution into its website, app, or customer service, it should verify that the notice is enabled and that the design or configuration does not obscure it.
Requirement to technically label AI-Generated content
Providers of systems that generate or manipulate text, images, audio, or video must incorporate markers that allow computer tools to detect that the content has been created or altered using AI. They may use metadata, watermarks, or other effective and interoperable technical solutions.
This marker may remain hidden from the user. For this reason, it must be distinguished from the visible or audible warning that must be included by those who publish certain deepfakes or texts of public interest. The obligation does not apply when the system is limited to standard editing functions or does not substantially modify the data or its meaning.
Article 50 takes effect on August 2, 2026. However, providers of systems subject to this technical marking requirement that were placed on the market before that date have until December 2, 2026, to bring them into compliance. This transitional period is limited to the labeling and detection requirements set forth in Article 50(2): it does not affect systems placed on the market on or after August 2, nor does it defer other transparency obligations (Amendment to Regulation (EU) 2026/1744).
What should the company review? Even if it uses a third-party tool, it is advisable to verify that the tool incorporates the marking and that this marking is preserved when downloading, editing, or publishing content. Technical documentation and contracts should clarify how this works.
Requirement to report on emotion recognition and biometric categorization
Organizations that use emotion recognition or biometric categorization systems must inform the individuals subject to such systems. These technologies analyze facial features, voice, gestures, or other biometric signals to infer emotions or classify individuals. They may be used in market research, customer service, healthcare, security, transportation, or the management of public spaces.
Providing this information does not make any use of these technologies legitimate. The AI Act prohibits, among other applications, emotion recognition in the workplace and educational settings, except for limited exceptions based on medical or security grounds. It also prohibits certain biometric categorizations intended to infer particularly sensitive characteristics, such as political opinions, religious beliefs, union membership, or sexual orientation.
What should the company review? Before implementing one of these systems, it must verify that the use is permitted, what data is being analyzed, who will be affected, and how they will be informed. It must also ensure compliance with the General Data Protection Regulation.
Requirement to identify deepfakes and certain texts of public interest
Companies and professionals who publish images, audio, or videos considered to be deepfakes must clearly indicate that they have been generated or manipulated using AI.
The AI Act defines a deepfake as content that depicts real people, places, objects, entities, or events and may lead viewers to believe it is authentic. The warning must be understandable and noticeable upon first viewing. A technical mark hidden in the metadata is not sufficient.
This requirement also applies to AI-generated or AI-manipulated text published to inform the public about matters of general interest. Such content must be identified unless it has undergone substantive human review or editorial oversight and a person or entity assumes editorial responsibility for its publication.
To be considered sufficient, the review must be conducted with professional knowledge and judgment and include fact-checking of data and sources, evaluation of arguments, correction of errors, and necessary modifications. A spell check or purely formal review is not sufficient.
What should the company review? The departments that publish content need a protocol that determines which materials must be identified, how the disclaimer will be included, who will review them, and who will assume editorial responsibility.
Should all content created using AI be labeled?
The answer is no. Article 50 does not establish a general obligation to label everything produced with the involvement of artificial intelligence. The AI Act excludes strictly personal and non-professional use. However, when there is a professional or economic purpose, a natural person —for example, a self-employed individual, journalist, publicist, lawyer, or consultant— may act as the controller.
Content created before August 2, 2026, should not be retroactively tagged.
Summary of the four obligations
A practical approach to preparing the company
To facilitate compliance with the obligations set forth in Article 50, companies to which these obligations apply should incorporate them into their internal processes and operations. We propose a model based on six practical checks, developed in accordance with the obligations established by the AI Act and, with regard to content labeling and tagging, the guidelines set forth in the Code of Best Practices on Transparency of AI-Generated Content.
- Take inventory of the tools and determine how each department uses them.
- Determine the company’s role in each system.
- Check notifications from chatbots, agents, voice assistants, and avatars.
- Verify the technical tagging provided by vendors.
- Define labeling and review criteria with identified editorial managers.
- Train the teams involved in the use, oversight, and security of AI.
Failure to comply may result in penalties
In addition, the AI Act provides for fines of up to 15 million euros for noncompliance with obligations such as those set forth in Article 50, or, if the violator is a company, up to 3% of its total global turnover for the previous fiscal year. These are maximum limits, and their application must take into account, among other factors, the severity and duration of the violation, the number of people affected, the measures taken, and the size of the organization. In the case of SMEs, proportionality criteria apply.
In Spain, the Draft Organic Law on the Proper Use and Governance of Artificial Intelligence, still pending in Parliament, classifies breaches of Article 50 by providers and those responsible for deployment as serious. For these violations, it proposes fines of up to 7.5 million euros or 1% of global turnover from the previous fiscal year. In the case of SMEs, including startups, the lower of the two amounts would apply.
In short, the European obligations take effect on August 2, 2026. However, the specific Spanish penalty regime has not yet entered into force and may change during the parliamentary process.