AI Now Has to Tell You It's AI: The EU's Transparency Rules Are Now Law
As of 2 August, Article 50 of the EU AI Act obliges chatbots to identify themselves, AI-made media to be marked, and deepfakes disclosed — backed by fines up to €15m or 3% of global turnover. What each rule requires, the carve-outs, and where it is still soft.

AI Now Has to Tell You It's AI: The EU's Transparency Rules Are Now Law
As of 2 August, a slice of the EU AI Act that touches almost everyone who uses a chatbot, sees a synthetic image, or reads an online article quietly became binding. Article 50 — the transparency obligations — is now in application across the European Union. It is narrower than some of the headlines suggest, and its enforcement is softer than its penalty ceiling implies. But the direction is clear: in Europe, AI is now legally supposed to identify itself.
Here is what actually changed, who it binds, where the carve-outs are, and why a labelling law is only as strong as the technology meant to enforce it.
What took effect on 2 August
The AI Act does not switch on all at once. Its prohibited-practices ban applied in February 2025. The bulk of the heavy obligations — the high-risk system rules that industry lobbied hardest against — were pushed back to December 2027 by the Digital Omnibus package, which took effect on 27 July, barely a week before this transparency layer went live. What arrived this weekend is the transparency layer: a set of duties about telling people when they are dealing with a machine or with machine-made content.
It splits along a simple line. Some duties fall on providers — the companies that build and supply the AI system. Others fall on deployers — the businesses and people who put it to use.
The four things the rules now require
1. Chatbots have to say they are chatbots. Providers must design systems that interact directly with people so that those people are told they are dealing with an AI — "at the latest at the time of the first interaction." The exception is where it would be obvious to a reasonably observant person anyway. A customer-service bot that opens by announcing it is automated already complies; one built to pass as a human agent does not.
2. AI-generated media has to be marked. Providers of systems that produce synthetic audio, image, video, or text must mark the outputs "in a machine-readable format and detectable as artificially generated or manipulated." This is the watermarking-and-metadata obligation — the machine-side counterpart to a visible label. It is also where the law hedges hardest, as we will come to.
3. Deepfakes have to be disclosed. Deployers who publish deepfakes — manipulated image, audio, or video of real people, places, or events — must disclose that the content is artificial. There is a carve-out for work that is evidently artistic, creative, satirical, or fictional: there, the disclosure only has to note that manipulated content exists, in a way that does not spoil the piece.
4. AI-written text on public-interest matters has to be flagged — unless a human signed off. Deployers who publish AI-generated text "to inform the public on matters of public interest" must disclose that it was machine-made. The important exception: content that has undergone human review and editorial control, with a named person or organisation taking editorial responsibility, is exempt. A newsroom that runs AI drafts past a human editor does not have to stamp every article; a site that publishes an unreviewed model's output as though a person wrote it does.
There is a fifth, quieter duty too: deployers of emotion-recognition or biometric-categorisation systems must tell the people exposed to them that the system is running.
Across all of it, the form of disclosure matters. Article 50 requires the information to be given "in a clear and distinguishable manner," no later than the first interaction, and in line with accessibility requirements. A disclosure buried in a terms-of-service page is not the same as one shown at the point of contact.
The teeth
Breaches of Article 50 sit in the AI Act's middle penalty tier. Under Article 99, a transparency-obligation breach can draw an administrative fine of up to €15 million, or 3% of the offender's total worldwide annual turnover, whichever is higher. For scale: the top tier, reserved for the outright-prohibited practices, reaches €35 million or 7%; supplying regulators with incorrect information sits lower, at €7.5 million or 1%.
The catch is who imposes them. The AI Act leaves penalties to the member states — each government "shall lay down the rules on penalties," set them up, and report the fines it issues back to the Commission. There is no single European enforcer writing cheques. That means the ceiling is Union-wide, but the appetite to reach for it will vary country by country, and most national authorities are still being stood up.
Where the law is softer than it looks
A transparency rule is only as good as the mechanism behind it, and this one has three places where the gap between text and reality shows.
The first is the phrase attached to the marking duty: providers must make outputs detectable "as far as this is technically feasible." Machine-readable watermarks and provenance metadata are real, but they are also fragile — a screenshot, a re-encode, a crop, or a paraphrase can strip them, and no standard is yet universal across the industry. We have written before about how the EU's voluntary labelling code is guidance, not the law itself, and about how the music industry's AI-song labels mean little when the platforms decline to display them. A "detectable as far as feasible" standard inherits all of that fragility.
The second is a grace period. The machine-marking obligation is not fully live for everything today: systems already on the market before 2 August get a transitional window to 2 December 2026 to comply. The disclosure duties on chatbots, deepfakes, and public-interest text apply now; the deeper watermarking retrofit has a few more months.
The third is enforcement itself. National authorities are new, under-resourced, and untested against these provisions. The likeliest near-term effect is not a wave of fines but a shift in default behaviour: large providers building disclosure in to avoid becoming the test case, rather than regulators hunting down every unmarked image.
What it means if you are on the receiving end
If you are in the EU, the practical change is that a chatbot should now tell you it is one, and AI-made media should carry a label or a mark. Treat both as a floor, not a guarantee. The obligation to disclose is real and now enforceable; the technology meant to carry the disclosure is defeatable, and the people meant to enforce it are still finding their feet. A label is a signal that the system worked, not proof that its absence means a human was involved.
This is one layer of a law that will keep switching on in stages through 2027. It is also the layer most likely to touch an ordinary user's day — the moment the question "am I reading, watching, or talking to a machine?" stopped being only a matter of etiquette, and started being one of law.
For the wider structure this sits inside, see our explainer on how the EU AI Act's risk tiers actually work, and — for the question underneath the rule — when should AI disclose itself at all.
Ask Relay — he reads every question himself and replies personally by email.
