EU AI Act Transparency Rules Now Apply: What Chatbot and AI App Owners Need to Know
The transparency rules in Article 50 of the EU AI Act started to apply on August 2, 2026. They are the part of the Act most likely to touch an ordinary business product: a support chatbot, an AI writing or image feature, a voice assistant. The European Commission published guidelines on these obligations on July 20, 2026, shortly before the date.
At the same time, the stricter rules for high-risk AI systems were pushed back. The result is a timeline that is easy to misread: some duties are live now, one has a short grace period, and others are more than a year away. If you run or are planning custom software with AI features that people in the EU can use, it helps to know which is which.
This is a high-level summary of what the Commission has published. It is not legal advice.
What applies now and what was postponed
The Commission's AI Act page, last updated on August 3, 2026, sets out the timeline. The Act entered into force on August 1, 2024. Prohibited AI practices and AI literacy obligations have applied since February 2, 2025, and the obligations for general-purpose AI models since August 2, 2025. The Act became generally applicable on August 2, 2026, with some exceptions, and the transparency rules are part of what came into effect then.
The exceptions matter. According to the same page, the rules for AI systems used in certain high-risk areas, including biometrics, critical infrastructure, education and employment, will apply from December 2, 2027. High-risk AI embedded in regulated products has an extended transition period until August 2, 2028. The Commission attributes these changes to the AI Omnibus, which it says was proposed on November 19, 2025, reached political agreement on May 7, 2026 and entered into force on July 27, 2026.
So the high-risk regime is announced with future dates. The transparency rules are current.
The four transparency obligations
The Commission's FAQ on Article 50 splits the duties between providers, who develop an AI system or have one developed and place it on the EU market under their own name, and deployers, who use an AI system in a professional capacity.
Providers
Providers of AI systems designed to interact directly with people must make sure those people are informed that they are dealing with an AI system, unless that is obvious. The FAQ says the notice has to be given from the start of the first interaction, in a clear and distinguishable way.
Providers of systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format so it can be detected as artificially generated or manipulated. The FAQ lists exceptions, among them source code, outputs that pass only between machines, and assistive functions for standard editing.
Deployers
Deployers must inform people who are exposed to an emotion recognition or biometric categorization system. They must also disclose deepfakes, and label AI-generated or manipulated text that is published to inform the public on matters of public interest. The FAQ says text is exempt from labeling where it has gone through human review or editorial control, and that a superficial check of spelling or grammar does not count.
The grace period for content marking
There is one transitional date to note. The FAQ describes a limited grace period that covers only AI systems placed on the market before August 2, 2026, and only the marking and detection obligation for AI-generated content. Providers of those systems must comply from December 2, 2026.
The grace period does not extend to the other duties. The FAQ also states that content generated before August 2, 2026 does not need to be labeled retroactively, although the Commission encourages deployers to do so where possible.
The guidelines and the voluntary Code of Practice
Two documents explain how to comply. The guidelines clarify who counts as a provider or deployer and which obligation falls on whom along the value chain. The Code of Practice on Transparency of AI-generated Content, which the Commission's page says was published in final form on June 10, 2026, offers practical measures in two sections: marking and detection for providers, and labeling of deepfakes and AI-generated text for deployers.
The Commission is explicit that signing the Code is voluntary while the Article 50 requirements themselves are legal obligations. The guidelines page says organizations may demonstrate compliance through the Code or through alternative, equivalently adequate means.
Does this reach US and UK companies?
The AI Act is EU law, and neither the US nor the UK is a member state. That does not settle the question. The Commission's FAQ says providers established or located outside the EU are also subject to the rules if the output of their AI system is used in the EU.
For a US or UK business, the practical test is therefore about where your product is used, not where your company is registered. A SaaS tool sold to customers in Germany or France, or a consumer app available in EU app stores, is the kind of case to check with a lawyer. A product used only in your home market is a different situation. UK and US rules on AI are separate and are not covered here.
What this means for your product
The points below are our reading of the Commission's material, offered as guidance.
The first question is your role. A company that builds a chatbot on top of a third-party model and offers it under its own brand may be treated differently from a company that simply uses an off-the-shelf tool internally. The FAQ we read does not give a one-line answer for integrators, so this is the point to raise with your legal adviser, using the guidelines as the reference.
The second is the "obvious" exception. The FAQ says the assessment is made from the viewpoint of an average person who is reasonably well-informed, circumspect and observant. A widget clearly named as a virtual assistant sits differently from a chat window that presents a human name and photo. Relying on the exception is a judgment call; a short, plain disclosure at the start of the conversation is usually the lower-risk design. Our article on AI agents, chatbots and workflow automation explains the differences between these system types, which affects whether there is direct interaction with a person at all.
The third is content marking. If your product generates images, audio, video or text, find out whether the model or API you rely on already applies machine-readable marks and whether your own pipeline strips them out, for example when images are resized or re-encoded.
The FAQ states that fines can reach EUR 15 million or 3 percent of total worldwide turnover for the preceding financial year, with proportionality taken into account for smaller companies. Enforcement sits mainly with national market surveillance authorities.
What to do next
- List every AI feature in your products and note whether it talks to people, generates content, or analyzes emotion or biometric traits.
- For each, record whether people in the EU can use it and whether you are likely the provider or the deployer.
- Add or review the AI disclosure in chat and voice interfaces.
- Ask your model vendors how their output is marked, and plan for the December 2, 2026 date if you had a generative system on the market before August 2, 2026.
- Decide who reviews AI-written public content, and document that review.
If your system could fall into a high-risk category such as employment or education, the later dates give you more time, not an exemption. Use it to plan documentation and oversight properly.
Conclusion
The EU AI Act's transparency rules have applied since August 2, 2026. Chatbots must disclose that they are AI unless it is obvious, generative systems must mark their output, and deployers must label deepfakes and certain AI-generated public-interest text. Marking for systems already on the market has until December 2, 2026, and the high-risk rules now start on December 2, 2027 and August 2, 2028. Non-EU companies are covered where their system's output is used in the EU.
Most of the engineering involved is small: a disclosure line, a metadata check, a review step. If you want help adding these to an existing product or designing them into a new one, you can request a quote from Entrant Technologies. For the legal assessment, use the Commission's guidelines and your own counsel.