How to prepare for the EU's new transparency and marking rules for AI
We break down the new EU’s 51-page transparency and marking guidelines for AI systems and AI-affected content.
While previous discussions on complying with the AI Act mostly revolved around high-risk systems, big companies, and the new EU transparency rules for AI systems, AI-generated content will land on the to-do list of many individuals and companies within and outside the EU once the summer recess ends.
The new rules, which came into force on August 2, 2026, will apply to a large set of actors - both individual and legal persons, be it companies, media outlets, non-governmental organizations, designers, advertising agencies, and more. The rules will apply not only to entities or individuals based in the EU, but also to those outside it if the systems or content are used in the EU market. Additionally, the obligations will apply irrespective if the service is paid or free of charge.
While some exemptions or lighter rules apply to individual use, research and scientific purposes, open-source systems, and artistic, creative, or satirical content, it’s best to take the guidelines seriously and assess which operations, products, and content must be marked to avoid potential penalties. Providers and deployers who do not comply with the new rules may be fined up to 15 million euros, or up to 3% of total worldwide turnover. EU institutions may be fined up to 750 000 euros.
4 major transparency obligations for AI systems and AI-affected content
The guidelines come as an explanatory document for the AI Act’s Article 50, where transparency obligations are set out for 4 major groups:
- Article 50(1) sets out obligations for AI systems that directly interact with natural persons, requiring providers to design and develop AI systems so that an individual is aware they are interacting with an AI system.
- Article 50 (2) sets out obligations for AI systems that manipulate synthetic image, video, audio, or text content. This means that providers should mark AI outputs in a machine-readable, detectable format.
- Article 50(3) sets out obligations for AI systems built to recognize emotions and for biometric recognition. Here, the deployers must inform natural persons that they are being exposed to the AI system.
- Article 50 (4) sets out obligations for AI systems that generate, manipulate, or publish deep fake or text to inform the public on the “matters of public interest”. Here, deployers must disclose that the content has been AI-generated, enhanced, or otherwise manipulated.
AI systems affected: chatbots, agents, bots
For an AI system to have obligations under Article 50 of the AI Act, the system must fulfill the EC’s definition: the system must interact with natural persons, must be built with an intention to interact with natural persons, and interact with them directly (in real-time or near real-time).
This means that AI-enabled voice assistants, chatbots, AI hotlines, AI companions, AI avatars, robots, AI bots, coding agents, and other AI agents all have obligations under the AI Act’s Article 50 and must follow the EC’s guidelines.
To-do list for authors, designers, social media influencers, podcasters
A new rule of thumb should be to mark all AI-generated, enhanced content - be it audio, video, image, text, or deepfake, especially if it’s related to the “matters of public interest”. Although exemptions and lighter rules exist for content that has only been edited with the help of AI without substantially changing the input, or has undergone human/editorial review, the lines between what constitutes “substantial change” are blurry. Similarly, editorial review/overview should also be substantial, not focused only on minor grammar or spelling corrections, with a specific individual having full responsibility for the content published.
For writers, authors, and bloggers: content such as AI-generated text summaries, texts, and paraphrasing that changes style, structure, and meaning should be marked. If the AI-generated or significantly enhanced text contains information relating to the “matters of public interest,” such as politics, public administration and services, administration of justice and law enforcement, fundamental rights, public security, health, environmental protection, consumer safety, economy, and more, it should also be marked. What doesn’t need to be marked: minor grammar correction, spellchecking, and stylistic polishing.
For social media influencers and those who love face-editing apps: the content should also be marked if the faces in the existing photos are replaced or undergo substantial facial modification. While editing images for personal use is outside the transparency obligations, any content that is commercially oriented may fall under the EU’s new transparency obligations.
For graphic and video designers: all video and image content where objects and persons are removed, replaced, or inserted in existing videos needs to be marked. As should be the content that alters the body shape, skin color of a person, and where extreme lightening, darkening, color, and contrast changes that change the meaning, intent, and messaging of the content. Generation of videos where events that did not occur are depicted should also be marked. As should be images or videos that modify the representation of persons, objects, events, or facts, or any other substantial alteration of the content. What doesn’t need to be marked: general formatting, editing (enhanced clarity, cropping, minor color/light adjustments, sharpening, removal of dust and spots, red-eye, backgrounds, pixelation and blurring of faces), scaling video clip, video stabilization, minor adjustments to playback speed, and other general editing that does not alter the content extremely.
For podcasters, audio editors, and radio hosts: synthesis of realistic speech in a specific person’s voice should be marked.
Who’s responsible in the client-agency and employer-employee relationship?
If a company is buying design services from an advertising/graphic design agency and does not make decisions or exercise control over whether and how the advertising agency uses AI, the transparency obligations fall to the agency, not the customer.
Similarly, the transparency obligations are a responsibility of an employer/legal entity, not an individual employee or even a contractor that is producing AI-affected content:
(14) “Where the deployer of an AI system is a legal person under whose authority the system is used (e.g. an advertising company), the individual employees that act under the instructions and under the control of that legal person (e.g. digital animators, web designers, content creators, journalists) should not be considered as separate deployers for that system. A legal person remains a deployer even if it involves third parties (e.g. contractors, freelancers) in the operation of the system on its behalf and under its responsibility and control.”
Deepfake rules
The deepfakes need to be marked if they resemble existing persons, objects, places, entities, or events that could falsely appear to a person as authentic and truthful. Again, exemptions exist for content that is artistic, creative, satirical, or fictional; however, if the deepfake is used for professional purposes, it should nevertheless be marked.
Deepfakes of real people, politicians, celebrities, company CEO’s, AI-generated audio voice cloning or even AI-generated images of product advertisements and packaging that look better than in real life - all need to be marked.
Exemptions: individual use, open-source, law enforcement, scientific, and research purposes
Exemptions from transparency obligations apply to deployers who are natural persons using AI for personal, non-professional activities, scientists and researchers, open-source systems, and law enforcement.
However, if an individual is acting on their personal behalf and their personal activity overlaps with their professional activity, and economic benefit is gained, it’s likely that the transparency obligations might kick in.
Open-source-wise, both providers and deployers still need to ensure compliance with their respective transparency obligations.
Marking suggestions
Providers have to mark their AI systems in a machine-readable format to ensure machine-to-machine detection and ensure that the outputs of their AI systems are detectable as AI-generated or manipulated. Deployers must, on their own behalf, mark AI-generated or manipulated content in a clear, distinguishable manner.
The EC's guidelines state that some AI marking techniques are not necessary or insufficient if used alone, such as:
- disclosures contained only in terms and conditions, URLs, or documentation
- machine-readable markings, such as metadata or watermarks, that are not visible to users
- unclear or ambiguous signals (e.g., generic references such as “assistant”)
- generalistic disclosures (e.g., “services on this website use AI”)
- overly technical descriptions (e.g., “this system uses LLMs”)
The European Commission has published a set of icons that can be used to mark AI-generated or enhanced content in a visible, distinguishable manner (See below).
