Policy · Help Net Security ·

EU begins enforcing AI Act transparency rules for chatbots

The EU's AI Act transparency rules took effect August 2, requiring chatbots to disclose themselves and AI-generated content to carry clear labels, with fines up to 15 million euros.

Based on reporting by Help Net Security — analysis by dalili

Europe's AI Act enforcement moved from paper to practice on August 2, when the European Commission's AI Office and national authorities began enforcing new transparency rules under Article 50 of the regulation. Chatbots and other AI systems that interact directly with people must now identify themselves as automated rather than human, deepfakes require a visible label, and AI-generated or altered content must carry machine-readable marks so it can be detected automatically. Companies that ignore these obligations risk fines of up to 15 million euros or 3% of worldwide annual turnover, whichever is higher.

The rules apply to four scenarios: AI systems interacting directly with individuals, such as chatbots and voice assistants; deepfakes, which need visible marking; AI-generated text on matters of public interest, unless it underwent substantive human editorial review; and emotion-recognition or biometric categorization systems, which require a warning to users. The obligations apply immediately to all in-scope systems regardless of when they were placed on the market, though content published before August 2 does not need retroactive labeling.

Not every part of the AI Act arrived on schedule. Rules for high-risk AI systems embedded in regulated products, such as machinery, have been pushed back to 2028, and high-risk use cases in recruitment, credit scoring, and law enforcement now face a December 2027 deadline rather than this year, following the EU's formal simplification package agreed in May. The rules apply extraterritorially to any AI product or advertising that targets European users, meaning the transparency requirements reach well beyond companies headquartered in the bloc. A voluntary Code of Practice on AI-content labeling already had roughly 190 organizations signed on by the end of July.

Key takeaways

  • EU AI Act transparency rules took effect August 2, requiring chatbots to self-identify and AI content to carry machine-readable labels
  • Fines reach 15 million euros or 3% of global annual turnover, whichever is higher
  • Rules apply extraterritorially to any AI product targeting EU users, while high-risk system rules were delayed to 2027-2028

Why it matters

This is the first time a major regulatory bloc has moved AI transparency from voluntary guidance to enforceable law with real fines, and because it applies to any product targeting EU users, it effectively sets a global default for how chatbots and AI content must identify themselves.

Related

  1. The Verge ·

    Microsoft: Almost No One Read NYT Articles via Chatbot

  2. TechCrunch ·

    OpenAI Agents Escape Again, Renewing Calls for AI Oversight

  3. Ars Technica ·

    Trump may reveal secret federal AI safety testing rules