EU AI Act: What Changes for Businesses, Chatbots and AI-Generated Content

Artificial Intelligence & Compliance
AI Act: Phase 2 Now Applies to Businesses, Chatbots and AI-Generated Content
From 2 August 2026, a key part of the European AI Act becomes applicable, introducing significant transparency obligations for chatbots, deepfakes, public-interest text and content generated or manipulated by artificial intelligence.
The postponements introduced by the Digital Omnibus for certain high-risk AI systems do not mean that businesses are exempt from compliance. From 2 August, organisations need to know which AI systems they use, properly inform users and document the measures they have adopted.

Illustrative image created with the support of artificial intelligence.
What does 2 August 2026 mean?
From 2 August 2026, individuals must be informed whenever they interact directly with certain artificial intelligence systems, unless the artificial nature of the interaction is already obvious.
The following obligations also become applicable:
- chatbots and virtual assistants;
- AI-generated or AI-manipulated audio, video, images and text;
- deepfakes;
- texts published to inform the public on matters of public interest;
- emotion recognition systems;
- biometric categorisation systems;
- machine-readable markings for synthetic content;
- supervision and enforcement of the rules applicable to general-purpose AI models.
Businesses must therefore identify which AI systems they use, their intended purposes and the types of content they generate.
What is the European AI Act?
The AI Act is Regulation (EU) 2024/1689, the European regulation establishing harmonised rules for the development, placing on the market and use of artificial intelligence systems within the European Union.
The Regulation adopts a risk-based approach. The applicable obligations therefore depend on the function of the AI system, the context in which it is used and its potential impact on individuals.
In general terms, the AI Act distinguishes between:
Prohibited practices
These are AI uses considered incompatible with the European Union’s fundamental rights and values.
High-risk AI systems
These include systems used in particularly sensitive areas such as employment, education, access to essential services, biometrics and certain regulated products.
Transparency-related AI systems
These include, among others, systems that interact with individuals and systems capable of generating or manipulating synthetic content.
Limited or minimal-risk AI systems
These systems may generally be used without the regulatory regime applicable to high-risk AI, while remaining subject to other legislation and any relevant transparency obligations.
The Regulation entered into force on 1 August 2024, but its provisions have become applicable progressively. 2 August 2026 marks one of the most significant milestones in its implementation.
The AI Act Milestone of 2 August 2026
From 2 August 2026, the transparency obligations set out in Article 50 of the AI Act become applicable.
The underlying principle is straightforward: whenever artificial intelligence may lead someone to believe they are interacting with a human being, or whenever it generates artificial content that is difficult to distinguish from authentic content, the role of AI must be clearly disclosed.
| Area | Responsible party | Main obligation |
|---|---|---|
| Chatbots and interactive systems | Provider of the AI system | Inform users that they are interacting with an AI system, unless this is already obvious. |
| Synthetic content | Provider of the generative AI system | Ensure that outputs are detectable and marked in a machine-readable format. |
| Deepfakes | The person using the system and distributing the content | Clearly disclose that the content has been artificially generated or manipulated. |
| Public-interest text | The person using AI to generate or manipulate the text | Disclose the use of AI, except where the editorial control and human responsibility exemptions apply. |
| Emotion recognition systems | Professional user of the system | Inform individuals who are subject to the system. |
| Biometric categorisation systems | Professional user of the system | Inform the individuals concerned, while also complying with applicable data protection legislation. |
Provider and deployer are not the same
Under the AI Act, the provider is the person or organisation that develops an AI system or places it on the market under its own name or trademark.
A deployer, on the other hand, is the person or organisation that uses the AI system under its authority in the course of a professional activity.
A company using ChatGPT, Gemini, Copilot, Canva AI or a third-party chatbot is normally considered the deployer of the system. However, it may assume broader responsibilities if it substantially modifies the system, integrates it into one of its own products or markets it under its own brand.
What Has Been Postponed by the Digital Omnibus?
The Digital Omnibus has amended the implementation timeline for certain provisions relating to high-risk AI systems.
The postponement mainly concerns the specific obligations applicable to AI systems classified as high risk. It does not postpone the transparency obligations under Article 50, which remain applicable from 2 August 2026.
| Type of AI system | Examples | New date |
|---|---|---|
| Standalone AI systems listed in Annex III | Recruitment, education, credit assessment, biometrics and access to certain essential services. | 2 December 2027 |
| AI systems integrated into products covered by Annex I | AI embedded in medical devices, machinery and other products subject to harmonised EU legislation. | 2 August 2028 |
A postponement is not an exemption
The postponement of certain obligations for high-risk AI systems should not be interpreted as an exemption from compliance. Organisations should use the transitional period to prepare in a structured way, ensuring that appropriate processes, responsibilities and documentation are in place well before the new deadlines.
This means identifying the AI systems currently in use, classifying their use cases, determining which may fall into the high-risk category, assessing AI providers, defining internal responsibilities and progressively preparing the documentation needed to demonstrate compliance.
The postponement applies only to specific obligations under the AI Act. Other applicable legislation remains fully in force, including the GDPR, employment law, consumer protection rules, intellectual property law, product safety requirements and contractual obligations.
Chatbots and Virtual Assistants: What Must Be Disclosed?
Whenever a person interacts directly with an artificial intelligence system, they must be informed that the interaction is with AI, unless this would already be obvious to a reasonably well-informed and reasonably observant person.
This requirement may apply to:
- chatbots embedded in websites;
- virtual customer support assistants;
- AI-powered voicebots;
- AI assistants integrated into e-commerce platforms and customer portals;
- digital avatars interacting with users;
- AI agents that collect requests or provide recommendations.
How should users be informed?
The information should be clear, timely and easy to understand. It should be presented no later than the beginning of the user’s first interaction with the AI system.
Example of a chatbot disclosure
You are interacting with an AI-powered virtual assistant. Responses may be generated automatically and could contain inaccuracies. If your request requires human review, please contact our customer support team.
Simply hiding this information in the privacy policy or the website’s terms and conditions is not sufficient. Users should be able to recognise immediately that they are not communicating with a human.
Is a disclosure always required?
A specific disclosure may not be necessary when the artificial nature of the system is already obvious—for example, if the chatbot is clearly presented as an AI assistant through its name, visual appearance or interface. However, to avoid ambiguity and provide a better user experience, an explicit disclosure is generally the safest and most transparent approach.
AI-Generated Content: Machine-Readable Marking and Detectability
Article 50 requires providers of AI systems capable of generating synthetic content to implement technical measures ensuring that AI-generated or AI-manipulated outputs can be detected as such.
The marking should be:
- effective;
- interoperable;
- robust;
- reliable;
- technically feasible;
- machine-readable.
This responsibility primarily lies with the developers and providers of generative AI systems. It does not mean that every company using an AI tool must develop its own watermarking technology.
However, organisations using AI should verify whether the selected platform supports content provenance technologies such as technical marking, provenance metadata or other identification mechanisms.
Is the technical marking always visible?
No. A machine-readable marking may be embedded in metadata, incorporated into the file itself or applied through techniques that are not immediately visible to the human eye.
It should therefore not be confused with a simple text label such as AI-generated image.

Two Different Levels of Transparency
Compliance may require both a machine-readable technical marking, typically implemented by the AI system provider, and a human-readable disclosure, which may be required in specific situations for the person or organisation publishing or using the content.
Deepfakes: When Is AI Disclosure Mandatory?
The AI Act defines a deepfake as an image, audio or video content generated or manipulated by artificial intelligence that resembles real persons, objects, places, entities or events and could falsely appear authentic or truthful.
Anyone using an AI system to generate or manipulate a deepfake and subsequently making it available to others must clearly disclose that the content has been artificially created or altered.
The disclosure should be clear, distinguishable and provided no later than the moment the content is first presented to the public.
Examples of content that may fall within these requirements
- videos in which a person appears to say words they never actually spoke;
- audio recordings that imitate the voice of a real individual;
- photorealistic images depicting events that never occurred;
- AI-generated recreations of public figures;
- promotional content in which real endorsers are artificially recreated;
- realistic representations of non-existent places or products presented as authentic.

Artistic, satirical and creative works
For content that is clearly artistic, creative, satirical or fictional, the disclosure requirement should be applied in a way that does not unnecessarily interfere with the enjoyment or understanding of the work.
We previously explored this topic in our article on how to recognise fake news.
The artificial nature of the content should nevertheless be indicated in an appropriate manner.
Example of a disclosure label
Content generated or manipulated using artificial intelligence.
Where appropriate, the wording can be made more specific, for example: “AI-generated video”, “Synthetic voice” or “Photorealistic image generated with AI”.
AI-Generated Text on Matters of Public Interest
Article 50 also covers text generated or manipulated by artificial intelligence when it is published with the purpose of informing the public about matters of public interest.
In such cases, the person using the AI system must disclose that the text has been generated or manipulated by artificial intelligence.
This provision may apply, for example, to:
- news and informational articles;
- press releases and announcements on public-interest topics;
- political or institutional communications;
- content relating to health, safety, the environment and the economy;
- publications that may influence public debate.
The Human Editorial Oversight Exception
A disclosure may not be required where AI-generated content is subject to meaningful human review or editorial oversight and a natural or legal person assumes editorial responsibility for the publication.
This exception should not be interpreted as allowing the automatic approval of any AI-generated text.
An organisation should be able to demonstrate:
- who reviewed the content;
- which verification activities were carried out;
- who assumes editorial responsibility;
- which version was approved;
- when the approval took place.
A purely formal human review is not enough
Simply clicking “Publish” after a quick read-through does not necessarily constitute adequate editorial oversight. At a minimum, the content should be reviewed for accuracy, sources, tone, potential bias or discrimination, third-party rights and consistency with the publication’s objectives.
AI Literacy and Training
Article 4 of the AI Act requires both providers and professional users of AI systems to take appropriate measures to ensure that staff and other persons involved in the use of AI systems have a sufficient level of AI literacy.
This obligation has applied since 2 February 2025.
Training should be proportionate to:
- the technical knowledge of the personnel involved;
- their role within the organisation;
- the context in which the AI system is used;
- the individuals or groups that may be affected by the system;
- the risks associated with the specific use case.
A generic training course is not always sufficient
Someone using AI to translate a product description does not necessarily require the same level of training as someone using AI to screen job applicants, analyse customers, generate healthcare information or automate decision-making processes.
A credible training programme should distinguish at least between:
General users
Proper use of AI platforms, data protection, output verification, copyright considerations and recognising AI hallucinations.
Managers and team leaders
Assessment of AI use cases, approvals, human oversight, supplier management and content validation.
Developers and technical staff
Security, data quality, logging, testing, monitoring, robustness and integration controls.
Executive management and governance
Organisational risks, accountability, compliance, incident management and the impact of AI on business processes.
How to document AI training
It is good practice to retain:
- training programmes and course materials;
- attendance records;
- dates and duration of training activities;
- participants’ roles and the AI systems they use;
- assessment or learning test results, where applicable;
- evidence of periodic refresher training.
At HT&T Consulting, we started internal AI training as soon as the first regulatory requirements emerged, providing our entire team with practical guidance and raising awareness of the opportunities and risks associated with AI. Since 2025, we have also delivered AI training programmes for client organisations and external participants through collaborations with the Chamber of Commerce and Fondazione ISI – Institute for Innovation and Business Development.
How Does the AI Act Affect Digital Agencies, Marketing Firms and Web Development Companies Such as HT&T?
Digital agencies can use artificial intelligence across a wide range of activities, including copywriting, graphic design, video production, translation, advertising, data analysis, chatbots, software development, customer support and workflow automation.
Not all of these use cases trigger the same legal obligations, but they should all be identified, assessed and managed appropriately.
| Use case | Potential compliance requirement |
|---|---|
| Chatbot deployed on a client’s website | Provide a clear notice that users are interacting with an AI system and define an escalation path to a human operator. |
| Clearly illustrative AI-generated images | Assess whether a disclosure is appropriate based on the context and retain information about the AI tool and creative workflow. |
| Photorealistic AI-generated images of people or events | Determine whether the content qualifies as a deepfake and, where applicable, disclose that it has been artificially generated or manipulated. |
| AI-generated informational articles | Implement documented editorial review or disclose the use of AI where required. |
| AI-assisted translations | Apply human review proportionate to the level of risk, particularly for technical, legal, medical or commercial content. |
| Advertising creatives | Verify transparency, copyright compliance, image rights and ensure that the content is not misleading. |
| Recruitment or candidate assessment | Carry out a dedicated risk assessment, as the system may fall within the high-risk AI category defined in Annex III. |
| RAG chatbot developed for a client | Clearly define contractual roles, data sources, logging, human oversight, security measures, transparency requirements and incident management procedures. |
Major advertising platforms already provide options to label AI-generated advertising creatives. However, responsibility ultimately remains with both the agency and the client, who must ensure that AI-generated content is used transparently and in compliance with applicable regulations.
Can a digital agency become an AI provider under the AI Act?
Yes, in certain circumstances.
An agency that merely configures or deploys a third-party AI service will generally remain an integrator or deployer. However, if it develops an AI-based system, markets it under its own name or brand, substantially modifies it, or changes its intended purpose, it may assume the role of an AI provider rather than that of a deployer.
These responsibilities should therefore be clearly defined in contracts with clients, suppliers and technology partners.
What Is the Relationship Between the AI Act, C2PA and Content Credentials?
The AI Act establishes transparency objectives and, for providers of generative AI systems, requires synthetic content to be detectable through machine-readable markings.
However, it does not generally require organisations to adopt a single specific technology.
The C2PA standard and Content Credentials represent one of the most significant solutions currently available for documenting the origin and modification history of images, videos, audio files and other digital content.
Content Credentials may include information such as:
- the origin of the file;
- the tool used to create it;
- the modifications applied;
- whether artificial intelligence was used;
- the entity that signed the provenance information.
C2PA can therefore contribute to the technical transparency required by the AI Act, but it does not by itself satisfy every compliance obligation.
The Digital Passport for Content
In our dedicated guide we explain how C2PA, Content Credentials and content provenance verification systems work, and how they help improve trust in digital content.
Is C2PA mandatory from 2 August 2026?
No. The AI Act requires transparency and detectability outcomes but does not require every organisation to adopt C2PA.
Nevertheless, C2PA is likely to become one of the most valuable technologies for demonstrating file provenance and preserving information about content transformations.
Does writing “Generated with AI” replace technical marking?
Not necessarily.
A visible label informs people, whereas technical marking enables platforms and automated tools to identify synthetic content. The two mechanisms serve different purposes and can complement each other.
Enforcement, Liability and Penalties
From 2 August 2026, additional elements of the AI Act’s governance and enforcement framework become applicable.
For providers of general-purpose AI models, the European Commission, through the AI Office, is empowered to exercise supervisory and enforcement powers.
The Regulation establishes different levels of administrative penalties depending on the nature of the infringement. Maximum fines may reach:
- up to €35 million or 7% of worldwide annual turnover for certain prohibited AI practices;
- up to €15 million or 3% of worldwide annual turnover for other violations of the Regulation;
- different amounts or percentages where incorrect, misleading or incomplete information is provided to the competent authorities.
The actual penalty depends on the type of organisation involved, the specific infringement and the circumstances of the individual case. Small and medium-sized enterprises benefit from proportionality criteria and specific maximum thresholds.
Compliance Is About More Than Financial Penalties
Poor governance of artificial intelligence can also lead to reputational damage, contractual disputes, intellectual property issues, privacy violations, discriminatory outcomes and liability towards customers or affected individuals.
Maintaining an AI register, providing staff training, ensuring meaningful human oversight and assessing AI suppliers are therefore not only regulatory requirements but also essential components of effective enterprise risk management.
Practical Examples: What Companies Should Actually Do
Compliance with the AI Act does not depend solely on the name of the platform being used. Organisations must assess the purpose of the AI system, the type of content it generates, the context in which that content is published and the role assumed by the organisation.
The key principle
Using ChatGPT, Gemini, NanoBanana, Claude, Midjourney, Canva or any other AI platform does not automatically trigger the same legal obligations in every situation. Responsibilities change depending on whether the AI interacts with people, generates a deepfake, produces public-interest content or is integrated into a service offered to customers.
What should an SME do from 2 August 2026?
At a minimum, an SME should know which artificial intelligence systems are being used within the organisation and for what purposes. The first practical step is to create an inventory of AI systems and AI use cases.
The organisation should then:
- identify all AI platforms, accounts and integrations currently in use;
- determine who is responsible for using each AI system;
- verify whether public-facing chatbots or virtual assistants are deployed;
- review how AI-generated images, audio, video and text are published;
- define who reviews and approves AI-assisted content;
- provide staff with AI training appropriate to their roles and responsibilities;
- document the measures that have been implemented;
- review contracts and terms of service with AI providers.
For SMEs using AI solely as an internal productivity tool, compliance obligations may remain relatively limited. However, organisations must still promote AI literacy among staff and comply with applicable legislation relating to data protection, confidentiality, copyright and liability. Article 4 of the AI Act applies to both providers and deployers, including SMEs, requiring measures that are proportionate to the specific context and level of risk.
Does using ChatGPT or Claude at work mean the AI Act applies?
Yes. Professional use of ChatGPT may fall within the scope of the AI Act. However, this does not mean that every employee entering a prompt must comply with every obligation contained in the Regulation.
A company using ChatGPT is generally considered a deployer, meaning a professional user of an AI system supplied by another organisation.
The organisation should therefore assess:
- the purpose for which the AI system is being used;
- the type of data entered into the system;
- whether the outputs are published or used to support decisions;
- whether the content concerns matters of public interest;
- whether effective human oversight is in place;
- whether staff have received appropriate AI training.
Using ChatGPT to improve the wording of an internal email is fundamentally different from using it to automatically publish news articles, screen job candidates or autonomously respond to customers.
Do I need to disclose AI-generated images on LinkedIn?
Not every image created with artificial intelligence requires the same visible disclosure.
Disclosure becomes particularly important where the image:
- realistically depicts an identifiable person;
- portrays an event that never actually happened as though it were real;
- artificially alters an authentic photograph;
- could reasonably be mistaken for documentary evidence;
- falls within the AI Act definition of a deepfake;
- is used to inform or influence the public on an important matter.
For clearly illustrative, conceptual or abstract graphics, the risk of misleading viewers is generally much lower. Nevertheless, indicating that AI has been used remains good practice whenever this information helps users correctly understand the content.
Suggested wording for LinkedIn
Illustrative image created with the support of artificial intelligence.
For realistic or manipulated content, a more explicit disclosure is preferable, for example: “AI-generated image. This does not depict a real event.”
Updated AI Act Implementation Timeline
| Date | What changes |
|---|---|
| 1 August 2024 | The European Artificial Intelligence Regulation enters into force. |
| 2 February 2025 | The rules on prohibited AI practices and the AI literacy obligation become applicable. |
| 2 August 2025 | Obligations for newly placed general-purpose AI models (GPAI) become applicable. |
| 2 August 2026 | Article 50 transparency obligations become applicable; additional supervisory mechanisms and enforcement powers for GPAI models enter into operation. |
| 2 December 2026 | End of the transitional period for certain technical marking requirements applicable to generative AI systems already on the market before 2 August 2026. |
| 2 December 2027 | Obligations for standalone high-risk AI systems listed in Annex III become applicable. |
| 2 August 2028 | Obligations for high-risk AI systems integrated into products covered by Annex I become applicable. |
What Should Companies Do Now?
An organisation that uses artificial intelligence only for internal activities should not assume that it is automatically outside the scope of the AI Act.
The first step is understanding which AI technologies are being used and for what purposes.
The main operational priorities are:
Identify
Maintain an up-to-date inventory of the AI systems, accounts and integrations used across the organisation.
Assess
Evaluate the intended purpose, processed data, affected individuals and potential level of risk for each AI use case.
Inform
Provide appropriate disclosures in chatbots and in publications that fall within the AI Act transparency obligations.
Document
Maintain records, risk assessments, editorial reviews, training activities and supplier evaluations.
Supervise
Ensure meaningful human oversight over activities that may have significant consequences for individuals or organisations.
Review
Regularly update internal policies and procedures, as AI platforms, regulatory guidance and legal interpretations continue to evolve.
Conclusions
2 August 2026 does not mark the simultaneous application of every obligation introduced by the AI Act. However, it represents a major milestone for transparency requirements relating to AI systems and AI-generated content.
For many organisations, the most immediate compliance obligations concern chatbots, synthetic content, editorial workflows, staff training and the governance of AI suppliers.
While the Digital Omnibus grants additional time for compliance with certain high-risk AI systems, it does not remove the need for organisations to understand, manage and govern the artificial intelligence technologies already used within their business processes.
Key takeaway
Transparency, training and documentation should not be viewed merely as regulatory formalities. They are the means by which an organisation can demonstrate that artificial intelligence is being used responsibly, under appropriate human oversight and within a structured governance framework.
Frequently Asked Questions about the AI Act and the Obligations Applicable from 2 August 2026
What does the date of 2 August 2026 mean under the AI Act?
From 2 August 2026, several additional provisions of the AI Act become applicable, including the transparency obligations under Article 50 relating to chatbots, synthetic content, deepfakes, emotion recognition systems, biometric categorisation systems and certain AI-generated texts on matters of public interest.
Have the obligations for high-risk AI systems been postponed?
Yes. The Digital Omnibus postpones the application of the rules for standalone high-risk AI systems listed in Annex III until 2 December 2027 and for AI systems integrated into Annex I products until 2 August 2028.
Does a website using an AI chatbot have to inform users?
Generally, yes. Users must be informed that they are interacting with an AI system unless the artificial nature of the interaction is already obvious. The notice should be provided before or at the beginning of the first interaction.
Do I have to disclose every image created with artificial intelligence?
No single rule applies to every AI-generated image. The assessment depends on the nature of the content, its context, whether it could reasonably be perceived as authentic and whether it qualifies as a deepfake. Deepfakes must be clearly identified as artificially generated or manipulated.
Is simply writing “AI-generated image” sufficient?
A visible label may satisfy the obligation to inform people in certain situations, but it does not necessarily replace the machine-readable technical marking required from providers of generative AI systems.
Do AI-generated images published before 2 August 2026 need to be labelled retrospectively?
No. The European Commission expressly states that content generated before 2 August 2026 does not need to be labelled retrospectively. Updating previously published content is encouraged where appropriate but is not generally mandatory. Moreover, not every AI-generated image requires a visible disclosure. The publication obligation primarily concerns deepfakes, namely images, audio or video closely resembling real people, objects, places or events that could appear authentic. Clearly illustrative, conceptual or fictional graphics do not automatically fall into this category.
Does C2PA become mandatory from 2 August 2026?
No. The AI Act does not generally require organisations to adopt the C2PA standard. However, C2PA and Content Credentials can help demonstrate the provenance, authenticity and modification history of digital content.
If I publish an AI-generated image on LinkedIn, do I need to disclose it?
It depends on the content and the context. A clearly illustrative graphic is not automatically considered a deepfake. Disclosure becomes particularly important when the image appears authentic, depicts real people, reconstructs events or could reasonably mislead the audience.
Do Canva’s AI features fall within the scope of the AI Act?
Yes, when Canva is used to generate or manipulate content using artificial intelligence. Simply using Canva as a graphic design application does not automatically trigger the obligations applicable to synthetic content.
How should a WordPress website using an AI chatbot be adapted?
The website should clearly inform users that they are interacting with an AI system, display the notice before or during the first interaction and, where appropriate, provide a way to escalate to a human operator. Organisations should also review privacy implications, transmitted data and the AI provider’s contractual terms.
Does using ChatGPT professionally mean a company must comply with the AI Act?
Generally, yes. A company using ChatGPT in a professional context is typically considered a deployer. The applicable obligations depend on how the system is used. AI governance and staff training are broadly relevant, while transparency and additional obligations depend on the specific content or services produced.
Must every article written with ChatGPT be disclosed?
Disclosure is required for AI-generated or AI-manipulated text published to inform the public about matters of public interest. It may not be required where there is effective human editorial oversight and a natural or legal person assumes responsibility for the publication.
Does the AI literacy obligation start on 2 August 2026?
No. The AI literacy obligation has applied since 2 February 2025. Training should be proportionate to people’s roles, the AI systems they use and the risks associated with their activities.
Does using ChatGPT automatically make a company an AI provider?
No. In most cases, a company using a third-party AI service acts as a deployer rather than a provider. However, it may become a provider if it develops, substantially modifies or markets an AI system under its own name or brand.
What is the first document an organisation should prepare for AI Act compliance?
The most useful starting point is an inventory of AI systems and AI use cases. Without a complete inventory, it is impossible to determine responsibilities, assess risks, identify transparency obligations or plan training and governance activities.
Do SMEs also have to comply with the AI Act?
Yes, whenever they fall within the scope of the Regulation. The applicable obligations depend on the organisation’s role and the way AI is used, rather than on company size alone. The AI Act nevertheless provides proportionality measures and specific support for SMEs.
Who is responsible for enforcing the AI Act?
Enforcement involves the European Commission, the AI Office and the competent national authorities. The authority responsible in practice depends on the organisation, the sector and the type of AI system involved.
References and Further Reading
This article is based on the text of the AI Act and the official documents published by the institutions of the European Union. European guidelines support the interpretation of the Regulation but do not replace the legal text or a case-specific legal assessment.
European Artificial Intelligence Act
European Union
Official text of Regulation (EU) 2024/1689 establishing harmonised rules on artificial intelligence within the European Union.
Guidelines on Article 50
European Commission
Official guidance on the application of the transparency obligations for providers and deployers of AI systems.
Transparency Obligations FAQ
European Commission
Official questions and answers on the Article 50 transparency obligations applicable from 2 August 2026.
Transparency of AI-Generated Content
European Commission
Official guidance on technical markings, disclosures and the detectability of synthetic content.
Digital Omnibus and Updated Deadlines
Council of the European Union
Official communication describing the amendments and revised implementation dates for high-risk AI systems.
Rules for General-Purpose AI Models
European Commission
Guidelines for providers of General-Purpose AI (GPAI) models and the enforcement framework applicable from 2 August 2026.
C2PA and Content Credentials
HT&T Consulting
Our in-depth guide to the digital passport for content, media provenance and the technologies used to identify AI-generated files.
Continua a leggere
And it consumes less energy.
To return to the page you were visiting, simply click or scroll.


