The EU AI Act Takes Effect: What Changes for Companies Using AI
On August 2, 2026, the transparency requirements of the EU AI Act began to apply.
Until now, companies adopting AI have mainly focused on performance and operational efficiency. Going forward, they also need to consider whether users are clearly informed when they are interacting with AI and whether AI-generated content can be identified as such.
These requirements are particularly relevant to customer service chatbots, AI avatars, and image, video, audio, and text generation tools that users encounter directly. They may apply not only to companies that develop and sell AI systems, but also to businesses that use third-party AI services for marketing, customer support, training, and other operations.
Under Article 50 of the EU AI Act, these transparency obligations apply from August 2, 2026.
So, what exactly changes for companies using AI? Here are the key requirements businesses should review in practice.
Why Is the EU AI Act Receiving Attention Again?
The EU AI Act does not regulate every AI system in the same way. Its requirements vary depending on how an AI system is used and the level of risk it presents.
Rules on prohibited AI practices and AI literacy began to apply in February 2025, while obligations for general-purpose AI models took effect in August 2025. From August 2026, the Act’s broader provisions, including transparency requirements for chatbots, synthetic content, and deepfakes, began to affect day-to-day business operations.
Some requirements for high-risk AI systems will be introduced separately according to their respective implementation schedules.
For many companies, the most relevant changes concern AI services and content that customers or employees encounter directly.
People should be able to tell whether they are communicating with another person or with an AI system. They should also be able to determine whether an image, audio clip, or video is an authentic record or something generated or manipulated by AI.
For businesses, disclosing the use of AI is no longer simply a matter of good practice. It is becoming part of the operating standards that must be considered when designing services and publishing content.

① Companies Must Disclose When Users Are Interacting with AI
When a company provides a customer service chatbot, AI assistant, or AI avatar that communicates directly with people, the system should be designed so that users understand they are interacting with AI.
For example, if a customer service interface uses a human-sounding name and profile image while the responses are actually generated by AI, users should be able to recognize this easily.
A company could provide a notice at the beginning of the conversation stating that the service is AI-powered. It could also display a persistent label identifying the system as an AI assistant throughout the interaction.
A separate notice may not be necessary when it is already obvious to a reasonable user that the service is operated by AI.
The key question is not whether the company internally knows that the system uses AI. It is whether an ordinary user can reasonably recognize that fact while using the service.
Companies should therefore review more than the technical functionality of their chatbots. The chatbot’s name, profile image, introductory message, and on-screen labels should also be examined.
② AI-Generated Content May Require Machine-Readable Marking
Separate obligations apply to providers of AI systems that generate or manipulate images, audio, video, or text.
The outputs of these systems should include machine-readable information that makes it possible to identify the content as AI-generated or AI-manipulated.
This may include metadata, digital watermarks, or content provenance information that platforms and detection systems can use to determine how the content was created.
In other words, simply placing a visible “AI-generated” label in the corner of an image may not be enough to satisfy the technical marking obligations that apply to providers.
The European Commission expects marking methods to be effective, reliable, and, where technically feasible, interoperable with other systems.
These obligations mainly concern companies that develop and provide generative AI systems under their own name. Developers of AI models and content-generation services may therefore need to consider content provenance and traceability from the product design stage.
③ Deepfakes Must Be Clearly Disclosed to Viewers
When AI is used to synthesize a real person’s face or voice, or to create an image or video that appears to depict a real event, viewers should be informed that the content was generated or manipulated.
For example, a company that uses a realistic AI-generated advertising model or creates a promotional video with a synthetic version of an executive’s voice may need to provide a visible disclosure.
Embedding technical information inside the file may not be enough. The viewer should be able to recognize from the screen, caption, or accompanying description that AI was involved.
This is especially important for advertising, corporate communications, training videos, and customer-facing content that could easily be mistaken for footage of a real person or event.
The EU AI Act distinguishes between the provider’s responsibility to include machine-readable marking and the user company’s responsibility to disclose deepfake content to people.
This means that the company developing the AI tool and the company using it to produce and publish content may each have separate obligations.

④ AI-Written Content on Matters of Public Interest May Also Require Disclosure
The EU AI Act does not require every AI-assisted document or post to carry a label.
However, disclosure may be required when AI is used to generate or manipulate text that is published to inform the public about matters of public interest, including politics, the economy, society, health, and public safety.
Possible examples include news-style articles, explanations of public policy, and informational content addressing significant social issues.
An exception may apply when a person reviews the content, exercises editorial control, and accepts responsibility for the final publication.
The key issue is therefore not simply whether AI was used. What matters is whether a person meaningfully reviewed the content and took editorial responsibility for it.
A company does not necessarily need to label every blog post or press release that was drafted with AI assistance. However, if AI effectively produced public-interest content with little or no meaningful human review, the company may need to examine whether the transparency requirement applies.
Before publication, it should be clear who is responsible for fact-checking, editing, and final approval.
⑤ Emotion Recognition and Biometric Categorization Also Require Notice
Companies using systems that analyze a person’s face, voice, or behavior to infer emotional states may also need to inform the individuals being analyzed.
The same applies to systems that categorize people based on biometric information.
These technologies receive particular attention because they may evaluate individuals without their knowledge.
Companies adopting such systems should therefore assess more than their technical accuracy. They should also determine when and how the people affected will be informed.
Depending on the purpose and context, emotion-recognition and biometric-categorization systems may also be subject to additional restrictions or prohibitions.
Before deployment, companies should review not only the transparency obligation but also whether the intended use is permitted at all.
Companies Using Third-Party AI Services Must Review Their Responsibilities Too
The EU AI Act distinguishes between companies that provide AI systems under their own name and organizations that use third-party AI systems in their operations.
A company that develops an AI system, commissions its development, and places it on the market under its own name may be considered a provider.
A company using an external AI service for customer support, content creation, or internal operations may instead be treated as a deployer.
Even if a company does not develop its own model, separate disclosure obligations may still arise when it uses deepfake content in advertising, publishes AI-generated public-interest information, or deploys emotion-recognition technology.
It is therefore difficult to conclude that the regulation is irrelevant simply because a company is not an AI developer.
Businesses should first review the following:
- Which AI systems are currently being used, and for what purposes?
- Does the company provide the system directly, or use a third-party service?
- Are AI-generated outputs shown to customers or the general public?
- Can users easily recognize when AI is involved?
- Is there a human review and approval process before publication?
Marketing, customer service, human resources, training, and security teams deserve particular attention because their AI systems often interact directly with employees, customers, or members of the public.

Responsible AI Use Requires More Than a Label
The central purpose of the EU AI Act is not simply to discourage companies from using AI.
It is to ensure that users can recognize when AI is involved and that companies manage AI-generated outcomes responsibly.
Going forward, the important question will not only be how widely a company uses AI. It will also be whether that AI is being operated under clear principles, responsibilities, and procedures.