Skip to main content
Enterprise AI

EU AI Act Transparency Rules: What Actually Changed on 2 August 2026

The EU AI Act's transparency duties became enforceable on 2 August 2026, and national regulators started supervising the AI literacy obligation the same day. The high-risk regime most companies budgeted for slipped to December 2027. Here's what applies now.

kju Team

kju Team

AI Education Experts

5 min read
Two colleagues reviewing printed AI policy documents together in a bright European office, illustrating EU AI Act transparency and AI literacy obligations

On 2 August 2026 the EU AI Act stopped being a planning exercise. The transparency duties in Article 50 became enforceable that day, and national market surveillance authorities began supervising the AI literacy obligation in Article 4.

The part most companies spent 2025 budgeting for — the high-risk regime — is not what arrived. It moved to December 2027.

So the obligations that landed are the ones almost nobody built a programme for: telling people when they are talking to a machine, marking synthetic content, and being able to show that your staff know what they are doing with AI.

Article 99(4) sets the ceiling for breaching the Article 50 transparency duties at administrative fines of up to €15 million or, for an undertaking, 3% of total worldwide annual turnover, "whichever is higher" — confirmed in the Commission's 2 August 2026 announcement. For SMEs and start-ups, Article 99(6) flips it: whichever is lower.

What Changed on 2 August 2026?

Three things became live: Article 50 transparency duties, national supervision of the Article 4 AI literacy obligation, and a shifted calendar for everything else. The Commission confirmed on 31 July that the AI Office and national authorities would begin enforcing from 2 August, alongside a voluntary Code of Practice on transparency of AI-generated content that more than 180 organisations have already signed.

The calendar is the fastest way to see what you actually owe and when.

ObligationStatus as of today
Article 4 AI literacyApplicable since 2 February 2025; supervised and enforced by national authorities since 2 August 2026
Article 50 transparency (chatbot disclosure, synthetic content marking, emotion-recognition notice, deep fake and AI-text labelling)Enforceable since 2 August 2026
Marking of systems placed on the market before 2 August 2026Grace period to 2 December 2026
Prohibition on generating non-consensual intimate imagery and CSAM2 December 2026
National regulatory sandboxes2 August 2027
Standalone high-risk systems (Annex III)Moved from 2 August 2026 to 2 December 2027
Product-embedded high-risk systems (Annex I)Moved from 2027 to 2 August 2028

The delays came through the 2026 Digital Omnibus, analysed in detail by Gibson Dunn and Jones Walker. Both reach the same conclusion: the high-risk postponement did not touch transparency, and 2 August still mattered.

What Do the Transparency Rules Actually Require?

Article 50 turns five everyday AI behaviours into disclosure duties. They apply to ordinary tools — support chatbots, marketing image generators, voice agents, drafting assistants — not just to systems anyone would call high-risk. The Commission's quick facts page is the clearest summary of scope.

In practice:

  1. Interaction disclosure (50(1)). If a person is talking to a chatbot, an agent or an AI avatar, they have to be told — unless it is obvious to a reasonably well-informed, observant and circumspect person.
  2. Synthetic content marking (50(2)). Providers of systems generating synthetic audio, image, video or text must mark the outputs in a machine-readable format, detectable as artificially generated or manipulated.
  3. Emotion recognition and biometric categorisation (50(3)). Deployers must inform the people exposed to the system that it is operating, and process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. Read this one next to Article 5(1)(f), which prohibits inferring emotions in the workplace and in education institutions altogether, except for medical or safety reasons. If someone is pitching you sentiment analysis on employee calls, where it infers emotion from voice or other biometric signals, that is the article to quote.
  4. Deepfake disclosure (50(4)). Deployers publishing AI-generated or manipulated image, audio or video content constituting a deep fake must disclose that it has been artificially generated or manipulated.
  5. AI text on matters of public interest (50(4)). Text published to inform the public has to be labelled as AI-generated — unless a human reviewed it and someone holds editorial responsibility for it.

The last duty is the one with teeth for ordinary teams. It does not say "do not use AI to write". It says a named human has to have actually reviewed the output and be willing to own it. That is a judgement standard, not a tooling standard — and it is the same standard your AI fluency programme should already be teaching.

Why the High-Risk Delay Doesn't Buy You Time

The AI literacy obligation was not delayed, and as of 2 August it has a supervisor. The Commission's guidance names the national market surveillance authorities "which start supervising and enforcing the rules as of 2 August 2026".

What did change is the wording. The Commission now describes Article 4 as requiring providers and deployers "to take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf" — and adds, in terms: "This does not imply that a certain level of AI literacy of any individual is required."

Article 4 of the EU AI Act requires providers and deployers to take measures to support the development of AI literacy among staff operating AI on their behalf. The Commission is explicit that "no specific – or 'sufficient' - level is mandated (Article 4(1))". The duty is proportionate to role and context — and since 2 August 2026 it has a supervisor.

Read that carefully before relaxing. It removes the phantom obligation to certify every employee at a fixed standard. It does not remove the obligation to have done something deliberate, proportionate to role and context, and demonstrable when a regulator asks. If anything, a softer standard shifts the burden from a certificate you can buy to a practice you have to show.

We covered the underlying duty in detail in our guide to EU AI Act Article 4 and AI literacy. The short version: it is sector-agnostic, size-agnostic, applies regardless of risk class, and reaches contractors and vendors operating AI on your behalf.

Every one of the new duties resolves to a decision an individual employee makes, usually in under a minute, with no lawyer present. Someone drafts a customer response and decides whether to disclose. Someone generates a campaign image and decides whether to mark it. Someone publishes a summary and decides whether they have actually reviewed it.

The evidence says those decisions are being made badly right now — not maliciously, but reflexively.

SignalFindingSource
Work delivered without understanding41% say they sometimes deliver AI-generated work they couldn't explain if askedGlean Work AI Index 2026 (n=6,000, fielded Dec 2025–Jan 2026)
Knowingly shipping bad output12% knowingly ship AI-generated output they believe is wrongGlean Work AI Index 2026, section 05
Unapproved toolsRoughly 1 in 3 professionals rely on AI their organisation has not approvedThomson Reuters Future of Professionals 2026 (n=1,816, 62 countries, fielded Mar–Apr 2026)
Feeling equippedOnly 36% of workers say they have the training and resources they need to use AI — down from 45% in 2024JFF / AudienceNet (n=3,020, fielded Nov–Dec 2025)

An employee who cannot explain the output they just sent has not performed the human review that Article 50 relies on. That is not a compliance gap you close with a policy PDF. It is a capability gap — the same supervision work that follows every AI output, now with a legal consequence attached — and the shadow AI dynamic that kept it invisible is what makes it a live regulatory risk today.

What to Do in the Next 90 Days

Start from your AI inventory, not your policy library. Enforcement questions will be concrete: which systems, which disclosures, which people, what did you teach them, and when.

Five moves that hold up:

  1. List every place your organisation shows AI output to a person. Support chat, voice menus, generated imagery, published copy. Each one maps to one of the five duties above.
  2. Fix the machine-readable marking at the tool layer. Watermarks and provenance metadata are a procurement and configuration job, not something a workforce can do by hand. Check what your vendors already emit.
  3. Make the human-review standard explicit. Write down what "reviewed" means for your content: claims verified, sources checked, a named owner. Then teach it as a skill.
  4. Tier your literacy programme by role. The Commission asks for proportionality. Executives, front-line users, technical teams and procurement need different depth — and that is the same tiering good enterprise AI training uses anyway.
  5. Keep records. What was delivered, to whom, when, on what topic. The proficiency bar softened; the evidentiary expectation did not.

The organisations that will find August 2026 uneventful are not the ones with the thickest AI policy. They are the ones where a person who generated something can tell you what it says, where it came from, and why they trust it. That is a daily practice, and the next enforcement date is already on the calendar.

Frequently Asked Questions

What does the EU AI Act require from 2 August 2026?
From 2 August 2026, the AI Act's Article 50 transparency duties are enforceable. Chatbots and AI agents must tell people they are not human, providers must mark synthetic audio, image, video and text in a machine-readable format, deployers must disclose deep fakes, and national authorities began supervising the Article 4 AI literacy obligation the same day.
Are the EU AI Act's high-risk rules delayed?
Yes. The 2026 Digital Omnibus pushed the standalone high-risk regime under Annex III from 2 August 2026 to 2 December 2027, and product-embedded high-risk systems under Annex I from 2027 to 2 August 2028. The transparency duties and the AI literacy obligation were not delayed.
Do companies have to label AI-generated content?
Yes, in two ways. Providers must mark synthetic image, audio, video and text in a machine-readable format. Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest must be labelled unless a person reviewed it and holds editorial responsibility.
Does the AI literacy obligation apply if we only use chatbots?
Yes. Article 4 applies to any organisation deploying an AI system in the EU, regardless of risk class, and everyday assistants and chatbots count. Since 2 August 2026, national market surveillance authorities supervise it. The obligation is to support AI literacy proportionate to role and context, not to certify anyone at a fixed level.
What are the penalties for breaching the AI Act transparency rules?
Article 99(4) sets fines of up to 15 million euro or, for an undertaking, 3% of total worldwide annual turnover, whichever is higher. Article 99(6) caps SMEs and start-ups at whichever is lower, and Article 100 caps EU institutions and bodies at 750,000 euro. National market surveillance authorities apply the penalties.