On 2 August 2026, the transparency obligations of the EU AI Act came into force. They are short, they are practical, and they apply to a great many companies that have never once thought of themselves as an AI company.
The rule, in plain words: if a person is dealing with an AI system, they have to be able to know it. If content has been artificially generated or manipulated, it has to be marked as such in a way a machine can read.
Most of the attention this summer went to the high-risk deadline moving to December 2027. This one did not move. It started.
Four places it usually lands
1. The support chatbot. The commonest case, and the easiest to fix. If a visitor could reasonably think they are talking to a person, they should be told they are not — at the start of the conversation, not buried in a policy.
2. AI-drafted content you publish. Newsletters, product descriptions, social copy, generated images. Where content is artificially generated or altered, it needs marking, and the marking needs to survive being copied.
3. Synthetic voice. Call-centre agents, IVR, voice assistants. The same principle: a caller should not have to work out whether the voice is a person.
4. Anything that looks like somebody real. A generated likeness or voice of a real person carries its own disclosure duty, and it is the one that turns into a story rather than a fine.
Why this is easier than it sounds
Nothing here asks you to stop using AI, to slow anything down, or to explain how a model works. It asks you to be plain about what a person is dealing with. In almost every case the fix is a sentence, a label, or a field in a template.
What makes it awkward is not the rule. It is the inventory. Most organisations cannot answer “where do we use AI where a member of the public can see the output?” in one sitting, because the answer is spread across marketing, support, product and whichever team bought a tool last quarter.
A one-hour version you can run yourself
- List the touchpoints, not the tools. Every place a customer, candidate or member of the public receives something. Then mark which of those involve AI anywhere in the chain.
- Name an owner for each. Not a department — a person.
- Write the sentence once. One approved form of words for “you are talking to an assistant” and one for “this was produced with AI”, so four teams do not invent four versions.
- Check what your vendors emit. If a tool generates content or speech for you, ask what marking it applies and get the answer in writing.
- Write down what you decided, and why. The decision is worth more than the sentence, because it is what you will be asked about.
The part worth taking seriously
Transparency obligations are the ones a customer, a journalist or a competitor can check from the outside, without any access to your systems. That makes them unlike almost everything else in the Act. You do not find out you have a problem through an audit. You find out publicly.
Which is also the opportunity. Being visibly straight about where AI is used is cheap, it is checkable, and very few of your competitors have bothered. It is one of the rare pieces of compliance work that reads as confidence rather than caution.
The question to ask on Monday
Where could someone outside this company meet our AI without being told? If nobody can answer that in the room, the answer is “somewhere”.