EU's AI transparency rules come into force, demanding clear disclosure of AI use in customer interactions

The European Union has implemented its first major transparency requirements under the AI Act, requiring companies to disclose when AI systems influence customer-facing content, marking a shift towards greater accountability in artificial intelligence deployment.

The first major transparency obligations under the EU’s Artificial Intelligence Act took effect on 2 August, marking a shift from broad political debate to day-to-day compliance for businesses that use AI in front of customers. The regulation entered into force on 2 August 2024 and is being rolled out in stages, with the latest phase focused less on banning technology than on forcing companies to disclose when AI is shaping what people see or read. According to the European Commission and the official text of the Act, the framework is designed to make AI systems safer, more trustworthy and more transparent.

The law is built around risk tiers. The most intrusive practices, including social scoring and certain forms of manipulation, were already prohibited earlier this year, while high-risk uses such as recruitment, education, credit assessment and critical infrastructure are subject to fuller compliance obligations on later timelines. For most firms outside the technology sector, however, the immediate issue is simpler: if AI sits between the business and the public, that fact has to be made visible.

Article 50 is the key provision. The European Commission says it requires people to be told when they are interacting with an AI system, and it also covers synthetic content, deepfakes and certain systems that infer emotion or classify biometric data. In practical terms, a customer-facing chatbot must identify itself as such, and AI-generated or manipulated material that could be mistaken for reality needs clear disclosure.

That matters because the rule is narrower than some public discussion suggests. It is not a general requirement to label every AI-assisted image or every piece of machine-edited text. The focus is on material where a reasonable viewer might believe they are seeing a real person, a real event or an unassisted human message. The transparency duty is therefore aimed at deception risk, not at all uses of generative software.

Greece has already moved to put enforcement in place. The national law published in July assigns oversight of the transparency rules to the Hellenic Data Protection Authority, which already has an established complaints process and an enforcement role familiar to the public. The legislation also gives authorities power to publish decisions naming the offender, a sanction that can matter as much as any fine for smaller firms.

One provision has drawn particular attention: deliberate removal of AI labels or of notices identifying deepfakes may carry criminal penalties as well as financial ones. That scope is broad enough to cover not only the original creator of the material but also anyone who edits or republishes it after the label has been stripped. For content teams, that makes workflow design a legal issue, not just a technical one.

The Act also expects firms to ensure staff have an adequate level of AI literacy. The Commission says that requirement has applied since February 2025, and the Greek legislation allows regulators to take training into account when assessing penalties. That does not remove liability, but it does mean employee training may become part of a company’s defence file as well as its governance programme.

For smaller businesses, the challenge is likely to be practical rather than ideological. Compliance costs will be easier to absorb in a large multinational than in a local accountancy firm or a small media operation. Yet the direction of travel is clear: Europe has chosen disclosure over prohibition in this part of the AI market, and from now on the question is not whether AI is used, but whether its use is openly stated.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.