The rules divide responsibility between companies that provide AI systems and those that use them, with maximum fines set at the higher of €15 million or 3% of worldwide annual revenue.
The European Commission published guidelines Monday explaining how companies must follow EU AI transparency rules that take effect Aug. 2.
The rules require companies to disclose when people are interacting with AI or being analyzed by systems that assess emotions or use biometric data to categorize them. They also require companies to make AI-generated content detectable and clearly label deepfakes.
The Commission issued the guidelines less than two weeks before Article 50 of the EU AI Act takes effect. The 50-page document explains which systems and content fall under the rules, what companies must disclose and how regulators will enforce the requirements.
Providers must build transparency into AI systems
Under the AI Act, a provider is a company or organization that develops an AI system itself, or hires another party to develop it. Then it makes the system available or begins using it under its own name. This includes systems sold to customers, provided for free or developed for the company’s own internal use.
Providers of AI systems that interact directly with people must make clear from the first interaction that the person is dealing with AI. The disclosure is not required when the AI interaction is already obvious, although the guidelines say regulators should apply that exception narrowly.
Providers of generative AI systems must also place machine-readable marks in synthetic text, images, audio and video. Those marks must allow automated tools to detect that AI generated or changed the content.
Standard editing that does not substantially change the original material is generally outside that requirement. The guidelines also exclude source code, short strings of numbers or symbols, and content used only in closed industrial or production systems before it becomes a final output.
Businesses using AI have separate duties
The AI Act defines a deployer as a company or organization using an AI system under its authority. Employees and contractors operating the system under the company’s control are not treated as separate deployers.
Deployers using emotion recognition or biometric categorization must tell people exposed to those systems.
Companies must also clearly label AI-generated or altered images (i.e., “Deepfakes”) and audio or video that could falsely appear authentic. The disclosure must be visible or audible by the time a person first encounters the content. A hidden machine-readable mark alone is not enough.
AI-generated or altered text published to inform the public about matters such as politics, public health, consumer safety, or financial developments must also carry a label. The label is not required when the text has received either substantive review by someone with relevant knowledge or meaningful editorial review, and a person or organization accepts legal responsibility for its publication. Spell-checking or grammar correction alone does not count.
Deadline, grace period and fines
Most EU AI transparency rules apply starting Aug. 2. The guidelines provide a limited grace period extending to Dec. 2 for systems placed on the market before Aug. 2, but only for the requirement to add machine-readable marks to synthetic content. Content generated before Aug. 2 does not have to be labeled retroactively.
Government regulators appointed by each EU country will investigate most violations and impose penalties. The Commission’s AI Office will handle cases involving systems built on general-purpose AI models when the same company provides both the model and the finished system. It will also oversee AI systems integrated into the EU’s largest online platforms and search engines. The European Data Protection Supervisor will enforce the rules for AI used by EU institutions and agencies.
For companies, fines can reach the higher of €15 million or 3% of worldwide revenue from the previous financial year. For small and medium-sized companies, the maximum is the lower of those two amounts.
The guidelines explain how the Commission interprets the AI Act but are not legally binding. The EU has separately issued a voluntary Code of Practice that sets out specific methods for marking and labeling AI-generated content. Companies can formally commit to following the code by having a senior executive sign and submit the required commitments to the European Commission. Companies that follow those commitments can point to them as evidence of compliance. Those that do not join must show regulators that their own methods meet the law equally well.

