EU AI Transparency Guidelines Set August 2 Disclosure Deadline for Providers and Deployers
The European Commission’s July 20 guidelines explain how providers and deployers must disclose AI interaction and label certain generated or manipulated content from August 2.
The European Commission published guidance on July 20, 2026, ahead of the August 2 start date for the EU AI Act’s transparency obligations. The rules are designed to help people recognise when they are interacting with AI and when content has been generated or altered by AI. The practical shift is not a universal “AI label” on everything: different duties apply to providers that build or supply systems and deployers that put them in front of people.
Associated Press — European lawmakers vote on Artificial Intelligence Act
Associated Press provides legislative background on the AI Act behind the Commission’s transparency guidance. If the player fails, use the direct YouTube link.
The Commission says the guidance covers interactive AI systems and the marking and labelling of AI-generated content. It clarifies which providers and deployers must comply under Article 50 of the AI Act, making the August 2 date a useful checkpoint for companies, publishers, public bodies and other organisations that use generative systems in public-facing workflows.
PanoramaDigest has covered the wider policy environment in its AI policy topic hub and its report on the Shanghai World AI Conference. This is a different kind of AI story: the question is not who has the most capable model, but how people are told what they are seeing, hearing or interacting with.
- Interactive systems: Providers must design systems to inform people when they are directly interacting with AI.
- Generated or manipulated content: Providers must add machine-readable marks that enable detection.
- Deepfakes: Deployers must inform people when they are exposed to deepfake content.
- Public-interest content: Deployers must disclose AI-generated content on matters of public interest when it lacks human review or editorial control.
- Biometric and emotional systems: People must be informed when exposed to emotion-recognition or biometric-categorisation systems.
Providers and deployers have different jobs
The distinction between provider and deployer matters because responsibility follows the point of control. A provider designs or supplies an AI system. A deployer uses it in practice, such as placing a chatbot on a service website, publishing generated material, or operating a system that categorises or assesses people. The Commission’s guidance is intended to help organisations determine which obligations apply to their role.
For a provider, the central task is system design. The Commission says providers will have to make users aware when they are directly interacting with AI and add machine-readable marks to AI-generated or manipulated content. A visible notice may help a person, but machine-readable marking is aimed at technical systems that need to detect or process the signal at scale.
For a deployer, the question is exposure. The Commission specifically identifies deepfakes, public-interest content produced without human review or editorial control, and emotion-recognition or biometric-categorisation systems. That means a compliance process cannot stop at the model vendor. Organisations using an external tool still need to understand how their own deployment is presented to people.
Why machine-readable marking matters
A visible label and a machine-readable mark solve different problems. A label is meant to help the person looking at a post, image, video or interface. A machine-readable mark can help platforms, search systems, moderation tools and other software identify that content has an AI origin or has been manipulated.
The approach reflects a larger problem in synthetic media: content can travel far beyond the context in which it was created. A user may see a video after it has been reposted, cropped or translated. If disclosure depends only on a caption that disappears during redistribution, the signal is fragile. Machine-readable information is not a complete solution, but it gives downstream systems something more durable to inspect.
Deepfakes and public-interest content receive special attention
The Commission’s wording puts deepfakes and certain public-interest content in a higher-scrutiny category for deployers. This is understandable: a synthetic image of a fictional character and a fabricated video presented as evidence about an election, disaster or public-health event can have very different consequences.
The public-interest rule also includes an important qualification in the Commission’s summary: the obligation concerns AI-generated content on matters of public interest when there is no human review or editorial control. That does not turn “human in the loop” into a magic exemption. It does mean organisations will need to document how review works and whether a person actually exercised editorial judgment rather than merely clicking approve.
What organisations should do before August 2
| Step | Question to answer | Evidence to keep |
|---|---|---|
| Map the systems | Where do people interact with AI or receive AI-generated content? | Vendor list, product owners and deployment inventory. |
| Assign the role | Is the organisation a provider, deployer or both? | Contracts, technical ownership and workflow diagrams. |
| Define disclosures | Where will people see notices, labels or machine-readable marks? | Interface examples and content-handling rules. |
| Review public-interest use | Who checks AI-generated material before publication or distribution? | Named reviewer, review record and escalation path. |
| Test redistribution | Does the signal survive export, reposting, translation or editing? | Test files, screenshots and machine-readable validation. |
These steps are an operational checklist, not legal advice. The Commission’s full guidelines, questions and answers, factsheet and Code of Practice are the controlling sources for organisations assessing their own obligations.
What the guidance does not establish
The July 20 publication is guidance, not a claim that every compliance question has been resolved for every business model. It does not mean that users can identify every synthetic image with certainty, and it does not replace sector-specific rules or an organisation’s own risk assessment. It also does not make a visible label proof that content is authentic when no label appears.
The larger policy bet is that disclosure becomes part of the technical infrastructure of AI services rather than an optional courtesy. If providers build reliable signals and deployers use them consistently, people may gain more context when they meet an AI system or encounter synthetic media. If labels are inconsistent, removable or too vague, the rules will be harder to apply and easier to misunderstand.
Watch related newsroom context: the Associated Press video European lawmakers vote on the Artificial Intelligence Act provides background on the law behind today’s guidance. If the player does not load, use the direct YouTube link.
Read Next
Related Stories
Shanghai World AI Conference: Xi Pitches China's Global AI Cooperation Plan
At the World Artificial Intelligence Conference in Shanghai, Xi Jinping called for shared AI governance and announced training, weather-tool access and new cooperation initiatives for developing countries.
EU Agrees €115 Million AGILE Defence Innovation Programme for SMEs
The EU reached a provisional agreement on AGILE, a €115 million programme designed to help defence startups and SMEs move emerging technologies from prototypes toward operational use.
Apple Sues OpenAI Over Trade Secrets as the AI Hardware Race Moves Into Court
Apple's July 10 lawsuit accuses OpenAI, io and former Apple executives of using confidential Apple knowledge to speed up AI hardware development. The larger technology story is that the next device fight is now about suppliers, recruiting discipline and what courts will let labs build from insider know-how.