← Back to all posts
News

The EU Starts Requiring AI Labels on Sunday, With Fines to 3% of Turnover. The Final Rulebook Landed 13 Days Before the Deadline.

July 28, 2026 ยท 10:14 UTC · News
The EU Starts Requiring AI Labels on Sunday, With Fines to 3% of Turnover. The Final Rulebook Landed 13 Days Before the Deadline.

TL;DR

On Sunday, August 2, Article 50 of the EU AI Act becomes enforceable. From that date, chatbots serving EU users must disclose they are AI, providers of generative systems must embed machine-readable marks in every synthetic image, video, audio clip, and text output, and deployers must visibly label deepfakes and AI-written text on matters of public interest. Non-compliance carries fines of up to 15 million euros or 3% of worldwide annual turnover under Article 99. The European Commission adopted the final implementation guidelines on July 20, which gave everyone shipping an AI product in Europe 13 days to read them.


What switches on Sunday

Article 50 splits its duties between providers (whoever builds the system and puts it on the market under their own name) and deployers (whoever uses it professionally). That distinction decides which problems are yours.

who owes what under article 50, from aug 2 chatbot must disclose it is AIPROVIDER outputs carry machine-readable marksPROVIDER emotion / biometric systems disclosedDEPLOYER deepfakes + civic AI text labeledDEPLOYER provider = ships the system under their name; deployer = uses it professionally
Four duties, two roles. If you ship the system, the top two are yours; if you publish with it, the bottom two are.

The marking duty is the one most builders have not priced in. The Act requires outputs to be "marked in a machine-readable format and detectable as artificially generated or manipulated," with solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible." Note who that lands on: the provider of the AI system, not the lab behind the base model. If your product calls a model API and emits images under your name, the provider is you.

The rules affect professional use; the EU has said individuals using AI in a purely personal capacity are not affected, per The Local's explainer. China, for what it is worth, has required labels on AI-generated content since September 2025. The EU is arriving second, with bigger fines.

The rulebook landed 13 days before the deadline

The obligations were enacted in 2024, but the how-to arrived in a sprint this summer. Draft guidelines appeared on May 8, the consultation closed June 3, the final Code of Practice on Transparency of AI-Generated Content was published June 10, and the Commission adopted the final guidelines on July 20. The window to join the first wave of Code signatories closed at 18:00 CET on July 22. The Commission shipped its compliance documentation the way the rest of us ship launch-day landing pages: at the last possible minute, with a form to fill out.

may 8draft rules jun 10final code jul 20final guidelines jul 22sign-by aug 2LIVE dec 2: proposed marking grace, not yet adopted
From draft guidance to enforceable law in 86 days. The final guidelines gave builders 13 days.

The Code is voluntary, but not decorative. Signing it buys a recognized path to compliance; skipping it means demonstrating "alternative equivalently adequate means" to a regulator, with the evidentiary burden that implies, per Greenberg Traurig's analysis.

One moving part is still moving: the pending AI Omnibus package would push the machine-readable marking duty for systems already on the market to December 2, 2026. It has not been formally adopted, so August 2 is the operative date. The Act's high-risk tier (hiring, credit scoring, and the rest) sits on a slower track toward late 2027.

A watermark alone does not save you

Article 50 layers two different kinds of transparency, and conflating them is the easiest way to be non-compliant while feeling compliant. The machine-readable mark is for software: metadata, watermarks, and provenance signals that detection tools can query. The disclosure duties are for humans: a person seeing a deepfake or chatting with a bot must actually be told. Think of a grocery item: the barcode is for the scanner, the ingredients label is for the shopper, and the law wants both on the package.

The Commission's guidelines are explicit that invisible marks do not discharge the human-facing duties, because users do not notice metadata at the point of interaction; they call for combined approaches such as plain-language notices, audio cues, and persistent visual indicators, and the Commission has published a harmonized icon set for labeling AI content. On the machine side, the Code points to layered solutions combining metadata, watermarking, and provenance standards rather than mandating one technique. The existing tooling maps cleanly: C2PA Content Credentials for provenance metadata, and watermarking systems like Google DeepMind's SynthID for the imperceptible layer.

TechPolicy.Press flags the honest caveats: there are no evaluation standards for what counts as a robust mark, forensic detection remains unreliable, and the line between a deepfake and ordinary editing is still fuzzy. The framework is a starting point that will be interpreted in enforcement, which is exactly the kind of sentence that should make you keep receipts.

The fine print on fines

Several headlines this week quoted fines of 35 million euros or 7% of turnover. That is the Act's top tier, reserved for prohibited practices like social scoring. Transparency violations sit in Article 99(4): up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. Small and medium-sized enterprises pay the lower of the applicable caps.

max fine per tier, art. 99 (EUR millions, or % of turnover if higher) banned practices35m / 7% art. 50 labeling15m / 3% smes: the lower of the caps applies (art. 99(6))
Unlabeled AI content is the 15M/3% tier. The 35M/7% number in the headlines belongs to social scoring, not your image generator.

The exemptions that matter

  • Obvious bots. Chatbot disclosure is waived when it is obvious to a reasonably well-informed person that they are talking to a machine. Your CLI agent is fine; your suspiciously friendly support widget is not.
  • Assistive editing. Systems performing an assistive function that does not substantially alter the input escape the marking duty. Autocomplete and denoising, yes; full generation, no.
  • Art and satire. Evidently artistic, creative, satirical, or fictional work only needs minimal, non-intrusive disclosure of the AI's existence.
  • Edited text. AI-drafted text that went through human review with someone holding editorial responsibility is exempt from the civic-text labeling duty.

One sharp edge from the guidelines: the deepfake duty does not depend on any intent to deceive, and it covers photorealistic depictions of people who do not exist. In the EU, a person who was never born is still entitled to a caption saying they are not real.

What to do before Sunday

If EU users touch your product: put an "AI" disclosure on any conversational surface where that is not already obvious. Turn on whatever provenance and watermarking your model host exposes, and emit C2PA metadata on generated media you serve. If your users can publish realistic depictions of people from your tool, give them a visible-label path, because their deployer duty becomes your support ticket. And read the Commission's guidelines directly; they are the document a regulator will quote back at you.

Key Takeaways

  • Article 50 of the EU AI Act applies from Sunday, August 2, 2026: chatbot disclosure, machine-readable marking of synthetic content, and visible labels on deepfakes and AI-written public-interest text.
  • The marking duty falls on whoever ships the system under their own name, including thin wrappers around model APIs.
  • Fines reach 15 million euros or 3% of worldwide turnover (Article 99(4)); the widely quoted 35M/7% is the prohibited-practices tier.
  • The final guidelines were adopted July 20 and the final Code of Practice on June 10; the first signatory window closed July 22.
  • Invisible watermarks alone do not satisfy the human-facing duties; the guidelines demand notices people actually see, on top of machine-readable marks.
  • A pending Omnibus amendment could delay the marking duty for existing systems to December 2, but it is not adopted; August 2 stands.

Sources: EU AI Act, Article 50, EU AI Act, Article 99, European Commission: Guidelines on Transparency of AI-Generated Content, European Commission: Code of Practice on AI-Generated Content, Greenberg Traurig, The Local, TechPolicy.Press

AIEU AI ActRegulationDeepfakesWatermarkingCompliancePolicy
CONSOLE
$