Brussels has finally told AI developers what "label your deepfakes" actually means in practice — and it has done so with less than two weeks to spare before the rule bites.

On Monday, 20 July 2026, the European Commission published its final Guidelines on the transparency obligations in Article 50 of the AI Act, a non-binding but closely watched document that translates the law's spare statutory language into worked examples, exemptions and edge cases. The timing is not incidental. Article 50's core transparency duties — telling people when they are talking to a chatbot, marking AI-generated content in a machine-readable way, and labelling deepfakes — become legally applicable on 2 August 2026, the same date the Commission's enforcement powers over general-purpose AI (GPAI) model providers switch on.

"With today's guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people, such as chatbots and AI agents, and AI content more transparent and trustworthy," said Henna Virkkunen, the Commission's Executive Vice-President for Tech Sovereignty, Security and Democracy. "These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI."

What the guidance actually requires

The Guidelines organise Article 50 around a handful of concrete scenarios. Providers of directly interactive systems — chatbots, voice assistants, AI agents — must design them so a person is explicitly told they are dealing with a machine, unless that fact is already obvious from the context. Providers of generative systems that produce synthetic audio, images, video or text must embed machine-readable markers so the output can be detected downstream as artificially generated or manipulated. Deployers carry their own duties: anyone using emotion-recognition or biometric-categorisation tools must inform the people exposed to them, and anyone publishing a deepfake, or AI-generated text on a matter of public interest that has not had human editorial review, must disclose it.

Crucially, the Commission stresses that these duties sit apart from the Act's risk tiers. Article 50 can catch an ordinary consumer chatbot that is nowhere near "high-risk," and complying with it does not discharge the separate high-risk obligations under Chapter III. The Guidelines also spell out the escape hatches. Interaction disclosure can be waived where the artificial nature is obvious — the document cites a diagnostic tool used only by trained clinicians as an example. Marking duties do not bite where a system performs only "standard editing" or minor alterations, such as technical reconstruction or annotation of a medical image.

The Guidelines complement a voluntary Code of Practice on marking and labelling AI-generated content that the Commission published on 10 June 2026. That Code points providers toward a layered technical approach — cryptographically signed C2PA content credentials combined with imperceptible watermarking of the kind Google's SynthID represents — and offers signatories a presumption that they are meeting Article 50(2). Firms that go their own way must still show their measures are adequate.

A transparency-first bet, with hard timing

The through-line of the EU's approach is a wager that disclosure — not prohibition — is the workable lever for synthetic media at scale. It is a lighter touch than an outright ban, but it lands unevenly. Under the AI Omnibus that the Council gave final approval on 29 June 2026, the bloc pushed back its most demanding high-risk deadlines — Annex III systems now have until December 2027, Annex I until August 2028 — yet deliberately left the Article 50 transparency clock untouched at 2 August 2026. Providers whose generative systems were already on the market get a four-month grace period, to 2 December 2026, to retrofit detectability. Separately, a new ban on AI "nudifier" tools and intimate-image deepfakes takes effect on 2 December 2026.

The enforcement question is where the transparency-first bet gets tested. Critics have noted a mismatch between the mandate and the maturity of the technology: watermarks can be cropped, compressed or stripped, and no marking scheme is yet robust across every format. The Guidelines and Code lean on "state-of-the-art" and "adequacy" standards rather than a fixed technical bar, which gives regulators flexibility but leaves companies guessing at where the line sits.

Running alongside the transparency package is the Commission's Action Plan on Cybersecurity and AI, presented on 7 July 2026 with the EU agency ENISA. It creates no new obligations, but sets out how existing rules — the AI Act, NIS2, the Cyber Resilience Act and DORA — will be applied to advanced models, and promises an independent EU model-evaluation capability by 2027 and a secure testing platform by the end of 2026.

What to watch

Watch whether the AI Office actually exercises its new compulsion powers after 2 August, or spends the autumn in persuasion mode. Watch the take-up of the voluntary labelling Code among the big model providers — thin sign-up would signal that industry sees the technical mandate as running ahead of what watermarking can deliver. And watch the December grace-period cliff, when systems already on the market must be detectable in practice, not just in principle.

"These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI."
- Henna Virkkunen, EVP for Tech Sovereignty, European Commission
Aug 2
Article 50 applies
July 20
Guidelines published
Dec 2
Detectability grace period
July 7
Cyber action plan