New EU rules on artificial intelligence are now in force: what do businesses need to know?

Artificial intelligence is already part of the daily operations of thousands of companies—from customer service and content creation to data analysis, automation and business decision support.

However, from 2 August 2026, the use of certain AI systems in the European Union is subject to new and more specific obligations.

The new rules do not prohibit the use of artificial intelligence. They require greater transparency, traceability and human accountability.

What changes from 2 August 2026?

From 2 August 2026, the transparency rules under Article 50 of the European Artificial Intelligence Act, known as the EU AI Act, begin to apply. People must be able to understand when they are interacting with artificial intelligence and when the content they see or hear has been generated or substantially altered using AI.

💬

AI chatbots

Users must be clearly informed that they are interacting with an AI system rather than a human operator.

🎨

AI-generated content

Certain generated or manipulated content must carry appropriate visible and technical labelling.

🎭

Deepfake materials

The artificial or manipulated nature of realistic images, video and audio must be clearly disclosed.

🛡️

Biometric systems

People must be informed when emotion-recognition or biometric-categorisation systems are being used.

What matters most for businesses?

Companies need to review where and how they use artificial intelligence. The requirements may affect both developers of AI solutions and businesses using ready-made tools in websites, online stores, marketing campaigns and internal processes.

Systems you should review

  • AI chatbots and virtual assistants;
  • automatically generated images and videos;
  • synthetic voices and deepfake content;
  • emotion-recognition systems;
  • biometric categorisation;
  • AI-generated texts on matters of public interest.

Does the entire AI Act apply at once?

No. The European Artificial Intelligence Act applies in stages. Therefore, 2 August 2026 is a key date, but it does not introduce every requirement simultaneously.

1 August 2024

The Regulation enters into force.

2 February 2025

Prohibited AI practices and certain AI literacy requirements begin to apply.

2 August 2025

Some of the rules for general-purpose AI models begin to apply.

2 August 2026

The general supervisory framework and important transparency obligations begin to apply. Some requirements for specific high-risk systems will apply later.

Which companies may be affected?

The rules do not affect only technology companies developing large language models. They may also apply to organisations using chatbots, AI agents, digital avatars, image and video generators, synthetic voices, AI recruitment systems, biometric systems or tools for publishing information of public interest.

A small business using an off-the-shelf AI chatbot on its website will generally be considered a deployer of the system. A company that develops and offers its own AI system under its name may be considered a provider. The specific obligations depend on the organisation's role, the type of system and how it is used.

What should an AI chatbot change?

When a person interacts directly with an AI system, they must be informed that they are not communicating with a human operator, unless this is obvious from the context.

You are interacting with an AI assistant.

It is also good practice to explain the system's limitations. In more complex, individual or sensitive cases, users should be able to reach a person. This is particularly important for online stores that use AI to answer questions about products, availability, delivery, payments and returns.

How should AI-generated content be labelled?

Providers of certain generative AI systems must ensure effective, machine-readable marking. The purpose is to enable images, videos, audio and text to be technically recognised as generated or manipulated by artificial intelligence.

Visible disclosure

A label such as “Created with AI” informs users about the origin of the content.

Machine-readable marking

Technical information that allows platforms and software systems to identify the origin of content automatically.

Does every article written with AI need to be labelled?

Not every use of AI automatically requires a visible label on the text. Particular attention is given to AI-generated or manipulated content published to inform the public on matters of public interest.

Different conditions apply when the text has undergone meaningful human review and a natural or legal person bears editorial responsibility for it.

What does meaningful human review include?

  • checking the facts and sources used;
  • editing the conclusions;
  • adding genuine expertise;
  • removing misleading claims;
  • approving the final version.

Correcting spelling or grammar alone should not automatically be regarded as sufficient editorial control.

What are the rules for deepfake content?

Deepfake content includes images, video or audio generated or manipulated with AI that may falsely appear authentic. When a company, media outlet or organisation publishes such material, its artificial or manipulated nature must be clearly disclosed.

This is especially important for realistic AI avatars, synthetic voices, generated faces, manipulated interviews, videos featuring public figures and content in which a real person appears to say or do something that never happened.

What is required for emotion recognition and biometric categorisation?

When an organisation uses an AI system for emotion recognition or biometric categorisation, the people exposed to the system must be informed. This may apply to the analysis of faces, voices, gestures, behaviour or other biometric characteristics.

Providing notice does not remove data-protection obligations or automatically mean that every use is permitted. A company must assess both the AI Act and the applicable data-protection rules.

What does meaningful human review mean?

Human review must be substantive rather than merely formal. A person with appropriate knowledge should check the facts, arguments, sources used, potential risks and conclusions.

Example process for a company blog

  1. AI supports the research or produces an initial draft.
  2. An expert checks the facts and sources.
  3. The text is enriched with the company's real experience.
  4. Unsupported claims are removed.
  5. A responsible person approves the final publication.
  6. The article is updated when the information changes.

Is there a grace period?

A limited transitional period is provided for certain AI systems placed on the market before 2 August 2026 regarding the machine-readable marking of generated content. This does not mean businesses should delay their preparations.

What penalties may apply?

Breaches of certain provisions may lead to substantial penalties. The exact amount depends on the type of infringement, the company's role, the scale of the system used, annual turnover and the surrounding circumstances.

The principle of proportionality must be taken into account for small and medium-sized enterprises. However, this does not exempt smaller companies from applicable obligations.

What should businesses do now?

📋

Create an inventory

List all AI tools used across your website, customer service, advertising, social media, human resources and internal processes.

🔍

Determine your role

Establish whether the company is a provider or deployer and which obligations arise from the specific system and its use.

Introduce controls

Ensure chatbot transparency, disclosure of deepfake materials, preservation of markings and meaningful human review.

Practical questions to check

  • When was the AI system introduced, and who is its provider?
  • Which technical markings does it support?
  • Can the marking be removed during processing?
  • Who is responsible for publication?
  • How are users informed?
  • Who performs and documents the human review?

How are the AI Act and AI optimisation connected?

AI optimisation, also known as AEO or GEO, aims to make business content clear, credible, structured and easy for systems such as ChatGPT, Gemini, Copilot, Perplexity and Google AI Overviews to use.

The AI Act does not determine which website will appear in generated answers, and compliance does not automatically guarantee greater visibility. However, there is an important strategic connection: clear authorship, verified sources, specific dates, editorial accountability and direct answers create a more trustworthy information environment.

Read our article “AI optimisation vs traditional SEO: which should you choose?”, as well as the practical guide “AI optimisation is the new SEO”.

How does CompassBG help businesses?

At CompassBG, we see SEO, AI optimisation, content, websites and automation as parts of one connected digital system.

Technical analysis

We analyse website accessibility and build a clear technical and content foundation.

Question-and-answer content

We structure expert knowledge in a format that is useful to people, Google and AI systems.

AI solutions and visibility

We build custom AI chatbots and track brand mentions and visibility.

Conclusion

The new rules applying from 2 August 2026 do not prohibit the use of artificial intelligence. They require greater clarity, traceability and human accountability.

Do you know where your business uses AI, whether people are properly informed, and whether you can demonstrate compliance?

Companies that combine automation with transparency, meaningful human oversight and credible content will be better prepared for both European regulation and the new AI search environment.

Contact CompassBG

This material is provided for informational purposes only and does not constitute individual legal advice.