NEWS

AI Act: What's changing starting August 2, 2026? New rules for businesses, chatbots, and AI-generated content.

By July 22, 2026No Comments
AI Act: What's changing starting August 2, 2026? New rules for businesses, chatbots, and AI-generated content.

Many companies already use artificial intelligence to respond to customers, create images, write texts, analyze data, or automate business tasks. The problem is that these tools were often introduced without considering who controls the results, how users are informed, and who responds in the event of errors.

From the August 2, 2026 This informal management becomes much riskier. The transparency obligations set forth in Article 50 of the AI Act, the European regulation on artificial intelligence, come into force. People will need to be able to recognize when they are interacting with an automatic system and when content has been artificially generated or modified.

The change isn't just about big tech platforms. It can involve businesses, professionals, e-commerce sites, publishers, agencies, public bodies, and organizations using chatbots, voice assistants, content generators, biometric systems, or emotion recognition tools.

The real question, therefore, is no longer just: “Are we using artificial intelligence?”
AND: “Do people know when we’re using it, and does anyone actually monitor what they produce?”

What is the AI Act?

The AI Act, formally EU Regulation 2024/1689, is the European legislation that governs the development, distribution, and use of artificial intelligence systems.

The regulation follows a risk-based approach. It does not treat all applications equally, but introduces different obligations depending on the impact a system may have on people, security, and fundamental rights.

Applications considered minimally risky remain largely exempt from specific requirements. For systems with risks of manipulation, poor transparency, or significant impacts on individuals, however, controls, mandatory reporting, and more specific responsibilities are introduced.

The goal isn't to prevent companies from using artificial intelligence. It's to prevent it from being used in an invisible, uncontrolled, or potentially deceptive way.

Why August 2, 2026, is a crucial date

The AI Act came into effect on August 1, 2024, but its implementation has been staggered.

Prohibitions on certain practices deemed unacceptable and AI literacy requirements became applicable on February 2, 2025. Other provisions, including those regarding general-purpose AI models, began to apply on August 2, 2025.

The August 2, 2026 However, a much broader scope of the regulation will come into force. Among the most significant changes for businesses and professionals are the transparency obligations of Article 50, the rules relating to numerous high-risk systems, and new control and enforcement powers. However, some provisions will continue to follow later deadlines, particularly for certain categories of high-risk systems. Therefore, it is not entirely correct to state that the entire AI Act will be fully applicable from that date.

The date remains a watershed moment: using AI without knowing where it is being used, what content it produces, and how it is communicated to users will no longer be simply a matter of internal disorganization.

The central principle: People must know when AI intervenes

The most obvious change concerns people's right to understand when they are interacting with an automated system or when they are faced with artificially generated content.

Article 50 distinguishes between suppliers, that is, those who develop or make available certain systems, and professional users, defined by the regulation as deployers, i.e. companies and organizations that use those systems in their activities.

Obligations vary based on the role. Those who provide a system must design it compliantly. Those who use it must verify how it is used, inform people when necessary, and maintain concrete accountability for the results.

Using software developed by another company, therefore, does not automatically eliminate all liability.

Chatbots and virtual assistants will have to declare themselves

When a person interacts directly with an AI system, they must be clearly informed of the automatic nature of the interaction, unless this is already obvious from the circumstances.

The rule may concern:

  • chatbots installed on websites;
  • virtual assistants for customer service;
  • voice systems for reservations and switchboards;
  • automated agents used in sales;
  • tools that perform an initial selection of requests;
  • digital assistants integrated into portals and applications.

It shouldn't take you to the end of the conversation to realize you weren't talking to someone. The information should be understandable and presented at a useful time.

For businesses, this means checking initial messages, screenshots, voice recordings, support paths, and handoffs to a human agent.

The problem isn't using a chatbot. It's making the user think they're talking to a person when they're not.

Generated images, audio, video and text must be recognizable

Providers of systems that generate or modify synthetic content will have to use technical solutions that make such content detectable as artificial.

The marking must be machine-readable, interoperable, effective, and technically reliable. It may therefore take the form of metadata, digital watermarks, or other identification systems embedded in the content.

This obligation falls primarily on system providers, but companies integrating them into their processes must also be cautious. Content can be cropped, compressed, modified, exported, or uploaded to a platform that eliminates part of the original information.

Before using an image, audio, or video generator, it's not enough to ask yourself how realistic the result is. It's worth checking:

  • if the system applies a marking;
  • what type of marking does it use;
  • if it remains present after export;
  • if it can be removed during subsequent modifications;
  • What information does the manufacturer provide on compliance.

Creating content is easy. Proving its origin and proper management can be much more difficult.

Deepfake: When Labeling Becomes Mandatory

The AI Act defines deepfake audio, video, or visual content generated or manipulated by artificial intelligence that represents existing people, objects, places, entities, or events and may appear falsely authentic.

Anyone using a system to create or modify this type of content must clearly state that the material has been artificially generated or manipulated.

The topic includes advertising campaigns, political communications, informational content, corporate videos, realistic reconstructions, concise testimonies, and materials published on social media.

For artistic, satirical, creative, or fictional works, more flexible arrangements are provided so as not to compromise the experience of the work. Transparency, however, does not disappear completely.

It's not enough to simply include a hidden text in the description or at the bottom of a page. Communication must be clear, visible, and appropriate for the medium used.

The European Commission has also made specific icons available to flag artificially generated content. Their use is optional, while the obligation to provide information remains mandatory in the cases provided for.

Articles and content of public interest: not everything AI writes needs to be declared

One of the most sensitive issues concerns texts generated or manipulated by artificial intelligence and published to inform the public on topics of general interest.

In these cases, the use of AI must be declared, unless the content has undergone a human review process or editorial control and a person or organization takes responsibility for its publication.

This step is crucial because it avoids a widespread simplification: from August 2, 2026, it will no longer be necessary to indiscriminately write "AI-generated content" under any text in which an automatic tool has been used.

It's how AI is used that matters.

An article produced automatically and published without review presents a different problem than a text in which artificial intelligence has been used as an aid, but which has been checked, corrected and approved by an editorial manager.

Compliance will therefore not depend solely on the tool used. It will depend on the existence of a real control process.

Emotion recognition and biometric categorization

Transparency obligations also apply to systems that analyze biometric characteristics or claim to recognize people's emotions and states.

Those who use these tools must inform those exposed to their operation. This obligation may apply both when the analysis occurs in real time and when it is performed subsequently on recordings or collected data.

Applications may include:

  • workplaces;
  • shops and shopping centers;
  • events;
  • security systems;
  • customer analysis;
  • personnel selection and management;
  • services accessible to the public.

The disclosure required by the AI Act does not replace privacy obligations. If the system processes personal or biometric data, the company must also verify its compatibility with the GDPR and other applicable regulations.

Just because a technology is available on the market does not mean it can be used for any purpose.

Who has to adapt

The obligations do not only concern those who develop complex artificial intelligence models.

Organizations using systems purchased from third parties or integrated into their own processes must also be cautious. Potentially affected entities include companies, professionals, agencies, publishers, e-commerce sites, public bodies, digital platforms, and companies that automate customer, user, or employee interactions.

The first mistake to avoid is to think: “We didn’t develop the system, so it doesn’t concern us.”

A company may be a supplier in one project, a professional user in another, and part of a broader chain in a third. To understand the obligations, it's first necessary to identify the role it plays in each case.

What companies actually need to do

To prepare for August 2, 2026, it's not enough to add a generic statement to your privacy policy. We need to reconstruct where and how artificial intelligence actually enters into business processes.

1. Map all the tools used

It is necessary to census chatbots, text generators, creative platforms, voice systems, analytics tools, and AI functions integrated into software and services used by employees.

Even seemingly secondary functions can produce relevant content, decisions, or interactions.

2. Distinguish the role of the company

For each system, it is necessary to establish whether the organization is a supplier, integrator, distributor, or professional user.

Without this distinction, it is difficult to understand which obligations fall on the company and which on the producer.

3. Check interfaces and messages

Chatbots, voice assistants, and automated agents must clearly inform the user when the interaction is taking place with an AI system.

The message must appear at the right time, not be hidden in general conditions that no one consults during use.

4. Check supplier markings and functionality

Companies using generative tools should ask producers what markup and detection systems are applied to the content.

Generic acceptance of the terms of a software does not mean that you have verified its compliance.

5. Define who controls and approves

When AI produces text, images, analyses, or responses intended for the public, it must be clear who performs the final check.

“The system created it” is not a procedure and does not eliminate the organization’s responsibility.

6. Maintain evidence of audits

Internal policies, instrument logs, operating instructions, audits performed, and assigned responsibilities help demonstrate that AI is not being used unregulated.

Compliance isn't just about doing the right thing. It's also about being able to demonstrate how it was done.

The European Code of Conduct can help, but it does not replace the law

The European Commission has published a Code of Conduct on the transparency of AI-generated content.

Participation is voluntary, but it can help suppliers and users demonstrate compliance with content marking and labeling requirements. Those who choose not to participate must still be able to demonstrate that the alternative solutions adopted are adequate.

The Code does not replace the AI Act and does not automatically make every system compliant. However, it provides a common framework for applying the rules more predictably.

Is there an extension until December 2, 2026?

Particular attention is needed on this point.

Article 50 applies from August 2, 2026 and, generally, from that date, suppliers and users must comply with transparency obligations. The Commission specifies that a possible transitional period concerns only the technical marking and detection requirement set out in Article 50, paragraph 2, for certain systems placed on the market before 2 August 2026.

The modification foreseen by the AI Omnibus agreed at European level envisages, for these existing systems, an adaptation within the December 2, 2026. At the moment, however, the application of this provision remains tied to the final adoption of the regulatory amendment. Therefore, it is not a general extension for chatbots, deepfakes, information notices, or content published without editorial control.

Using this potential transition as a reason to postpone the entire adjustment would be a mistake.

The sanctions provided for by the AI Act

For violations other than those related to prohibited practices, the AI Act provides for penalties that can reach up to 15 million euros or to the 3% of total annual worldwide turnover of the previous financial year, if higher.

The regulation provides specific criteria and thresholds, with application proportionate to the size of the company.

Fines, however, are not the only risk.

A chatbot that doesn't disclose its nature, an unverified article, a synthetic image presented as authentic, or an incorrect automatic response can also cause reputational damage, contractual disputes, customer problems, and professional liability.

Transparency isn't just about avoiding fines. It's about ensuring people's trust isn't lost when they discover AI has been used covertly or uncontrolled.

Real change isn't putting a label on something.

Reducing the AI Act to just “artificially intelligent content” misses the point of the legislation.

The change affects the entire chain of responsibility: those who choose the tool, those who monitor its functioning, those who verify the results, those who inform people and those who respond when something doesn't work.

A label can make content transparent. It can't correct an uncontrolled process.

From August 2, 2026, companies will have to demonstrate that they understand the artificial intelligence they use, not just that they have purchased or activated it.

How to prepare for August 2, 2026

The starting point isn't to eliminate AI tools. It's to stop using them without a comprehensive vision.

Before the deadline, each organization should be able to accurately answer a few questions:

  • Where is AI used?
  • Who authorized those tools?
  • Do people know when they are interacting with an automated system?
  • Is the generated content recognizable?
  • Does anyone check texts, images, and responses before publishing?
  • Is there anyone responsible when the system fails?
  • Have suppliers provided sufficient compliance information?

If the answers aren't clear, the problem isn't just regulatory. It means that part of the business's operations are being entrusted to systems the organization doesn't truly govern.

Artificial intelligence can speed up processes. But uncontrolled speed also makes errors more likely.

It's not enough to use AI. You need to know where it operates, what it produces, and who is responsible for it.

If your company uses chatbots, generative tools, or automation but hasn't yet mapped out how they fit into processes, the first step isn't adding a label. It's understanding where AI communicates, makes decisions, or produces content instead of people.

Contact Digife: we analyze the tools used, the points of contact with users and the publishing processes, to identify where they are lacking transparency, check is responsibility.