
The transparency requirements of the EU AI Act have been in effect since August 2, 2026.
These obligations apply to chatbots, AI assistants, avatars, synthetic voices, automatically generated images and videos, AI-generated corporate publications, and certain biometric applications. Article 50 of the AI Act thus goes beyond the labeling of deepfakes.
What needs to be considered depends on the specific use case, the company’s role, and the type of content involved. Companies should ask themselves the following questions:
The key factor in determining transparency requirements is whether a company acts as a provider, an operator, or in both roles.
Providers include the developers of the models, as well as, in general, companies that commission the development of an AI system and bring it to market or put it into operation under their own name or brand. By contrast, an operator is generally the organization that uses an AI system under its own responsibility for professional purposes.
Whether a company is merely an operator or can also be considered a provider depends, in part, on the extent to which it customizes an AI system and makes it available under its own responsibility.
With white-label solutions, integrated AI agents, and custom-configured chatbots, a company may have to fulfill both provider and operator obligations simultaneously for different parts of the same application.
Practical Recommendation
A written role matrix should be created for every AI system. It should identify, at a minimum, the system provider, model provider, integrator, internal system administrator, business operator, and content publisher. Supplier contracts must clearly define these roles.
Article 50(1) of the AI Act requires operators to inform individuals that they are interacting with an AI system. An exception applies if this is already obvious.
However, this exception must be interpreted narrowly. It depends on the perspective of a reasonably well-informed, observant, and prudent average person in the specific context of use.
A cartoon robot next to a text input field might make an AI chatbot recognizable. The situation may be different with a neutrally designed service window, a human-like voice, an avatar, or an assistant with a common human name. Even a technically savvy target audience does not automatically make disclosure unnecessary.
This information must be provided no later than the start of the first direct interaction. Systems that operate exclusively in the background, communicate only machine-to-machine, or have no direct contact with people, however, are not subject to this specific requirement.
Practical Recommendation
Companies should not rely on the “obviousness” exception if a brief notice can be included without significantly impairing the user experience. An explicit notice such as “You are communicating with an AI-powered assistant” provides greater legal certainty than a mere product name.
To the extent that generative AI systems generate images, audio, video, or text content, not only users but also machines must be able to recognize it.
Providers of generative systems must therefore mark such content in a machine-readable format. The law does not prescribe a specific method. However, the method must be designed in such a way that AI-generated content can be reliably identified, even if it is further processed or distributed via other systems.
On June 10, 2026, the European Commission originally published, as part of the Code of Conduct, three versions of EU icons for voluntary use (basic icon, “AI GENERATED,” and “AI MODIFIED”) for labeling certain AI-generated or AI-modified content; however, these are only suitable for human recognition and do not replace the requirement for machine-readable labeling.
Determining responsibility is particularly challenging in multi-tier technical supply chains. If a SaaS provider uses a base model via an API, it must be clarified whether the model already provides appropriate provenance or tagging information, whether this information is preserved during further processing, and who can demonstrate the model’s functionality to regulatory authorities.
According to the Commission’s guidelines, certain types of content do not need to be technically marked up. These include very short strings (such as individual words, image captions, and alt text), source code, automatic translations as the default output, exclusively machine-processed outputs, and certain content in closed industrial development environments. In addition, the guidelines provide for further exceptions for certain closed industrial use cases. However, these are narrowly defined and do not apply to public or consumer-oriented AI systems.
The obligation to label generally rests with the provider of the AI system that generates or manipulates the content in question. Even if technical solutions from other providers are used in the process, the responsibility for complying with the requirements remains with the system provider.
Incidentally, existing systems do not need to be modified immediately; they can be retrofitted by December 2, 2026.
Practical Recommendation
The legal and IT departments should work closely together on this issue. Contracts with model and platform providers should require binding specifications regarding the tagging method used, supported file formats, metadata preservation, detection capabilities, and technical changes. Mere marketing claims such as “AI detectable” are not sufficient to demonstrate compliance.
Anyone who uses AI solely for technical or supportive editing of existing content is not required to label the content as AI-generated.
Drawing the line can be difficult in everyday practice. Spell-checking, technical noise reduction, minor color correction, or automatic translation are unlikely to trigger a labeling requirement. According to the Commission’s final guidelines, automatic transcriptions, subtitles, and text-to-speech features for accessibility are generally considered standard processing and therefore do not typically need to be labeled as AI-generated.
On the other hand, replacing a voice, creating new image segments, substantially rewriting a text, or altering the message of a video may go beyond the scope of a mere assistance function.
Practical Recommendation
In an application-specific decision matrix, companies should document which processing operations are considered purely technical or supportive, and at what level of change a flag is applied. When in doubt, the processing operation should be flagged.
The machine-readable marker embedded in a file does not replace the disclosure of a deepfake to people.
According to the Commission’s guidelines, operators must label deepfakes in a way that is understandable and noticeable to people, for example, through a visible or audible indicator.
In the case of satire, art, or other obviously fictional content, the disclosure may be less prominent under certain circumstances. However, companies should not be too quick to apply this exception, as it generally does not apply to informational or promotional content—even if such content is also creative.
Practical Recommendation
Operators should label deepfakes directly within the media file or publication itself, rather than solely in metadata or accompanying text that can be easily removed. For audio content, audible indicators should be provided; for visual content, the placement, duration, and legibility of such indicators should be specified in advance and made mandatory.
However, there is no retroactive labeling requirement. According to the final guidelines, the date of creation is the determining factor for image, audio, and video deepfakes, while the date of publication is the determining factor for texts on matters of public interest.
Under the AI Act, deepfakes are AI-generated or manipulated image, audio, or video content that resembles real people, objects, places, institutions, or events and could be mistaken for the real thing. According to the Commission’s final guidelines, content that does not depict an actual person or object may also be considered a deepfake. The key factor is whether the depiction appears realistic and could be mistaken for the real thing. For this reason, photorealistic depictions of fictional people or AI-generated avatars may also fall under the deepfake rules.
The more realistic the depiction and the greater the risk of confusion with reality, the more likely it is that labeling requirements will apply.
Practical Recommendation
The assessment should not be left solely to the creative or marketing department. A documented legal assessment is particularly advisable for advertising, political communication, influencer campaigns, and corporate videos that appear realistic. In practice, there are significant gray areas. When in doubt, the content should be labeled.
Operators must also label AI-generated or manipulated text that they use to inform the public about matters of public interest.
These include:
This may also include company websites, association information, legal updates, ESG reports, and health information.
The key factor here is whether a text contains only advertising or also factual information on a public issue, and what target audience the text is aimed at.
It is not necessary to label AI-generated texts on matters of public interest if the text has undergone a process of human review and editorial oversight and a natural or legal person bears editorial responsibility for its publication. Mere spelling, grammar, or formatting checks are not sufficient.
Practical Recommendation
For relevant publications, a mandatory approval process should be implemented, with individuals designated by name or role as responsible parties. The documentation should include, at a minimum, the system used, the reviewer, the review date, significant corrections, source verification, and the approval decision.
Operators of emotion recognition or biometric categorization systems must inform the affected individuals about the operation of the system. According to the Commission’s guidelines, this obligation applies to both real-time applications and retrospective analysis. In addition, it must be determined whether the specific use is permissible at all. For example, Article 5 of the AI Act prohibits certain forms of emotion recognition in the workplace and in educational institutions, as well as certain forms of biometric categorization based on sensitive characteristics.
Particularly in public areas, at events, in call centers, during video analysis, and when reviewing recorded conversations, notices must be posted in such a way that they cannot be overlooked.
In addition, operators must comply with data protection laws, which impose strict requirements on such systems.
Practical Recommendation
In addition to labeling, companies need a legal basis under data protection law, a data protection impact assessment, and must comply with any restrictions under labor law.
Another key practical challenge is likely to be providing proof of labeling. National market surveillance authorities may require such proof. Violations of Article 50 may be punishable by fines of up to 15 million euros or 3 percent of global annual turnover.
The Code of Conduct on Transparency of AI-Generated Content, published on June 10, 2026, is voluntary. It includes practical measures for machine-readable tagging and detection, as well as for labeling deepfakes and certain AI-generated texts. The Commission and the AI Board assessed it on July 8 and 9, 2026, respectively, as a suitable instrument for demonstrating compliance. Those who do not adhere to the Code must demonstrate the adequacy of their own measures by other means; according to official guidance, more extensive requests for information from regulatory authorities may be expected in such cases.
However, joining the initiative does not exempt companies from assessing their own scope of application or from fulfilling their obligations regarding direct AI interactions, emotion recognition, and biometric categorization.
Companies should have established at least one reliable basic process that includes the following measures:
Partner
Head of Technology Law
THE SQUAIRE Am Flughafen
60549 Frankfurt am Main
Tel.: +49-69-951195770
fheynike@kpmg-law.com
Senior Manager
Fuhlentwiete 5
20355 Hamburg
Tel.: +49 40 360994-5483
danieltaraz@kpmg-law.com
© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.
KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.