The EU AI Act's new transparency rules: What businesses need to know

 
August 2026
Man and woman talking at office desk.

Artificial intelligence has moved from experimentation to everyday business reality.

Employees are using AI to draft content, summarise meetings, analyse data, automate processes and support decision-making. Organisations are racing to unlock productivity gains, while technology providers continue to release increasingly capable AI tools and agents.

The challenge is that governance has struggled to keep pace.

According to Microsoft's UK research (2025), 71% of employees have used unapproved AI tools at work, with more than half continuing to do so every week. Microsoft describes this growing trend as "Shadow AI" and warns it creates significant security, compliance and data protection risks for organisations.

At the same time, McKinsey's latest global survey found that 88% of organisations are now using AI in at least one business function, up from 78% the previous year. Yet most organisations still have not scaled AI effectively across the enterprise.

Against this backdrop, regulators are beginning to catch up.

Last week, the Irish Independent reported on the latest phase of the EU AI Act, highlighting new obligations for organisations deploying AI and potential fines of up to €15 million for non-compliance. The article also noted the challenges facing regulators as they attempt to govern a technology evolving faster than traditional legislation. 

For organisations embracing AI, the message is clear: the era of experimentation is giving way to the era of governance.

Important note: Being a company based in the UK does not automatically exempt your organisation from the EU AI Act. If your business serves EU customers, has employees in the EU, or deploys AI systems whose outputs are used within the EU, the legislation may still apply.

What's changed in August 2026?

On 2 August 2026, new transparency obligations under Article 50 of the EU AI Act came into force. These rules are designed to help people recognise when they are interacting with AI or consuming AI-generated content.

While many organisations assume the changes only affect large AI providers such as OpenAI, Google or Anthropic, the reality is much broader.

Users must know when they are interacting with AI

Organisations using chatbots, AI assistants, virtual agents or AI-powered customer service tools must ensure users understand they are interacting with AI rather than a human, unless this is already obvious from the context. 

For example:

  • A customer support chatbot on a website

  • An AI-powered service desk assistant

  • A virtual HR assistant helping employees find policies

  • An AI sales agent responding to customer enquiries

These systems may now require clear disclosure that AI is involved. 

Some AI-generated content may require labelling

This is the area most organisations are likely to be asking questions about.

The AI Act requires certain AI-generated or AI-manipulated content to be appropriately marked or labelled. The European Commission specifically references synthetic images, audio, video and text. 

However, this does not automatically mean every blog post, social media update, or marketing asset produced with ChatGPT or Microsoft Copilot must carry a visible "AI-generated" label.

The guidance distinguishes between different scenarios and includes exemptions where there is substantive human editorial oversight and accountability. The Commission's guidance specifically notes that text may not require disclosure where meaningful human review and editorial responsibility have been applied. 

For marketing teams, this means the key question is not simply:

"Was AI used?"

Instead, it becomes:

"How much human involvement, review and accountability existed before publication?"

This is likely to become an increasingly important governance consideration for organisations using AI-assisted content creation at scale. 

Deepfakes are no longer just a Big Tech issue

Many organisations hear the term "deepfake" and assume it has little relevance to their business.

In reality, deepfake technology has become increasingly accessible through mainstream AI tools capable of generating realistic images, video and audio. Regulators are concerned about the potential for impersonation, deception, misinformation and fraud at scale.

The new transparency rules require deepfake content to be disclosed as artificially generated or manipulated.

Examples where this could become relevant include:

  • Marketing campaigns using AI-generated people in advertising imagery.

  • Corporate communications using synthetic avatars for video content.

  • Training and learning content featuring AI-generated presenters.

  • Media, publishing and content production organisations using AI-generated visual assets.

Importantly, the European Commission's guidance notes that deepfake disclosure requirements can apply even where there is no intention to deceive. The obligation is focused on transparency rather than proving malicious intent.

Emotion recognition and biometric AI face greater scrutiny

Organisations deploying AI systems that recognise emotions or categorise people using biometric characteristics must also provide transparency to affected individuals. 

While this may not affect every organisation today, it is particularly relevant for sectors adopting advanced workplace monitoring, surveillance or customer analytics technologies.

The real challenge isn't technology. It's governance.

The compliance challenge facing organisations is not simply understanding the legislation.

It's understanding where AI is already being used.

Microsoft's finding that 71% of employees have used unapproved AI tools demonstrates how quickly adoption can outpace oversight. 

Many organisations cannot confidently answer:

  • Which AI tools are currently in use?

  • What organisational data is being shared?

  • Which teams are using AI most frequently?

  • Have AI agents already been deployed?

  • Who owns AI governance?

As AI adoption continues to accelerate, these questions will become increasingly difficult to avoid.

What happens next?

Organisations should not assume that August 2026 represents the end state of AI regulation.

The transparency requirements that came into force this month are just one phase of a broader regulatory programme. Additional obligations relating to higher-risk AI systems are expected to follow in later implementation phases.

For business leaders, the direction of travel is becoming increasingly clear.

AI adoption is growing rapidly. Regulators are increasing oversight. Customers, employees and stakeholders are demanding greater transparency. And governance is becoming a business requirement rather than a compliance checkbox.

The organisations that act now to establish policies, accountability, AI literacy and governance frameworks will be far better positioned to scale AI safely and confidently in the years ahead.

Not sure whether your organisation is ready for the latest EU AI Act requirements?

Microsoft Purview and Compliance Manager can help organisations gain visibility into AI usage, strengthen data protection controls, map compliance obligations and build a more robust AI governance framework.

Speak with our security specialists to assess your current AI risk exposure and identify practical next steps.

 


Sources

This article references publicly available information and guidance from:

Back to all blogs