Data Protection & AI

AI Transparency under the AI Act

What companies need to know about the new EU guidelines

On 20.07.2026, the European Commission published its final guidelines on transparency obligations pursuant to Article 50 of the AI Act („Guidelines on Transparency of AI-Generated Content“aka „Transparency Guidelines“) published.

The bulky title of the document may seem confusing at first glance. This designation is due to a still pending formal intermediate step by EU bureaucracy: the responsible specialized departments have finalized the text and are now submitting it to the College of Commissioners for formal approval before it is published as an official communication of the Commission.. However, in terms of content and for legal compliance practice, the present text is already to be considered final and authoritative. 

The document is the result of a comprehensive consultation process that incorporated feedback from a wide range of stakeholders and Member States via the European Artificial Intelligence Board (AI Board).. The objective of the guidelines is to provide practical guidance to national supervisory authorities as well as to providers and deployers of AI systems.. This is to ensure that the transparency obligations under Article 50 of the AI Act are implemented consistently, effectively, proportionately, and uniformly across the Union..

For companies, the guidelines provide orientation in a crucial first step: they help to identify the AI applications used in their own operations in the first place and to legally qualify them. The guidelines provide the concrete criteria for assessing whether a system falls under the transparency obligations at all.

It is necessary to correctly classify the legal nature of the document: The Commission's guidelines are formally non-binding.. The binding final interpretation of the AI Act remains exclusively the responsibility of the European Court of Justice (ECJ).. Nevertheless, this document will function as a central benchmark in practice going forward. The regulatory authorities are thus specifying the rules of the game; anyone who deviates from these guidelines when implementing AI systems will de facto bear the burden of proof in regulatory proceedings.

Since Article 50 applies from August 2, 2026, companies now urgently need to take action. We have summarized the key points for you.

AI Act Transparency Guidelines

Table of Contents

From guidelines & practical guides

At first glance, the „accompanying legislation“ to the AI Act can be confusing. For example, the EU Commission recently published, in addition to these guidelines, the practical guide (Code of Practice on Transparency of AI-Generated Content) presented. To properly classify the system, a simple distinction is sufficient:

  • The guidelines serve as a legal interpretation tool. They define the legal scope, clarify key terminology, and set out the exceptions for all covered AI systems pursuant to Article 50 of the AI Act..
  • By contrast, this practical guide focuses on the operational and technical implementation of generative AI.. It provides concrete standards for providers and operators – for example, regarding the implementation of machine-readable markings or the design of visible labels for deepfakes.

For compliance practice, the practical guide is essential: its adherence serves as primary evidence for generative systems that legal requirements are met. If a company deviates from it, it must proactively demonstrate to the supervisory authority that its alternative solutions are equivalent and effective.

A lot more material is yet to come: delegated acts, implementing acts, codes of practice, codes of conduct, guidelines, harmonized standards, common specifications. For a good initial overview of the „accompanying legislation“ to the AI Act, we recommend the clear RTR Information Page on this topic.

Moving on to the content of the Transparency Guidelines:

AI agents: Show yourselves!

The use of autonomous and semi-autonomous AI agents is increasing rapidly in business transactions. Whether in automated bookings, direct customer contact, or even independent contract negotiations, AI agents are increasingly taking over operational tasks.. This is precisely where the final guidelines on Article 50(1) of the AI Act establish strict rules. As soon as these systems interact directly with natural persons in the execution of their tasks, they must identify themselves accordingly..

In any case, it must be clearly recognizable to the respective negotiation partner or customer:

  • That it is an Artificial Intelligence.
  • The name of the person or company the agent is acting on behalf of.

The background to this strict requirement is legally and economically fundamental: it concerns the transparency of delegated powers and the legal accountability (liability) for the system's actions.. When an AI agent acts in a legal transaction, it must be clear to the counterpart beyond a shadow of a doubt to whom the actions of this system are legally attributable.

Anyone deploying AI agents should also ensure that the agent's decision-making powers are transparent and understandable to the counterpart at all times. Before integrating such systems operationally into customer interactions, the scope of action and disclosure obligations must be strictly measured against not only the AI Act, but also general corporate and civil law, and precisely verified.

Beware of „That was obvious!“ 

The AI Act (specifically Article 50(1)) provides for an exception to the information obligation for interactive AI systems if it is „obvious“ to an informed, observant, and reasonable person anyway that they are interacting with an AI.. However, the guidelines emphasize unequivocally: this exception is to be interpreted extremely restrictively.. The mere general knowledge that AI exists and is being used increasingly is by no means sufficient.

According to the Commission, whether an interaction is actually obvious requires an assessment based on the standard of European consumer protection law (the image of the „average consumer“).. Companies must precisely assess the target group, the reasonably foreseeable audience, and their respective AI literacy.. An absolutely crucial factor in this regard is the composition of the audience: as soon as a system is accessible to the general public and can therefore also reach vulnerable groups (such as children, the elderly, or individuals with cognitive impairments), the exception is generally void, as these individuals must be effectively protected..

Given voices that sound increasingly human, realistic avatars, and sophisticated dialogue capabilities, the commission states that relying on „obviousness“ only leaves room when there is practically „no longer any doubt“ about the artificial nature of the interaction.. Indeed, the exception can certainly apply in practice—for example, with programming assistants for professionals or internal AI tools used for organizational purposes by specially trained employees.. However, the compliance rule is: A blanket „they must have known that“ misses the mark. Anyone relying on this exception urgently needs a documented, target-group-specific assessment to be able to survive an official audit procedure..

Exempt from labeling

The Commission provides a detailed list of content that is not subject to the labeling and detection obligations under Article 50(2) of the AI Act. This expressly includes:

  • Source code and technical formats (including APIs, SQL, JSON)
  • Machine-to-machine communication without human contact as well as pure observation and measurement data (such as recordings from AI sensors, smart meters, or GPS trackers in industry)
  • Short outputs like single words or UI labels
  • Internal analyses and recommendation systems that merely structure, arrange, or rank existing data, but do not summarize or alter its content.
  • Assistance with standard processing, such as grammar checks, translations, format conversions, or minor image corrections (e.g., noise reduction).
  • Inconsequential modifications that do not alter the semantics of the original data, such as mere conversation transcriptions or technical markers in medical images.
  • Intermediate results in closed film, gaming, and advertising processes (only the final product must be marked)
  • Ephemeral real-time content, such as in the VR or gaming sector, that is not saved unless marking is technically unfeasible and users are informed otherwise.

In addition, there are special rules for narrowly defined industrial and B2B scenarios.. If the AI output is of a purely technical nature, is processed only by a closed circle of professionals, does not go public, and is protected against misuse by security measures, the labeling requirement does not apply..

Deep Dive on Deep Fakes 

According to Article 50(4) of the AI Act, deployers who use AI systems to generate or manipulate so-called deepfakes must disclose that these contents have been artificially generated or altered.. The guidelines now significantly help companies narrow down the legal scope and identify what even qualifies as a deepfake..

Legally, a deepfake exists when AI-generated or AI-manipulated image, audio, or video content resembles existing persons, objects, places, or events and could falsely appear to a person as authentic or truthful. The guidelines provide essential clarification for this assessment:

  • A deepfake must resemble realistic, actually existing (or plausibly existing) subjects. Content that obviously contradicts the laws of nature (such as a flying human without technical aids or fictional creatures) falls outside the scope of application, as there is no serious risk of deception with them.
  • Whether content is mistakenly believed to be authentic must always be evaluated in the overall context.. The guidelines clarify that photorealism alone is not enough. The decisive factors are the context of publication and the expectations of the audience – for example, whether a manipulated video appears in a documentary (high expectation of truth) or within the context of a recognizable video game sequence.
  • Minor AI-assisted adjustments to existing material (e.g., color corrections, noise reduction, cosmetic enhancements, or format-related background adjustments) generally do not significantly alter the perception of authenticity.. Such standard edits do not make content a deepfake.
  • For content that is clearly part of an artistic, creative, satirical, or fictional work, the guidelines provide for relaxed transparency obligations.. Disclosure here only needs to be made in such a way that it does not hinder the presentation or enjoyment of the work.. However, this exception is to be interpreted restrictively and does not apply to purely commercial or informative content (such as advertising or news).

When private individuals generate and share deepfakes in a purely personal and non-professional context, they fall outside the labelling obligation under Article 50(4) of the AI Act in their role as operators.. While the provider's obligation for machine-readable labeling at the system level remains, the strict legal stance is softened for purely private use.. Nevertheless, the following applies to consulting practice: The classification always depends on whether the person in the individual case is actually acting purely privately and not economically or professionally..

Human Review: More than just a spell-check

For AI-generated or manipulated texts that inform about matters of public interest, Article 50(4) of the AI Act provides for a particularly practically relevant exception to the labeling requirement.. This applies provided the content is subject to genuine human review or editorial control and a natural or legal person bears editorial responsibility.

The guidelines set clear rules here to prevent circumvention of transparency obligations:

  • A purely automated check, a superficial grammar and spelling check, or a formal rubber-stamping without engagement with the content are by no means sufficient. A conscious examination of the substance by persons with appropriate professional judgment is required.. Reliable fact-checking of the information and sources is the explicit minimum requirement..
  • The concept of editorial responsibility presupposes that a person or entity (such as the editor-in-chief or the publishing company) assumes ultimate legal responsibility as well as the decision-making authority regarding the content of the publication.. To ensure public accountability, the guidelines explicitly require that the identity and contact details of the controller be easily discoverable and made publicly accessible (for example, in the legal notice or terms and conditions).
  • A substantial AI intervention that takes place only after human review (for example, if the AI automatically shortens or reformulates the approved text prior to publication) regularly invalidates the exception.. The final human approval must strictly include the text in the exact form in which it is ultimately published..

What needs to be done now:

The time for abstract interpretations is over. To avoid having to make difficult explanations in an emergency, you should check the following points by 08/02/2026:

  • Carefully check where your AI systems communicate directly with natural persons (Article 50(1) AI Act).
  • Sensure that autonomous or semi-autonomous AI agents make their artificial nature and their principal transparent.
  • Identify internal and technical workflows that are exempt from the obligations (e.g., B2B scenarios or obvious interactions). 
  • Ensure that „human review“ is always the final step before the final publication of AI-generated texts on topics of public interest..
  • If you rely on the journalistic-editorial exemption, make the identity and contact details of the responsible person or entity (e.g., in the imprint) easily accessible..
  • Ensure that transparency notices and labels are designed to be accessible and—depending on the target audience (e.g., when involving children or older adults)—easy to understand..

Conclusion

With the transparency guidelines, the European Commission aims to create legal clarity in highly complex transparency issues.. In practical application, the document turns out to be pleasingly proportionate, which represents a valuable legal demarcation, particularly for industry and internal technical workflows due to clearly defined exceptions..

In the future, risks will primarily arise wherever compliance is based on mere assertions rather than on reliable facts.. On the other hand, those who timely establish well-founded processes, take documentation and verification obligations seriously (ideally by using the practical guide), and maintain transparency toward end customers will avoid legal disputes.. Anyone who takes these steps now will be on the safe side for the upcoming entry into force in August..

Frequently Asked Questions (FAQs)

Are the new transparency guidelines of the EU Commission legally binding?

No, formally they neither directly bind companies nor courts. The final authority for interpreting the AI Act remains the Court of Justice of the European Union (CJEU).. Nevertheless, in practice, the guidelines function as a crucial legal benchmark for regulatory authorities. In the event of proceedings, companies that deviate from these guidelines de facto bear the full burden of proof.

What information must AI agents disclose to users?

Once autonomous or semi-autonomous AI agents interact directly with natural persons—for example, in contract negotiations or customer service—they must clearly communicate two things: they must disclose their artificial nature and unequivocally state on behalf of which natural or legal person they are acting..

Can I dispense with a label if the use of AI is „obvious“ anyway?

Although the law provides for this exception in the case of interactive systems, it is to be interpreted extremely restrictively.. Users' mere general knowledge of the existence of AI is by no means sufficient.. Anyone relying on this exception (for example, in the case of tools for trained employees) must carry out a documented, target-group-specific assessment that also takes vulnerable groups into account.. A mere „That was obvious“ does not provide protection in administrative matters when doubt arises.

When is the AI labeling for editorial texts no longer required?

AI-generated texts on topics of public interest do not require an AI label if they have undergone genuine human review (including fact-checking) and a person or entity bears ultimate editorial responsibility.. Important: The guidelines require that the identity and contact details of the controller must be made publicly accessible.. In addition, a substantial AI intervention that takes place only after human approval regularly nullifies this exception..

 

Are you planning to use AI systems or do you need support in implementing the new transparency obligations?

At ATB.LAW, we provide companies with practical and sound advice on the legal requirements for using AI systems, particularly regarding the AI Act. We evaluate your existing AI applications, adapt your compliance structures accordingly, and legally secure your business operations. Contact Stefan Knotzer and Roman Taudes at any time under office@atb.law or by phone at 01 39 12345 for a non-binding initial consultation.

More articles

EU Commission CRA Guidelines

Cyber Resilience Act: EU Commission guidelines published

Get companies out of standby mode and into the fast lane for the CRA.
Picture of Stefan Knotzer
Stefan Knotzer

When the model sings: Copyright limits of AI training after the Suno ruling

Where AI & Copyright Hit a Sour Note
Picture of Stefan Knotzer
Stefan Knotzer
Laptop is losing data

Data Breach: The Devil Never Sleeps

What Austrian companies can learn from the incident at a major US law firm
Picture of Stefan Knotzer
Stefan Knotzer