Menu
a blue lines and dots

What the EU's final AI transparency guidelines mean for providers and deployers

Posted on 31 July 2026

Reading time 8 minutes

In brief

  • The European Commission has published the final version of its Guidelines on the transparency obligations under the EU AI Act, which largely apply from 2 August 2026. This contains a number of important clarifications and updates compared to the draft version issued in May.
  • In particular, the finalised Guidelines address key issues of scope, such as the territorial reach of the obligations, the cumulative application of multiple obligations to a single AI system, and which parties (providers, deployers, intermediaries and open-source providers) are caught, with specific wording directed at AI agents.
  • Providers and deployers of in-scope AI systems should pay close attention to the updated guidance on transparency for interactive AI systems, machine-readable marking and detection of AI-generated content, and labelling of deepfakes. This includes the Commission's strict approach to what constitutes a deepfake, and the limited scope of the exception for obvious AI interactions.

The European Commission has published the final version of its Guidelines on the implementation of the transparency obligations for certain AI systems under the EU AI Act. We discussed the four categories of transparency obligation under the Act in our recent article, in which we also explored the draft version of the Guidelines published in May, as well as the Code of Practice issued by the Commission (which has now also been approved). In this article, we highlight some of the key additions in the updated Guidance.

Scope

The Guidelines provide further guidance on the territorial reach of the Act's transparency provisions:

  • Providers outside the EU are subject to the Act if the output of their AI system is used in the EU. However, any incidental, unforeseeable or unauthorised downstream use should not, on its own, trigger application of the obligation (subject to assessment by the relevant market surveillance authority).
  • In relation to a deployer outside the EU, the transparency obligation will apply where it foresees dissemination and use of the AI outputs in the EU (e.g., by posting deepfakes on the internet), but not where the content reaches EU audiences through unforeseeable channels outside of its control.

The Guidelines also deal with the situation where an AI system engages more than one of the transparency obligations, confirming that the obligations apply cumulatively. So, for example, if an AI system generates images as part of a direct interaction with a natural person, that would mean the provider must engage with the obligations under both Art 50(1) and (2); and, if it can also be used to generate images that are deepfakes, the deployer would need to comply with its obligations under Art 50(4). Similarly, an operator may fulfil the role of provider and deployer concurrently.

Of interest to advertisers, the Guidelines note that a company that merely commissions an advertising agency to produce an advert, without taking decisions and exercising control over how the agency uses AI, would not be a deployer. Meanwhile, whilst intermediaries (such as hosting services) are not caught by the Act, the Guidelines "strongly encourage" them to preserve marking and labelling, and to implement measures to enable natural persons to detect AI-generated or manipulated content.

Transparency for interactive AI systems (Art 50(1))

Providers of AI systems directly interacting with natural persons must design and develop their systems so that those persons are informed that they are interacting with an AI system. There is an exception to the disclosure requirement for obvious interactions with an AI system. The Guidelines note that this exception must be interpreted restrictively, with a number of factors to take into account. For example, if the AI system may be accessed by the general public or consumers that include vulnerable persons for whom the interaction is less obvious, the exception cannot be relied upon to protect those users. Further, the Guidelines caution that it is becoming increasingly hard for natural persons to identify whether an interaction is with an AI system or a human. Therefore, the obviousness exception should be limited to those cases where there is "almost no doubt left" as to the nature of the interaction for an average person in the targeted and reasonably foreseeable audience.

Obvious interactions with an AI system include AI-powered code assistance and review, ambient-AI embedded in home appliances and interactions with AI-enabled Non-Playable Characters (NPCs), provided the nature of the game makes it clear that no other natural person can participate and interact with the user and the AI nature of the interaction is also obvious for all users. Meanwhile, non-obvious interactions include AI-powered companion pets.

Further specific guidance is also given in the update on the application of the requirements to AI agents where they are capable of interacting with natural persons (including those instructing them) when executing tasks. They must be designed and developed in such a way that they disclose both their artificial nature and the person on whose behalf they are acting, including where multi-agent architectures are used. Where it is not possible for the provider of the agent to identify in advance that there will be direct interaction, the agent should be designed at the architecture level and instructed to disclose itself as such in every situation where it is reasonably likely that it may interact with a natural person.

As for the nature of the disclosure under Art 50(1), the Guidelines provide information on its format and substance. In most cases, a single, prominent notification before the first interaction of the AI system with a particular natural person will likely suffice. However, in certain riskier situations, periodic reminders and context-aware disclosure are likely to be necessary, particularly where the system interacts with vulnerable persons.

Marking and detection of AI-generated or manipulated content (Art 50(2))

Providers of AI systems generating synthetic content are required to implement solutions that enable machine-readable marking and detection of their systems' outputs. The updated Guidelines provide more detail on how this will apply in relation to AI agents, namely where the agent's action leads to AI-generated or manipulated content that is perceptible to natural persons. However, intermediate processing steps by the agent would not be in scope of the obligation.

The Guidelines also provide further clarification on the marking and detection obligations and how they can be met in practice. They set out examples of standard editing and minor alterations that will be excepted, in contrast to semantic changes that will require marking.

Emotion recognition systems and biometric categorisation systems (Art 50(3))

The Act imposes an obligation on deployers of such systems to inform natural persons who are exposed to them, unless an exception applies. The updated Guidelines contain limited changes in relation to the guidance on this obligation.

Labelling of deepfakes and certain text publications (Art 50(4))

Deployers of generative AI systems must make clear and distinguishable disclosures of (1) deepfakes and (2) AI-generated or manipulated text that is published with the purpose of informing the public on matters of public interest.

A 'deepfake' is defined in the Act as an "AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful". The Guidelines underscore that it is sufficient that someone or something could plausibly have existed. Therefore, digital replicas of real persons, realistic AI-generated human avatars or personas, and personal characteristics will be caught. Whether content will falsely appear to be authentic or truthful must be assessed as a whole. It is an objective assessment (i.e., the deployer's intention is irrelevant), taking into account the level of resemblance, the potential substantive message, the intended and foreseeable deployment contexts, the environment in which the content is presented, and the intended and reasonably foreseeable audience.

Taking the film industry as a case in point, the Guidelines give the following examples of what would be considered to be, and not be, a deepfake:

AI-generation or manipulation of background scenes, special effects, or technical pre- and post-processing are unlikely to make content falsely appear to be authentic or truthful.

However, using AI to generate or manipulate essential elements that impact audience perception is likely to do so (e.g., fully AI-generated actors digital replicas of real or deceased actors, de-aging etc). Specifically, the Guidelines note that a high degree of photorealism renders it more likely that such content should be considered a deepfake.

As for the attenuated labelling requirement where deepfakes are used in an artistic etc context, the Guidelines stipulate a strict interpretation. Where a deepfake combines both informative and creative elements, the informative character should always prevail and require compliance with the labelling requirements.

Timing and enforcement

The transparency obligations start to apply from 2 August 2026, other than the detection/marking obligation on providers for AI systems put on the market before that date, which will kick in on 2 December 2026. Deployers do not need to label deepfakes retroactively.

Providers and deployers that sign the Commission's Code of Practice can point to this to demonstrate compliance with their transparency obligations, with the benefit of a streamlined compliance pathway. Google has confirmed that it has signed the Code of Practice.

Providers and deployers should map their AI systems and audit their full functionality to ensure they are able to comply with their transparency obligations. They should also review and update internal guidance for marketing and other affected teams, and implement robust requirements around approval processes (not least given the potential for significant fines for a breach of the EU AI Act obligations, of up to €15 million or 3% of annual worldwide turnover, whichever is higher).

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else