Ven. Ott 9th, 2026
Conceptual graphic synthesis with no text of any kind: a human silhouette facing a screen-shaped rectangle from which a stream of small abstract geometric marks flows outward, the marks fading before they reach the silhouette; flat shapes, cool palette, no letters, numbers, labels or logos.

Since 2 August, the transparency block of the AI Act has been applicable across the European Union. If you build a chatbot, an image generator, a voice cloner or an emotion recognition system, or if you put one to work in front of other people, you now owe those people something you did not owe them before. They must be told when they are interacting with an AI system, unless that is obvious from the context. Synthetic output has to carry a technical mark, and in defined cases the organisation deploying the tool has to say so out loud. The regulation had been in force for two years when this block bit, and it is the part of the law that touches ordinary life most directly. Not the high-risk classification, not the conformity paperwork. Just this: you should be able to know when you are talking to a machine, and when what you are looking at was manufactured.

Two months in, it is worth asking the rude question. Has anything changed in what you actually see on a screen?

What the rules say

The first obligation is simple and good. People must be informed when they interact with an AI system, unless that is evident from the context. The drafters had vulnerable users in mind, children first among them, and anyone who has watched a twelve-year-old confide in a chatbot knows why that sentence exists.

The second obligation is the one that will shape the next decade, and it has two halves that should not be confused. Providers of systems that generate synthetic audio, images, video or text must apply technical markings that allow the output to be identified as artificially produced, in a form other software can detect, using solutions that the relevant technical standards require to be effective, interoperable, robust and reliable. Deployers, meaning the organisations that actually use the tools, carry a separate duty: they must tell people when they are exposed to deepfakes, to AI-generated content on matters of public interest published without human review or editorial control, and to emotion recognition or biometric categorisation systems. Machine marking and public notice are two different obligations, and neither one absorbs the other.

The penalties are not symbolic. Up to fifteen million euro, or, for companies, up to three per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. That is, I would bet, the register in which this kind of conversation finally gets read inside a large organisation: the paragraph with a number at the end of it.

The flaw hiding in the words “machine-readable”

Here is where the architecture quietly undercuts the purpose. The marking the providers must apply is machine-readable. It is a signal embedded for other software to detect.

That is excellent engineering and it is genuinely useful: platforms, archives, newsrooms and forensic tools can build pipelines on it. But the person the rule is meant to protect is not running a detection pipeline. She is somebody’s mother, watching a thirty-second clip at eleven at night in which a politician appears to say something he never said. The provenance signal is present. She has no reader. We have written the ingredients label as a barcode and left the scanner in the hands of whoever is selling the product.

The deployer notice is supposed to close that gap, and where deployers act in good faith it does exactly that. The difficulty sits with one specific category. Somebody who assembles a political deepfake in order to deceive is covered by the obligation like everyone else, and has every reason to ignore it; the same goes for an operation farming engagement. The duty exists for them. What does not exist is any incentive to comply with it voluntarily. So the visible weight of the rule falls on the organisations that were already careful, while the cases the law was actually written about depend on somebody detecting the breach and going after it. Enforcement, not drafting, is now the whole game.

The clause worth keeping

There is one exception in the package that shows real legal intelligence. No disclosure is required for text on matters of public interest that has been subject to human review or editorial control, where a natural or legal person takes editorial responsibility for the published content. Both halves matter: the review, and somebody signing for it.

Read that twice, because it inverts the entire framing. The question is not whether a machine was involved. The question is whether a named human being answers for the result. A newsroom that uses AI tools and keeps a human filter over what goes out is not hiding anything, and the law correctly declines to make it stamp a warning on its own journalism. The safety regimes I would hold up as working, from pressure vessels to aviation, tend to rest on that same move: find the person who is accountable, and make the accountability survive the technology. Labelling is a proxy. Responsibility is the thing.

Two years of law, under two weeks of instructions

Then there is the timing, and it is embarrassing. The lawyer Ernesto Belisario, who works in technology law, welcomed the deadline as the moment the AI Act finally gets serious, while pointing out that the Commission’s guidelines were published less than two weeks before the obligations began to apply, leaving businesses a very narrow margin to adapt to technologies that move extremely fast.

The two figures are not in competition, and it is worth separating them. The regulation had been in force for two years, so nobody can claim the date was a surprise. The operational guidance arrived with under a fortnight to spare, and that is the margin Belisario denounced. You can diary a deadline for two years and still, if your last choices were waiting on those indications, find yourself finishing the work in a fortnight. For a listed platform with a standing legal department, closing that last stretch is an unpleasant sprint. For a mid-sized company, a hospital or a municipality running a customer-service chatbot it bought from a vendor, it is an invitation to sloppy work. The practical to-do list was never exotic: map where chatbots and content generators are actually in use, check whether the marking solutions in your stack do what the standards require, update the notices you give users and customers, and fold all of it into the compliance processes you already run. None of that is hard. An organisation that held those decisions open until the guidance landed, though, had very little time left in which to take them.

So here is the outcome I expect. A new line in a privacy notice. A small grey sentence under a chat window. A supplier’s assurance that the watermark is compliant, which the people signing it off may have no practical way of testing. The rule is correct, the deadline arrived, the boxes get ticked, and the deepfake that lands in a family chat this evening may well still carry nothing any of them can see without software to look for it.

The AI Act got the principle right. Whether the principle means anything now depends on something no regulation delivers by itself: somebody actually checking, and penalties that land.

Raffaele Di Marzio

All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html