Skip to content
ki verordnung
Aug 10, 2026, 8:41:38 AMLesedauer: 9 Min  |   Legal Compliance

Update on the AI Regulation

 

Compliance Update from July 29th 2026

On August 2nd 2026, the general applicability of the AI Act takes effect. A milestone for a central topic: the labelling of AI-generated content. The new transparency requirements affect companies of all sizes, from startups to large enterprises.

Transparency requirements for AI-generated and manipulated content

According to Art. 50 of the AI Act, both providers and operators of an AI system must disclose when people are interacting with AI or when content has been artificially generated or manipulated. The requirements vary slightly depending on the role and the type of content. Providers of AI systems must ensure their AI systems are designed so that individuals are explicitly informed whenever they interact directly with an AI system. In addition, AI-generated audio, image, video or text content must be labelled in a machine-readable format, i.e. technically marked so that computers can detect it. Operators of an AI system that generates or manipulates image, audio or video content that is a deepfake must, by contrast, visibly label for humans that the content was artificially generated or manipulated.

It is the same fundamental obligation: transparency and honesty towards users.

 

What is a deepfake that requires labelling?

A deepfake must meet three criteria:

  • Looks real: the viewer should think “That could be real”

  • Depicts something realistic: real people, places, objects or events

  • Falls into these categories: people, objects, places, living beings, events and scenes (including historical ones)

 

How must content be labelled?

In June 2026, the European Commission published a Code of Practice on the transparency of AI-generated content with practical measures to meet the transparency requirements. The Code of Practice serves as a voluntary but practically binding guide. By following it, companies signal legal compliance and build trust.

The European Commission has also created EU icons for labelling AI-generated content that operators of generative AI systems can use to label their AI-generated content. The Code of Practice is further complemented by the Guidelines on transparency obligations for providers and users of certain AI systems published in July 2026.

Under Art. 50(5) of the AI Act, disclosure must take place no later than at the first interaction or first contact. The guidelines emphasise that a notice solely in the terms and conditions or hidden menus is not sufficient.

 

Examples of providing information at the first interaction or first contact in accordance with Article 50(5) of the AI Act:

  • Chatbots and physical systems: labelling at the start of the conversation

  • Videos with deepfakes: labelling at the beginning

  • AI-generated or manipulated texts on public-interest topics: labelling at the start

  • Deepfakes on social media: labelling upon first viewing

The transparency requirements can be demonstrated through the Code of Practice or equivalent alternatives. Providers and operators can define additional appropriate measures themselves.

 

The AI Omnibus comes into force

On July 27th  2026, the Digital Omnibus Regulation on AI came into force and eases implementation timelines and compliance shortly before the AI Act’s general applicability as of 02/08/2026:

  • Due to delays in the availability of standards, common specifications and national authority structures, the start dates for obligations for high-risk AI systems are postponed: standalone systems under Annex III to December 2nd 2027, systems embedded in regulated products under Annex I to August 2nd  2028. The different timelines provide the necessary adjustment period. In future, the Commission is to provide guidance, standards, common specifications and practical guidance in due time to ensure legal certainty and a uniform application in the Member States.

  • The Omnibus eases the AI literacy obligation under Art. 4 of the AI Act: providers and operators of AI systems must still take measures to develop AI literacy among their staff, but are not required to guarantee a specific level of AI literacy for any individual. The Commission and Member States will in future support providers and operators through training, information resources, exchanges of best practices and other initiatives.

  • The Omnibus provides basic simplifications for small and medium-sized enterprises, including simplified documentation obligations and measures to promote innovation and support by national authorities.

 

 

Conclusion: Transparency in focus, implementation staggered

On 2 August 2026, the AI Act becomes generally applicable, with transparency obligations for AI-generated and manipulated content as a central milestone. Direct interactions with AI must be recognisable, AI-generated content must be labelled in a machine-readable way, and deepfakes must be visibly marked as such for people. The Code of Practice and the EU guidelines offer practical orientation, with labelling required no later than at the first interaction.

In parallel, Germany’s AI‑MIG and the EU-wide AI Omnibus provide breathing room: the Bundesnetzagentur takes over central supervision in Germany, high-risk requirements are deferred to 2027 and 2028, and SMEs receive relief from obligations.

The result is a balanced framework: strict transparency obligations now, realistic implementation timelines for more complex requirements, and targeted relief for smaller players. For companies this means: act immediately on transparency, and plan specifically for high‑risk requirements.



Compliance Update from 2 December 2025

Review: The AI Act 2025

The EU’s AI Act has been in force since 1 August 2024, but its effect unfolds in stages. This means the individual requirements take effect at different times and do not apply in full immediately. The first obligations already became effective on 2 February 2025, including the AI literacy requirements under Art. 4 AI Act as well as the rules on prohibited AI practices under Art. 5 AI Act. Further obligations followed on 2 August 2025, affecting in particular new GPAI systems, i.e. general-purpose AI. From that date, the governance rules in Chapter VII and the sanctioning provisions in Chapter XII of the AI Act have also applied.

Key dates at a glance

  • 01.08.2024: Entry into force of the AI Act
  • 02.02.2025: First obligations for AI literacy under Art. 4 and rules on prohibited AI practices under Art. 5 AI Act
  • 02.08.2025: Further obligations for, among others, new GPAI systems; governance and sanctioning rules
  • 02.08.2026: General applicability
  • 02.08.2027: Obligations for GPAI models placed on the market before 02.08.2025
  • 31.12.2030: Special deadline for AI systems in large-scale IT systems (Annex X)


General applicability in August 2026

The majority of obligations take effect after the 24‑month transition period from 02 August 2026. This date marks the so‑called general applicability of the AI Act. Particularly affected are AI systems with transparency risk under Art. 50 AI Act, new high-risk AI systems under Annex III AI Act, and existing high-risk AI systems under Annex III that are significantly modified after 02 August 2026.

Special cases with longer transitional periods

  • Exception Annex I + third‑party assessment
    Exceptions apply to certain high‑risk AI systems that are part of a product under Annex I (or a safety component thereof). This particularly concerns cases where a conformity assessment by a third party is required prior to placing on the market – or where the system is significantly modified after 2 August 2026.
  • Transitional period for “legacy” GPAI models
    For GPAI models placed on the market before 2 August 2025, a 36‑month transitional period applies. The corresponding provisions therefore only apply from 2 August 2027.
  • Large‑scale IT systems (Annex X)
    AI systems that are part of a large‑scale IT system under Annex X and were placed on the market or put into service before 2 August 2027 fall into the last group. For them, the corresponding provisions apply from 31 December 2030.

What’s next: The German act implementing the AI Act

Why Germany needs an implementing act
The AI Act is directly applicable EU law and fully binding in all EU Member States. It does not require national transposition to become legally effective. Nevertheless, the AI Act requires complementary national implementing measures to be practically applicable. Under the AI Act, each Member State should by 2 August 2025 have established or designated at least one notifying authority and at least one market surveillance authority, as well as enacted national sanctioning provisions and measures to support innovation. The German legislator was unable to meet this deadline due to the formation of a new government.

Status as of September 2025: Draft bill and next steps
In September 2025, the Federal Ministry for Digital and Transport adopted a draft bill for Germany’s act implementing the AI Act. At present, federal states, associations, organisations and institutions can submit written comments before the draft proceeds through the legislative process to the Bundesrat, Bundestag and final publication.

The draft envisages close cooperation between various authorities such as the Bundesnetzagentur, BaFin, BSI, the data protection authorities and the Federal Cartel Office. The Bundesnetzagentur is designated as the central market surveillance authority and will establish a coordination and competence centre to support other authorities. In addition, the German legislator fulfils the required measures to promote innovation and provides for information and training offerings by the Bundesnetzagentur, particularly to support SMEs and startups. Furthermore, AI sandboxes are to be set up for testing and experimentation under real‑world conditions, alongside capacity building, networking and standardisation.

Digital Omnibus: The EU revises the AI Act

The AI Act’s phased applicability is intended to allow all stakeholders to build on experience – both providers and operators as well as the European Commission. The obligations already in force have clearly shown that important standards and instruments for practical implementation are missing. Many companies faced unclear boundaries between the AI Act and other EU legislation, leading to inconsistencies and burdensome compliance. The European Commission is now responding to implementation challenges with the new Digital Omnibus and is publishing targeted adjustments to create a simpler, more consistent and innovation‑friendly legal framework.

 

Contact

Your personal contact

Do you have any questions about our blog post, our services, or our Compliance Management Software Eticor? We are looking forwar to hearing from you.
 
eileen-müller-rund
Eileen Müller
LL.M.
AI & Legal Compliance Expert
e.mueller@eticor.com
+49 151 1636 2629
tim bieber
Tim Bieber
LL.M.
Legal Compliance Expert
t.bieber@eticor.com
+49 6022 2656 127