Compliance Update from July 29th 2026
On August 2nd 2026, the general applicability of the AI Act takes effect. A milestone for a central topic: the labelling of AI-generated content. The new transparency requirements affect companies of all sizes, from startups to large enterprises.
Transparency requirements for AI-generated and manipulated content
According to Art. 50 of the AI Act, both providers and operators of an AI system must disclose when people are interacting with AI or when content has been artificially generated or manipulated. The requirements vary slightly depending on the role and the type of content. Providers of AI systems must ensure their AI systems are designed so that individuals are explicitly informed whenever they interact directly with an AI system. In addition, AI-generated audio, image, video or text content must be labelled in a machine-readable format, i.e. technically marked so that computers can detect it. Operators of an AI system that generates or manipulates image, audio or video content that is a deepfake must, by contrast, visibly label for humans that the content was artificially generated or manipulated.
It is the same fundamental obligation: transparency and honesty towards users.
A deepfake must meet three criteria:
Looks real: the viewer should think “That could be real”
Depicts something realistic: real people, places, objects or events
Falls into these categories: people, objects, places, living beings, events and scenes (including historical ones)
In June 2026, the European Commission published a Code of Practice on the transparency of AI-generated content with practical measures to meet the transparency requirements. The Code of Practice serves as a voluntary but practically binding guide. By following it, companies signal legal compliance and build trust.
The European Commission has also created EU icons for labelling AI-generated content that operators of generative AI systems can use to label their AI-generated content. The Code of Practice is further complemented by the Guidelines on transparency obligations for providers and users of certain AI systems published in July 2026.
Under Art. 50(5) of the AI Act, disclosure must take place no later than at the first interaction or first contact. The guidelines emphasise that a notice solely in the terms and conditions or hidden menus is not sufficient.
Examples of providing information at the first interaction or first contact in accordance with Article 50(5) of the AI Act:
Chatbots and physical systems: labelling at the start of the conversation
Videos with deepfakes: labelling at the beginning
AI-generated or manipulated texts on public-interest topics: labelling at the start
Deepfakes on social media: labelling upon first viewing
The transparency requirements can be demonstrated through the Code of Practice or equivalent alternatives. Providers and operators can define additional appropriate measures themselves.
On July 27th 2026, the Digital Omnibus Regulation on AI came into force and eases implementation timelines and compliance shortly before the AI Act’s general applicability as of 02/08/2026:
Due to delays in the availability of standards, common specifications and national authority structures, the start dates for obligations for high-risk AI systems are postponed: standalone systems under Annex III to December 2nd 2027, systems embedded in regulated products under Annex I to August 2nd 2028. The different timelines provide the necessary adjustment period. In future, the Commission is to provide guidance, standards, common specifications and practical guidance in due time to ensure legal certainty and a uniform application in the Member States.
The Omnibus eases the AI literacy obligation under Art. 4 of the AI Act: providers and operators of AI systems must still take measures to develop AI literacy among their staff, but are not required to guarantee a specific level of AI literacy for any individual. The Commission and Member States will in future support providers and operators through training, information resources, exchanges of best practices and other initiatives.
The Omnibus provides basic simplifications for small and medium-sized enterprises, including simplified documentation obligations and measures to promote innovation and support by national authorities.
On 2 August 2026, the AI Act becomes generally applicable, with transparency obligations for AI-generated and manipulated content as a central milestone. Direct interactions with AI must be recognisable, AI-generated content must be labelled in a machine-readable way, and deepfakes must be visibly marked as such for people. The Code of Practice and the EU guidelines offer practical orientation, with labelling required no later than at the first interaction.
In parallel, Germany’s AI‑MIG and the EU-wide AI Omnibus provide breathing room: the Bundesnetzagentur takes over central supervision in Germany, high-risk requirements are deferred to 2027 and 2028, and SMEs receive relief from obligations.
The result is a balanced framework: strict transparency obligations now, realistic implementation timelines for more complex requirements, and targeted relief for smaller players. For companies this means: act immediately on transparency, and plan specifically for high‑risk requirements.
Compliance Update from 2 December 2025
The EU’s AI Act has been in force since 1 August 2024, but its effect unfolds in stages. This means the individual requirements take effect at different times and do not apply in full immediately. The first obligations already became effective on 2 February 2025, including the AI literacy requirements under Art. 4 AI Act as well as the rules on prohibited AI practices under Art. 5 AI Act. Further obligations followed on 2 August 2025, affecting in particular new GPAI systems, i.e. general-purpose AI. From that date, the governance rules in Chapter VII and the sanctioning provisions in Chapter XII of the AI Act have also applied.
The majority of obligations take effect after the 24‑month transition period from 02 August 2026. This date marks the so‑called general applicability of the AI Act. Particularly affected are AI systems with transparency risk under Art. 50 AI Act, new high-risk AI systems under Annex III AI Act, and existing high-risk AI systems under Annex III that are significantly modified after 02 August 2026.
Why Germany needs an implementing act
The AI Act is directly applicable EU law and fully binding in all EU Member States. It does not require national transposition to become legally effective. Nevertheless, the AI Act requires complementary national implementing measures to be practically applicable. Under the AI Act, each Member State should by 2 August 2025 have established or designated at least one notifying authority and at least one market surveillance authority, as well as enacted national sanctioning provisions and measures to support innovation. The German legislator was unable to meet this deadline due to the formation of a new government.
Status as of September 2025: Draft bill and next steps
In September 2025, the Federal Ministry for Digital and Transport adopted a draft bill for Germany’s act implementing the AI Act. At present, federal states, associations, organisations and institutions can submit written comments before the draft proceeds through the legislative process to the Bundesrat, Bundestag and final publication.
The draft envisages close cooperation between various authorities such as the Bundesnetzagentur, BaFin, BSI, the data protection authorities and the Federal Cartel Office. The Bundesnetzagentur is designated as the central market surveillance authority and will establish a coordination and competence centre to support other authorities. In addition, the German legislator fulfils the required measures to promote innovation and provides for information and training offerings by the Bundesnetzagentur, particularly to support SMEs and startups. Furthermore, AI sandboxes are to be set up for testing and experimentation under real‑world conditions, alongside capacity building, networking and standardisation.
The AI Act’s phased applicability is intended to allow all stakeholders to build on experience – both providers and operators as well as the European Commission. The obligations already in force have clearly shown that important standards and instruments for practical implementation are missing. Many companies faced unclear boundaries between the AI Act and other EU legislation, leading to inconsistencies and burdensome compliance. The European Commission is now responding to implementation challenges with the new Digital Omnibus and is publishing targeted adjustments to create a simpler, more consistent and innovation‑friendly legal framework.