The EU’s August AI Deadline: What Bots and Synthetic Content Need Now

Illustrated infographic summarizing: The EU’s August AI Deadline Reaches Bots and Synthetic Content

By Greg Nowak. Last updated 2026-09-29.

The EU AI Act’s 2 August 2026 transparency deadline has passed. If your business uses a customer bot, publishes AI-generated material or commissions synthetic media, the useful question now is simple: what does a person actually see or hear, and does the right disclosure reach them in time?

Article 50 assigns different duties to providers, who make AI systems available under their own name or trademark, and deployers, who use them under their authority. An agency or business may need to assess more than one role across its projects. Buying a tool does not tell you whether the website, publication or media workflow using it is covered.

The deadline has passed, with one narrow transition

Article 50 has applied since 2 August 2026. The Commission’s current Article 50 FAQ describes a transition until 2 December 2026 for providers of systems placed on the market before 2 August, and only for the machine-readable marking and detection duty in Article 50(2). It is not a general extension for bot notices or deployer disclosures. The Commission also says content generated before 2 August does not have to be labelled retroactively.

For an operations lead, that means checking live experiences now, while separately confirming whether a provider you rely on qualifies for the marking transition. Record the reason for any exception or transition decision rather than treating a vendor’s general compliance statement as the answer.

Which control belongs where?

The duties are easy to mix up because they concern similar content. A machine-readable mark helps identify an output as AI-generated or manipulated; it is not the same thing as a notice a person can understand. Equally, labelling a published image does not settle whether the system that produced it has the required technical marking capability.

Touchpoint Question to settle Practical control
Customer chat or AI agent Does AI communicate directly with a person? Clear, accessible notice from the first interaction, unless AI involvement is genuinely obvious in context
Generated text, image, audio or video Who provides the system, and does an exception or transition apply? Check machine-readable marking and whether it survives the output workflow
Image, audio or video presented as authentic Does it meet the Act’s definition of a deepfake? Human-perceivable disclosure when the audience first encounters it
Public-interest text Was AI used to generate or manipulate published text, and was there substantive human review or editorial control? Disclosure or a recorded assessment of the editorial exception
Emotion recognition or biometric categorisation Who is exposed to the system? Accessible notice about its operation and a separate privacy review
Use this as an inventory prompt; the legal classification depends on the system and its use.

Map the experience, not just the software licence

One AI service can sit behind a website chat widget, an internal drafting tool and an agency content pipeline. List those as separate touchpoints. For each, record the audience, where the interaction or output appears, who controls the interface, who approves publication and which vendor supplies the underlying system. Give each touchpoint a business owner and a technical owner.

Then walk through a real example. On mobile, does a visitor see that the support conversation is with AI before exchanging messages? If an editor generates an image, does its mark remain detectable after cropping, compression and export through the CMS? If a campaign uses a realistic synthetic voice or scene, will the disclosure travel with the clip when a client or social platform republishes it? These checks reveal gaps that a vendor questionnaire alone will miss.

Make publishing decisions repeatable

Not every AI-assisted edit needs the same treatment. The Commission’s final guidelines distinguish standard editing from more substantial generation or manipulation. A deepfake is also narrower than “any AI image”: it concerns image, audio or video that resembles an existing person, object, place, entity or event and could falsely appear authentic or truthful. Have the relevant adviser assess borderline cases before a team builds a blanket labelling rule.

For text published to inform the public on matters of public interest, the editorial exception requires meaningful human review or editorial control and an identifiable person or organisation with editorial responsibility. Spell-checking alone is not substantive review. A useful CMS process records who checked the claims and sources, who could change or reject the piece, and who accepted responsibility for publication. Where disclosure is required, make it a required publishing field rather than a reminder in a spreadsheet.

Notices should be clear, distinguishable and accessible at the first interaction or exposure. Test them in the formats people actually use: an embedded bot, a mobile page, a silent video preview and a shared social post. The Commission’s voluntary Code of Practice on Transparency of AI-generated Content offers measures for marking and labelling. Its scope does not remove the separate work on direct AI interaction, emotion recognition or biometric categorisation.

Turn the inventory into a delivery plan

Start with public bots, realistic synthetic media and automated publishing because people encounter those outputs directly. For each touchpoint, record the provisional provider or deployer role, the applicable duty, the current control, the evidence you tested and the person who can approve a fix. Route uncertain classifications and exceptions to legal counsel; route personal-data questions to the privacy team.

Then place fixes in the systems that produce the experience: chat components, CMS templates, media export steps, vendor requirements and release checks. Re-test the published result after changes. If several teams and suppliers are involved, Greg can help coordinate the inventory and delivery work so decisions become controls people can actually use.

Related on GrN.dk

Need help with this kind of work?

Discuss your AI transparency project with Greg Get in touch with Greg.

Sources

Latest articles

When an OpenAI request stalls, customers need an accurate status. Set sensible retry limits, preserve submissions, and make unresolved work visible.

I learned server operations by breaking my own servers. I want someone who stands next to me while I do it, then does it themselves the week after.

I am good at building and bad at calling. Here is who I want next to me, what is easiest to sell, and how we split it.

An AI assistant can prepare a refund, but a person should approve the exact payment and amount. Here is how to make that approval hold up through execution and retries.

AI can pull together onboarding tasks before a new hire’s first day. See how the manager approves specific access and how outstanding tasks are followed through.

An internal AI assistant can cite an obsolete handbook with confidence. Here is how to manage document ownership, updates, deletions, access and answer review.

Cloudflare Free provides useful website protection, but its rate limiting and bot controls have limits. Here is how to assess them for a WordPress site.

An AI assistant can answer questions and guide customers to a booking. Here are practical boundaries for prices, delivery times, personal data, and contact with a staff member.

Google and Bing now offer first-party AI search visibility reports. Here’s how to build a useful baseline without inventing a misleading GEO score.

AI crawlers can copy a familiar name. Here’s how to verify signed agents at the edge while keeping legitimate automated traffic moving.