AI Act Transparency Rules Now Live in Your Interface
AI August 11, 2026 · 5 min read

AI Act Transparency Rules Now Live in Your Interface

AI Act Transparency Rules Now Live in Your Interface cover

The EU spent most of this year arguing about whether its own AI deadlines were realistic. The answer arrived six days before the biggest one. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and pushed the heavy high-risk obligations back by more than a year. What it did not push back is the part that lives on screen.

The split is worth getting exact. Standalone high-risk systems under Annex III, a list that includes creditworthiness checks, employment screening and biometric identification, now apply from 2 December 2027. AI embedded in regulated products under Annex I moves to 2 August 2028. The Commission's own timeline page carries both dates. The transparency rules under Article 50 stayed where they were and took effect on 2 August 2026. So the first thing that actually came due under the AI Act is not model documentation or a conformity assessment. It is interface work: what the screen says, and when it says it.

What Article 50 asks for

Providers have to make sure people know they are interacting with an AI system, unless that would already be obvious to a reasonably well informed person. Providers of systems that generate synthetic audio, image, video or text have to mark the output as artificially generated in a machine-readable format. Deployers running emotion recognition or biometric categorisation have to inform the people exposed to it. Deployers publishing deepfake image, audio or video content have to disclose that it was artificially generated, with a narrower exception for artistic and satirical work. The timing language is the part most teams have skimmed. Disclosure has to happen at the latest at the time of the first interaction or exposure, in a clear and distinguishable manner, and it has to meet accessibility requirements. That quietly rules out several patterns that are shipping today. A disclosure that only exists in the terms page is late. A one-time onboarding notice is late for anyone arriving mid-flow from a push notification or a deep link, and late again for the second person on a shared device. Nine-point grey text under the composer is not clear and distinguishable, and it fails contrast long before anyone argues about placement.

The deferral makes design work more urgent, not less

There is a reading of the omnibus where everyone relaxes until late 2027. It is the wrong reading, and finance shows why. Creditworthiness checking sits in the Annex III list, so the risk management, logging and human oversight stack wrapped around a scoring model does now have until December 2027. That is real relief for the data science side. But the assistant sitting in the mobile app, the one that answers questions about a declined payment and nudges people toward a credit product, is not the scoring model. It is a chatbot, and its disclosure duty applied on 2 August 2026. The deferral moved the slow, expensive, document-heavy work and left the fast, visible work exactly where it was. Marketing has the same problem from the other direction. If a campaign page for a card product uses a generated portrait of a customer who does not exist, the deployer disclosure obligation attaches to that image, not to the model that made it. In the fintech products we work on, the in-app assistant and the marketing site are almost always owned by different teams on different release trains. That is usually how one of them ends up out of compliance while everyone assumes the other team handled it.

Designing a disclosure that holds up

The default move is a banner on first open. A few approaches hold up better than that. Make the label persistent rather than one-shot. A dismissible notice satisfies a checklist reading of the rule and fails the actual requirement, because the next entry into that surface is also a first interaction. Attaching the label to the surface itself, in the chat panel header or as a byline on generated copy, survives every route in. Every route in then needs its own pass. Deep links, push notifications, search results, a support handoff, a widget on the account dashboard: each one can be somebody's first exposure, and each one has to carry the disclosure. The work is tedious, and it is where most teams have a gap right now. The label also has to track who is actually answering. When a conversation moves from an automated agent to a human, and back again, the label moves with it. Users notice when it lies to them, and the trust cost of being caught is worse than the regulatory one. Accessibility is named in the article itself, which makes a visual-only badge unfinished work. That means real text instead of type baked into an image, contrast that passes, and something a screen reader will actually announce. Over-disclosing has its own cost. The rule exempts cases where the AI involvement is already obvious, and stamping "AI generated" across every surface trains people to stop reading the label. That is the opposite of what the rule protects.

The December date nobody has in the calendar

The other date worth writing down is 2 December 2026, the runway for machine-readable marking of AI-generated output under Article 50(2). Marking is not a visible watermark. It is provenance metadata, and metadata has to survive a pipeline that was never designed to protect it. An export step re-encodes the file. A CMS strips the metadata block on upload. A crop tool writes a fresh image with none of the original fields. Compliance gets solved in the model layer and quietly undone in the asset layer, usually by tooling that predates anyone thinking about this. If nobody owns that chain end to end, the marking obligation is not met, no matter what the model does.

What it costs to get wrong

Penalties for Article 50 breaches reach 15 million euro or 3% of total worldwide annual turnover, whichever is higher. Prohibited practices under Article 5 carry 35 million euro or 7%. The omnibus also added a new prohibition on AI-generated non-consensual intimate imagery, which sits in that higher band. Most of the coverage this summer has been about the delay. The practical effect for product teams is narrower and lands sooner. The obligations that need lawyers and documentation moved to 2027. The obligations that need a designer applied this month. If your AI features shipped before August and nobody has looked at how they announce themselves, that is the review worth running this week.

Sources

1. European Commission, "AI Act", last updated August 3, 2026
2. EU Artificial Intelligence Act, "Article 50: Transparency Obligations for Providers and Deployers", Regulation (EU) 2024/1689
3. EU Artificial Intelligence Act, "Article 99: Penalties", Regulation (EU) 2024/1689
4. Hunton Andrews Kurth, "EU Digital Omnibus on AI Enters Into Force", July 28, 2026
5. Jones Walker, "Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain", July 16, 2026
6. Travers Smith, "EU agrees to delay key AI Act compliance deadlines", May 8, 2026

Need a partner who tracks this stuff?

We build for the markets and rails ahead of the curve.

Talk to us

Keep reading

All posts
iGaming

Why Nobody Opens Your Responsible Gaming Tools

10 min · August 6
Marketing

AI Mode Ads Don't Buy Citations. Your Pages Do.

5 min · August 3