Regulation (EU) 2024/1689 on artificial intelligence (the “AI Regulation”) introduces, under Article 50, four transparency obligations applicable from 2 August 2026. From that date, they apply not only to high-risk AI systems but, in principle, to any AI system. In practice, almost each company that uses a chatbot, generates content with AI, or uses emotion-recognition systems is caught by the rules.

It should be pointed out, however, that employees operating a system on their employer's instructions (for instance, a content creator or journalist working for a company) are not themselves treated as separate operators: the obligations remain with the company. Nor do the obligations apply to individuals who use an AI system strictly for personal, non-commercial purposes.

On 20 July 2026, the European Commission published guidelines clarifying how the rules apply. We summarise them below in practical terms, focusing on who each obligation applies to, what exceptions exist, and what non-compliant companies risk.

  1. Informing people that they are dealing with an AI system

Providers of AI systems must design any system that holds a conversation with a person (chatbots, voice assistants, AI agents) so that the person knows they are talking to an AI, from the very first contact.

With the single exception, disclosure is not required where it is obvious to a reasonably well-informed, careful and cautious person that they are interacting with an AI system. The Commission's guidelines propose a two-step test:

  • identify the target audience the system is aimed at;
  • assess whether an average member of that audience, reasonably attentive and circumspect, would realise from the context that they were talking to an AI (for example, from the system's name, the way its responses are phrased, or the commercial context in which it is used).

It is important to note that the exception must be interpreted in strict terms, precisely because it removes a person's right to be informed. The Regulation does not require companies to draw up an internal document justifying use of the exception, but we recommend keeping a brief internal note setting out the reasoning — useful in the event of an inspection, given that the burden of justification falls on the provider.

  1. Machine-readable marking of AI-generated content

Providers of generative systems (text, image, audio, video) must embed a technical marker (metadata, digital watermark) that allows an automated tool — not necessarily the human eye — to subsequently detect that the content was generated or altered by AI. This is a different obligation from the visible label discussed at point 4 below: there, the person must see the disclosure; here, only systems need to be able to detect it.

This obligation does not apply where the AI system merely performs an assistive function for standard editing tasks (for example, grammar correction), where it does not substantially alter the input data or its meaning, or in the case of systems authorised by law to detect, prevent, investigate or prosecute criminal offences. Systems already on the market as of 2 August 2026 have until 2 December 2026 to comply.

Providers that join the Code of Practice on the Transparency of AI-generated Content, drawn up with the Commission's support, can more readily demonstrate compliance with this obligation; joining is voluntary, but it reduces the risk of further information requests from the authorities.

In practice, joining the Code means signing one or both sections of the document, drafted by independent experts and assessed as adequate by both the European Commission and the European Artificial Intelligence Board. The Code is structured in two distinct sections, corresponding to the two categories of actor covered by the transparency obligations: Section 1 covers measures for generative AI systems suppliers — those actually subject to the legal obligation to label content — but can also be signed by providers of labelling and detection solutions, as well as by providers of AI models that support implementation of these measures; Section 2 covers measures for operators (deployers), i.e. entities that actually use these systems in their own operations. Section 1 has already been signed by 82 organisations, including Google, Microsoft, Meta, OpenAI, Anthropic, Mistral and Cohere. Section 2 has 152 signatories, including Lufthansa, Getty Images, Iberdrola and Bulgari. By the end of July 2026, around 190 organisations from sectors such as IT, telecoms, education and retail had joined the Code, almost half of them small and recently established companies. In effect, a company that signs commits to a set of standardised measures, already vetted by the authorities, giving it a predictable compliance route that is recognised in every member state regardless of the competent national authority, and that reduces the risk of further inspections or of diverging interpretations between countries. Signatories are also invited to join two working groups due to launch in September 2026, dedicated to exchanging industry best practice.

(Data on the Code's signatories was published by the European AI Office, part of the European Commission, on the digital-strategy.ec.europa.eu platform, in a statement dated 31 July 2026 entitled “Strong backing for the Code of Practice on Transparency of AI-generated Content”. The full list of signatories is updated periodically on the same page.)

  1. Transparency of emotion-recognition and biometric categorisation systems

This time, the obligation is not on the provider but on the operator (deployer) — the entity that actually uses the system in its own operations, under its own authority.

Important to point out that we are not talking about biometric identification systems (for example, facial recognition used to establish who a person is), which are subject to stricter rules, but rather:

  • emotion-recognition systems: those that infer emotional states or intentions from biometric data (facial expressions, voice, heart rate, etc.);
  • biometric categorisation systems: those that place a person into categories on the basis of biometric data (for example, estimating certain demographic characteristics), without seeking to identify them.

The obligation is therefore particularly relevant for operators in retail, human resources (for example, automatically analysed video interviews), marketing, or workplace safety. Those affected must be informed about how the system works, and any processing of the biometric data involved must comply with the rules on the protection of personal data (GDPR).

The obligation does not apply to systems authorised by law for the detection, prevention or investigation of criminal offences, provided appropriate safeguards for third-party rights are in place.

  1. Disclosure of deepfakes and AI-generated texts on matters of public interest

(a) Deepfakes

First, operators of AI systems that generate or manipulate image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated.

Article 3(60) of the AI Regulation defines deepfakes as AI-generated or AI-manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. The Commission's implementation guidelines clarify that content that is obviously fanciful or physically impossible (for example, dragons or elephants driving cars) does not fall within the definition of a deepfake.

Suggested approaches for informing users include permanent visual labels, warning notices displayed at the start of videos, and audible warnings on audio files.

The obligation does not apply where use is authorised by law to detect, prevent, investigate or prosecute criminal offences.

Furthermore, where deepfake content forms part of a work or programme that is evidently artistic, creative, satirical, fictional or similar in nature, the disclosure obligation is reduced: it is limited to disclosing the existence of generated or manipulated content in a suitable manner that does not interfere with the presentation or enjoyment of the work.

(b) AI-generated texts on matters of public interest

Second, operators of AI systems that generate or manipulate texts published to inform the public on matters of public interest must disclose that the text has been artificially generated or manipulated.

This obligation does not apply where use is authorised by law to detect, prevent, investigate or prosecute criminal offences, or where the AI-generated content has undergone human review or editorial control, with a natural or legal person assuming editorial responsibility for its publication. It should be noted that a simple grammar check or a purely formal review is not enough to benefit from this exception.

For these obligations too, joining the Code of Practice on the Transparency of AI-generated Content, described above, can help demonstrate compliance more easily.

Penalties and competent authorities

Fines can reach €15 million or 3% of global turnover (a reduced regime applies to SMEs). Enforcement generally falls to national market surveillance authorities. Only in certain cases does it fall to the European AI Office or the European Data Protection Supervisor.

The current situation in Romania

On 12 March 2026, the Government adopted a memorandum proposing ANCOM as the supervisory authority and single point of contact, alongside the ASF/NBR (financial services) and ANSPDCP (biometrics, law enforcement). The memorandum, however, is only an administrative commitment: the domestic law that would set out the organisation and cooperation between authorities and the penalty procedure is still being drafted, and the European deadline for designating the authorities (2 August 2025) has already been missed. In practice, checks and penalties at national level cannot begin in earnest until this law is passed.

Conclusions

The new transparency obligations under the AI Regulation bring concrete rights for users, but also clear responsibilities — backed by significant potential penalties — for providers and operators of AI systems. At European level, the framework is already operational. At national level, in Romania, the institutional framework has only been sketched out, and the law needed to make it operational is still being drafted.

For companies in Romania seeking a faster route to compliance, joining the Code of Practice — already signed by names such as Google, Microsoft, Meta and Lufthansa — remains, at least until the national framework is clarified, the most readily available way of demonstrating good faith to the authorities.

 

Authors:
Ioana Chiper Zah
Horea Ardelean