From the AI Act to a visible obligation for internet users

The European Union is taking a new step in the implementation of its regulation on artificial intelligence. Transparency and labeling rules intended to make AI systems and certain AI-generated content more identifiable are now taking effect. As The Verge reports in its article on this entry into force, the objective is clear: to allow users to more easily know whether they are interacting with a machine or viewing, listening to, or reading content created or modified by artificial intelligence.

This deadline is particularly important because it affects the most visible uses of generative AI. Conversational assistants, tools that create images, speech synthesis services, video generators, and platforms distributing artificially manipulated content are directly concerned. At the heart of the European framework are deepfakes: audio, visual, or audiovisual content generated or altered by AI, capable of depicting a person as having said or done something they never said or did.

The European regulation on artificial intelligence, often referred to as the AI Act, is based on a risk-tiered approach. Certain practices are prohibited, while others are subject to strengthened obligations, particularly for systems classified as high-risk. But transparency requirements hold a distinct place. In principle, they do not seek to prohibit the use of generative models or conversational interfaces. Instead, they impose an information framework: when content or an interaction is artificial under conditions defined by the text, that artificial nature must be made known to the person concerned.

The logic is less dramatic than a prohibition, but it is structuring. For several years, public debate on generative AI has been dominated by the technical capabilities of models: producing plausible text, imitating a voice, creating a realistic image, or generating a video sequence. The AI Act brings another question into the regulatory sphere: that of the legibility of the digital environment. Internet users must be able to distinguish what comes from a person, an automated system, or content whose form has been modified by AI.

This direction comes at a time when generation tools have become accessible to a very broad public. Synthetic content is no longer reserved for laboratories, specialist studios, or technical teams. It can be produced by consumer platforms, integrated into creative software, used in customer services, communication campaigns, productivity tools, or search interfaces. For the European Union, the question is therefore not only about regulating model developers: it also concerns companies and platforms that deploy these systems to citizens.

In the text of the AI Act, this dimension is addressed through transparency obligations applicable to certain systems and certain uses. The regulation notably provides that systems intended to interact directly with natural persons must be designed and developed so that those persons are informed that they are interacting with AI, unless this is obvious from the circumstances and context of use. The obligation therefore covers customer-service chatbots, digital assistants integrated into a website, or conversational interfaces responding to a user.

For the general public, the change may seem simple: a message, label, or clear indication must signal the presence of AI. In practice, it is a profound change in how digital services design their user journeys. The information must be intelligible, appear at a useful moment, and not be buried in terms and conditions or a long settings screen. The European rule does not turn every form of automation into a suspicious experience. It seeks to prevent users from being left uncertain when interacting with a system intended to pass itself off as a person.

Chatbots, synthetic images, and deepfakes: what the rules cover

The scope of the transparency rules is not limited to conversations with assistants. The AI Act also addresses systems that generate or manipulate synthetic content. The regulation covers audio, image, video, or text content generated or modified by AI. Providers of systems capable of producing such content must design and develop their tools so that outputs are marked in a machine-readable format, enabling detection of their artificial origin or manipulation.

This detail is essential. Europe is not merely asking for a uniform visual notice to be displayed in every case. The text also addresses the technical traceability of content. The mark must be designed to be as effective, interoperable, robust, and reliable as technically feasible, taking into account in particular the characteristics of the type of content, generally recognized technical limitations, and implementation costs. In other words, the regulation sets a design and detection requirement, without claiming that all forms of marking will have the same effectiveness on a still image, a recompressed video, an audio file, or copied text.

The issue of deepfakes is nonetheless what makes the new operational phase of the AI Act most immediately tangible. When an AI system is used to generate or manipulate image, audio, or video content that deceptively resembles existing persons, objects, places, entities, or events and falsely appears to be authentic or truthful, the deployer of the system must indicate that the content has been artificially generated or manipulated.

The regulation requires this information to be provided clearly and distinguishably, no later than at the time of the first exposure or first interaction. The principle is important for platforms and publishers: information buried on a secondary page, in a menu, or in a note that is difficult to access does not meet the spirit of an obligation designed to inform the immediate reception of content. For an internet user, the promise is therefore not to have to guess afterwards that a political video, a fake statement, or a viral image was generated or modified by AI.

Several responsibilities must nevertheless be distinguished. The provider of a generation tool must incorporate mechanisms enabling the produced content to be marked. The deployer, meaning the actor actually using a system in a given context, has an obligation to provide information in the situations provided for. This distinction lies at the heart of European regulation. It avoids placing all obligations on the company that developed a model, when the risk of deception often depends on how the system is used, distributed, and presented to the public.

An image-generation tool may, for example, be offered to companies for graphic design. The provider is concerned by technical requirements relating to the identification of outputs. But the company that publishes a synthetic image in a campaign, on a website, or on a social network must also examine obligations linked to its actual use. The issue is even greater when a real person is imitated, a fictional event is presented as real, or content may influence public perception.

The regulation also provides provisions specific to AI-generated or manipulated textual content published for the purpose of informing the public on matters of public interest. The text requires disclosure of that artificial origin, with an exception where the content has undergone a process of human review and editorial responsibility, and where a natural or legal person holds editorial responsibility for its publication. This nuance is particularly significant for media outlets, publishers, public authorities, and organizations that use generative tools in their production processes.

It does not mean that every use of AI in a newsroom or public service becomes invisible. It recognizes that editorial responsibility, human review, and a publisher's capacity to take responsibility for published content are distinguishing factors. At the same time, it does not exempt the actors concerned from considering transparency towards their readers, customers, or users. The European rule sets a legal floor; editorial or commercial policies may go further.

The obligations also cover emotion-recognition or biometric-categorization systems when people are exposed to them. In these cases, the deployer must inform the persons concerned about the operation of the system. This part of the framework is less visible to an internet user viewing a video or using a chatbot, but it is a reminder that transparency under the AI Act does not exclusively concern content creation. It also concerns systems that analyze individuals or interact with them in an automated way.

Implementation as part of the European Union's gradual timetable

The entry into application of these rules does not occur in isolation. The AI Act is European Regulation 2024/1689, published in the Official Journal of the European Union in 2024. It entered into force on August 1, 2024, but its application was organized according to a gradual timetable. This architecture reflects the complexity of the text, the diversity of covered systems, and the need to give companies, authorities, and standardization bodies time to adapt their practices.

The first prohibitions provided for by the regulation became applicable in February 2025. Obligations concerning general-purpose AI models then constituted another important stage. The transparency rules now applying correspond to a particularly concrete phase of the timetable: they address services that the public is likely to encounter daily, rather than only technical infrastructure or specialized industrial uses.

This gradual approach has sometimes made the European debate difficult to follow. The AI Act was adopted as a single framework, but its obligations did not all apply on the same date. For users, the difference is considerable. A rule applicable to a provider of a general-purpose model may remain abstract. A rule requiring that an interaction with a chatbot be signaled or that the artificial nature of a deepfake be indicated, on the other hand, manifests itself directly in interfaces, content, and publishing practices.

The Verge highlights this shift toward labeling and information obligations. The term “labeling” used by the American media outlet refers to a simple but politically charged expectation: making AI content and systems recognizable. European regulation does not automatically solve every problem of disinformation, fraud, or identity theft. It does, however, add explicit responsibility for actors making these technologies available or using them.

This approach is part of the European Union's recent regulatory history. The General Data Protection Regulation, the GDPR, placed personal data and individuals' rights at the center of the European digital economy. The Digital Services Act, or DSA, strengthened obligations applicable to certain intermediary services and platforms regarding content and systemic risks. The AI Act operates in a different area: the design, placing on the market, deployment, and use of artificial intelligence systems.

The three texts are not interchangeable. A deepfake may raise questions of data protection, image rights, copyright, defamation, misleading commercial practices, or security, depending on the case. The AI Act adds a specific layer of AI requirements. For companies, the difficulty is therefore not simply displaying a notice. It is understanding which set of rules applies to a feature, campaign, internal tool, or platform accessible to the public.

The nature of a European regulation is decisive for France. Unlike a directive, a regulation is directly applicable in Member States, even though its implementation requires competent authorities, control mechanisms, and national adjustments. A French company and a company established in another Member State therefore face the same European baseline when they place on the market or deploy systems covered by the text in the Union.

The scope of the regulation does not mechanically stop at European companies. The AI Act has extraterritorial reach in certain cases, particularly where the output of a system is used in the European Union. For major international providers as well as software publishers targeting the European market, the challenge is therefore to integrate European requirements into their products, interfaces, and deployment conditions. This is one reason why transparency choices made for Europe may influence the design of services offered in other regions of the world.

For French companies, a compliance project that goes beyond a simple badge

In France, the consequences are concrete for a very broad range of actors: digital platforms, software publishers, communications agencies, e-commerce companies, banks, insurers, healthcare actors, local authorities, media outlets, educational institutions, and AI start-ups. They do not all have the same obligations, since these depend on the role played and the system used. But all may need to examine the generative tools they integrate into their products or processes.

The first task is to identify situations in which a user interacts with AI. A chatbot available on a retail website, an appointment-booking assistant, a technical-support tool, a conversational interface in an application, or a voice agent may fall under the information obligation. In some cases, the automated nature of the interaction will be obvious. In others, the company will need to make that information explicit. The central point is that information can no longer be treated as a mere user-experience consideration left solely to the publisher's choice.

The second project concerns the content production chain. A company may use an external model, a tool integrated into a software suite, an API, a creation platform, or a system developed in-house. It must then know whether the content produced is generated or manipulated by AI, whether the provider provides machine-readable marking, how that marking is retained, and what information must be communicated to the public upon distribution.

This issue is particularly sensitive in organizations where several teams publish content. The communications department may produce visuals, the marketing department videos, sales teams presentations, customer service automated responses, and human resources training materials. Without an inventory of tools and use cases, a company risks discovering too late that its content or interfaces fall under transparency obligations.

Compliance cannot be reduced to adding a generic “created by AI” logo. The European text distinguishes interaction with a system, technical marking of produced content, information on deepfakes, publication of texts in the public interest, and certain systems for analyzing people. A notice may be relevant in one case and insufficient in another. Companies must therefore link their labeling policy to a precise classification of uses.

There is also a documentation issue. When a tool is acquired from a service provider, the professional customer must be able to understand the capabilities of the system and the transparency mechanisms offered. When a system is developed in-house, technical and editorial choices must be formalized. This need reflects a broader reality of the AI market: purchasing a model or API does not automatically transfer all responsibilities to the provider.

Small businesses and start-ups are not spared by this development, even if their compliance resources differ from those of major platforms. For them, the challenge may be twofold. They must comply with a demanding European framework while often relying on technological building blocks designed by major international providers. In this context, the availability of traceability functions, clear documentation, and reusable information mechanisms may become a technological selection criterion.

For companies developing products intended for the French-speaking market, the linguistic issue is also important. Transparency information must be understandable to its intended user. A vague indication, inaccurately translated, or placed in a confusing interface may weaken the legibility objective sought by the regulation. Companies operating in France, Belgium, Luxembourg, Switzerland, or French-speaking Canada are not all subject to the same legal framework, but design decisions made for the European market may have a much broader reach in the French-speaking world.

Transparency may also become a competitive issue. Companies that clearly incorporate information about the use of AI into their products may seek to differentiate themselves through a promise of trust. Conversely, insufficient transparency may fuel mistrust, especially in sectors where human relationships are valued: consulting, insurance, banking, education, recruitment, healthcare, or information. The AI Act does not dictate a commercial strategy, but it changes the framework within which that strategy must be considered.

The limits of labeling in the face of content circulation and circumvention risks

Labeling content generated or manipulated by AI should not be presented as a definitive technical solution to the proliferation of deepfakes. The regulation itself recognizes the diversity of content and technical constraints. An image may be cropped, a video recompressed, an audio track converted, or text copied and then republished. At each stage, technical information associated with the file may be altered, removed, or become difficult to use.

This is precisely why the AI Act combines several levels of response. It imposes design obligations on providers of generative systems, but also disclosure obligations on deployers in certain circumstances. This combination does not guarantee that malicious content will always be detected after multiple republications. It nevertheless creates responsibilities at the origin of the chain and when content is used with the public.

There is also a fundamental distinction between transparency and truthfulness. Content properly labeled as AI-generated may still be misleading in its message, staging, or dissemination context. Conversely, authentic content may be presented misleadingly without using AI. Transparency rules therefore replace neither journalistic fact-checking, platform moderation, electoral rules, nor protections against fraud and impersonation.

In the case of deepfakes, information on artificial nature nevertheless has value in itself. It can reduce ambiguity when content is used for entertainment, advertising, a technical demonstration, or a creative work. It becomes more decisive when content depicts an identifiable person, an executive, a public figure, or an event that may be taken as real. The issue is then less about judging the artistic quality of content than protecting the public's ability to understand what it sees.

The exceptions provided for certain uses also show that the European legislator sought to avoid a mechanical approach. Clearly artistic, creative, satirical, fictional, or similar content may be subject to specific disclosure arrangements, provided that the information does not prevent the display or enjoyment of the work. The text therefore does not treat every synthetic creation as deception. It primarily targets situations in which the appearance of authenticity may lead the public into error.

This nuance will be important for creators, studios, agencies, and platforms. AI-assisted creation can be used to produce visual effects, fictional characters, illustrations, synthetic voices, or scenarios. The AI Act does not prohibit these uses merely because they are artificial. It does, however, encourage actors to clarify the boundary between acknowledged fiction, identifiable creation, and content presented as a faithful representation of reality.

Implementation will also depend on choices made by major platforms. Social networks, video-sharing services, and creation tools account for a significant share of the production and circulation of synthetic content. They may have metadata, technical signals, or user declarations. But they also host content produced by third-party tools, sometimes outside the European Union, sometimes modified before publication. Applying transparency in this environment will rely on technical systems, internal procedures, and moderation decisions that do not all fall under the AI Act alone.

For French internet users, the most visible effect will probably be the more frequent appearance of signals indicating that an assistant is automated or that content has been generated or modified by AI. Their effectiveness will depend on their consistency. If interfaces multiply ambiguous wording, unexplained icons, or warnings placed outside the field of view, the information risks becoming a formality. If it is clear, contextualized, and consistent, it can help establish new habits of digital reading.

Toward a new digital trust infrastructure in Europe

The application of transparency rules opens a period in which generative AI will have to be considered not only as a production technology, but as a technology for relating to the public. During the phase of rapid adoption of assistants and generators, many companies sought to make AI seamless, discreet, and integrated into existing uses. The AI Act introduces an opposite movement in certain respects: automation must be made perceptible when its identity or effects are relevant to the user.

This development could influence software design standards. Indicating that a chatbot is AI may become an ordinary interface element, like identifying advertising space, sponsored content, or an automated message. Technical identification of synthetic content could also become more important in professional tools, particularly when organizations need to retain production records, collaborate with partners, or publish across several channels.

For European companies, the long-term challenge is to turn a regulatory obligation into operational capability. This requires knowing which models are used, understanding the limitations of their marking mechanisms, defining who decides to publish synthetic content, and training teams likely to deploy conversational tools. Compliance will not be solely the responsibility of legal departments: it will concern product, security, communications, data, design, and editorial teams.

France has an AI ecosystem bringing together research laboratories, public actors, established companies, and young specialized firms. For this ecosystem, European transparency may represent a compliance constraint, but also a framework for differentiation. In a market where users question the origin of content, the ability to explain the use of AI and signal synthetic content may become a component of service quality.

The main test will come from the real-world application of the rules. It will be necessary to observe how providers integrate machine-readable marking, how deployers signal deepfakes, how platforms handle modified content, and how authorities interpret borderline cases. The regulation provides vocabulary and obligations. It does not by itself determine usage habits, concrete interfaces, or the technical solutions that will prevail.

Over the longer term, the AI Act could help shift the question posed to internet users. It will no longer only be a matter of asking whether content is true or false, but also knowing how it was produced, modified, and presented. This distinction does not replace critical thinking, but it provides additional information at a time when synthetic content is becoming ordinary. For French companies and major international platforms alike, the phase now opening is that of a web where AI will have to declare itself more before seeking to persuade.

Back to all news

Comments· 2 comments

  1. David Brown· 4 août 2026

    Does anyone have the exact legal reference or guidance clarifying which chatbot disclosures are mandatory at the interface level? The headline sounds broad, but the practical distinction between informing users they are interacting with AI and labelling synthetic content is likely to matter a lot.

    1. Anna Miller· 4 août 2026

      The most useful starting point may be the European Commission’s AI Act materials and any published codes of practice or implementation guidance. I’d also check the final text’s definitions and the relevant transparency provisions directly, since the required notice, its timing, and possible exceptions may depend on the system’s use and the type of content involved.

Leave a comment