The European Commission published the final version of its AI content labelling Code of Practice on June 10, 2026. The playbook is voluntary, but the law behind it is not. The transparency obligations it addresses come into force on August 2, 2026, and they apply to every business operating in the EU whether or not it signs the Commission's guidance.
Signing the Code simply gives a company a recognized way to show it complies. Not signing does not exempt anyone.
Three categories of AI use will require clear disclosure from August. First, any interactive AI system, such as a customer-service chatbot, a virtual assistant, or an AI phone line, must tell users they are talking to a machine. Second, AI-written text published on matters of public interest must be labelled, unless a human has genuinely reviewed and taken editorial responsibility for it. Third, deepfakes, including AI-altered images, voices, or video used in any context, must be visibly flagged. This covers advertising campaigns that use synthetic voices or AI-modified faces of real people.
The definition of deepfake under the guidelines is broader than most businesses expect. What matters is whether the content would appear authentic to an ordinary person, not whether there was any intent to deceive. An AI-generated spokesperson in a video advertisement falls inside the definition regardless of whether the advertiser meant to mislead anyone.
The law also does not care where the company is headquartered. Any provider or deployer of AI systems serving EU users is in scope. A retailer in Southeast Asia running an AI chatbot for European customers is subject to the same rules as a German insurer.
The split of responsibility runs through the supply chain. The companies that build AI models are required to embed machine-readable marks in their outputs so the content can be detected downstream. The companies that deploy those models in real products handle the visible labelling that users actually see.
For businesses that have been running AI tools without any disclosure, this requires action now. Non-compliance with these transparency rules carries fines up to 15 million euros or 3% of total worldwide annual revenue, whichever is higher. That ceiling sits above GDPR's maximum, making the AI Act the second-largest percentage-based penalty regime in EU digital regulation.
There is a narrow grace period for AI systems already on the market before August 2. Under a provisional agreement reached in May 2026, those existing systems have until December 2, 2026, to meet the machine-readable marking requirement specifically. Everything else, including the chatbot disclosure and deepfake labelling, is expected to apply from August 2 without delay.
Regulators have also indicated they will look more favorably on organizations that can show they were working toward compliance, even if not fully there on day one. Documented effort matters. Doing nothing does not.
The practical steps are not complicated. Any customer-facing AI tool needs a clear disclosure at the start of the interaction. Any AI-generated content published for public audiences needs a label. Any deepfake or AI-altered media needs a visible marker. The Commission has also released a standard EU icon that businesses can use, so there is no need to design a disclosure system from scratch.