On August 2, Europe’s landmark AI law moves from policy debate into daily business operations. The first deadline is narrower than many headlines suggest—but it reaches far beyond technology companies.
For years, businesses have discussed the European Union’s AI Act as something coming later.
Later has arrived.
On August 2, 2026, major transparency requirements begin applying to companies that develop or deploy certain artificial-intelligence systems in the European market. Customer-service bots may need to identify themselves. Providers of generative systems must support detection of AI-generated material. Businesses publishing deepfakes or certain AI-produced public-interest content must disclose what they have done.
This does not mean every provision of the AI Act suddenly activates on the same day. Some of the most demanding rules for high-risk systems have been delayed. But the August deadline marks the point at which ordinary business uses of AI begin carrying explicit operational obligations.
The AI Act is no longer a future legal problem. It is becoming a workflow problem.
Customers Must Know When They Are Talking to AI
The most immediate requirement concerns interactive systems.
Providers must design AI systems so people are informed when they are directly interacting with artificial intelligence, unless that fact is obvious from the circumstances. A customer who opens a chatbot on a banking, retail or service website should not be led to believe they are speaking with a human employee.
The European Commission’s guidelines on AI transparency obligations clarify that the rules also cover machine-readable marking of AI-generated or manipulated content.
For businesses, this affects more than the small label beneath a chat window.
Companies must determine which customer interactions use AI, who controls the disclosure, whether a software vendor provides the required notice and what happens when a conversation moves between an automated agent and a human employee.
A company using a third-party chatbot cannot assume the vendor has solved every compliance issue. The provider may be responsible for designing the system, while the business deploying it remains responsible for how it is presented and used.
Not Every AI-Generated Sentence Needs a Warning Label
The transparency rules have already produced confusion, particularly among marketers.
The law does not simply require a warning on every email, advertisement or social-media caption touched by AI. The obligations depend on the type of content, how realistic it is, how it is published and whether a human has reviewed it.
Deepfakes—realistic AI-generated or manipulated images, audio and video—must generally be disclosed. Businesses should expect this to affect synthetic spokesperson videos, altered customer testimonials, cloned voices and realistic product demonstrations.
AI-generated text published to inform the public about matters of public interest may also require disclosure when it is released without meaningful human review or editorial responsibility.
That distinction makes the workflow important. A company that uses AI to produce a draft subsequently checked and approved by an accountable editor is in a different position from one automatically publishing generated articles without supervision.
The practical challenge is proving which process occurred.
Businesses will need records showing who reviewed important content, which tool generated or altered it and who accepted editorial responsibility before publication.
Emotion Recognition Brings Another Disclosure Duty
Companies using AI to infer emotions or categorize people using biometric information must inform the individuals exposed to those systems.
This could affect workplace-monitoring tools, interview-analysis software, customer sentiment systems, security technology and experimental retail analytics.
The issue is not limited to whether the technology works. Employees and customers must understand when it is being used on them.
Businesses buying AI products therefore need to ask vendors more precise questions. Does the system analyze facial movement, voice, behavior or emotional state? Does it merely transcribe an interaction, or does it classify the person? Where is that classification stored, and who uses it?
A feature marketed as “engagement analytics” may carry different implications from ordinary transcription.
The High-Risk Deadline Has Moved—Not Disappeared
Some of the AI Act’s most demanding requirements were scheduled to take effect in August 2026 but have been pushed back.
Rules affecting many high-risk workplace systems are now expected to apply from December 2, 2027. These can include AI used to filter job candidates, rank applicants, evaluate employee performance, allocate work or influence promotion and termination decisions.
The delay gives employers additional preparation time, but it does not remove the classification problem. A Reuters analysis of workplace AI compliance notes that businesses must assess what a tool actually does rather than relying on labels such as “productivity,” “automation” or “decision support.”
A scheduling tool may be routine. A tool that assigns desirable shifts based on worker scores may influence employment conditions.
A résumé organizer may be administrative. A system that ranks applicants or removes candidates from consideration may fall into a much more sensitive category.
The deadline moved. The need to understand the software did not.
What Businesses Should Do Now
The first step is not hiring a committee. It is building an inventory.
List every AI tool used in marketing, customer service, recruiting, HR, operations and employee productivity. Include features embedded inside existing software; many companies are already using AI they never formally purchased as a separate product.
For each use case, record who provides the system, who operates it, which employees or customers are affected, what data it uses, whether people know AI is involved, whether it generates public content, whether a human reviews the output, whether it ranks or evaluates individuals and who owns the business decision.
Companies should also review vendor contracts and documentation. A supplier’s assurance that its product is “AI Act ready” does not explain which responsibilities remain with the customer.
The larger lesson is that AI governance is moving into normal business administration.
Companies have spent the past three years asking what AI can do. Europe is now forcing a second question: who is responsible when it does it?





