Deepfakes and AI-written news in Europe now carry legal disclosure duties. The EU AI Act’s transparency tier became enforceable on August 2, 2026, turning voluntary guidance into binding obligations for model makers and the companies that deploy them, with penalties reaching €15M or 3% of global annual turnover.
The duties extend beyond the EU’s borders. Any provider or deployer whose AI output is used inside the bloc is covered, wherever it is based. Chatbots must identify themselves as machines, synthetic media needs interoperable machine-readable marks, deepfakes demand visible labels, and AI text on politics, health, justice or security must be flagged unless a human has reviewed it. Systems placed on the market before the date get until December 2, 2026 to meet the marking rule.
Around 190 organizations have signed the code of practice designed to demonstrate compliance, from Anthropic, Google, Meta, Microsoft, Mistral, OpenAI and Cohere on the provider side to Getty Images, Lenovo and Lufthansa as deployers. Signatories can point to the code’s measures across all 27 member states; everyone else must prove equivalent compliance case by case.
OpenAI has published how its existing safeguards map onto the rules, citing pre-release testing, system cards, its red-teaming network and the Preparedness Framework. It also launched an EU Cyber Action Plan in May that gives vetted defenders access to advanced cyber models.