
EU AI Act: from 2 August 2026 you must disclose AI-generated content — what your business has to do
By, zero-adm
- 29 Jun, 2026
- 1.5k Views
From 2 August 2026, Article 50 of the EU AI Act requires anyone using AI to disclose it: chatbots must tell users they’re talking to an AI, and AI-generated content — text, images, audio, video, deepfakes — must be marked as artificial. The AI Act’s transparency obligations aren’t just for AI labs: they hit any company running a chatbot on its site or generating marketing content with AI. Fines reach €15 million or 3% of worldwide annual turnover, whichever is higher.
What changes on 2 August 2026
Article 50 of the EU AI Regulation becomes applicable. In short:
- Chatbots and virtual assistants: users must be told they’re interacting with an AI.
- Generative AI (text, images, audio, video): outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated.
- Deepfakes (image/audio/video): whoever publishes them must disclose the content is artificial.
- AI text on matters of public interest: same disclosure.
The Commission has published guidelines and is finalizing a Code of Practice on marking and labelling.
Is my business really in scope?
The common misconception is that the AI Act only concerns OpenAI, Google or the big models. Article 50 actually targets deployers: the company that uses AI in front of the public. Run a support chatbot? Generate posts, emails, images or synthetic voices with AI? You’re in scope. And mind the extraterritorial reach: the regulation is European, but if your AI content or products are used in the EU — or you serve EU customers — you must comply even based in Chiasso or elsewhere in Switzerland.
And in Switzerland? When the AI Act actually applies to you
Switzerland is not part of the EU, so the AI Act is not Swiss law and doesn’t apply automatically. It only concerns you if your AI “touches” the EU: if you offer or sell AI systems on the EU market, or if the output of your AI is used by people in the EU. If you use AI only for your business and customers within Switzerland, the EU AI Act’s obligations don’t apply to you.
In parallel, Switzerland is taking a lighter path: no “Swiss AI Act”, but ratification of the Council of Europe’s AI Convention and targeted tweaks to existing laws (a draft for public consultation is expected by the end of 2026), focused on transparency and data protection. In short: if you also work with the EU, it’s worth getting ready now; if you’re Switzerland-only, keep an eye on the upcoming national rules.
What to do now (4 moves before 2 August)
- Map where you use AI toward the public: chatbots, generated emails/social, images, video, synthetic voices, auto-summaries.
- Turn on transparency: a “you’re talking to an AI assistant” notice; disclosure/labels on generated content; for generators, machine-readable marking (e.g. C2PA / Content Credentials).
- Update policies and contracts: who approves AI content, how it’s labelled, what you require from AI-tool vendors.
- Check your EU footprint: if you publish or sell in the EU, document compliance before the deadline.
2 August is only weeks away. Could you list, right now, every place your business puts AI content in front of a customer? See also how AI is reshaping both attack and defense in our guide to AI in cybersecurity.
Frequently asked questions
What is Article 50 of the EU AI Act?
The rule requiring transparency about AI use: telling users when they’re talking to an AI and labelling artificially generated or manipulated content. It applies from 2 August 2026.
Is my Swiss company subject to the EU AI Act?
Not automatically. Switzerland isn’t in the EU, so the AI Act isn’t Swiss law. It only applies if you offer AI systems on the EU market or your AI’s output is used by people in the EU; if you operate only in Switzerland, it doesn’t. Separately, Switzerland is implementing the Council of Europe’s AI Convention with lighter, sector-specific rules.
Do I have to label posts or emails written with AI?
For deepfakes and AI text on matters of public interest, disclosure is explicitly required; for ordinary marketing, the prudent practice is to disclose and mark synthetic content anyway.
What are the penalties?
For transparency-obligation breaches, up to €15 million or 3% of worldwide annual turnover (prohibited practices reach €35M or 7%).
Recent Posts
- Chat Control: More MEPs Voted No Than Yes, and It Passed Anyway
- Time-to-Exploit Just Went Negative: Why Patching Is No Longer Enough in 2026
- EU AI Act: from 2 August 2026 you must disclose AI-generated content — what your business has to do
- Digital Sovereignty in Switzerland: Why 2026 Rewrites the Cloud Rulebook for Government and Business
- IoT Security Risks: How Connected Devices Are Expanding the Cyberattack Surface
Category
- Cyber Security (90)
- Vulnerability Assessment (71)
Newest Posts
All Tag
2025 AI Automation Awareness Business CISO Compliance Cybercriminals CyberSecurity Academy Cybersecurity Awareness CyberSecurityRating Dataprotection EU AI Act Future GDPR Malware nFADP NIS2 nLPD Phishing Privacy Ramsonware Ransomware Supply Chain Threat Intelligence Treat Detection Vulnerability Assessment Vulnerability Management Zero-Day Zeroedge Academy
