Skip to content
PrivateAI
← Back to Home
guides

The AI Disclosure Rules Are Live: What Actually Changed for You

8 min readBy PrivateAI Team

If you have noticed more AI tools announcing themselves lately — a support chat that opens by saying it is automated, an image with a small "AI-generated" marker — that is not a coincidence or a design trend. On 2 August 2026, a set of disclosure rules in the EU AI Act became enforceable, and companies started complying.

You may have also seen headlines saying the AI Act was delayed. Both things are true, and the distinction matters. The delay applied to a different part of the law: the heavy obligations on high-risk AI in hiring, lending, and essential services moved to December 2027. The disclosure rules — the part you actually encounter — took effect on schedule and are in force now.

Here is what that means in practice.

You get told when you're talking to a machine

The clearest change is that AI systems interacting with people generally have to make that obvious.

This targets a specific frustration: the support chat that opens with "Hi, I'm Alex!" and never clarifies whether Alex is a person. That ambiguity is no longer acceptable for in-scope systems serving EU users, and the disclosure has to be understandable to a normal person rather than buried on page four of the terms.

It is a smaller change than it sounds, because it does not require companies to stop using AI for support, and it does not entitle you to a human. But it does let you calibrate. Knowing you are talking to a system changes how you phrase things, how much you trust an unusual answer, and how quickly you ask to escalate.

AI-generated content gets marked

The second change is labelling. Content generated or manipulated by AI has to be indicated as such, including in machine-readable form so that platforms and tools can detect it downstream.

That machine-readable part matters more than the visible badge. A label a person can see helps that person. A marker embedded in the file lets a social platform, a search engine, or a browser extension flag synthetic media at scale, without depending on anyone noticing a small icon.

This is where you will see the most inconsistency for the rest of 2026. Systems already on the market before 2 August got a transitional period and have until 2 December 2026 to implement marking and detection. So unlabelled AI content right now does not necessarily mean anyone is breaking the rules.

You get notice when a system is reading you

The third category is the one most people do not know exists. If a system is applying emotion recognition or biometric categorisation to you — inferring mood from your face or voice, or sorting you into categories from biometric data — you are supposed to be told.

These systems turn up in places you would not expect: recruitment screening, some retail analytics, driver-monitoring in vehicles, certain customer-service quality tools. Most people have never been informed this was happening because there was no obligation to inform them. Now, in defined circumstances, there is.

Three things worth internalising

A label is provenance, not a quality rating. The rule governs how something was made, not whether it is true. A labelled AI summary can be confidently wrong. Use the marking to decide how much verification a claim deserves, not as a stamp of reliability.

Absence of a label proves less than you would think. Between the December 2026 transitional deadline, systems that fall outside scope, and providers outside the EU's reach, plenty of synthetic content will stay unmarked. "No label, therefore human" is not a safe inference and will not be for some time.

The rules apply to systems, not to countries. The law protects people in the EU, but companies overwhelmingly ship one global product. The same dynamic carried GDPR's privacy controls worldwide. If your tools changed in August, this is likely why, wherever you live.

What to actually do

Not much is required of you, which is the point — the obligation sits with providers and deployers, not users. But a few habits make the new information useful.

When a chat discloses that it is automated, treat unusual or high-stakes answers as unverified. Automated support is fine for a password reset and weak for a disputed charge.

When you encounter AI-marked media in a context that matters — a news claim, a product review, anything you would act on — spend the extra minute finding a primary source. The marking is a prompt to check, and it works best used that way.

And if you are in the habit of thinking about what your tools collect while doing any of this, the disclosure rules pair naturally with reducing what you hand over in the first place. Tools like Proton that encrypt mail and files by default limit how much of your material is available to be processed at all — a different problem from disclosure, but the same instinct.

The part that hasn't happened yet

Worth keeping in view: the obligations governing AI that makes consequential decisions about you — whether you get the interview, the loan, the place at the school — are the ones that were postponed, to December 2027 for standalone systems and August 2028 for AI embedded in already-regulated products.

So the current situation is slightly lopsided. You now have a right to know when you are talking to a bot. You do not yet have the full set of protections for when a system is deciding something that materially affects your life. That gap closes at the end of 2027, assuming the deadline holds.

For why that deadline moved in the first place, and what the split between the two halves of this law reveals about how AI regulation is likely to unfold, see the three lessons from the AI Act rollout.