Deepfakes, AI-generated content and biometric systems are moving further into the regulatory spotlight. From 2 August 2026, additional provisions of the EU AI Act become applicable, introducing binding transparency requirements and strengthening enforcement across Europe.
The European Union’s AI Act is entering another decisive phase. From 2 August 2026, following a two-year transition period, further provisions of the regulation become applicable. At the centre are transparency requirements for certain AI systems as well as artificially generated or manipulated content. At the same time, competent authorities will be able to monitor compliance and impose penalties for infringements.
For companies, the implications extend beyond legal compliance. The new requirements directly affect digital identities, synthetic media, automated communication and biometric technologies – areas that are becoming increasingly relevant to cybersecurity and corporate security.
AI Chatbots Must Identify Themselves
One of the most visible requirements concerns AI systems that interact directly with people. As a general rule, users must be informed when they are communicating with an AI system rather than a human.
This affects chatbots, virtual assistants and other AI-based interfaces used in customer service and digital business processes. Organisations will need to review whether their systems provide users with sufficiently clear information about the nature of the interaction.
The requirement also has a security dimension. Generative AI can automate communication at a level of linguistic sophistication that makes artificial interactions increasingly difficult to distinguish from human ones. At the same time, cybercriminals are using AI to scale social engineering and create more convincing messages and digital personas.
Clear disclosure of legitimate AI interactions therefore becomes one component of a broader environment in which organisations must establish trust in digital communications.
Deepfakes Become a Compliance Issue
Of particular relevance to security professionals are the transparency requirements for artificially generated or manipulated images, video and audio. Deepfakes that could appear authentic must be disclosed as artificially generated or manipulated.
The rules address a technology that has rapidly developed into a potential security threat. Synthetic voices, manipulated video calls and realistic images can strengthen traditional social-engineering techniques and make identity-based attacks more difficult to detect.
For businesses, deepfakes are therefore no longer merely a reputational or communications risk. They can become part of attacks on operational processes. Employees may, for example, receive apparently authentic instructions from executives asking them to disclose confidential information, change payment details or authorise financial transactions.
The AI Act does not provide a technical defence against such attacks. Mandatory disclosure does, however, establish a regulatory framework for greater transparency in legitimate uses of synthetic media.
AI-Generated Content Must Become Machine-Readable
Providers of generative AI systems newly placed on the market must generally ensure that artificially generated or manipulated content is identifiable in a machine-readable format. According to German digital association Bitkom, systems already in use benefit from a transition period until December 2026.
This means that identifying synthetic content is no longer intended to depend solely on visible labels for human users. Information about artificial generation should also be technically detectable and processable.
For the security industry, this development is significant. As the volume and quality of synthetic content increase, reliable manual identification becomes increasingly difficult. Machine-readable information on content provenance could therefore become relevant to automated verification, monitoring and security processes.
However, technical marking cannot eliminate malicious manipulation. Criminal actors are unlikely to comply voluntarily with transparency obligations. Organisations will therefore continue to require independent mechanisms to verify identities, communications and critical requests.
Disclosure Requirements for AI-Generated Text
The transparency requirements also extend to certain AI-generated or manipulated texts intended to inform the public about matters of public interest.
There are exceptions, particularly where AI-generated content undergoes human review and a natural or legal person assumes editorial responsibility for publication.
This provision is relevant to media organisations as well as companies, public institutions and other organisations using generative AI in external communications. The decisive issue will increasingly be not simply whether AI was involved in producing content, but how human oversight and editorial responsibility are structured.
For organisations, this makes governance processes around generative AI an important part of regulatory compliance.
Biometric AI Requires Greater Transparency
Additional transparency obligations apply to emotion-recognition and certain biometric categorisation systems. Individuals affected by these technologies must be informed about their use.
This is particularly relevant in security environments, where AI-based analytics are increasingly combined with camera, access-control and other sensor technologies. Wherever biometric characteristics are analysed or individuals are categorised by AI systems, AI regulation intersects with data protection, fundamental rights and cybersecurity requirements.
Operators therefore need to assess more than the technical capabilities of a system. They must determine its regulatory classification, identify applicable information obligations and integrate these requirements into existing privacy, security and governance frameworks.
Companies Need Visibility Into Their AI Environment
As further provisions become applicable, one fundamental requirement becomes increasingly important: organisations need to know where and how they are using AI.
This is not necessarily straightforward. Generative AI capabilities are now embedded in numerous cloud services, business applications and software platforms. Individual departments may use AI assistants, content-generation tools or analytical functions without these systems being fully incorporated into central IT or security governance.
For CISOs, data protection officers, legal departments and compliance teams, maintaining an accurate inventory of AI systems is therefore becoming increasingly important. Organisations need visibility into the systems they operate, the functions they perform and the data they process before regulatory requirements and security risks can be systematically assessed.
Bitkom Warns of Continuing Legal Uncertainty
Despite the two-year transition period, Bitkom argues that companies still face significant uncertainty regarding implementation.
“The AI Act is intended to create a uniform EU-wide legal framework for the development and use of artificial intelligence. However, too many questions remain unanswered to implement the new rules with legal certainty,” says Bitkom President Dr Ralf Wintergerst.
According to the association, key guidelines and interpretative guidance were published only recently, leaving businesses with significantly less practical preparation time than the formal transition period suggests.
Bitkom is therefore calling on supervisory authorities to provide pragmatic guidance, ensure proportionate enforcement and coordinate implementation consistently across Europe.
The association welcomes relief measures such as extended deadlines for high-risk AI and efforts to avoid duplicate testing and documentation processes in the machinery sector. However, it argues that greater clarity is still needed for the transparency obligations now becoming applicable.
AI Transparency Becomes Part of Corporate Security
The next stage of the AI Act marks a shift from regulatory preparation to operational implementation. Companies will increasingly need to integrate AI transparency obligations into existing IT, cybersecurity, data protection and compliance structures.
This will also require clear responsibilities across departments. Legal teams may determine regulatory obligations, but implementation can involve IT, cybersecurity, data protection, communications and individual business units.
Regulatory transparency should not, however, be confused with technical security. An AI-generated item carrying a label is not automatically trustworthy, just as an unlabelled image, video or voice recording cannot automatically be considered authentic.
In an environment shaped by deepfakes and AI-enabled social engineering, organisations will continue to need robust identity verification, approval procedures for critical transactions and employee awareness measures.
The application of further AI Act provisions from 2 August 2026 therefore represents more than another regulatory deadline. For security professionals, it highlights a broader development: AI governance, regulatory compliance and cybersecurity are becoming increasingly difficult to address in isolation.
Commentary: EU AI Act: Compliance starts with the data, not the text of the law
By Tim Pfälzer, GM and SVP EMEA at Veeam
“The deadlines for individual requirements of the EU AI Act keep being pushed back. Yet, despite all the criticism, the 2 August deadline remains a key turning point for European organisations. At first glance, the transparency rules for AI governance and accountability that will then come into force appear relatively straightforward to comply with. After all, the stricter requirements for high-risk areas have been postponed for the time being. In practice, however, implementing them is significantly more difficult. Companies realise this at the latest when they try to adapt their existing AI systems to these requirements. After all, it is not enough simply to tick a ‘compliance’ box. Instead, companies must rethink their entire data landscape. Only in this way can the audit trails, governance guidelines and stable foundations that AI needs on a large scale be established.
There is much discussion about the lack of clarity in the legislation – and a recent survey we conducted confirms this: 63 per cent of companies in the EMEA region say that ambiguities in the legislation pose a clear compliance risk. Yet this shifts the focus to the wrong problem. Whilst the regulations could be clearer, transparency and explainability cannot be achieved through rules alone anyway. To see where their own data is located, how it is used, who has access to it and how it feeds into AI decisions, most companies need to completely overhaul their data landscape from the ground up. This is precisely what will be crucial: proactively creating transparency, establishing governance frameworks and prioritising resilience. This is the only way to ensure that the data underpinning AI is secure, regulated, available and recoverable. After all, AI results are only as trustworthy as the data on which they are based.
Although 85 per cent of companies in the EMEA region say the new law makes them even more willing to invest in AI tools, they should not base their decisions solely on the law. Anyone wishing to invest successfully in AI tools must first establish the transparency and traceability required for regulatory compliance from 2 August onwards. And this can only be achieved through a comprehensive restructuring of their own data landscape. Without a solid foundation of trust, companies run the risk of creating new problems with every step they take towards adding value – particularly in the areas of governance, security and compliance. When it comes to artificial intelligence, the greatest competitive advantage does not necessarily come from the fastest implementation, but from the most trustworthy one. This legal deadline should therefore not be seen as a finish line, but as a starting point for the stable data infrastructure that makes future-proof AI innovation possible in the first place.”


