Since 2 August 2026, the European Union has begun applying a key part of the Artificial Intelligence Act (AI Act), introducing new transparency obligations for providers and users of AI systems. The entry into force of these measures marks one of the most significant milestones in the gradual implementation of Regulation (EU) 2024/1689 and represents a decisive step in the European strategy to ensure the safe, trustworthy and responsible use of artificial intelligence.
Among the new obligations is the requirement for conversational systems and chatbots to explicitly inform users that they are interacting with a machine, unless this is already obvious from the circumstances. Likewise, content generated or manipulated using artificial intelligence, including so-called deepfakes, must be clearly identified so that recipients can recognise its artificial origin.
The Regulation also requires providers of AI systems to implement technical mechanisms enabling the automatic identification of synthetic content. In particular, text, audio, images and videos generated through artificial intelligence must incorporate machine-readable markers that allow such content to be recognised as artificially created and facilitate traceability of its origin.
These transparency obligations are intended to address increasingly widespread phenomena such as disinformation, digital identity impersonation and audiovisual manipulation, while strengthening public confidence in AI-based technologies.
Oversight and Complaint Mechanisms
The effective implementation of these obligations will be supported by supervisory and enforcement mechanisms. Any natural or legal person who believes that a provider or user is failing to comply with the requirements laid down in the Regulation may file a complaint with the competent national market surveillance authority.
The institutional framework established by the AI Act distributes supervisory responsibilities among several bodies. The newly established European AI Office, within the European Commission, will oversee general-purpose AI models (GPAI), certain systems built upon those models, and AI systems deployed by the largest online platforms and search engines.
National authorities will be responsible for supervising all other AI systems within their respective jurisdictions, while the European Data Protection Supervisor will exercise oversight over the institutions and bodies of the European Union. The framework is complemented by a panel of sixty independent experts providing technical advice to regulators, as well as dedicated reporting channels for complaints and whistleblower submissions.
In Spain, the authority responsible for establishing and conducting the procedures for the assessment, designation and notification of conformity assessment bodies, as well as their supervision, is the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), established in 2023. According to its official mission, the agency is responsible for promoting the ethical and safe use of artificial intelligence and ensuring that both public and private entities comply with applicable rules, safeguarding privacy, equal treatment and fundamental rights.
Obligations for General-Purpose AI Models
The Regulation also applies to providers of general-purpose AI models, including those used as the foundation for AI agents and advanced content-generation tools.
These providers must maintain up-to-date technical documentation, implement copyright compliance policies, and publish sufficiently detailed summaries of the material used to train their models. In addition, providers of the most capable or impactful models will be subject to enhanced obligations aimed at managing security-related risks, including chemical, biological and nuclear risks, loss of control, cybersecurity threats and potentially manipulative uses of the technology.
A Gradual Implementation Timeline
The European AI Act provides for a phased implementation of its various obligations:
- 1 August 2024: Formal entry into force of the Regulation.
- 2 February 2025: Application of the prohibitions on unacceptable-risk AI practices and AI literacy obligations.
- 2 August 2025: Entry into force of obligations for general-purpose AI models and activation of the penalties regime.
- 2 August 2026: Application of transparency obligations and most of the Regulation’s general provisions.
- 2 December 2027: Application of specific obligations for high-risk AI systems.
- 2 August 2028: Entry into force of obligations relating to high-risk AI systems integrated into products subject to sector-specific regulation.
Upcoming Regulatory Phases
Despite the significance of the measures that are already applicable, some of the most demanding obligations have yet to take effect. An amendment adopted in 2026 postponed the application of a substantial part of the high-risk AI systems regime until December 2027 and, for certain regulated sectors, until August 2028.
Furthermore, specific prohibitions concerning the generation of child sexual abuse material and non-consensual sexual imagery through artificial intelligence will become applicable from December 2026.
The entry into force of these transparency obligations therefore represents a significant milestone in the implementation of the AI Act and reflects the European Union’s determination to establish a pioneering global regulatory framework for the development and use of artificial intelligence, founded on the principles of transparency, accountability and the protection of fundamental rights.