Back to blog
AI

EU AI Act: What It Actually Means for You

The EU AI Act transparency rules apply from August 2, 2026. Here is what the law means for you as a user, and what really changes in the apps you already use.

Ronkay ArslanRonkay ArslanFounder, Tase8 min read

On August 2, 2026, the transparency rules in the European Union AI Act start to apply. If you use AI apps, the practical effect is short. Software built to talk to you has to tell you it is software. Generated images, audio, video and text have to carry a machine readable mark. Deepfakes of real people have to be labelled where a human can see the label. Systems that read your face or voice for emotional signals have to say so. You do not have to register anything, install anything or change a single setting. The duties land on the companies. What changes for you is what an app is allowed to leave unsaid.

What did not arrive on that date matters almost as much. The heavier obligations for high risk uses, things like AI in hiring, education and biometrics, were pushed back to December 2027 and August 2028. So August 2 is not the day AI becomes safe. It is the day it becomes required to introduce itself.

What actually starts on August 2, 2026

The AI Act came into force in August 2024 and switches on in stages rather than all at once. Reading the calendar is the fastest way to understand where the law is today and what is still coming.

DateWhat applies
2 February 2025Banned AI practices, plus AI literacy duties for the people deploying these systems
2 August 2025Rules for general purpose AI models and the governance structure behind the Act
2 August 2026Transparency duties, including chatbot disclosure and content marking, plus most of the remaining Act
2 December 2026Grace period ends for marking duties on some systems that were already on the market
2 December 2027High risk duties for standalone systems in areas such as employment, education and biometrics
2 August 2028High risk duties for AI built into regulated products
Dates as published by the European Commission. See its regulatory framework page for AI for the full timeline.

The 2027 and 2028 rows moved later than originally planned. That delay got most of the headlines, which is why a lot of coverage this summer implied nothing happens on August 2. Plenty happens on August 2. It is just the part aimed at ordinary users rather than at compliance departments.

The four things an app now has to disclose

The consumer facing core of the Act is Article 50. Strip out the legal phrasing and it comes down to four disclosures, each aimed at a moment where people get fooled.

  • You are talking to a machine. A system built to interact directly with people has to make that clear from the start of the first interaction, unless it is already obvious to a reasonably attentive person. No more support chat where you spend four minutes wondering.
  • This media was generated. Providers of generative systems have to mark synthetic audio, images, video and text in a machine readable format, so the output can be detected as artificial further down the line, even after it has been copied and reposted.
  • This is a deepfake. Anyone publishing manipulated image, audio or video of real people has to disclose it clearly to the person seeing it, with a carve out for work that is evidently artistic or creative.
  • This system is reading you. Emotion recognition and biometric categorisation systems have to inform the people exposed to them that this is happening.

The European Commission published its own plain language answers on these duties in its FAQ on Article 50 transparency obligations, which is worth ten minutes if you want the primary text rather than someone summarising it, including this one.

After August 2, silence is information

If an app still cannot tell you plainly when you are talking to a model, or which parts of what you see were generated, that is now a choice rather than a technical limitation. Treat it as a signal about the company, not about the technology.

Why a European law changes the apps on your phone anywhere

Two reasons, and neither of them requires you to live in Europe. The first is scope. The rules follow the market rather than the company address, so a provider based anywhere is covered when its system is placed on the EU market or its output is used there. A team in California with European users is inside the rules.

The second reason is cheaper engineering. Almost nobody builds two versions of the same product, one that discloses and one that stays quiet, because maintaining two behaviours costs more than maintaining one. The usual outcome is that the stricter behaviour ships everywhere. Over the next few months you will see more AI labels, more first message disclosures and more generated content badges in apps that have no European connection at all. That is this law arriving sideways.

What the AI Act does not do

This is the part that gets lost, and it matters more than the part that made the news. The Act closes a specific gap. It does not close the ones people assume it does.

  • It is not a privacy law. What an app may collect, keep and share about you is governed by data protection rules, and in the United States by a patchwork of state laws. The AI Act governs disclosure and risk, not appetite for data.
  • It does not stop an assistant reading your messages, photos or calendar. If you grant that access, the Act has nothing to say about it. That decision is still entirely yours.
  • It does not make AI answers correct. Nothing in the transparency rules promises accuracy, and a properly labelled wrong answer is still a wrong answer.
  • It does not give you a button that shows everything a model learned from. Marking output as generated is not the same as explaining where it came from.
  • It does not apply the strict high risk rules yet. Those are the ones covering hiring, credit, education and biometrics, and they are still more than a year out.

So the practical questions still land on you. The ones worth asking before you hand an assistant your calendar, your health notes and your spending are in our guide to AI assistant privacy questions, and none of them are answered by a disclosure banner.

A five minute check on the assistants you already use

Rather than reading the regulation, run it against your own phone. Pick the two or three AI tools you actually open every week and walk through this. It takes about five minutes each and tells you more than any privacy policy.

  1. 1

    Start a fresh conversation and read the first screen

    Does the app tell you, before you type, that you are talking to an AI system? A tool that buries this in a settings page or a help article is already behind where the rules now sit.
  2. 2

    Ask it what it remembers about you

    Then go looking for that list in the interface. If the assistant claims a memory it cannot show you, you have no way to correct it when it is wrong, and it will eventually be wrong.
  3. 3

    Find the delete path for a single item

    Not the delete my account button. One specific memory, one note, one entry. If the smallest unit you can remove is your entire history, the product was not built for you to stay.
  4. 4

    Check what happens to generated content

    If the app makes images, audio or video, look for a marking or label option and whether it is on by default. From August 2, off by default is a position, not an oversight.
  5. 5

    Look for the export

    An app that lets you take your data out is an app that expects to earn the next month. An app with no export is counting on the cost of leaving.

What to do with what you find

Most people finish that audit with one tool that passes comfortably and one that quietly does not. You do not need to delete the second one that afternoon. You need to know which category it is in, and stop giving it the material it has not earned. The bigger decision, whether to let an assistant index your messages and photos at all, deserves its own sitting, and we walked through it in should you let an AI assistant read your messages.

The direction the law is pushing is the one good assistants were already heading in. An assistant is useful in proportion to what it remembers about you, and it is trustworthy in proportion to how much of that memory it will show you on request. Those two things sound like they are in tension. They are not, as long as the memory is visible, editable and yours to delete. That is the argument we made in an assistant that actually remembers you, and August 2 turns a good habit into a floor.

Do I have to do anything on August 2, 2026?+

No. The obligations fall on the companies building and deploying AI systems, not on the people using them. There is nothing to sign up for, opt into or configure. The only thing that changes for you is what apps have to tell you.

Does the EU AI Act apply to me if I live outside the EU?+

The law does not protect you directly outside the EU, but you will still feel it. The rules cover providers whose systems are placed on the EU market or whose output is used there, regardless of where the company sits, and most companies apply one disclosure behaviour worldwide because building two is more expensive.

Does this mean AI apps have to stop using my data?+

No. The AI Act is about transparency and risk, not data collection. What an app may gather about you is still a question for data protection law and for the permissions you grant it. A clearly labelled assistant can still be reading a great deal.

Why did the high risk rules move to 2027 and 2028?+

The timeline for high risk systems was changed after the Act came into force, moving standalone high risk systems to December 2027 and AI built into regulated products to August 2028. The transparency duties that arrive in August 2026 were left where they were.

Will every AI generated image now carry a visible label?+

Not necessarily a visible one. The requirement is a machine readable mark so the content can be detected as generated further downstream. Visible disclosure is specifically required for deepfakes of real people, where the person seeing the content has to be told.

An assistant that shows you what it knows

Tase keeps what it remembers about you in one place you can read, edit and delete, and your data can be exported or removed whenever you decide.

Try it free

Related guides

privacyairegulationtrust