On 2 August the European Union began enforcing the part of its AI Act that reaches ordinary internet users for the first time. Chatbots and other systems that talk to people must now make clear they are machines, not humans. AI-generated images, video and audio have to be labelled, and synthetic content must carry hidden, machine-readable marks so software can detect it.

The rules sit in Article 50 of Regulation (EU) 2024/1689, the transparency section of the law. From that date the Commission's new AI Office and national regulators in the 27 member states can enforce them. Firms that break the rules face fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

The disclosure duty is broad. It covers text chatbots, voice assistants, AI companions and "agentic" systems that start conversations on their own, without a person asking. Users must be told at the first interaction, and the notice has to be easy to see. A line buried in terms and conditions or hidden under menus does not count. The only exemption is when the AI is already obvious.

The duty does not stop at the EU's borders. A company based anywhere is covered if its system is placed on the EU market or its output is used inside the bloc. A US or UK chatbot serving European customers is therefore caught.

To help firms comply, the Commission issued guidance and set up a voluntary Code of Practice on marking AI content, which more than 180 organisations have signed. Providers of generative tools already on the market before 2 August get until 2 December to add the required marks.

Pieter Arntz, a malware intelligence researcher at the security firm Malwarebytes, frames the change as consumer protection against deception rather than a ban on AI: the rules remove an AI system's ability to pretend to be human.

The marking rules are the weak spot. The technology for watermarking AI content can be stripped out by a screenshot or a re-upload. The Act itself asks only for marking "as far as this is technically feasible." The technical standards that would define compliance are still being written. Enforcement is also split across 27 national authorities, so the same chatbot could be judged differently in different countries.

Whether these rules curb the manipulation the law targets will depend on how strictly regulators enforce the marking requirements and whether detection tools catch up. For everyday users, the visible change is simple: chatbots that announce they are not human, and labels on AI-made images, video and audio. The wider pattern is the part to watch: Europe is writing rules that companies worldwide follow to keep access to its market. The rest of the AI Act phases in through 2027 and 2028.