Getty Images - marchmeena29AI Act
Key provisions have applied since August.
AS – 09/2026
Since 2 August, new transparency obligations under the European AI Act have applied to AI systems and AI-generated content. In addition, further requirements that were already applicable can now be enforced. Longer transition periods, however, apply to high-risk AI systems.
New transparency requirements for AI content
For certain AI systems, users must be made aware that they are interacting with an AI system rather than a human. This applies, for example, to chatbots, unless the use of AI is already obvious.
New requirements also apply to AI-generated or manipulated content. Providers of generative AI systems must ensure that such content can be technically identified as having been generated or altered by AI. In particular, operators must clearly label so-called deepfakes. Specific rules apply to certain texts on matters of public interest as well as to artistic, creative, satirical or fictional content.
For practical implementation, the Commission has published a voluntary Code of Practice on Transparency of AI-Generated Content. It is intended to support companies and organisations in complying with the legal requirements. Around 190 organisations had signed the Code by the end of July.
Requirements for certain AI Models are now enforceable
Specific requirements apply to general-purpose AI (GPAI) models, which can be used for a wide range of different purposes. Among other things, their providers must provide technical documentation and information to downstream providers, comply with EU copyright law, and publish a summary of the content used for training. These requirements can also be enforced as of 2 August.
Additional requirements apply to particularly powerful models in areas such as risk assessment, cybersecurity and risk mitigation. They cover, among other things, risks to fundamental rights and public safety, as well as risks arising from chemical, biological, radiological or nuclear applications and potential loss of control. Violations of prohibited AI practices can also now be penalised. Prohibited practices include certain manipulative systems, the targeted exploitation of people’s vulnerabilities, and unlawful social scoring.
Who is responsible for monitoring compliance?
European and national authorities are responsible for enforcement. The AI Office is primarily responsible for general-purpose AI (GPAI) models and certain related AI systems. Other AI systems are supervised by national authorities, while the European Data Protection Supervisor is responsible for AI systems used by EU institutions. The authorities are supported by a scientific panel of 60 independent experts.
Violations can result in fines of up to 15 million euros or three per cent of the company’s worldwide annual turnover. Higher maximum penalties apply to prohibited AI practices.
More preparation-time for high-risk AI
For social security institutions, the requirements for high-risk AI are particularly relevant. The deadlines for their application were postponed by the AI Omnibus Package, which entered into force in July. The relevant provisions will generally apply from 2 December 2027, while high-risk systems that are components of regulated products will be subject to the requirements only from 2 August 2028. This gives public bodies and other organisations concerned more time to prepare for the new requirements.
DSV contributes to the AI Advisory Forum.
The further implementation of the AI Act is supported by the AI Advisory Forum. The forum brings together stakeholders from business, research, civil society and the public sector. It advises the European Commission on the practical implementation of the AI Act.
The DSV is also represented on the forum, allowing it to directly contribute the experience and specific requirements of the German social security system. By the end of 2026, the Forum is expected to contribute, among other things, to guidance on the classification of and requirements for high-risk-AI, as well as on the interaction between the AI Act and the Cyber Resilience Act.