Correction, 25 August 2026. This article contained four factual errors, now corrected. It gave the penalty for breaching the transparency duties as €35 million or 7 percent. Under Art. 99(4) it is up to €15 million or 3 percent; the higher tier applies only to the prohibited practices in Art. 5. It cited an "Operational Security Act", which does not exist in German law. It dated the AI-literacy duty to 1 July, when it has applied since 2 February 2025. And it attributed the transparency duties to an omnibus package, when they come from the AI Act itself.
The EU is tightening AI regulation significantly: from 2 August 2026 the transparency duties in Art. 50 of the AI Act, Regulation (EU) 2024/1689, apply. The Digital Omnibus, Regulation (EU) 2026/1744, expressly did not move that date. This affects you directly as a business owner – whether you operate a chatbot, publish AI-generated content, or work with deepfakes. The labeling requirement applies regardless of how your AI system is classified. This means: Even low-risk applications must clearly disclose that they are AI-generated.
The rules become particularly strict for sensitive applications. Deepfakes, emotion recognition, and biometric categorization must be clearly labeled from August onwards. It gets even tougher from December 2, 2026: Nudification tools and intimate deepfakes without explicit consent from the affected person will be completely banned. Existing AI systems must also comply with the new transparency requirements by then – there is no grandfathering clause.
The penalties are substantial. Failing to implement the transparency requirements from August risks fines of up to €15 million or 3 percent of worldwide annual turnover under Art. 99(4). The higher tier of €35 million or 7 percent applies only to the prohibited practices in Art. 5. But that's not all: German courts have already confirmed platform operators' liability for AI errors. Munich Regional Court ruled in May that operators are liable for AI-generated summaries. The Hamm Higher Regional Court attributed chatbot errors directly to the operator in May. This means for you: You cannot simply say "the AI did it."
Who Inside the Company Answers for It
Responsibility stays with company management, but it does not come from any AI-specific statute. It follows from the general duty of care in § 43 GmbHG, from § 91 AktG for stock corporations, and for cybersecurity from NIS2 and the BSIG. In parallel, the AI-literacy duty in Art. 4 of the AI Act has applied since 2 February 2025: anyone deploying AI must ensure the people working with it understand it.
Germany is preparing accordingly. On July 2, a new AI task force began its work – with planned cooperation with the British AI Safety Institute. Other EU countries are following suit: Ireland plans an independent "AI Office of Ireland" with regulatory sandboxes for startups. Spain distributes oversight across multiple authorities. This means: Oversight becomes fragmented but intensive.
High-Risk Systems Get a Reprieve – But Limited
There is some good news, though limited. Standalone high-risk AI systems under Annex III get until December 2, 2027 to comply. Manufacturers of AI security components even until August 2028. But this reprieve only partially helps you: Transparency requirements from August apply alongside other digital laws like NIS2. You'll need to build your compliance infrastructure anyway.
The EU Commission has already published a code of conduct on labeling. That's your guidance. For German companies, this concretely means: Now is the time to audit your AI systems, establish labeling processes, and brief your management team on personal liability. The EU AI Act deadlines are tight – delays will be costly.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




