Disclosure is now a design requirement, not a courtesy

Harsh Chhajer
3m read

A chatbot bubble that doesn't say it's a bot. An AI-generated product photo with no marking anywhere near it. Neither of those used to be a legal question. As of August 2, 2026, in the EU, both of them are.

What actually changed on that date

The EU AI Act's high-risk system deadlines got pushed back this year, to December 2027 for most standalone systems and August 2028 for AI embedded in regulated products. That postponement is real, and it's easy to read as "the Act got weaker." It didn't, for the part that touches interface design directly.

Article 50 requires that a system built to interact directly with people ensure those people are told they're talking to an AI, that generative outputs be marked in a detectable, machine-readable format, and that deployers disclose deepfake content as artificially generated. Compliance trackers report those obligations, and national enforcement powers to act on them, became enforceable on August 2, 2026, untouched by the postponement.

Which parts moved and which did not:

ObligationStatus
Article 5: subliminal manipulation and dark patterns bannedIn force since 2 Feb 2025
Article 50: chatbot disclosure, content marking, deepfake labelingEnforceable from 2 Aug 2026
High-risk standalone systems (Annex III)Postponed to 2 Dec 2027
AI embedded in regulated productsPostponed to 2 Aug 2028

The two rows that touch interface design directly are the two that did not move. The Act's separate ban on subliminal manipulation and dark patterns that exploit cognitive biases has been in force even longer, since February 2025.

A checkbox buried in a terms-of-service page technically discloses something. It doesn't disclose it in any sense a regulator focused on user-facing transparency is likely to accept, and it doesn't disclose it in any sense a real user actually absorbs either. The obligation is written as a legal requirement, but satisfying it well is a design problem: how do you make a disclosure both compliant and actually noticed, without turning every AI-touched surface into a wall of warning text nobody reads.

That's a genuinely hard design brief. Too subtle and it fails the spirit of the law, and arguably the letter of it. Too loud and heavy-handed, and you've traded a dark pattern of omission for a different dark pattern: disclosure theater designed to be skipped past rather than read.

The size of getting this wrong

The penalty ceilings attached to this enforcement window are not small: up to EUR 35 million or 7% of global annual turnover for the broadest violations, with a separate EUR 15 million or 3% ceiling specifically for general-purpose AI providers. Those numbers exist for the worst violations, not a badly-worded tooltip, but they establish that this category of compliance now has real financial stakes attached to it in a way it didn't twelve months ago.

The one-hour audit worth doing this week

Pick one surface in your product where a user interacts with an AI system, a chatbot, a generated image, a summarised result, and time how long it takes a first-time user to notice it's AI-generated at all. If the honest answer is "they wouldn't," that's the surface to redesign first, before a regulator or a user finds it for you. This is directional guidance, not legal advice: if you operate in the EU, the actual compliance requirement is worth a real conversation with counsel, not a blog post's best guess at the letter of Article 50.