As of August 2, 2026, the transparency rules of the European artificial intelligence regulation are now in effect. If your business publishes AI-generated visuals or AI-written copy, or has a chatbot on its website, you have specific AI Act obligations, and transparency penalties reach up to €15 million or 3% of global annual turnover. The good news is that for a small business these obligations can be met within days, and a large part of design work does not fall under them at all. The line between the two defines your entire task list.
What the AI Act Is and Why It Affects Your Branding
The AI Act is Regulation (EU) 2024/1689 – the world’s first comprehensive regulation of artificial intelligence. As a regulation, it applies directly in every member state, including Bulgaria. It does not wait for a Bulgarian law, ordinance, or guidance: you have AI Act obligations from the dates set in the regulation itself.
The regulation divides participants into two main roles. A provider is the one who develops and offers the AI system – OpenAI, Midjourney, Canva for its AI features. A deployer is anyone who uses an AI system professionally. Here is the catch for small businesses: upload an AI-generated visual to an ad on your company page and you are a deployer within the meaning of the regulation. You do not need to develop anything. Use alone is enough.
For design and branding, the question is not whether AI is used, but whether you know which AI Act obligations you take on when you use it. The answer depends on what you generate and where you publish it.
AI Act Obligations: The Key Dates
The regulation takes effect in stages. Here is what applies from when and what actually touches marketing and design:
| Date | What takes effect | Does it affect design and branding? |
| February 2, 2025 | Prohibited AI practices + AI literacy requirement for teams | Yes, literacy covers the marketing team too |
| August 2, 2025 | Rules for GPAI models (ChatGPT, Gemini, etc.) | Indirectly, through the providers |
| August 2, 2026 | Transparency under Article 50: deepfakes, AI text, chatbots | Yes, directly |
| December 2, 2026 | Deadline for machine-readable marking for systems placed on the market before August 2, 2026 | Through the tools you use |
| December 2, 2027 / August 2, 2028 | High-risk systems (postponed) | Rarely, marketing is usually not high-risk |
In July 2026, the EU adopted the Digital Omnibus package (published on July 24, in force since July 27, 2026), which postponed the rules for high-risk systems to December 2027 and August 2028, respectively. If you have read headlines like “The AI Act is being postponed,” they refer only to that part. Transparency under Article 50 is not postponed and applies from August 2, 2026. The only grace period is the technical one – tools placed on the market before that date have until December 2, 2026 to build in the machine-readable marking. Your AI Act obligations as a deployer have no such grace period.

The Four Obligations Already in Effect
For a business that commissions design and content or makes them in-house, the real AI Act obligations come down to four.
1. You Label Deepfake Content
Under the regulation, a deepfake is an AI-generated or manipulated image, audio, or video that resembles real people, objects, places, or events and would appear authentic. In marketing, that is the photorealistic AI image – a non-existent model holding your product, an office photo that no one would recognize as generated. You label such content clearly, at the user’s first contact with it, for example with the notice “Image generated with AI.” The same applies to audio and video – an AI voice that sounds like a real speaker in a Reels video falls under the same regime. The practical test is a single one: would your customer mistake the content for a real photo or recording? If the answer is yes, you label it. For clearly artistic or satirical content, the regime is softer: disclosure in a way that does not spoil the enjoyment of the work. We cover the specific techniques, from the EU icons to embedded metadata, in our guide on how to label AI content.
2. You Label AI Text on Matters of Public Interest
If you publish AI-generated text whose purpose is to inform the public on matters of public interest – health, finance, safety, rights – it must be labeled. The exception is substantial human editing: when a person actually reviews, changes, and takes editorial responsibility for the text, no labeling is required. An AI-written article on how new health requirements affect your customers is exactly that kind of text; a product description in your online store is not. For the typical company blog with an editor, this obligation rarely comes into play, but the rule should be written into your process.
3. Your Chatbot Identifies Itself as AI
People talking to an AI system must know that, unless it is obvious from the context. Building this in is the chatbot provider’s obligation, but you decide how the bot appears on your website. A bot with a human name, a real photo, and “consultant” for a title works against you – first with the customer, then with the regulator. The fix is to give it a name like “AI assistant” and add one sentence at the start of the conversation making clear that it is an AI assistant.
4. Your Team Understands the Tools It Uses
The AI literacy requirement has been in effect since February 2, 2025 and covers every company using AI professionally. No certificates are required. What is required is that the people generating visuals and copy know what the tools can do, where they go wrong, and which AI Act obligations come with publishing the output. Internal training, documented with a date and topics, covers the need for a small team.
When You Have No AI Act Obligations
AI Act obligations do not arise from the mere fact that an algorithm touched the file.
- Design made by a human. Zero new obligations. Logos, banners, and visuals made by a designer are not labeled in any way.
- Stylized AI visuals. Logos, icons, illustrations, and abstract compositions are not deepfakes: they do not resemble real people, places, or events, and no one would mistake them for a real photo. No labeling under Article 50 is required.
- Assistive features. Retouching, background removal, upscaling, and color correction are standard editing, not generated content, as long as they do not change the meaning of the original.
- Internal drafts. What you do not publish is not subject to labeling.
The gray area is the combination – a real product on a photorealistic AI background, a real face in an AI-extended scene. Here the judgment goes visual by visual, using the same authenticity test. If you hesitate over whether a visual looks like a real photo, treat it as a deepfake. The label costs you nothing, while skipping it turns one of the easiest AI Act obligations into the risk of a fine.
The machine-readable marking that the tool embeds in the file is not something you should deliberately remove: it is the provider’s obligation, and removing it works against you in a dispute. Ad platforms have their own requirements beyond the regulation: Meta and Google require an AI content declaration in certain cases regardless of whether it is a deepfake.

Who Is Responsible: You, the Agency, or the Tool
Responsibility under Article 50 is split, and that is worth knowing before you sign with a vendor.
The provider of the tool owes the technical marking – the output must be machine-readably marked as generated. The major providers are moving in that direction in an organized way – the final Code of Practice on AI content transparency was published on June 10, 2026, and by the end of July it had been signed by around 190 companies. You owe the visible part: labeling deepfakes and AI text on matters of public interest, an honest chatbot, and team training. These AI Act obligations remain yours even when the visual was made by an external vendor – outsourcing does not transfer them automatically.
So before signing, find out whether the agency or designer uses AI in the projects they deliver and at what stage, who applies the labeling when AI is used, and whether that is written into the contract. A vendor who answers confidently and in writing saves you the entire puzzle of who carries which AI Act obligations.
Fines for Non-Compliance with AI Act Obligations
Transparency violations under Article 50 are punishable by up to €15 million or up to 3% of global annual turnover, whichever is higher. For small and medium-sized enterprises the mirror rule applies – the lower of the two values is used, so the ceiling for a small company is far below the headline millions. For prohibited practices, penalties reach up to €35 million or 7%. The amount is not automatic: severity and duration of the violation and your cooperation are weighed, and a documented labeling process is your strongest argument.
Where does Bulgaria stand? As of September 2026 there is still no national implementing law: the bill was submitted to the National Assembly in October 2025, and the supervisory authorities are yet to be designated. None of that cancels anything listed so far, because the regulation applies directly. In practice, this means a window: AI Act obligations are already a fact, while active enforcement in Bulgaria will pick up speed with the national mechanism. The smart move is to put your processes in order now, while inspections are not yet running, instead of explaining later why your company’s ad tricks the eye without a label.
First Steps: Put Everything in Order Step by Step
These AI Act obligations do not require an in-house lawyer – just five working steps:
- Map where AI comes in. A list of the tools, the people who use them, and the channels the output goes to. Include the hidden uses too – the colleague who leans on ChatGPT for social posts belongs on the list. Half an hour of work, and you bring to light things no one had thought about.
- Decide your policy for visuals. Human design, AI with labeling, or a combination – what matters is that the decision is made, not left to happen on its own.
- Build labeling into the process. Before publishing, someone checks: is this a deepfake, is this AI text on a matter of public interest? If the answer is yes, the label travels with the file itself.
- Run the Article 4 training. Short, documented, built around the team’s specific tools.
- Update your contracts. An AI clause for every external vendor: is AI used, who labels, who is responsible.
For most small businesses, the entire list can be completed within a week.
Frequently Asked Questions About AI Act Obligations
Do I have to label every AI-generated image?
No. AI Act obligations to label arise for deepfake content and for AI text on matters of public interest. A stylized logo, illustration, or abstract banner is not a deepfake and is not labeled. Separately from the regulation, ad platforms may require their own AI content declaration.
What counts as a deepfake in marketing visuals?
An AI image, audio, or video that resembles real people, objects, places, or events and would appear authentic – a photorealistic image of a non-existent model with your product is the typical example. For such content the deployer has AI Act obligations: clear labeling at the user’s first contact.
What are the fines for transparency violations?
For unmet AI Act obligations on transparency: up to €15 million or up to 3% of global annual turnover, whichever is higher. For small and medium-sized enterprises the lower of the two values applies. Violations in the “prohibited practice” category are punished more severely: up to €35 million or 7% of turnover.
Does the AI Act apply to a small Bulgarian company that only uses off-the-shelf AI tools?
Yes. Using AI in a professional context makes you a deployer, and deployers have AI Act obligations too: labeling deepfakes and AI text on matters of public interest, an honestly presented chatbot, and a trained team. The volume is small and is covered by a one-time setup of your process.


