In a services company, generative AI affects people, facilities, outcomes and conversations with customers. This guide explains what the AI Act requires and how to apply it on your website, in acquisition, support, video and recruitment.
A practical guide for services companies
This document explains what European AI regulation requires from 2 August 2026, what falls outside its scope and what to do at each customer touchpoint. It is not legal advice: for decisions with potential exposure to penalties, you should validate it with your legal adviser.
What changes for you
A services company does not sell a box: it sells trust. That is why generative AI touches exactly where misuse hurts most: people, facilities, outcomes and conversations with customers.
From 2 August 2026, you must provide information when publishing a generated image, video or audio that resembles real people, places or events; when someone interacts with an AI system; and when publishing public-interest text without editorial review.
And in Spain there is a second law that affects you if you provide basic services of general interest or are a large company: Law 10/2025 on customer service, in force since December 2025, with an adaptation deadline of 28 December 2026. Among other things, it prohibits customer service from being based exclusively on automated systems: if a person asks, they must be able to speak to someone.
The four obligations in the regulation, and who is responsible for each
The most common mistake is to treat this as a single obligation. There are four, and each falls on a different actor.
| Obligation | Who is responsible | What it means in practice |
|---|---|---|
| The person must know that they are interacting with an AI system, unless this is obvious from the context | The person or company that makes the system | You choose and configure the tool, and you are responsible for the welcome message. If you put your brand on a third-party system and present it as your own, you may be considered a provider |
| Mark outputs in a machine-readable format | The company that makes the generative tool | It is not your obligation to create it, but you should avoid destroying it: exporting or recompressing content can remove its origin metadata |
| Provide information when emotion-recognition or biometric-categorization systems are used | The deployer, that is, you | This affects tone or facial-expression analysis. Inferring emotions from employees or students has been directly prohibited since February 2025 |
| Disclose deepfakes and AI-generated text published about matters of public interest | The deployer, that is, you | This is the obligation that affects you directly |
The information must be provided clearly and distinctly, no later than the time of first exposure, and must be accessible.
What exactly is a deepfake?
The regulation defines it as image, audio or video content generated or manipulated with AI that resembles existing people, objects, places, entities or events and would appear authentic to the person viewing it.
It is worth reading this twice: it is not talking only about famous people. It also covers objects, places and events. A recreation of a product, premises or real situation comes through this door. A clearly stylized illustration or an impossible scene does not.
Three exceptions that keep things simple
- Standard editing. Correcting color, removing noise, increasing resolution, cropping or removing a background without altering the meaning does not trigger any obligation.
- Human review, text only. If the text goes through review or editorial control and a person or company assumes responsibility for publication, no notice is required.
- Content from before 2 August 2026. You do not need to relabel what has already been published. For text, the publication date is what counts.
How to decide: three questions, four outcomes
Question 1. Does the piece represent something or someone that exists, in a way that could appear authentic?
Question 2. Does a notice solve the problem, or is the problem that the piece makes a false claim?
Question 3. Is there an identifiable person who has genuinely reviewed the content and stands behind what was published?
| Outcome | What it means |
|---|---|
| No notice | Instrumental use of AI. Publish normally |
| Mandatory notice | The regulation requires it. Do not publish without it |
| Recommended notice | The regulation does not require it, but commercial or reputational risk makes it advisable |
| Redo it | No label fixes the problem, because the problem is deception or lack of rights |
How to write the notice and where to place it
The regulation requires the information to be clear, distinct and accessible, and available before the person interprets what they see. That rules out most notices currently in circulation.
Not compliant: a line in the footer, a mention in the privacy policy or terms, text that appears for half a second in a video, a watermark covered by the interface, or a notice that disappears when the piece is downloaded or shared.
Compliant: a notice on the piece itself, visible on first exposure, placed where nothing covers it, embedded in the content wherever possible, written in plain language and with a text alternative for screen readers.
Official EU icons
The European Commission offers three example variants on its official page on icons for labelling AI-generated content. Their use is optional and does not by itself demonstrate compliance with Article 50: what matters is that the notice is clear, visible and accessible.



The European Commission has published a set of free icons, available for unrestricted use without attribution, in SVG and PNG. They are optional and work best accompanied by text rather than on their own. There are three variants: basic, fully generated with AI and partially modified with AI. Using them does not by itself prove compliance.
Formulas that work
| Situation | Formula |
|---|---|
| Product or service image | ‘Image generated with AI. Non-photographic recreation.’ |
| Space, premises or facility | ‘AI-generated recreation. It is not a photograph of the premises.’ |
| Video with a synthetic spokesperson | Label in the first seconds and persistent overlay: ‘Virtual spokesperson generated with AI.’ |
| Cloned audio or voice | Spoken notice at the beginning: ‘Voice generated with AI with the person’s authorization.’ |
| Chat or assistant | First message: ‘I am [brand]’s virtual assistant. I respond using artificial intelligence. You can ask to speak with a person at any time.’ |
| Informational text without review | Heading, not footer: ‘Text generated with AI. Published without editorial review.’ |
| Social media | The platform’s native label plus a notice inside the creative, because the native label is lost when the content is reshared |
Corporate website and acquisition pages
| Situation | What to do |
|---|---|
| AI-generated team photos | Redo it. Presenting a nonexistent team is deceptive about who provides the service |
| Real portrait retouched with AI without changing identity | No notice |
| Images of offices, clinics, construction sites or facilities that are not yours | Mandatory notice, and consider whether it is appropriate to use them |
| Recreation of a future project (renovation, development or installation) | Mandatory notice: ‘AI-generated recreation. Non-contractual image’ |
| Conceptual illustrations of the service | No notice |
| Service copy, FAQs and landing pages drafted with AI and reviewed | No notice |
| Case studies with invented data or customers | Redo it. In addition to being deceptive, this is the material people check most |
| AI-generated customer testimonials | Redo it. A false testimonial is prohibited by consumer regulations |
| Badges, awards or certifications represented with AI | Redo it if you do not possess them |
Acquisition: forms, chat and calls
| Situation | What to do |
|---|---|
| AI lead-qualification chat | Mandatory notice in the first message |
| Voicebot that makes or answers calls | Mandatory notice at the beginning of the call, with a clear voice and without pretending to be a person |
| Agent that books appointments through WhatsApp | Mandatory notice and route to a person |
| Support based only on a bot, with no human option | Not permitted for companies covered by Law 10/2025. General recommendation for everyone else: always offer an exit to a person |
| Automatic call transcription and summary | Inform people about recording and processing (GDPR) before starting |
| Analysis of the customer’s emotional tone during the call | Mandatory notice to the person exposed |
| Emotional analysis of your own employees or students | Prohibited since February 2025 in employment and education. Do not implement it |
Spokespeople, video and audio
| Situation | What to do |
|---|---|
| Synthetic avatar presenting the company or a service | Mandatory and permanent on-screen notice |
| Voice or image clone of a real person from the company | Mandatory notice and written authorization from that person, including scope and expiry |
| Dubbing or lip synchronization of a real video into another language | Mandatory notice: an existing person is being manipulated |
| Synthetic narration that does not imitate anyone | No notice |
| Automatic subtitles and translations | No notice, with review |
| Webinar or training with a virtual presenter | Mandatory notice at the beginning and in the description |
Public-interest content and regulated sectors
| Situation | What to do |
|---|---|
| Informational article about health, law, tax or security, reviewed and signed by a professional | No notice. Visible signature and review |
| The same article published automatically without review | Mandatory notice, and discouraged |
| Press release generated and reviewed by an owner | No notice |
| Visual recreation of a real event (accident, incident or occurrence) | Mandatory and highly prominent notice |
| AI-generated healthcare professional recommending a treatment | Redo it. Health risk and sector-specific advertising regulations |
| Generated or retouched before-and-after image of a patient or customer | Redo it if it does not correspond to a documented real case with consent |
| Digitally furnished property images | Mandatory notice stating what is virtual and what will be delivered |
People and recruitment
| Situation | What to do |
|---|---|
| AI-assisted job-offer writing | No notice |
| Automated candidate screening | This is not Article 50, but it will be a high-risk system (obligations postponed until December 2027). Start documenting criteria and human oversight now |
| Interviews with emotion analysis | Prohibited |
| AI-generated staff photos for the careers website | Redo it |
Three questions before publishing
- Could someone believe that this person, place or outcome is real?
- If the person asks whether they are speaking to a human, will the answer they receive be clear and honest?
- Is there an identified professional behind what is being claimed?
How to put it into practice
| Step | Content | Who |
|---|---|---|
| 1. Inventory | List where AI is used today in each channel: website, landing pages, chat, voicebot, video, automations and third-party tools | Impulsa3 with your team |
| 2. Classification | Run each use through the three questions and keep only those that result in ‘notice’ or ‘redo’ | Impulsa3 |
| 3. Quick fixes | Welcome message for chat and voicebot, guaranteed route to a person, notices on high-risk live assets | Impulsa3 |
| 4. Templates | Notice formulas by channel and a reusable block on the website | Impulsa3 |
| 5. Register | One row per published asset: which tool, what the AI did, what notice it carries and who approved it | Both |
| 6. Training | Short AI literacy session for the team. It has been a legal obligation since February 2025 and it is worth being able to evidence it | Impulsa3 |
About the register: eight fields in a spreadsheet are enough. Asset and URL, publication date, tool and version, exactly what the AI did, the outcome of the decision, the literal notice text and where it appears, who reviewed and approved it, and image or voice authorizations when people are involved. Do not store unnecessary personal data or discarded variants.
Sources
Regulations and official documentation consulted on 1 August 2026.
- Regulation (EU) 2024/1689 (European AI Regulation), Article 50. Transparency obligations. Official text on the European Commission service: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital AI Omnibus). Published in the Official Journal of the European Union on 24 July 2026, in force since 27 July 2026. It postpones high-risk obligations and gives until 2 December 2026 for the technical marking of systems already on the market. It does not postpone Article 50. https://www.boe.es/buscar/doc.php?id=DOUE-L-2026-81147
- European Commission. Code of Practice on transparency of AI-generated content, published on 10 June 2026 and considered an appropriate voluntary instrument by the Commission and the European AI Board on 8 and 9 July 2026. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- European Commission. Guidelines on the transparency obligations under Article 50 (final version). https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content
- Official EU icons for labelling AI-generated content, with placement, accessibility and free-use licence rules. https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content
- Draft Organic Law on the proper use and governance of artificial intelligence. Official Gazette of the Spanish Parliament, Congress, Series A, no. 97-1, 12 June 2026. Under consideration: designates AESIA as the central authority and specifies the penalty regime. https://www.congreso.es/public_oficiales/L15/CONG/BOCG/A/BOCG-15-A-97-1.PDF
- Law 10/2025 of 26 December, regulating customer-service services. BOE no. 312 of 27 December 2025. In force since 28 December 2025, with a twelve-month adaptation period. https://www.boe.es/buscar/act.php?id=BOE-A-2025-26698