Can the EU AI Act’s Transparency Rules Strengthen Democratic Resilience?
Taras Kovalchuk / Sep 3, 2026
Seeing More — Seeing Less by Anna Riepe & FARI / Better Images of AI / CC by 4.0
Since August 2, providers and deployers of certain AI systems have faced new obligations to disclose AI interactions, mark AI-generated or manipulated content, and label certain deepfakes and AI-generated text on matters of public interest. The European Commission says the rules are intended to reduce deception and manipulation and strengthen the integrity of Europe’s information environment.
The moment comes against a backdrop of concerns about declining democratic standards in Europe. As European democracies face risks from foreign interference, internal political divisions, and rapidly evolving AI systems, the newly enforceable AI Act provisions can strengthen transparency, accountability, and institutional readiness, but they cannot by themselves address the broader threats facing European democracies. The question, therefore, is whether greater transparency actually translates into greater democratic resilience.
What actually changed on August 2?
Several regulatory developments are noteworthy. First, Article 50's transparency rules took effect. Providers of certain AI systems must ensure that people are informed when they interact directly with an AI system, while providers of systems that generate or manipulate synthetic content must ensure that outputs are marked in a machine-readable format where required. Deployers have separate obligations concerning the disclosure of deepfakes and AI-generated public-interest text. These obligations come with several exceptions, however. They include law enforcement use, minor editorial assistance, artistic or satirical works, and content that has undergone human review with clear editorial responsibility.
Second, the AI Office gained full enforcement powers over general-purpose AI (GPAI) providers. Although the GPAI obligations had already applied since August 2025, full enforcement by the Commission did not start until August 2. Third, Article 4’s AI-literacy requirement, which has applied since February 2025, entered a new phase of supervision and enforcement. The provision requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others using AI systems on their behalf, taking into account their technical knowledge, experience, education, and the context in which the systems are used.
For democratic resilience, however, three aspects of this implementation deserve particular attention: transparency, accountability, and institutional readiness.
Where the newly enforceable rules can help
First, newly applicable rules can strengthen transparency. Democracy is built on the principle that political power stems from the informed consent of the governed. Without the ability to tell what they are looking at, voters cannot meaningfully analyze information, judge leadership, or hold power accountable. Article 50 and the GPAI provisions aim to prevent citizens from being deceived by synthetic media by requiring machine-readable marking of AI-generated content, mandatory disclosure of AI interaction, and documentation from GPAI providers. In doing so, the rules also aim to preserve institutional trust: citizens who stop believing what they see are citizens who may disengage from democratic participation altogether, or lean toward leaders who promise order over truth.
However, Anthropic's recent implementation of watermarking highlights both the promise and the limits of this approach. Honoring its commitment under the EU's Code of Practice on Transparency, Anthropic started embedding an invisible watermark in text generated by Claude models released after August 2, alongside provenance metadata attached to supported files. On the one hand, a positive aspect is that the new technology was rolled out globally rather than being limited to EU users.
On the other hand, watermarking only addresses the initial generation phase. The watermark remains vulnerable throughout a much longer lifecycle spanning distribution, modification, detection, and human interpretation. Anthropic itself noted that the absence of a watermark doesn't guarantee content wasn't AI-generated. Indeed, a screenshot, format conversion, or simple file re-save suffice to break the chain of provenance. Article 50 therefore targets a single point in the chain, but democratic resilience depends on what endures through several such points.
Second, the new rules enable accountability, an essential element of democracy as it ensures that power faces consequences for its actions. The GPAI provisions require providers to document training content, adopt copyright-compliant practices, and maintain risk-management records that the AI Office has the authority to request and assess. Although this does not prevent harm directly, it creates the documentation that is necessary for any enforcement.
Third, the rules contribute to institutional readiness. The latter is necessary to prevent judges, police officers, or civil servants from accepting algorithmic outputs as absolute truth, for instance, when setting bail. Training staff to understand a system's capabilities and limitations helps maintain human oversight that might otherwise default to machines. Article 4's literacy obligation, in force since 2025, pushes public bodies, campaigns, and newsrooms to achieve a baseline competence in spotting AI-generated content. While this might seem to be a small detail, transparency and accountability fail without institutional readiness: an official who is not aware of a disclosure requirement will not enforce it.
The limits of the new provisions
While the AI Act introduces essential regulatory guardrails, loopholes remain that will likely limit its effectiveness in safeguarding democracy.
To begin with, some actors will likely remain indifferent to the AI Act regardless of fines. Much of the disinformation targeting European democracies originates from Russia, and China. The foreign states are beyond the AI Act's jurisdiction and thus cannot be deterred directly. Its impact is instead indirect: constraining the commercial platforms, generative tools, and distribution channels used by foreign actors. Whether this indirect pressure actually limits state-backed operations, which can rely on non-compliant tools, remains an open question.
The AI Act also regulates companies placing systems on the EU market. However, it has almost no practical reach over a malicious actor running a modified, open-weight model on private infrastructure. Such an actor can generate harmful content entirely outside any provider's oversight and never trigger the newly enforceable rules.
A related problem is laundering. A bad actor can upload an illegal deepfake first on an unmonitored app like Telegram, where copying and screenshotting strip any hidden tracking data before regular users share it further. By the time the fake reaches major platforms, detection becomes more challenging, and Article 50's watermarking requirement offers little protection, since its markers were likely erased well before the content reached regulated platforms.
Mandatory labeling can also create an unintended defense. Bad actors can dismiss genuine footage simply by claiming it lacks a watermark or looks altered. This will help turn a tool built to expose fakes into one that helps deny reality. Should these tactics become popular, it will strike at the heart of democratic accountability. Indeed, if voters cannot agree on basic facts, how can they vote on an informed basis or hold leaders responsible?
Finally, the newly enforceable provisions do not address deeper societal problems like political polarization and declining institutional trust. People may choose to believe fake content or ignore official warnings no matter how prominently they are displayed. While the AI Act regulates how AI content is generated, it says nothing about why people are inclined to believe fakes in the first place.
What else democratic resilience requires
Given these limits, strengthening democratic resilience further requires tools beyond the AI Act. The Digital Services Act (DSA) is the most obvious complement. Where the AI Act addresses content generation, the DSA targets the algorithms that amplify it, and can force major platforms to detect and restrict viral fake media regardless of its origin. The mechanism works when it has teeth: once ChatGPT crossed the 45-million EU user threshold, the Commission classified it as a Very Large Online Search Engine, subjecting it to the DSA’s strictest rules. But the DSA has its own limits. Telegram, by contrast, has reported staying just below that threshold for over two years despite EU scrutiny, allowing it to evade the heightened obligations around detecting and mitigating coordinated manipulation.
Technical improvement would also help. Anthropic’s acknowledgment that provenance information can be lost or circumvented illustrates the need for more robust and interoperable approaches to content provenance. Greater harmonization of marking standards across platforms and file formats could make it harder for provenance information to disappear as content moves through the information ecosystem.
Beyond technology, institutions matter. Election commissions need the capacity to respond swiftly to AI-enabled incidents during active campaigns rather than through retroactive investigations; media literacy efforts should extend beyond Article 4's scope to reach the wider public; and allied democracies would benefit from closer coordination against the shared threat posed by state actors seeking to undermine their political systems.
What comes next
The newly applicable provisions of the EU AI Act could strengthen democratic resilience, but their impact should not be measured simply by how much AI-generated content receives a label.
The more important question is what happens after that label appears. If provenance information survives distribution, if platforms and institutions can interpret it, if journalists and election authorities can act on it, and if citizens trust and understand the signals they receive, greater transparency can contribute meaningfully to democratic resilience.
However, some actors will never comply voluntarily, and no labeling regime can eliminate political manipulation, polarization, or declining institutional trust.
The AI Act therefore should be understood as one layer of a broader resilience strategy. It needs to work alongside the DSA and other measures aimed at platform governance, election security, media literacy, technical provenance, and institutional capacity.
Ultimately, the AI Act can make synthetic content easier to identify. Whether that makes European democracies more resilient will depend on what governments, platforms, institutions, journalists, and citizens are able to do with that information.
Authors

