As AI becomes increasingly embedded in business, compliance is becoming less about the technology itself and more about accountability, transparency and knowing where responsibility lies when AI enters the workplace or interacts with customers.

Maltese businesses are facing new obligations under the European Union’s AI Act, with key transparency provisions becoming applicable on 2nd August 2026. The rules form part of the EU’s broader risk-based approach, which distinguishes between prohibited practices, high-risk systems, systems subject to transparency requirements and minimal-risk applications.

Under Article 50, providers of certain AI systems that interact directly with people must inform individuals that they are interacting with AI, unless this is already obvious from the circumstances. Transparency requirements can also apply to AI-generated or manipulated audio, images, video and text, including deepfakes and certain content concerning matters of public interest.

However, the rules do not mean that every piece of content produced with the assistance of AI must automatically be labelled. The requirements depend on the type of system, how it is being used and the role of the organisation.

The European Commission has also released a set of optional EU icons that businesses can use to clearly identify certain AI-generated or manipulated content. The icons are designed to make labelling more consistent and easier for businesses to implement across different types of content.

The Commission has also provided guidance on how the icons should be displayed, including ensuring that they are clearly visible at the first exposure to the content and, where appropriate, embedded directly into it. Businesses are encouraged to use clear accompanying language and ensure the labels are accessible to users.

The Malta Digital Innovation Authority (MDIA), Malta’s lead market surveillance authority for the AI Act, is urging organisations to understand how the legislation applies to their AI systems.

Speaking with BusinessNow.mt, the MDIA explained that "the requirements also depend on the business’s role, with two core stakeholders being the AI system's provider and deployer. A provider develops or commissions an AI system and places it on the market or puts it into service under its own name, while a deployer uses an AI system under its authority in a professional context. A business may hold different - (and multiple) - roles for different systems."

"In terms of implications, prohibited AI practices cannot be placed on the EU market. High-risk systems must meet dedicated safeguards, undergo conformity assessment to verify those safeguards, carry CE marking and be registered in a database at EU or national level depending on the use case. Transparency requirements may include AI disclosures and machine-readable markings or labels, as applicable. Minimal risk systems are not subject to specific requirements, though they may voluntarily follow codes of conduct to implement safeguards in their systems," MDIA said.

The Authority has also developed self-assessment tools, including an AI classification guide and compliance role finder, to help organisations determine their obligations.

The rules are particularly relevant to businesses using AI chatbots and virtual assistants, where customers may need to be informed that they are interacting with AI. This is increasingly important as companies adopt automated systems for customer service, sales and other direct interactions.

Speaking to BusinessNow.mt, a spokesperson from telecommunications company Melita said it "views AI as an important productivity enhancer, used responsibly and always under human oversight. We began labelling AI-generated content some months ago and all our marketing content goes through editing and verification before publication. Our AI virtual agents make clear from the outset that customers are speaking with a digital assistant, with a human agent available at any time."

For companies that have rapidly adopted generative AI, the new rules are likely to prompt a broader review of how the technology is being used across their operations. Businesses are being encouraged to create an inventory of their AI systems, establish their role under the Act, assess the relevant risk classification and identify which obligations apply.

The AI Act is being introduced in phases. Prohibited AI practices have been subject to restrictions since February 2025, while the transparency provisions became applicable in August 2026. Requirements relating to high-risk systems will follow according to the applicable timetable.

For Malta’s business community, the message is therefore not that all AI must now be labelled, but that businesses need to know what AI they are using, what it is being used for, what role they have under the Act and whether that use triggers specific regulatory obligations.

Related

‘Not the image Malta should portray’: MHRA President objects to soldiers patrolling Swieqi

August 12, 2026
by Nicole Zammit

'It is not their job and I wonder what powers they have in cases where a contravention is taking place'

Former San Luċjan oil depot earmarked for transformation into innovation hub

August 12, 2026
by Nicole Zammit

The framework seeks to safeguard surrounding agricultural land as well as nearby ecologically and historically sensitive protected areas

MFSA sounds alarm over rise in financial scams, flags unauthorised entities operating in Malta

August 12, 2026
by Nicole Zammit

Scammers and entities are keeping busy with a series of fraudulent campaigns and companies