About this Summary
This summary was created with the help of artificial intelligence (AI) to help readers quickly understand the key points of the article.
It has been reviewed by our editorial team before publication. For complete information and full details, please read the full article.
- Providers must clearly inform users when they are interacting with AI, including chatbots, AI agents and other interactive applications.
- The framework requires labelling of AI-generated or modified content, including synthetic text, images, photographs, audio and video.
- Deepfakes and AI-produced public-interest content must be disclosed to protect citizens from misinformation and deception.
- Cyprus is preparing for AI Act implementation, with a national strategy to 2032 and designated authorities, though key framework details remain unfinished.
Artificial intelligence is increasingly part of everyday life, from generating text and images to answering questions, analysing data and supporting businesses and public services. New AI Act rules are now moving the EU’s regulatory framework into a new phase of implementation and oversight.
What the new AI Act rules require
Under European Commission guidance, providers of AI applications must ensure that users are clearly informed when they are interacting with artificial intelligence.
The requirement covers chatbots, AI agents and other interactive applications based on AI systems.
The framework also introduces technical requirements for identifying and labelling content generated or modified using AI. These provisions cover synthetic text, images, photographs, audio and video.
The Commission’s guidance also clarifies which applications are subject to transparency requirements, what exemptions apply and how businesses can demonstrate compliance with the AI Act.
Focus on deepfakes
Particular emphasis is placed on deepfakes. Users must be informed when they are exposed to images, video or other audiovisual material that has been generated or manipulated using AI.
Similar transparency requirements apply to content concerning matters of public interest when it is produced by AI systems without meaningful human involvement or editorial oversight.
The aim is to strengthen transparency and protect citizens from misinformation and deception involving content that appears authentic but has actually been created using AI tools.
High-risk AI systems face stricter requirements
The implementation of the AI Act will continue over the coming years, with different provisions entering into force at different times.
The regulation establishes stricter requirements for high-risk AI systems used in areas where automated decisions can significantly affect people’s lives and rights. These include healthcare, education, recruitment, public services and critical infrastructure.
Depending on their use, such systems will have to meet strict requirements before deployment. Organisations developing or using them must assess and manage potential risks, ensure data quality, maintain technical documentation and logs, provide human oversight and take measures to ensure accuracy, reliability and cybersecurity.
In some cases, organisations will also be required to carry out a Fundamental Rights Impact Assessment (FRIA), examining whether an AI system could affect rights such as privacy, equal treatment and protection against discrimination.
However, not all obligations for high-risk systems took effect on 2 August 2026. The AI Act provides different implementation dates for different categories, with most of these requirements being introduced progressively.
Cyprus prepares for full implementation
Cyprus has begun preparing for the implementation of the AI Act and has also developed a National Artificial Intelligence Strategy extending to 2032.
According to the government’s strategy, Cyprus aims to become a trusted regional AI hub in the Eastern Mediterranean, promoting the safe and responsible development of AI applications and acting as a bridge between the EU and the wider region.
Speaking to Sigma, Commissioner for Personal Data Protection Maria Christofidou said Cyprus had already designated the authorities responsible for implementing and supervising the AI Act.
She explained that, following a decision by the Council of Ministers, the Commissioner for Communications was appointed as the main competent authority for implementation of the regulation. The Commissioner for Communications will act as the Market Surveillance Authority, Notifying Authority and Single Point of Contact.
The Commissioner for Personal Data Protection, meanwhile, will oversee matters relating to personal data protection.
Cyprus framework still being developed
Christofidou said the Deputy Ministry of Research, Innovation and Digital Policy, together with the two competent authorities, had commissioned a specialised company to prepare a techno-economic study.
The study will form the basis for designing the administrative and technical structures required for the full implementation of the AI Act in Cyprus.
However, she noted that several aspects of the framework remained under development because the study had not yet been completed and the relevant bill had not yet been put out for public consultation.
This means that final decisions have yet to be made on issues including staffing and training, the registration of AI systems, the complaints process and how supervisory and enforcement powers will be exercised.
Cyprus therefore remains at an early stage in both the wider adoption of AI across services and organisations and its full adaptation to the EU framework. The forthcoming public consultation is expected to allow businesses, professionals and other stakeholders to submit their views and proposals on how AI will be incorporated into public administration, the economy and everyday life.
Also read: Trump imposes 15% polysilicon tariff to counter Chinese chips
For more videos and updates, check out our YouTube channel


