Table of contents:
This summer, three major events took place concerning the European governance of artificial intelligence.
First, (1) the transparency obligations laid down in the EU AI Regulation became applicable as of 2 August across all Member States: chatbots must present themselves as such, AI-generated content must be labelled, deepfakes (in the broad sense of the definition) must be disclosed, and any person acquires the right to lodge a complaint with the national supervisory authority, under the threat of penalties of up to 15 million euros or 3% of global turnover. The latter, however, remains merely a theoretical right in Romania, until the authority that is supposed to receive/resolve such complaints is designated by law.
Next, (2) the European Commission finalised, in June and July, the toolkit for implementation, namely the code of good practice, the guidelines on Article 50, and the pictograms for the appropriate labelling of AI-produced content. And, finally, (3) the Digital Omnibus package postponed the EU obligations for high-risk systems until December 2027 and August 2028 respectively (without affecting the provisions on transparency that have now entered into force). It is worth noting, nonetheless, that the package deferring certain provisions was published on 24 July, a sign that artificial intelligence is a new topic for everyone, with a certain tolerance for such delays.
All of this directly concerns Romania, and we explore it in the paragraphs below; the domestic picture, however, remains for the time being an amalgam of institutions with fragmented responsibilities, without any implementing law and without an authority to oversee the country’s course in the age (and the governance) of AI. Although Romania is not the only European country in this situation, artificial intelligence is one (more) field in which it is worth not falling behind (yet again).
The rules applicable as of 2 August
Article 50 of the EU Regulation establishes the following obligations:
The obligation falls on the provider, that is, the one who develops or supplies the AI system, and requires the system to be designed in such a way that the person becomes aware that they are speaking with an AI: a bank’s chatbot, the voice assistant that takes calls at a call-centre or at a town hall must present itself from the very beginning of the conversation, or its artificial nature must be absolutely evident (for example, a virtual-assistant description).
This technical marking differs from the visible label under point (4): namely, the provider (OpenAI, Google, Anthropic) must embed in the generated files certain signals that verification tools can identify, such as provenance metadata (the C2PA standard) or invisible watermarks. The marking must be, within the limits of technical feasibility, effective, interoperable and robust, but assistance functions that do not substantially alter the content (corrections, standard edits) are exempt. It is only here that the Omnibus grace period operates as regards transparency: systems already on the market before 2 August have until 2 December 2026, whereas those placed after 2 August must comply immediately (which major companies such as Anthropic have already begun to implement).
The obligation falls on the deployer, that is, the one who uses the system: a call-centre that analyses the customer’s voice in order to infer their mood, or a shop that sorts visitors into age or gender categories on the basis of cameras, must tell this to the persons concerned, while the processing of data remains subject, in parallel, to the GDPR rules. It should also be borne in mind that the most sensitive area is already prohibited, separately, since February 2025: emotion recognition in the workplace and in education falls under the practices prohibited by Article 5, so the obligation to inform concerns only the uses that remain lawful, such as commercial ones.
Anyone who publishes a deepfake must visibly declare that the material is artificially generated or manipulated, and text generated by AI and published for the purpose of informing the public must likewise be declared as AI-generated (except for texts that have undergone human review for which someone assumes editorial responsibility). In this context, “deepfake” means any AI manipulation of an image, video or audio recording of existing persons, objects, places or other entities/events, a manipulation that could lead people to believe that the content in question is real. For example, an advertising agency that produces a commercial featuring a digital double of an actor must declare that the material is a deepfake, just as a company that presents its CEO in the form of a video avatar must do, and the same must be declared by a party/candidate who publishes a realistic clip made with AI, or by a newsroom that illustrates an article with an AI image of a real person or place.
Likewise, also as of 2 August, the mechanism for enforcing these provisions was put into operation: the supervisory authorities acquire the powers to investigate, to access documentation and to impose corrective measures. In the same vein, Article 85 of the EU Regulation grants any person, whether natural or legal, the right to lodge a complaint with the national supervisory authority for infringements of the rules we have set out, complaints “handled in accordance with the specific procedures established for that purpose” by these authorities.
Thus, for the infringement of the transparency obligations, the fine amounts to up to 15 million euros or 3% of the total annual global turnover, whichever is higher (for SMEs, whichever of the two amounts is lower). The fines are imposed by the national authorities, in accordance with procedures that national law must establish (which, as we explore in the lines below, Romania has not yet done).
Romania: only a memorandum
The deadline by which the Member States of the European Union were required to designate their supervisory authorities was 2 August 2025, but the Government adopted only on 12 March 2026, with a delay of 7 months, a memorandum proposing ANCOM as the market surveillance authority and single point of contact, and ADR as the notifying authority, as well as sectoral competences for ASF, BNR, ANSPDCP and other authorities.
The implementing law therefore remains in progress, the team and the procedures behind this future law have not yet been set up, and the right to lodge complaints or notifications, a right that the regulation grants the citizen as of 2 August, remains for the time being without a “counter” for Romanians.
Moreover, although the regulation is directly applicable and binding on all Member States, it contains numerous references to domestic law, whether of a mandatory nature (for example, the establishment or designation of the relevant authorities) or of an optional nature (authorising the use of remote biometric identification).
Thus, the following provisions are left to the discretion of Romania (and of each Member State):
Remote biometric identification
Regulatory sandbox
Retention of documentation for 10 years
For the sake of balance, Romania is not alone in this situation: roughly a quarter of the EU Member States have designated authorities and operational sanctions, half are somewhere in the middle, with designations made and laws still in progress, and another quarter, which is where Romania stands, has missed both the official deadline for designating an authority and the implementation of a law empowering that authority — a sign that the European Union is learning about this technology, and about the ensuing regulations, as it goes.
An argument about (un)predictable sanctions
It is relevant, however, to note that in a State with weak administrative capacity, the fine can become, relatively easily, a discretionary instrument, for where guidelines, procedures and people are lacking, sanctions may be applied selectively, according to the visibility of the case or the pressure of the moment.
The regulation clearly sets the ceilings of the fines and a set of criteria, but “Member States shall lay down the rules on penalties and other enforcement measures, which may also include warnings and non-monetary measures, applicable to infringements of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented” (Art. 99 (1)). Moreover, it is likewise left to the discretion of the Member States “the extent to which administrative fines may be imposed on public authorities and bodies established in that Member State” (Art. 99 (8)), an aspect which also requires enshrinement in legislation.
We raised the same objection with regard to the draft laws on the protection of children online, where fines based on percentages of turnover masked the absence of any enforcement mechanism, and we maintain it all the more given that the regime of fines for public authorities is also to be established by the national law.
In other words, the sanction can only make sense at the end of a system that works, and otherwise, sanctions can only produce uncertainty, for operators and citizens alike. We have written, with regard to the papal encyclical, about the need to regulate without stifling, and the application of the AI Act in Romania is precisely the test of this balance.
The foundations of a functional system before sanctions
1. Citizens' complaints
At this moment, a Romanian who encounters a deepfake or a chatbot that they wish to report is shuffled between a multitude of institutions:
Click on each institution to see what it does (not) handle.
Indeed, it is precisely ANCOM’s figures for 2025 that reveal this trajectory: approximately 400 notifications concerning digital services, 222 reports of potentially illegal content, and 8 complaints sent to the coordinators in the states where the platforms are established.
Thus, in matters of AI as well, the citizen becomes a courier between authorities, in a context where the regulation grants them, as of 2 August, the right to lodge a complaint with the supervisory authority.
It is easy to understand that citizens should be able to submit their complaint only once, in a single place, hosted by ANCOM as the future single point of contact, with triage and redirection carried out between institutions through a protocol with DNSC, ANSPDCP and the Police.
2. The labelling of content
The European Commission published, on 10 June 2026, the Code of Good Practice on the transparency of AI-generated content, together with a set of pictograms for labelling.
A month later, on 20 July, the guidelines for the application of Article 50 were also adopted, so that the toolkit exists and needs only to be translated into practice for newsrooms, advertising agencies and content creators, that is, for those who actually apply the labels.
By mid-August, the Code had gathered approximately 190 signatories, among them five entities from Romania, from the National Bank and the Harghita County Council to druid, Flipsnack and Minio Studio.
Accordingly, a guide in the Romanian language, built on the basis of that code and on the pictograms and followed by working meetings with newsrooms and agencies, could be produced at a low cost while also generating voluntary and measurable compliance.
3. The removal of deepfakes
DNSC constantly detects and flags them, from the fraudulent “investment” clips in which high-ranking Romanian officials are portrayed, to the BNR warnings regarding the forgeries featuring the governor. The process stops, however, at the flagging, for DNSC has, by law, neither the power to officially classify a material as a deepfake, nor the power to demand its removal from the platform, nor a mandate to monitor posts, so that the flagged clip remains online and continues to claim victims.
Moreover, the same AI tools appear even in information manipulation operations: the fourth European EEAS report documents 540 international incidents in 2025, of which 27% used AI tools, with Romania among the electoral targets of the operations attributed to Russia. Romania is, moreover, the only Member State of the Union (and among the only ones in the world) to have gone so far as to annul a presidential election because of an online influence operation, in December 2024, which is why attention to deepfakes can no longer be merely a theoretical exercise.
The instruments for such a deepfake-removal circuit already exist in Law 50/2024, where ANCOM, in its capacity as the digital services coordinator, can grant an institution the status of trusted flagger, and platforms are obliged to treat the notifications received as a priority. If DNSC were to receive this status, the flaggings would cease to be press communications and would become requests that the platform must resolve.
For platforms established in other states, ANCOM can bring the case before the European Commission or the counterpart authority in the respective state, while intermediaries established in Romania risk fines of up to 6% of turnover. The Romanian State has already built such a mechanism, only once, for elections: Emergency Ordinance 1/2025 obliged platforms to remove illegal content within at most 5 hours of the AEP notification, and such circuits ought to appear more often.
Measurement
All three directions explored above require, of course, indicators published quarterly: how many complaints were taken up and within what time they received a response, how many newsrooms and agencies worked through the labelling guide and how many marked materials resulted, how many clips were removed and within how many hours of the flagging. Such indicators keep institutions honest and make the difference between an authority and an e-mail address, all the more so as the European AI Office has opened a recruitment round for approximately 40 posts dedicated to the application of the regulation, with a deadline of 8 September 2026, while in Romania the staffing scheme for AI does not exist even on paper.
The implementation timeline
The timeline below presents what is already in force regarding the EU AI Regulation, as well as what is to come, with the amendments brought by the Digital Omnibus package. Click on a year to see the applicable deadlines.
The prohibited practices (Art. 5) and the AI literacy obligation (Art. 4): in force.
The rules for general-purpose models, governance and the regime of sanctions: in force; the deadline by which the Member States were to designate their authorities and notify the sanctions regime.
The transparency obligations (Art. 50), market surveillance, the right to complain to the supervisory authority and the European database: in force.
The end of the grace period for content marking in generative systems on the market before 2 August 2026; the new prohibitions on non-consensual intimate material and AI-generated child abuse material.
At least one national AI regulatory sandbox, operational; the compliance of general-purpose models on the market before 2 August 2025.
The obligations for high-risk systems under Annex III, including the fundamental rights impact assessment (FRIA) and the European registration.
The obligations for high-risk systems integrated into regulated products (Annex I).
The compliance of high-risk systems already in operation at public authorities.
Conclusion: capacity above all else
The Romanian citizen has new rights, and the companies and institutions that use AI bear new obligations, yet between these rights and the institutions that ought to defend them there remains a gap that a memorandum can no (longer) cover.
Thus, the application of the AI Act needs to become a priority of the new government, with at least the following commitments: an assumed implementation timeline, with deadlines and responsible parties who will bring to public consultation the draft law implementing the provisions of the AI Act, alongside funding for the capacity to apply the new provisions. And, finally, the Government must ensure that there will be a single point for lodging complaints, a labelling guide in the Romanian language and a deepfake-removal circuit, all of which can be built from now, on the already-existing legislation, with indicators published quarterly. Above all, such a capacity is needed.
Sources and references
European legal framework
- Regulation (EU) 2024/1689 on artificial intelligence, the Romanian-language version
- Regulation (EU) 2026/1744, Digital Omnibus AI (OJ, 24 July 2026)
The European Commission’s toolkit
- European Commission, Code of Good Practice on the transparency of AI-generated content (10 June 2026)
- European Commission, list of the code’s signatories (updated 12 August 2026)
- European Commission, the EU pictograms for labelling AI-generated content
- European Commission, Guidelines on the transparency obligations, Art. 50 (20 July 2026)
The state of implementation across the Member States
- Deloitte Legal / Reff & Asociații, the national implementation of the AI Act across the Member States (updated July 2026)
- Future of Life Institute, the national AI Act implementation plans
- European Commission, AI Office recruitment call, CNECT RL AI/2026 (deadline 8 September 2026)
Romania, the institutional framework
- The Government of Romania, the meeting of 12 March 2026 (the designation memorandum)
- ANCOM, The Regulation on artificial intelligence in Romania, the current state (24 July 2026)
- ANCOM, the annual DSA report for 2025
- ANCOM, DSA: the reporting of AI-generated content (9 May 2025)
- ANCOM, the trusted flaggers and Decision no. 336/2024
- Law no. 50/2024 on the implementation of the DSA
- Emergency Ordinance no. 1/2025 on the presidential elections
- Factual.ro, no institution can classify a material as a deepfake
The documented deepfake cases
- DNSC, deepfake alert Nicușor Dan and Ilie Bolojan (June 2025, via Gândul)
- DNSC, Nicușor Dan deepfake on Facebook (August 2025, via StartupCafe)
- BNR, deepfake-type fraud attempt featuring the governor (February 2024, via News.ro)
- BNR, warning regarding false posts featuring the governor’s image (18 February 2026, via Bursa)
- The Energy Minister’s criminal complaint over a deepfake, taken up by DIICOT (January 2024, Digi24)
Disinformation and electoral integrity
- EEAS, the fourth annual report on FIMI threats (March 2026)
- The Constitutional Court of Romania, Decision no. 32 of 6 December 2024 on the annulment of the presidential elections
Edge Institute
Back to:
Descoperă mai mult
de la Edge Institute
Trimitem saptamanal articole, idei, rapoarte si studii despre digitalizarea României
Folosim platforma Beehiiv pentru trimiterea newsletterelor. Prin abonare, confirmi că accepți Termenii și Politica de confidențialitate Beehiiv.