On August 2, 2026, the EU AI Act becomes fully applicable. That’s less than a month away, and it changes the rules for any application that uses artificial intelligence to process images, recognize faces, detect emotions, or generate content — which now includes a significant portion of the apps most people use to store and organize their photos.
This isn’t an announcement of a new law. The EU AI Act entered into force in August 2024, and providers have had two years to prepare. What’s new on August 2 is that enforcement can begin — and the transparency obligations that affect everyday consumer apps take full effect simultaneously.
What the EU AI Act Actually Is
The EU AI Act is a risk-tiered regulation. It doesn’t ban all AI; it classifies AI systems by the potential harm they can cause and applies stricter requirements to higher-risk categories.
Unacceptable risk — prohibited entirely. This includes AI systems that use real-time biometric surveillance in public spaces for law enforcement, social scoring systems, and AI that subliminally manipulates behavior.
High risk — permitted but subject to extensive pre-market obligations, documentation requirements, and ongoing monitoring. This covers AI used in critical infrastructure, employment decisions, education, credit scoring, and some biometric systems.
Limited risk — permitted with specific transparency requirements. This is the category that directly affects consumer apps most people use: chatbots, AI image generators, emotion recognition systems, and AI-generated content of all kinds.
Minimal risk — most AI applications fall here and face no mandatory requirements under the Act.
The August 2 deadline is primarily about the limited-risk transparency requirements coming into force simultaneously with other provisions. For photo and file apps, this is the layer that matters.
The Three Transparency Rules Taking Effect Now
1. Emotion Recognition Must Be Disclosed
If an app deploys an AI system capable of recognizing or inferring a person’s emotions from their face, the people being analyzed must be informed that this is happening — at the time of collection, not buried in a terms-of-service document.
This is broader than it might first appear. Several major photo-organization platforms have tested or deployed sentiment analysis features that infer emotional states from facial expressions in photos — to group memories by mood, surface photos from “happy” moments, or build timeline summaries. Under Article 50 of the AI Act, any such feature requires active disclosure, not just the setting’s existence in a privacy dashboard.
2. Biometric Categorization Must Be Disclosed
The Act’s transparency obligations also cover AI systems that categorize people by characteristics — including age, gender, and race — derived from biometric data. If a photo app is grouping or filtering images based on inferences about the people in them, the individuals whose data is being processed have a right to know.
This is distinct from the prohibited category of covert biometric surveillance; it’s not banned outright. It has to be disclosed.
3. AI-Generated Content Must Be Marked
Any AI system that produces synthetic images, audio, or video must ensure that output is labeled as machine-generated in a machine-readable format. This is particularly relevant to photo-editing features that generate new visual content — replacing backgrounds, synthesizing new faces, filling in erased portions of an image with AI-generated pixels.
The labeling requirement is intended to be machine-readable, not just a visible watermark. The goal is interoperability: downstream systems and platforms can detect AI-generated content even when a human might not recognize it as such.
Why the Legacy Carve-Out Matters
One point from the European Commission’s draft guidance published in May 2026 is worth sitting with: there is no legacy exemption for AI systems deployed before the Act took force.
If a photo app has been running emotion recognition or biometric categorization features since before August 2024, it still needs to comply by August 2, 2026. The two-year window was the preparation period — not a grandfather clause for existing deployments.
In practice, this means apps that added AI photo features years ago and never updated their disclosure practices now have an August 2 deadline to do so — or face enforcement. The European Data Protection Board has already signaled it intends to treat AI Act violations and GDPR violations as separate but potentially concurrent matters when both apply.
Which Features Put Photo Apps in Scope
Not every AI-powered feature brings a photo app into scope for the August 2 transparency requirements. But several commonly advertised features do.
Face grouping with inferred attributes: If an app not only groups photos by detected face but also assigns attributes — estimated age, inferred gender, flagged emotion — the latter triggers disclosure requirements.
“Memories” with sentiment filtering: Several platforms generate automatic memory albums by selecting photos based on facial expressions or detected mood. If the selection mechanism uses emotion recognition, disclosure applies.
AI-generated photo enhancements: Any feature that uses generative AI to synthesize or alter visual content — not just enhance existing pixels, but generate new ones — requires machine-readable labeling of the result.
Biometric search: Apps that let users search their library by characteristics derived from faces (find photos of smiling people, photos of children, photos by age group) are operating in biometric categorization territory.
Basic object recognition — “find photos with dogs” or “show me all beach photos” — falls into minimal-risk territory and isn’t covered by the August 2 disclosure requirements.
What Actually Changes for Users
The practical change for users is that the Act creates enforceable disclosure rights, not just industry voluntary practices.
Before August 2, a photo platform could run emotion recognition quietly and disclose it in a general way within their privacy policy. After August 2, disclosure must be active and at the point of collection — meaning when the feature processes your face, you’re supposed to know that’s what’s happening.
What this means in practice depends on enforcement. EU member states are each designating their own national competent authorities under the AI Act, and the European AI Office handles cross-border cases and systemic violations by general-purpose AI providers. Enforcement will be uneven at first, as it typically is with any new regulatory regime.
But there’s a meaningful difference between a right that exists only because a company chose to give it and a right that exists because regulators can impose fines for violations. The Act gives the latter — maximum penalties of 15 million euros or 3% of global annual turnover for violations of the limited-risk transparency rules.
How This Overlaps With GDPR
The AI Act and the GDPR are separate legal regimes with different scopes, but they overlap significantly when AI processes personal data.
GDPR already requires a lawful basis for processing personal data, a purpose limitation, transparency, and data subject rights including access, correction, and erasure. Biometric data — which includes facial geometry — is classified as a special category requiring explicit consent or another narrow lawful basis.
The AI Act adds requirements specific to the AI system itself, independent of the personal data it processes. A photo app could technically satisfy GDPR’s transparency requirements about data processing while still violating the AI Act’s specific requirements about disclosing that an emotion recognition system is operating.
Apps now need to satisfy both simultaneously — and where they conflict, the stricter requirement applies.
What Happens Outside the EU
The EU AI Act technically applies to providers and deployers of AI systems that are placed on the EU market or affect people in the EU, regardless of where the provider is based. A US company with EU users is in scope.
This follows the same extraterritorial model as the GDPR, and companies that already built GDPR compliance programs are familiar with the approach. In practice, it’s often simpler to apply the EU standard globally rather than build geofenced rule sets — which is why regulations like this one tend to have broader real-world reach than their formal territorial scope.
What to Look for in Your Own Apps
The August 2 date gives you a useful benchmark. Shortly after it passes, look at the photo and file apps you use most and check whether their in-app disclosure practices have changed:
- Does the app now notify you when an AI feature is processing your face, not just disclose it generally in settings?
- Have the apps added any labeling to AI-generated image content?
- Has any app updated its in-app messaging around features that analyze your facial expressions or categorize photos by attributes?
Providers that were prepared will have made these changes before the deadline. Providers who haven’t are either not yet in compliance or have assessed their features as not triggering the relevant requirements — both of which are worth understanding if you store personal photos on their platform.
What a Privacy-First Storage Approach Looks Like
The August 2 obligations are disclosure obligations — they don’t prohibit the features they require transparency about. A photo app can still run emotion recognition; it just has to tell you.
What they don’t require is a storage platform that processes your photos with AI at all. There’s a simpler alternative to worrying about which AI features your storage provider is running on your face: keeping your files somewhere that isn’t using them as training material or analyzing them for any purpose.
daftei doesn’t run AI features against the files you store. There’s no emotion recognition, no biometric categorization, no generative enhancement, and no AI training on your content — by any third party. Files are encrypted in transit with TLS 1.3 and at rest with AES-256. The platform is GDPR and CCPA compliant, doesn’t sell user data, and doesn’t run ads.
The EU AI Act’s transparency requirements are a step forward. But the simplest version of this problem is solved by not having the AI processing happen in the first place.