How AI Overviews and AI Search Fit Into the EU AI Act Conversation

SEO & GEO for WordPress websites

The EU AI Act is now in active enforcement. As of August 2026, transparency obligations apply, the AI Office has sanctioning powers, and generative AI companies are navigating a regulatory framework that did not exist three years ago. For businesses that publish content online, use AI tools, or rely on Google AI Overviews and AI search for visibility, understanding where the Act applies and where it does not is genuinely useful. This article breaks down the regulation’s structure, explains how AI Overviews fit into it, and identifies what businesses should monitor as enforcement matures.

What the EU AI Act actually regulates

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework governing artificial intelligence. It entered into force on 1 August 2024 and establishes a risk-based system of rules that applies to developers, deployers, importers, and distributors of AI systems used in the EU. Crucially, the regulation applies to companies based outside the EU if their AI output reaches European users.

The Act defines an AI system as software that, for explicit or implicit objectives, generates outputs such as predictions, recommendations, or decisions that influence physical or virtual environments. It covers the placing on the market, the putting into service, and the use of AI systems in the EU. AI systems used purely for scientific research and development fall outside its scope.

The regulation organizes AI into four risk tiers: unacceptable risk (prohibited), high-risk (heavily regulated), limited-risk (transparency obligations only), and minimal-risk (no mandatory requirements). Alongside this four-tier structure, the Act includes a separate regulatory track for general-purpose AI (GPAI) models, which are models capable of performing a wide range of tasks and being integrated into downstream systems. This GPAI track sits parallel to the risk tiers, not within them.

Enforcement is shared. The AI Office, housed within the European Commission, has sole authority over GPAI model compliance. National market surveillance authorities handle AI systems in other categories. The Act’s provisions phased in over time: prohibited practices became enforceable in February 2025, GPAI obligations from August 2025, and full transparency enforcement from August 2026.

Where AI Overviews and AI search fit in the risk tiers

No official EU Commission document has formally classified Google AI Overviews or Perplexity AI under a specific AI Act risk tier. What follows is an applied interpretation based on the Act’s structure and the best available legal analysis.

Generative AI systems like ChatGPT and Google’s AI Overviews are generally understood to fall into the limited-risk category when deployed as conversational or answer-generating tools. Limited-risk systems face transparency obligations but do not require conformity assessment or registration in the EU AI database. Search ranking algorithms, by contrast, are cited as examples of minimal-risk AI with no mandatory compliance requirements.

The more significant classification issue concerns the underlying models. Google’s Gemini, the model powering AI Overviews, qualifies as a GPAI model under the Act’s definition. GPAI models are regulated under Articles 51 to 55, which impose obligations on providers regardless of how the model is deployed. All GPAI providers must maintain technical documentation, publish a summary of training data content, and comply with EU copyright law. GPAI models presenting systemic risk face additional requirements, including model evaluations, adversarial testing, and incident reporting.

The provider versus deployer distinction matters here. Google, as the developer of Gemini, is the GPAI provider and carries the primary obligations. A business that integrates a third-party GPAI model into its own product becomes a deployer with lighter obligations, unless it substantially modifies the model, at which point it may be reclassified as a provider.

A separate but related development came in July 2026, when Germany’s media regulator ZAK ruled that AI Overviews operate as content publishers, not neutral conduits, stripping them of the standard EU platform liability exemption. This ruling is under national media law, not the AI Act, and the two regulatory tracks are distinct. Still, the ruling signals how regulators are beginning to think about AI search as something closer to editorial publishing than passive information retrieval.

Transparency and disclosure requirements for AI-generated content

Article 50 of the EU AI Act is the provision most directly relevant to businesses that publish AI-generated content. It establishes transparency obligations that became enforceable on 2 August 2026, and it applies to both providers and deployers of AI systems.

The core requirement is that outputs of generative AI systems must be identifiable as AI-generated or AI-manipulated. Deployers of AI systems that generate text “published with the purpose of informing the public on matters of public interest” must disclose that the content was artificially generated. Disclosures buried in terms and conditions or expressed through vague labeling do not meet the threshold.

What the disclosure obligation covers

Article 50 covers four areas: direct interaction with individuals (chatbots), AI-generated content, emotion recognition and biometric categorization, and deepfakes or AI-generated text on public-interest matters. Deepfake labeling obligations under Article 50(4) apply from August 2026. Machine-readable marking under Article 50(2) has a grace period to December 2026 for systems already on the market before August 2026.

The European Commission adopted final guidelines on Article 50 on 20 July 2026, clarifying scope, definitions, and exceptions. A Code of Practice on the Marking and Labelling of AI-generated Content was finalized in June 2026 through a process involving more than 180 participants. The AI Board assessed it as adequate for demonstrating compliance. The Code includes standardized visual labels and recommends a multilayered approach combining watermarks, visual labels, and machine-readable metadata. Point solutions that rely on a single technique are considered insufficient.

Google signed the Code of Practice in July 2026, adopting the C2PA standard and its proprietary SynthID watermarking technology as primary compliance tools. Google also noted that adding regulatory complexity while technical solutions are still evolving could risk confusing users if online content becomes saturated with overlapping AI labels. That tension between disclosure and usability remains unresolved.

Non-compliance with Article 50 can attract fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

How content creators and businesses are affected

The AI Act’s transparency obligations affect any business that uses AI to generate content intended to inform the public, regardless of industry. This includes landing pages, product descriptions, blog posts, advertising creatives, and social media content where AI has played a substantial role in generation.

The compliance obligation sits alongside a commercial reality that is already reshaping how content performs online. Zero-click searches reached roughly 68% in early 2026, meaning most searches now end without a user visiting any website. When an AI Overview appears in Google Search, click-through rates at the top organic position drop significantly. Publishers across sectors have reported substantial declines in referral traffic over the past two years.

The EU’s antitrust investigation into Google, launched in December 2025, examines whether Google breached EU competition rules by using web publisher content and YouTube videos to train its AI models without appropriate compensation and without offering publishers the ability to refuse. If found in violation, Google could face fines of up to 10% of its global annual revenue. This investigation runs under competition law, separate from the AI Act, but its outcome will shape how AI search products operate in Europe.

For content creators specifically, the GPAI obligation requiring providers to publish a summary of training data content (applicable from August 2025) gives regulators and creators visibility into how AI models learn. Combined with the EU Copyright Directive, the Act is reshaping how AI models are trained and how the value created from that training is distributed.

Businesses that want to remain visible in AI search while staying compliant need a content strategy that works across both traditional search and generative engines. Scaling content output with GEO-ready articles built for AI citation, not just keyword ranking, is becoming a practical necessity rather than an optional upgrade.

The unresolved questions regulators still face

The EU AI Act is a detailed and ambitious regulation, but several questions remain genuinely open as enforcement begins.

Accuracy is the most significant gap. Article 15 mandates accuracy requirements for high-risk AI systems only. For GPAI models deployed in everyday use cases such as answering health queries or summarizing documents, accuracy is neither required nor meaningfully regulated. The Act’s transparency obligation does not address AI hallucinations. When a generative AI system produces unverified content with apparent confidence, users may trust that content without verification, and the Act places no obligation on end users to check it.

The publisher versus platform question

Germany’s ZAK ruling that AI search outputs constitute editorial publishing raises a fundamental question for regulators across Europe: do AI search services make editorial choices, or do they function as neutral conduits? If the publisher framing gains traction in other member states or at the EU level, AI companies could face stricter obligations around accuracy, source selection, and their relationship with the news ecosystem. As of 2026, no formal EU-level position on this question exists.

Regulatory fragmentation and AI agents

Enforcement capacity is uneven. As of mid-2026, only 9 of 27 EU member states had fully designated both required national authorities under the Act; 12 had partial designations, and 6 had none. This creates real variation in how the regulation is applied across the bloc.

The AI Act’s transparency obligations also overlap with the Digital Services Act, and generative AI models blur the DSA’s categories of intermediary services in ways that complicate enforcement. Researchers have called for standardized “Answer Engine Transparency” reports requiring dominant AI search platforms to publish data on citation distributions, unsupported claim rates, and click-through patterns by topic. No such requirement exists yet.

The AI Office has described its regulatory considerations for AI agents as “only preliminary at this stage,” acknowledging that agentic AI is evolving faster than the Act’s current framework can accommodate.

What businesses should watch as the Act is enforced

Active enforcement began on 2 August 2026. The AI Office and national authorities now have formal investigative and sanctioning powers. The AI Office’s preferred initial approach is “technical compliance dialogues” with companies, but it can also send requests for information, require corrective measures, and impose fines. Any individual or business that considers an AI system non-compliant can file a complaint with a national market surveillance authority.

The Digital Omnibus (Regulation (EU) 2026/1744), adopted in July 2026, extended deadlines for high-risk Annex III systems such as hiring tools and credit scoring to December 2027. It did not delay Article 50 transparency obligations, GPAI enforcement powers, or the penalty regime. Those all took effect in August 2026. The Omnibus also added two new prohibited AI uses: applications that generate non-consensual intimate imagery and child sexual abuse material, both effective December 2026.

Three practical areas deserve attention from businesses operating in the EU or reaching EU users.

  • AI content labeling: If your business publishes AI-generated content on matters of public interest, Article 50 applies now. Review your disclosure practices against the Commission’s July 2026 guidelines and the Code of Practice requirements, not just a vague “AI-assisted” footnote.
  • GPAI integration: If you build products on top of GPAI models such as Gemini, GPT-4o, or Claude, confirm whether your use case modifies the model substantially enough to reclassify you as a provider. Most businesses integrating APIs remain deployers, but the line matters.
  • Regulatory overlap: Following an AI-related incident, reporting obligations may trigger under three separate frameworks with different timeframes: 24 hours for NIS2, 72 hours for GDPR, and 15 days for the AI Act. Integrating AI Act compliance into existing GDPR programs now reduces that administrative burden later.

The GPAI Code of Practice offers a voluntary safe harbor that carries weight in enforcement proceedings. Signing it reduces administrative burden but does not guarantee compliance; national authorities retain independent assessment powers under Article 50.

The regulatory picture around AI search is still forming. The Germany ZAK ruling, the EU antitrust investigation into Google, and the AI Office’s evolving position on AI agents all point toward a more demanding environment for AI search products over the next two to three years. Businesses that treat the Act as a compliance checklist will be slower to adapt than those that treat it as a signal about where the rules of online content and AI visibility are heading.

This content was generated with the help of AI and it may contain mistakes

Your customers are asking AI. Are you part of the answer?

In a quick demo, we show how WP SEO AI tracks your AI visibility, finds content gaps, and helps your website appear in ChatGPT, Google AI Overviews and more.

Dive deeper in