Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requiring certain AI systems to tell users when they’re interacting with AI and when content has been generated or altered by it. Under these rules, chatbots have to id

The European Union has begun enforcing its AI Act, with new transparency rules taking effect on August 2, 2026. These regulations mandate that certain AI systems must disclose to users when they are interacting with an AI or when content has been generated or altered by artificial intelligence. This includes requirements for chatbots to identify themselves as automated systems, for deepfakes to be labeled, and for machine-made or edited content to carry machine-readable marks for automatic detection.
Companies failing to comply with these obligations face significant penalties, including fines up to €15 million or 3% of their worldwide annual turnover, whichever amount is higher. The European Commission stated that the objective of these measures is to reduce deception and manipulation, enabling individuals to make more informed decisions, while also providing businesses with clearer compliance requirements.
The enforcement powers primarily target providers of general-purpose AI (GPAI) models, which are the foundational systems supporting numerous AI tools and services, including AI agents. The Commission highlighted that providers of the most advanced GPAI models must address risks of large-scale harm, such as chemical, biological, radiological, and nuclear incidents, loss of control, cyber offenses, harmful manipulation, and threats to fundamental rights.
All GPAI model providers are now required to document specific information and make it available to competent authorities or downstream providers. They must also establish a copyright policy and publish a sufficiently detailed summary of the content used to train their models.
Alongside the new enforcement, the Commission released an initial list of over 180 organizations that have signed the Code of Practice on transparency of AI-generated content. This voluntary framework offers companies a structured method to demonstrate adherence to the labeling and marking requirements, which are legal obligations under Article 50 of the AI Act.
While some aspects of the AI Act are now in force, others are being implemented on a staggered schedule. The AI Omnibus, a package of amendments to the Act, has postponed the rules for high-risk AI systems until December 2, 2027, and those for high-risk systems integrated into regulated products until August 2, 2028. Conversely, the Omnibus accelerates measures against harmful AI applications, banning AI systems that generate non-consensual sexually explicit content or child sexual abuse material starting December 2, 2026.
The European Commission has previously utilized other EU digital laws to scrutinize risks associated with generative AI. For instance, in January 2026, the Commission initiated a formal investigation into X under the Digital Services Act following the appearance of manipulated sexually explicit images and potential child sexual abuse material on the platform, involving its Grok tool.
Enforcement responsibilities are distributed among several bodies. The AI Office directly oversees general-purpose AI models, with authority to request technical documentation, conduct evaluations, demand corrective actions, and issue fines. National competent authorities are responsible for other AI systems operating within their respective borders, while the European Data Protection Supervisor ensures compliance among EU institutions themselves.
Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, emphasized that the Act provides legal certainty for innovators while safeguarding public interest, viewing enforcement as a crucial step toward fostering AI that is understandable and trustworthy for both individuals and businesses. However, some observers remain unconvinced that the AI Act will bring about substantial change, suggesting that user awareness of how AI tools handle data might be more impactful than the regulations themselves.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.