The European Union has begun enforcing its AI Act, with new transparency rules taking effect on August 2, 2026. These regulations mandate that certain AI systems must disclose to users when they are interacting with an AI or when content has been generated or altered by artificial intelligence. This includes requirements for chatbots to identify themselves as automated systems, for deepfakes to be labeled, and for machine-made or edited content to carry machine-readable marks for automatic detection.
Companies failing to comply with these obligations face significant penalties, including fines up to €15 million or 3% of their worldwide annual turnover, whichever amount is higher. The European Commission stated that the objective of these measures is to reduce deception and manipulation, enabling individuals to make more informed decisions, while also providing businesses with clearer compliance requirements.
The enforcement powers primarily target providers of general-purpose AI (GPAI) models, which are the foundational systems supporting numerous AI tools and services, including AI agents. The Commission highlighted that providers of the most advanced GPAI models must address risks of large-scale harm, such as chemical, biological, radiological, and nuclear incidents, loss of control, cyber offenses, harmful manipulation, and threats to fundamental rights.
All GPAI model providers are now required to document specific information and make it available to competent authorities or downstream providers. They must also establish a copyright policy and publish a sufficiently detailed summary of the content used to train their models.
Alongside the new enforcement, the Commission released an initial list of over 180 organizations that have signed the Code of Practice on transparency of AI-generated content. This voluntary framework offers companies a structured method to demonstrate adherence to the labeling and marking requirements, which are legal obligations under Article 50 of the AI Act.
While some aspects of the AI Act are now in force, others are being implemented on a staggered schedule. The AI Omnibus, a package of amendments to the Act, has postponed the rules for high-risk AI systems until December 2, 2027, and those for high-risk systems integrated into regulated products until August 2, 2028. Conversely, the Omnibus accelerates measures against harmful AI applications, banning AI systems that generate non-consensual sexually explicit content or child sexual abuse material starting December 2, 2026.
The European Commission has previously utilized other EU digital laws to scrutinize risks associated with generative AI. For instance, in January 2026, the Commission initiated a formal investigation into X under the Digital Services Act following the appearance of manipulated sexually explicit images and potential child sexual abuse material on the platform, involving its Grok tool.
Enforcement responsibilities are distributed among several bodies. The AI Office directly oversees general-purpose AI models, with authority to request technical documentation, conduct evaluations, demand corrective actions, and issue fines. National competent authorities are responsible for other AI systems operating within their respective borders, while the European Data Protection Supervisor ensures compliance among EU institutions themselves.
Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, emphasized that the Act provides legal certainty for innovators while safeguarding public interest, viewing enforcement as a crucial step toward fostering AI that is understandable and trustworthy for both individuals and businesses. However, some observers remain unconvinced that the AI Act will bring about substantial change, suggesting that user awareness of how AI tools handle data might be more impactful than the regulations themselves.






