The European Union's AI Office began enforcing the transparency provisions of the AI Act on 2 August 2026, marking the most significant shift in AI regulation since the law entered into force two years ago. From this date, chatbots, virtual assistants, and other interactive AI systems must tell users they are interacting with machines, not humans. Deepfakes, including AI-generated images, video, and audio, must carry visible labels. And all AI-generated text published to inform the public on matters of public interest must be clearly marked (European Commission, 2026).
The rules apply across the entire European Economic Area, covering companies that offer AI services to EU residents regardless of where those companies are headquartered. If a chatbot serves users in Germany, France, or Italy, it must comply, whether the provider is based in San Francisco, Beijing, or Berlin. The enforcement date was announced in a Commission press release on 31 July 2026, giving the industry a final weekend to confirm readiness.
What risk categories does the AI Act define?
The AI Act sorts every AI system into four risk tiers: unacceptable, high-risk, transparency, and minimal or no risk (European Commission, 2026). Unacceptable systems, including social scoring and untargeted facial recognition scraping, are banned outright. High-risk systems, such as AI used in hiring, education, and critical infrastructure, face strict obligations starting December 2027. Minimal-risk systems, like AI-enabled video games or spam filters, remain largely unregulated.
Today, only the transparency tier takes effect. The high-risk rules for employment, education, migration, and critical infrastructure have been pushed to December 2027, while product-integrated AI systems will not face full obligations until August 2028. The delay came through the AI Omnibus, which entered into force on 27 July 2026 and simplified the implementation timeline (European Commission, 2026).
The risk classification matters because it determines which rules apply and when. A company building a spam filter faces almost no regulatory burden, while a company deploying AI for credit scoring or visa processing must prepare for extensive documentation, human oversight, and ongoing monitoring requirements. The framework is designed proportionally, though critics argue the boundaries between risk tiers are often blurry in practice.
What do the new transparency rules actually require?
Three obligations start today. First, any AI system that interacts with people, including chatbots and virtual assistants, must clearly inform the user they are dealing with AI. Second, deepfakes, meaning images, video, or audio edited or generated using AI, must be labelled as such. Third, AI-generated or AI-altered content published to inform the public must carry machine-readable marks so detection tools can identify it (European Commission, 2026).
The machine-readable marking requirement is the most technically demanding piece. Providers must embed metadata, such as C2PA-standard content credentials, that allow downstream platforms and browsers to flag synthetic content automatically. For everyday users, the visible effect will be simpler: clear disclosure labels on chatbot interfaces and conspicuous tags on AI-generated images and video.
The Commission also published guidelines on the AI system definition to help developers determine whether their product falls under the AI Act at all. This matters because the regulation covers a broad range of software, from recommendation engines to autonomous decision-making tools, and the boundary between conventional software and regulated AI is not always obvious (European Commission, 2026).
Who signed the Code of Practice on AI-generated content?
More than 180 organizations signed the Code of Practice on transparency of AI-generated content, a voluntary framework published by the European Commission in July 2026 (European Commission, 2026). The Code operationalises the transparency rules by providing practical guidance on disclosure, labelling, and machine-readable marking. It also introduced a set of standardised icons that creators, publishers, and deployers can use to disclose the artificial nature of images, audio, deepfakes, and text.
The Code is not legally binding, but signing it signals good faith compliance. The Commission published a separate opinion assessing the Code's effectiveness, and it released guidelines on transparency obligations for providers and deployers of certain AI systems in July 2026 (European Commission, 2026). Together, these documents form the practical playbook for companies trying to meet today's deadline.
The voluntary nature of the Code raises questions about coverage. Not every AI provider operating in the EU has signed, and the Commission has no direct mechanism to compel participation. However, the Code serves as a safe harbour: companies that follow its guidance can demonstrate compliance more easily if regulators come asking. The 180 signatories include major technology firms, media companies, and AI startups, creating a broad baseline of voluntary adherence.
What are the penalties for non-compliance?
The AI Office can impose fines of up to 35 million euros or 7% of a company's total worldwide annual turnover, whichever is higher, for the most serious violations (European Commission, 2024). Those maximum penalties apply to prohibited AI practices, such as deploying banned social scoring systems. For less severe breaches, including transparency failures, fines can reach 15 million euros or 3% of annual turnover.
Enforcement is shared between the AI Office in Brussels and national authorities in each member state. The Commission has also launched an AI Act complaints tool and a whistleblower channel to make it easier for individuals and organizations to report non-compliance (European Commission, 2026). The enforcement infrastructure is now in place, and companies operating in the EU market face real financial consequences for ignoring the rules.
For context, GDPR fines reached billions of euros in their first years of enforcement, with Meta receiving a 1.2 billion euro penalty in 2023 alone (European Data Protection Board, 2023). The AI Act's penalty structure is calibrated similarly, signalling that the EU intends to enforce with the same ambition it brought to data privacy. The first test cases under the transparency rules will set the tone for the years ahead.
How did we get to August 2026?
The AI Act entered into force on 1 August 2024, giving companies and governments a phased runway to comply (European Commission, 2024). Prohibitions on the most dangerous AI practices, including social scoring and manipulative AI, took effect on 2 February 2025. The governance rules and obligations for general-purpose AI models followed on 2 August 2025.
Today brings the transparency tier, the third major milestone. The AI Omnibus, which entered into force on 27 July 2026, pushed the high-risk system deadlines further out, simplifying the timeline for businesses. A ninth prohibition, targeting AI systems that generate non-consensual sexually explicit content or child sexual abuse material, arrives in December 2026 (European Commission, 2026). The full compliance picture will not be clear until at least 2028.
How does the EU approach compare to other countries?
The AI Act is the first binding international framework for AI with real enforcement power. The United States has no comprehensive federal AI law; instead, it relies on voluntary industry commitments, executive orders, and sector-specific guidance from agencies like the FTC and FDA (Carnegie Endowment, 2025). China has enacted targeted regulations for deepfakes, recommendation algorithms, and generative AI, but they are narrower in scope and do not constitute a unified risk-based framework.
The EU's first-mover position gives it outsized influence, much as GDPR shaped global data privacy norms. Companies that build AI for the European market of roughly 450 million people will likely adopt the EU's transparency standards as their default worldwide, rather than maintaining separate compliance regimes. The question is whether enforcement keeps pace with the law's ambition.
Other regions are watching closely. The UK has pursued a sector-specific, principles-based approach through existing regulators rather than enacting a standalone AI law. Japan and South Korea have focused on voluntary guidelines and industry standards. Brazil and India are drafting AI governance frameworks, but none have enacted binding legislation with the scope and enforcement teeth of the AI Act. The EU regulation is, for now, the global benchmark.
What does this mean for AI companies and users?
For companies, the immediate task is straightforward: make sure every chatbot, virtual assistant, and interactive AI system discloses its nature to users. Apply visible labels to deepfakes and embed machine-readable metadata in AI-generated content. The Code of Practice offers a compliance shortcut, and the 180 signatories have already demonstrated that the technical requirements are achievable.
For users, the change is tangible. When you open a chatbot, you will see a clear notice that you are talking to AI, not a person. When you see an AI-generated image or video, it will carry a label. The era of indistinguishable synthetic content without disclosure is, at least in the EU, coming to an end. Whether the rest of the world follows remains an open question.
What comes next after transparency?
Transparency is the starting point, not the finish line. The high-risk rules arriving in December 2027 will impose far heavier obligations: mandatory risk assessments, human oversight requirements, detailed technical documentation, and logging of AI activity for traceability (European Commission, 2026). Companies building AI for hiring, education, healthcare, law enforcement, and migration will face a compliance burden that dwarfs today's disclosure requirements.
The AI Office is also developing standards for evaluating advanced AI models, with a cybersecurity and AI action plan launched in July 2026. Third-party assessment of AI capabilities and risks is expected to be operational by 2027. Europe is building the regulatory infrastructure in real time, and today's transparency rules are the first test of whether the system works.
The broader trajectory is clear: AI regulation is tightening globally, and the EU is setting the pace. Whether other jurisdictions adopt similar frameworks or take a lighter touch, companies building AI systems must now account for the strictest rules they face. For the AI industry, August 2026 is not the end of a compliance exercise. It is the beginning of a new operating environment.
Why you should never trust an AI answer without checking it first
The best AI models of 2026, ranked by real users
AI slop is eating the web. Platforms are fighting back
The dead internet proof: bots outnumber us now
Open-source AI and the locally-first movement
Sources and further reading
- European Commission — AI Act official page
- European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August
- European Commission — Guidelines on transparency obligations for providers and deployers of AI systems
- European Commission — Code of Practice on transparency of AI-generated content
- European Commission — Enforcement of the AI Act
- EUR-Lex — Regulation (EU) 2024/1689, the AI Act
- Carnegie Endowment for International Peace — The global AI governance landscape
Bottom line
The broader trajectory is clear: AI regulation is tightening globally, and the EU is setting the pace. Whether other jurisdictions adopt similar frameworks or take a lighter touch, companies building AI systems must now account for the strictest rules they face. For the AI industry, August 2026 is not the end of a compliance exercise. It is the beginning of a new operating environment.
What we still don't know
This is a fast-moving story. We update the post as new facts land — and we'll flag it when we do.
Enjoyed this? Pay it forward
Five people forward this newsletter before they finish their coffee. Make it six.