New high Policy
The EU started enforcing the AI Act on 2 August. Here is what actually changed.
Transparency obligations are now live, the AI Office has direct powers over general-purpose models, and fines reach €15 million or 3% of global turnover. The high-risk rules, meanwhile, have slipped to 2027.
The European Commission confirmed on 31 July that from 2 August 2026 its AI Office, working with national authorities, would begin enforcing the Artificial Intelligence Act. The same date switched on a set of transparency obligations that change what users of AI systems in the EU must be told.
After two years of consultation, codes of practice and lobbying, this is the point at which the AI Act stops being a compliance roadmap and becomes something a regulator can act on.
The transparency rules, in plain terms
According to the Commission's announcement, three obligations now apply:
- Chatbots and other interactive AI systems must tell users they are dealing with AI, not a human.
- Deepfakes — images, video or audio generated or edited using AI — must be labelled.
- AI-generated or altered content must carry machine-readable marks so it can be detected automatically.
The Commission frames the measures as reducing "deception and manipulation" while giving businesses "clearer obligations and a practical way to show compliance." Alongside enforcement it published a first list of more than 180 organisations that have signed the Code of Practice on transparency of AI-generated content, the instrument that operationalises these rules.
Who enforces, and what it costs
The AI Office handles general-purpose AI models directly. Reporting on the enforcement regime describes powers to request technical documentation, run evaluations, demand corrective steps and issue fines. Penalties for ignoring the obligations reach €15 million or 3% of worldwide annual turnover, whichever is higher.
The Commission has also stood up the machinery that turns rules into cases: an AI Act complaints tool, a whistleblower tool, and a dedicated complaints channel for downstream providers building on general-purpose models. That last one is worth watching. It gives companies that integrate a foundation model a formal route to escalate against their supplier — a very different dynamic from the usual enterprise procurement conversation.
From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence Act.
The part that slipped
What is not now enforceable matters as much as what is. The AI Omnibus, a package of amendments to the Act, pushed the rules for high-risk AI systems back to 2 December 2027, and those for high-risk systems embedded in regulated products to 2 August 2028. A separate prohibition — on AI systems generating non-consensual sexually explicit material or child sexual abuse material — takes effect on 2 December 2026.
So the sequencing is: disclosure first, then, more than a year later, the substantive obligations on systems used in hiring, credit, education, law enforcement and critical infrastructure. Providers building high-risk systems now have breathing room they did not have twelve months ago. Whether that is pragmatic phasing or a weakening of the regime is the argument that will run through 2027.
What security and AI teams should do
For organisations deploying AI in or into the EU, the immediate work is inventory rather than architecture:
- Identify every user-facing AI interaction and confirm the AI disclosure is present, visible and not buried in a settings page.
- Determine whether your generation pipelines emit machine-readable provenance marks, and whether they survive your own downstream processing — resizing, re-encoding and CDN transforms strip metadata routinely.
- Check whether your model provider has signed the Code of Practice, and what its published transparency documentation actually commits it to.
- Map which of your systems will fall under the high-risk classification in December 2027, and treat the delay as schedule, not reprieve.
One structural note for security teams specifically: the machine-readable marking requirement creates a detection surface that did not exist before. If compliant generators mark their output and the marks survive, provenance becomes a signal defenders can query. If they do not survive contact with ordinary web infrastructure, the requirement produces paperwork and little else. Which of those two futures arrives will be visible within a year.
Sources
- European Commission. Commission starts enforcing AI Act rules and new transparency requirements on 2 August, 31 July 2026
- European Commission. Press release IP/26/1714
- European Commission. Enforcement of the AI Act
- Help Net Security. EU begins enforcing AI Act, putting AI models under the microscope
- Cooley. EU AI Act: Transparency obligations take effect 2 August 2026
- Euronews. EU rules on AI models become enforceable. What's going to change?
Disclosure. AI Perimeter takes no advertising and no sponsored content. Nobody outside the newsroom saw this article before publication, and no company paid, directly or indirectly, for it to exist. We are funded entirely by reader subscriptions. See our editorial standards.