--- headline: "The EU AI Act's Transparency Rules Are Now Being Enforced. Here's What Changed" slug: eu-ai-act-transparency-enforcement category: policy story_number: 15 date: 2026-08-10 ---

For the past two years, Europe's landmark Artificial Intelligence Act has mostly been a promise on paper — a phased rulebook whose hardest edges kept arriving somewhere over the horizon. As of 2 August 2026, the horizon is here. On that date the European Commission's AI Office, working alongside national market surveillance authorities, switched on active enforcement of the Act, and a new set of transparency obligations began to bite. The practical upshot for anyone building or deploying AI that touches the EU market: your chatbot now has to admit it is a chatbot, and your synthetic media has to say so out loud.

What actually changed on 2 August

The centerpiece is Article 50 of the Act, which imposes disclosure duties across four scenarios. Systems that interact directly with people — chatbots, voice assistants, AI agents, avatars — must tell users they are dealing with a machine and not a human, unless that is already obvious. Providers of systems that generate or manipulate synthetic images, audio, video, or text must embed machine-readable markings and offer a way to detect them. Deployers of emotion-recognition and biometric-categorization tools must notify the people subjected to them. And deepfakes, along with AI-generated text published on matters of public interest, must be labeled as artificial — unless the content passed through genuine human editorial review.

"As enforcement begins, we are taking an important step toward artificial intelligence that people and businesses can understand and trust, and whose benefits are widely shared throughout our society," said Henna Virkkunen, the Commission's executive vice-president for technological sovereignty, security and democracy.

To operationalize the marking rules, the Commission published guidelines on 20 July and a voluntary Code of Practice on the transparency of AI-generated content, complete with a standardized set of EU icons for labeling. More than 180 organizations, including several major AI providers, had signed the code by the enforcement date. Signatories get a degree of presumption of conformity and a friendlier enforcement posture; everyone else has to prove compliance the hard way.

The penalties, and a grace period

Breaching the transparency rules can trigger administrative fines of up to €15 million or 3% of a company's total worldwide annual turnover, whichever is higher — a lower tier than the headline €35 million-or-7% penalties the Act reserves for outright prohibited practices, but hardly trivial. EU institutions face fines up to €750,000, and the law instructs regulators to weigh proportionality for small and mid-cap firms.

The obligations apply immediately to in-scope systems regardless of when they hit the market, though content published before 2 August need not be retroactively labeled. One meaningful cushion remains: generative AI systems already on the market get until 2 December 2026 to implement the marking-and-detection requirement. Enforcement is shared among national authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor when EU bodies are involved.

What did not happen — and why it matters

Just as consequential is what was quietly pushed off. The Act's most demanding provisions — the "high-risk" obligations governing AI used in biometrics, employment, education, essential services, and migration and border control — had been slated to apply on the same 2 August date. In May, EU lawmakers agreed as part of the Digital Omnibus package to postpone them until 2 December 2027, on the grounds that the technical standards underpinning compliance were not ready.

Virkkunen framed the delay as an effort to "make it easier to innovate without lowering the bar on safety." The Commission tied it to its broader competitiveness push, echoing Mario Draghi's 2024 warning that Europe's regulatory load is throttling growth. Digital rights groups read it differently, arguing that reopening a freshly adopted law rewards industry lobbying and risks setting a precedent for further slippage. Critics note the delay leaves people subject to automated decisions at borders and in asylum processing without the Act's strongest safeguards for an additional 16 months. "No amount of safeguarding or guidelines can circumvent structural biases against migrants," said Stefi Richani, advocacy lead at the Equinox Initiative for Racial Justice.

The bigger regulatory bet

The transparency rules land at a moment of sharp transatlantic divergence. Washington has leaned toward deregulation and voluntary commitments; Brussels is doing the opposite, betting that binding disclosure obligations will become a global default through the same "Brussels effect" that made GDPR a worldwide privacy benchmark. Because firms tend to build one compliant product rather than maintain separate EU and non-EU versions, an AI-labeling standard set in Brussels may quietly become the standard everywhere.

Industry's core complaint is not the principle of transparency but the compliance overhead. As legal analysts at Cooley noted, the immediate burden for most companies is operational: inventorying where AI is already embedded across products, customer interactions, and third-party tools, then wiring in disclosure, labeling, and editorial-review procedures. The Act does not ban the technology or require pre-approval — it adds a layer. Whether that layer is a reasonable price for consumer trust or a drag on European AI development is precisely the argument the next 16 months will test.

What to watch

Three things. First, the December 2026 deadline for marking existing generative systems — the first real test of whether machine-readable watermarking works at scale. Second, the first enforcement actions: regulators now hold information-request, model-access, and recall powers, and how aggressively they use them will signal whether this is a paper regime or a real one. Third, the fate of the delayed high-risk rules in December 2027 — and whether "implementation adjustment" turns into a pattern of postponement, or holds the line.

Sources

- [Commission starts enforcing AI Act rules and new transparency requirements on 2 August — Shaping Europe's digital future](https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august) - [Press release: Commission starts enforcing AI Act rules — European Commission](https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714) - [Safer and more transparent AI — European Commission](https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en) - [EU AI Act: Transparency Obligations Take Effect 2 August 2026 — Cooley](https://www.cooley.com/news/insight/2026/2026-08-03-eu-ai-act-transparency-obligations-take-effect-2-august-2026) - [What came into force with the EU's AI Act this week – and what didn't — Al Jazeera](https://www.aljazeera.com/news/2026/8/6/what-came-into-force-with-the-eus-ai-act-this-week-and-what-didnt)

"As enforcement begins, we are taking an important step toward artificial intelligence that people and businesses can understand and trust, and whose benefits are widely shared throughout our society."
— Henna Virkkunen, Executive VP, European Commission
2 Aug 2026
Enforcement / Article 50 rules take effect
€15M or 3%
Max fine for transparency breaches
180+
Signatories to the voluntary Code of Practice
2 Dec 2027
New deadline for high-risk obligations