Skip to main content

EU AI Act Enforcement Goes Live: Chatbots Must Identify Themselves, Deepfakes Must Be Labelled

Ilustrační obrázek
From today, 2 August 2026, the EU AI Office and national authorities begin actively enforcing the AI Act. Chatbots must tell users they are machines. Deepfakes must be labelled. AI-generated content must carry machine-readable watermarks. Companies that fail to comply face fines of up to €35 million or 7 % of global annual turnover — whichever is higher. Over 190 organisations — from OpenAI and Meta to Lufthansa and Bulgari — have already signed the Commission's Code of Practice on transparency. Here is what actually changes, who it affects, and how much non-compliance could cost.

What starts being enforced today

The AI Act has been on the books since 2024, but 2 August 2026 is the date its enforcement teeth actually grow in. Three categories of rules become enforceable today, according to the Commission's press release from 31 July:

1. Prohibited AI practices. The Act bans systems that manipulate people, exploit vulnerabilities, perform social scoring in ways that threaten rights, or conduct predictive policing based solely on profiling. These are the "unacceptable risk" practices — think Black Mirror, not a spam filter.

2. GPAI model obligations. Providers of general-purpose AI models — the foundation models everyone builds chatbots and copilots on top of — must now follow transparency rules, respect copyright, and, for the most advanced models, implement safety measures against systemic risks including chemical and biological incidents, cyber offences, and large-scale manipulation.

3. Transparency requirements for AI systems. This is the part most users will actually notice. Chatbots and interactive AI must inform people they are talking to a machine. Deepfakes — artificial images, video, or audio — must be clearly labelled. AI-generated content must embed machine-readable marks so detection tools can identify it. These are the rules that operationalise Article 50 of the AI Act.

The enforcement is split three ways: the AI Office handles general-purpose AI models and AI systems integrated into very large platforms; national market surveillance authorities handle everything else; and the European Data Protection Supervisor covers EU institutions that deploy AI. Twenty-seven member states, three layers of oversight. In theory, there is no regulatory gap. In practice — well, that is what we are about to find out.

The Code of Practice: 190 organisations sign up

Alongside the enforcement start, the Commission published a list of signatories to its Code of Practice on Transparency of AI-generated Content. The code was drafted by independent experts and endorsed by both the Commission and the AI Board. It gives providers and deployers of generative AI a streamlined path to demonstrate compliance.

The numbers are significant: 83 organisations signed Section 1 (targeting providers of AI systems), and 152 signed Section 2 (targeting deployers). About half of the signatories are small or young companies — a sign that even startups want regulatory clarity rather than uncertainty.

The Section 1 list reads like a who's-who of the AI industry: OpenAI, Google, Meta, Microsoft, Anthropic, Mistral, Cohere, Aleph Alpha, Black Forest Labs, Synthesia — all on board. Section 2 includes names you would not immediately associate with AI development: Bulgari, Lufthansa, Getty Images, Lenovo, Iberdrola, Fastweb. These are companies deploying AI in production — customer service, content moderation, travel operations — and they are betting that signing the code is cheaper than fighting compliance battles later.

Signing is voluntary, but the practical alternative is proving compliance through "equivalently adequate means" — a phrase that, in EU regulatory language, usually translates to "hire more lawyers." The code also opens the door to two task forces launching in September 2026, where signatories can shape best practices and give feedback on implementation.

What the fines actually look like

This is where the numbers get serious. The AI Act's penalty structure is tiered:

Violation Max fine % of global turnover
Prohibited AI practices €35 million 7 %
GPAI model obligations €15 million 3 %
Incorrect/incomplete RFI response (AI systems) €7.5 million 1 %

For context: 7 % of global turnover for a company like Google (2025 revenue ~$350 billion) works out to roughly $24.5 billion. For Microsoft (~$260 billion), about $18.2 billion. Even the lower 3 % tier for GPAI violations hits nine figures for any large tech company. These are not parking tickets. They are deliberately scaled to make the largest players care — in the same way the GDPR's 4 % penalty forced every company on the planet to install a cookie banner.

Compare this to the Digital Services Act, which carries fines of up to 6 % of global turnover, or the Digital Markets Act at up to 10 %. The AI Act sits in the middle of the EU's regulatory penalty range — serious, but not the most extreme on the books.

What this means for developers and businesses in the EU

If you run a SaaS product that wraps an LLM API — say, a customer support bot or an AI writing assistant — the transparency obligation is straightforward but non-optional: your users must know they are interacting with AI. That means a clear notice in the UI, not buried in terms of service nobody reads.

If you generate images, video, or audio with AI and publish them, you need machine-readable metadata embedded in the output. The major providers are already moving on this: Google's SynthID, Adobe's Content Credentials (C2PA), and Microsoft's provenance tools all predate this enforcement date. The AI Act makes them mandatory rather than optional.

For European AI startups, there is a silver lining. The Code of Practice was explicitly designed with SMEs in mind — the framework acknowledges that a 5-person startup in Prague cannot deploy the same compliance machinery as OpenAI. Half the signatories being small companies suggests the burden is manageable. Whether that holds true when national authorities start issuing their first RFIs is another question.

From where I sit — running production AI services on our own servers in the Czech Republic — the immediate takeaway is that transparency labelling is not technically difficult. Embedding a content credential or adding a "generated by AI" badge takes an afternoon of engineering. The real headache will be the GPAI obligations for anyone training foundation models in Europe, and we will not see how that plays out until the first major enforcement action lands.

What is NOT enforced yet

The timeline is staggered. Today's enforcement covers the first wave. What is still coming:

  • 2 December 2026: Prohibitions on generating or manipulating non-consensual intimate material and CSAM using AI — these got a later start date via the AI Omnibus amendment.
  • 2 December 2027: Rules for high-risk AI systems listed in Annex III (education, employment, law enforcement, migration, critical infrastructure — the full list).
  • 2 August 2028: Rules for high-risk AI systems embedded in regulated products (medical devices, machinery, toys).

So if your AI system falls into the high-risk bucket — say, an AI-powered recruitment screening tool or a medical imaging classifier — you have until December 2027 to get compliant. Today's enforcement is the opening act, not the finale. The Commission has also launched a suite of enforcement tools: an AI Act Complaint Tool, a Whistleblower Tool, and a dedicated channel for downstream providers who run into issues with GPAI model suppliers.

Does this affect me if I just use ChatGPT or Gemini as a consumer?

Indirectly, yes. The transparency rules mean these services must now clearly indicate when you are chatting with an AI — but you were probably already aware of that. The more visible change will be in content you consume elsewhere: AI-generated articles, deepfake videos, and synthetic audio must be labelled. If you publish AI-generated content yourself (e.g. on social media or a company blog), that labelling obligation applies to you as a deployer.

What happens if a US-based AI company ignores the EU rules?

The AI Act applies extraterritorially — any company whose AI output reaches users in the EU is covered. The AI Office can issue requests for information and, if necessary, impose fines. Collecting those fines from a non-EU entity is a practical challenge, but the GDPR has shown that large companies with EU revenue typically comply rather than risk market access disruption.

How do I check if my AI system is "high-risk"?

Start with Annex III of the AI Act, which lists high-risk categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and democratic processes. If your system falls into one of these areas, the compliance deadline is December 2027 — but you should start auditing now. If your system is embedded in a regulated product (medical device, machinery, toy), the deadline extends to August 2028.

X

Don't miss out!

Subscribe for the latest news and updates.