The European Commission's AI Office and national regulators across the bloc began enforcing a new set of transparency obligations under the EU's AI Act on Aug. 2, marking the law's most consequential deadline yet for companies operating AI systems that interact directly with people.
Under Article 50 of the law, chatbots and other interactive AI systems must now tell users they are dealing with artificial intelligence rather than a human. Deepfakes — images, audio or video that have been synthetically generated or manipulated to depict real people, places or events — must be labeled as such, and AI-generated or altered content more broadly must carry machine-readable marks so platforms and tools can detect it automatically. The Commission said the goal is to reduce "deception and manipulation" and help people "make informed choices," according to its official announcement. Content created before Aug. 2 does not need retroactive labeling, and tools already on the market before that date have until December to add machine-readable marking. More than 180 companies and organizations have signed the Commission's voluntary Code of Practice on the topic ahead of enforcement.
High-risk rules pushed back
Separately, and in the opposite direction, the Commission has given companies more time to comply with the law's toughest requirements. Under a Digital Omnibus agreement struck by the Council of the EU and the European Parliament in May, compliance deadlines for stand-alone "high-risk" AI systems — including tools used in recruitment, credit scoring, education, law enforcement, border control and critical infrastructure — have been pushed from August 2026 to Dec. 2, 2027. AI embedded in products that already go through separate safety regulation, such as medical devices or machinery, now has until Aug. 2, 2028.
The law also picked up a new prohibition. Lawmakers reached a political deal in March adding a ban, effective Dec. 2, 2026, on AI systems designed to generate non-consensual intimate imagery — so-called "nudifier" apps — alongside child sexual abuse material, regardless of whether the output comes from a dedicated app or a general-purpose image generator. The addition followed a wave of AI-enabled harms, including the uproar in December 2025 over X's Grok chatbot being used to produce sexualized deepfakes of real people without consent.
Penalties for noncompliance with the AI Act can reach €15 million or 3% of a company's global annual revenue, whichever is higher, with lower caps for small businesses, and the rules apply to any company serving users in the EU regardless of where it is based.
Mixed reaction
Digital rights groups have offered a mixed verdict on where the law now stands. European Digital Rights and allied civil society organizations have argued that implementation has been marked by delays, thin consultation and heavy industry lobbying, and that the law's carve-outs for law enforcement and migration authorities leave gaps even as new obligations take effect. Industry groups have broadly welcomed the delayed high-risk timeline as recognition that the technical standards underpinning compliance were not ready. Both the transparency rules and the delayed high-risk deadlines apply regardless of where a company is headquartered, meaning U.S. AI providers serving European users must comply on the same schedule as EU-based firms.