Europe's AI Act stopped being a rulebook on paper this month and became something regulators can actually enforce. From August 2, the European Commission's AI Office and national authorities gained the power to police a first tranche of the law, and the early focus is on transparency: telling people, plainly, when they are dealing with a machine.
What changed on the ground
The headline requirement is disclosure. Chatbots and other interactive systems now have to make clear that a user is talking to AI rather than a person. Synthetic media faces a parallel rule. Deepfakes and other AI-generated or AI-altered depictions of real people must be labelled, and systems that produce such content have to mark it in a machine-readable way. New products entering the EU market from August 2 need that marking from day one. Systems already on the market get until December 2 to comply.
The other half of the shift lands on the largest model builders. For providers of general-purpose AI, the models behind services like ChatGPT and Claude, the Commission's ability to penalize breaches of obligations that have applied since August 2025 is now live. So is a sharper enforcement toolkit: the AI Office can send formal information requests, demand access to a model, and in serious cases order a recall.
The penalties have teeth
Violations of the transparency duties and the general-purpose rules carry a maximum fine of the greater of 15 million euros or 3% of a company's total worldwide annual turnover. For the biggest firms, the percentage is the number that matters, and it is large enough to change behavior rather than get filed under the cost of doing business.
National regulators are already testing the machinery. In early August, France's data protection authority, the CNIL, sent formal information requests to 14 financial institutions running credit-scoring algorithms, asking for the technical documentation the law requires of higher-risk systems. It is a modest opening move, and a signal that the requests will keep coming.
A slower burn than the headlines suggest
Not everything arrives at once. Under a late-2025 revision, several of the toughest obligations on high-risk systems were pushed out to 2027 and 2028, so the full weight of the Act is still years from landing. What took effect this month is the part that touches ordinary users most directly. If you are in Europe and a bot does not tell you it is a bot, that is now a compliance problem for whoever deployed it.
The enforcement era arrives as the same companies fight over the rules elsewhere. Anthropic, for one, has been spending record sums on lobbying as it pushes back on export controls, a reminder that the regulatory map is being drawn in several places at once.
Commentarii · 0