The EU AI Act’s Transparency Rules Are Now Law. Most Companies Aren’t Ready |

0
1
The EU AI Act’s Transparency Rules Are Now Law. Most Companies Aren’t Ready |


No More Warnings: The EU AI Act Has Teeth Starting Now

As of August 2, any chatbot operating in the European Union has a new legal obligation: telling users they’re talking to a machine. The European Commission’s AI Office, working with national market surveillance authorities, began enforcing the transparency provisions of the EU AI Act this week, and the rules apply immediately, with no grace period for systems already on the market.

Under Article 50 of the Act, companies deploying interactive AI systems, generative content tools, or emotion recognition and biometric categorization software now face four concrete obligations. Chatbots and other conversational AI must disclose that users are interacting with a machine rather than a person. Deepfakes, meaning images, video, or audio edited or generated by AI, must carry a label. AI-generated or altered content must include a machine-readable mark so platforms and regulators can detect it. And anyone publishing AI-generated text on matters of public interest must disclose that origin.

The Commission drew a narrow distinction on timing. Generative systems already on the market before August 2 have until December 2, 2026, to implement the machine-readable marking requirement specifically. Every other obligation, including the requirement that chatbots identify themselves as AI, took effect immediately and covers systems regardless of when they were built or deployed.

Penalties Scale With Company Size

Non-compliance carries real financial exposure. The Act sets penalties at up to €15 million or 3% of a company’s global annual turnover, whichever is higher. EU institutions and agencies face a lower cap of €750,000. The regulation does build in proportionality for small and medium-sized enterprises, so a startup and a multinational platform won’t face identical exposure for the same violation, but the ceiling is high enough to force board-level attention at any company with EU users.

Enforcement runs through three bodies: national market surveillance authorities handle most cases, the European AI Office oversees systems under its direct supervision, and the European Data Protection Supervisor steps in when an EU institution is the AI provider or deployer. More than 180 organizations have already signed the EU’s Code of Practice on transparency of AI-generated content, a voluntary framework the Commission designed to give companies a documented path to compliance ahead of enforcement.

Why This Is Different From Past AI Regulation

Most technology regulation arrives with lengthy phase-in periods and soft enforcement in year one. This didn’t. The Commission’s own announcement frames August 2 as the start of active enforcement, not a symbolic milestone, and the absence of a blanket grace period for existing systems is the detail most compliance teams appear to have underestimated. A chatbot deployed in 2024 is just as exposed as one launched last week.

The practical burden falls hardest on companies using AI in customer-facing roles without having built disclosure into the product. Retrofitting a “you are speaking with an AI assistant” notice into an existing support bot is straightforward. Building a reliable machine-readable watermarking pipeline for AI-generated images, video, or text at scale is not, which is likely why the Commission carved out the extended deadline specifically for that requirement.

For companies operating across multiple jurisdictions, the AI Act now joins GDPR as a second EU compliance regime that assumes global reach. A US company with European customers doesn’t get to treat this as a regional problem. The realistic path forward is treating AI disclosure the way many companies already treat cookie consent: a baseline, not a feature, built into every AI-facing product by default rather than patched in after a complaint.

The companies that treated this deadline as a formality now have a compliance gap with an active enforcement mechanism behind it. The ones that built disclosure in early just gained a quiet competitive advantage: they can say, accurately, that they were ready before the rules had teeth.