Technology · AI regulation
EU AI Act enforcement powers take effect with new transparency rules
From 2 August the European Commission can investigate and fine AI providers directly, while labelling obligations for generated content and deepfakes become mandatory across the bloc.
The European Union's most ambitious attempt to govern artificial intelligence moved from paper to practice on Sunday, 2 August, when the core enforcement provisions of the AI Act became applicable. The European Commission now holds direct authority to investigate providers of general-purpose AI models, demand access to their systems, and impose fines that can reach 7% of global annual turnover for the most serious breaches. For an industry accustomed to voluntary codes and fragmented national oversight, the shift is abrupt.
Commission gains teeth through the AI Office
Until this week the Commission's role was largely supervisory. The AI Office, created inside the Commission to oversee implementation, can now open formal investigations, order companies to produce documentation, and in certain cases examine a model before it enters the European market. If a provider refuses to cooperate or supplies misleading information, the Office can levy penalties. The power to restrict or withdraw a model from the market entirely gives Brussels a lever it has never possessed over a technology developed overwhelmingly outside the EU.
National regulators retain responsibility for the bulk of AI systems, specialised or smaller-scale applications used in recruitment, credit scoring, or local government. But the most capable general-purpose models, which the legislation classifies as posing "systemic risk", fall squarely under the Commission's gaze. That distinction matters because the companies building those models, Anthropic, OpenAI, Google DeepMind, Meta, are almost all American. The AI Office's new powers are, in effect, the EU's first structural tool for inspecting foreign frontier systems before they reach European users.
Transparency rules target deepfakes and synthetic text
Alongside enforcement, a suite of transparency obligations took effect. Providers and deployers of AI systems that generate or manipulate images, audio, video or text must now ensure the output carries electronically detectable markings. Publishers of deepfakes, highly realistic synthetic media, are required to disclose that the material has been altered or artificially created. The rule applies whether the content is political satire, a marketing campaign, or a fabricated news clip.
Text generated to inform the public on matters of public interest must also be labelled, unless it has undergone human editorial review and a legal or natural person accepts responsibility for it. That exemption is designed to protect newsrooms using AI-assisted drafting, but it places the onus on publishers to demonstrate editorial control. Artistic, satirical and fictional works benefit from lighter labelling requirements so that creative expression is not unduly disrupted.
Systems already placed on the EU market before 2 August have a transition period until 2 December to meet the technical marking and detection standards. After that date, non-compliant systems can be ordered off the market. The Commission has signalled it will monitor compliance closely during the transition, particularly for widely deployed consumer-facing tools.
General-purpose models face documentation and copyright duties
Providers of general-purpose AI models, the large language and multimodal systems that power chatbots, coding assistants and content generators, must maintain technical documentation, publish summaries of training data, and establish policies to comply with EU copyright law. The copyright requirement is notable: it obliges providers to respect opt-outs expressed by rights-holders under the 2019 Copyright Directive, a provision that has already prompted litigation in several member states.
Models deemed to pose systemic risk, a threshold defined by compute used in training, capabilities benchmarks, and the Commission's own assessment, face additional duties. These include safety assessments, cybersecurity hardening, incident reporting, and mitigation measures for identified harms. The Commission publishes and updates the list of systemic-risk models, giving it a dynamic regulatory lever as capabilities advance.
Biometric surveillance and manipulation banned
The Act's prohibitions, in force since February 2025, are now backed by the full enforcement machinery. Indiscriminate scraping of facial images to build recognition databases is forbidden. Real-time remote biometric identification in public spaces is permitted only for law enforcement under tightly defined circumstances, such as searching for specific victims of abduction or preventing an imminent terrorist threat, and requires judicial or independent administrative authorisation. The narrowness of the exceptions reflects years of negotiation between member states wary of security carve-outs and MEPs determined to prevent mass surveillance.
AI systems that use subliminal or deliberately deceptive techniques to manipulate behaviour in ways likely to cause significant harm are also prohibited. So are systems that exploit vulnerabilities linked to age, disability, or socio-economic circumstance. These bans target practices such as addictive design in children's apps or targeted persuasion of financially vulnerable users, areas where the line between persuasion and exploitation has been fiercely contested.
Penalty regime calibrated for scale
The fine structure mirrors the GDPR model but with higher ceilings. Prohibited practices attract fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Breaches of other obligations, transparency, documentation, data governance, carry a maximum of €15 million or 3% of turnover. Supplying inaccurate information to regulators, refusing access, or failing to cooperate can also be penalised. Small and medium-sized enterprises face proportionate penalties based on size and financial circumstances, a concession negotiated to avoid choking off European AI start-ups.
The Commission has indicated it will publish guidance on how it calculates turnover for corporate groups with complex structures, a point of contention during the GDPR's early years. Until that guidance arrives, legal teams at major AI labs are modelling exposure scenarios that run into hundreds of millions of euros.
A phased timetable stretching to 2028
Sunday's milestone is the second of four major implementation dates. Obligations for high-risk AI systems used in healthcare, employment, education, migration, and security take effect in December 2027. Rules covering AI embedded in regulated products, medical devices, machinery, toys, lifts, follow in August 2028. The staggered approach reflects the complexity of conformance assessments for physical products, which often require notified bodies and type examinations that do not exist for pure software.
The Commission also plans to propose a ban on systems designed to create non-consensual sexually explicit images, including so-called nudification tools. That measure, not yet tabled, would extend the Act's prohibitions into a domain where open-source models have already enabled widespread abuse.
International friction already visible
The Act's extraterritorial reach, it applies to any provider placing a model on the EU market or putting it into service in the EU, regardless of establishment, has drawn criticism from Washington and industry groups. The US-EU Trade and Technology Council has discussed alignment on AI governance, but the American approach remains voluntary and sectoral. Anthropic's Mythos models, cited in Commission briefings as an example of non-EU systems now subject to pre-market scrutiny, illustrate the tension: a US company with no European subsidiary must still open its model to the AI Office if it wants European users.
Some US firms have responded by releasing "EU-compliant" variants with additional guardrails and documentation, while others have delayed European launches. The Commission argues this is evidence the regime works: it forces a safety baseline without banning the technology. Critics counter that it fragments the global market and advantages incumbents with the legal resources to navigate compliance.
Sources
Organisations
European Commission · AI Office · Anthropic