EU AI Act / Article 50
What AI writes can no longer be shipped in silence.
The EU AI Act's transparency duties — labeling AI-generated content, disclosing chatbot use — became applicable on August 2, 2026. The "next month" warnings that outlets ran back in July are over; this is now a live enforcement phase. Any company shipping generative-AI features into the EU needs to check this week whether labeling and audit trails are actually in place.
The "next month" warning just
became the present tense
The EU AI Act has moved through three phases since it entered into force in August 2024 — this is the fourth.
The EU's Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024, and has widened its scope in stages ever since. The prohibited-practice rules became applicable in February 2025; obligations for general-purpose AI (GPAI) model providers and the full operation of the AI Office followed in August 2025; and now, on August 2, 2026, the transparency obligations under Article 50 and most of the high-risk system obligations under Annex III have finally become applicable. Through July, most coverage still framed this as a "next month" warning. Now that August has arrived, it is a live enforcement phase.
On August 1 the European Commission published a revised operational guidance for Article 50 and announced that an enforcement support team for the 27 member states' market surveillance authorities has begun operating. According to an AI Office official, the first weeks will focus less on punishing egregious violations than on rolling checks of whether labeling has actually been implemented at all.
Article 50 imposes four main duties: (1) providers of AI systems that generate synthetic audio, image, video, or text must mark that output in a machine-readable format so it is detectable as AI-generated; (2) providers of chatbots must inform users they are interacting with an AI system, unless that is already obvious; (3) deployers of systems that generate or manipulate deepfakes must disclose that the content is artificially generated or manipulated; and (4) deployers publishing AI-generated text on matters of public interest must disclose that fact, unless the text has undergone human editorial review under an accountable editor.
Obligations scale with
how risky a system is
The AI Act sorts systems into four risk tiers, each carrying different obligations. What went into full effect on August 2 is mainly the transparency duties in the "limited risk" tier and most obligations for "high-risk" systems. The "unacceptable risk" prohibitions — subliminal manipulation, indiscriminate facial-recognition database scraping, and the like — were already applicable from February 2025 and are not new this time.
| Tier | When it applies / what it covers |
|---|---|
| Unacceptable risk | Banned since Feb 2025 (subliminal manipulation, etc.) |
| High-risk (Annex III) | Most obligations applicable from Aug 2, 2026 |
| Limited risk (transparency) | Labeling/disclosure duties from Aug 2, 2026 |
| Minimal risk | No legal duty, voluntary codes of conduct only |
Three years of phase-in,
since the Act took force
The rollout keeps adding obligations through August 2027.
The last milestone lands on August 2, 2027, when obligations kick in for high-risk AI embedded in products already covered by other EU product-safety law — medical devices, machinery, and the like (Annex I). In other words, this August 2 is not the finish line; it is the midpoint of a three-year rollout.
What a violation costs
Every tier is capped at whichever is higher — a flat euro figure or a share of global turnover — with a lower ceiling for SMEs and startups. The Commission's own explainer frames enforcement as staged correction rather than instant punishment.
Not "starting next month" anymore —
it starts this week.
Why this round is different
August 2025's rollout mainly targeted the labs that build and ship GPAI models themselves — a scope you could sum up as "a few dozen companies need to respond." This round is different. The transparency duties reach both providers of AI systems that generate synthetic content and the deployers who build products on top of them. That means a company that never trained a model of its own — one that simply wired OpenAI's or Anthropic's API into an image, voice, or chat feature shipped into the EU — is now a party to the obligation too. That the pool of affected companies has widened sharply is the biggest reason this round is different from what came before.
Who it hits, and how
If you ship generative-AI features into the EU, this is not someone else's problem.
Business / executives
If you ship a chatbot or image/voice generation into the EU, unimplemented labeling is a direct line to a penalty of up to €15 million or 3% of global turnover. Japanese-HQ SaaS and gaming companies serving the same feature set into the EU region are more exposed than they might assume.
PM / product owners
Add "disclose it's AI-generated" and "disclose it's a chatbot" as requirements, and work out this week exactly which UI copy goes where. It touches UX, so it needs to become tickets with real priority, not a footnote.
Engineers
Check whether watermarking or metadata embedding (content-provenance techniques) is implemented on output, and whether disclosure events are logged. The real question is whether your existing logging stack can already answer "when, which feature, and for which user was AI-generated content shown."
What to do this week
Inventory in-scope features
List every EU-facing feature that involves synthetic content generation, a chatbot, or emotion/biometric categorization.
Implement labeling and disclosure copy
Add both a machine-readable mark on the output and human-facing disclosure text in the UI ("This was generated by AI," etc.).
Keep an audit trail
Retain logs that can trace who, when, and through which feature AI-generated content was shown, so you can answer a regulator's inquiry.
Counter-view, risks, limits
Don't overreact either. The penalty regime under Article 99 has technically applied since August 2025, but a huge fine landing on day one for these newly-applicable provisions looks unlikely. Many member states' market surveillance authorities are still not fully staffed, and the working assumption is that warnings and corrective guidance will come first in practice. The exemption line is also blurry: text on matters of public interest is excused from disclosure "if it has undergone human editorial review under an accountable editor," but how far that covers an AI-drafted, human-edited article is something future guidance and case history will need to settle. Getting the scope right matters more than rushing to slap a label on everything.