The European Commission’s AI Office and national market surveillance authorities began enforcing Article 50 of the EU AI Act on Aug. 2, 2026, with maximum penalties set at €15 million or 3% of worldwide annual turnover, whichever is higher. The fines are calibrated to global revenue, not European revenue, which places every generative AI deployer with EU exposure inside the same enforcement perimeter as the platforms the law was ostensibly designed to constrain.

The obligations are concrete. Chatbots must identify themselves as AI. Deepfakes must be labeled. Synthetic content requires machine-readable marks, with a Dec. 2, 2026 deadline for systems already on the market. Emotion-recognition and biometric deployers must notify subjects. GPAI providers must publish a copyright policy and a training data summary. The AI Office supervises GPAI, national authorities handle transparency, and the European Data Protection Supervisor covers EU institutions themselves.

Voluntary scaffolding surrounds the hard rules. More than 180 organisations have joined a code of practice on transparency compliance, and the Commission published three optional icons distinguishing AI-involved, fully AI-generated, and human-made-with-AI-modifications content. Use is voluntary. Whether anyone reads them is a separate question.

Two structural weaknesses are already visible. Regulator capacity varies sharply across the 27 member states, and disclosures attached at creation can be stripped the moment content is edited or reposted, per Tech Policy Press. The AI Omnibus has meanwhile pushed high-risk system rules to Dec. 2, 2027 and high-risk AI in regulated products to Aug. 2, 2028. New prohibitions on AI-generated non-consensual sexual content and CSAM take effect Dec. 2, 2026.

Brussels has learned from GDPR’s slow first act. This time the fines start on day one; the harder parts are what got postponed.

Sources

Sources