On August 2, 2026, the European Commission’s AI Office began enforcing Article 50 of the AI Act, the transparency layer that requires chatbots to identify themselves as machines and AI-generated content to carry machine-readable marks. The headline is enforcement; the subtext is sequencing. Brussels chose to switch on the visible, consumer-facing rules first while quietly conceding ground on the parts industry cared about most.

Non-compliance now carries fines up to €15 million or 3% of global annual turnover for companies, and €750,000 for EU institutions. Providers have to embed technical traces in generated content. Deployers have to display clear labels and disclose any use of emotion recognition or biometric categorization. Systems already on the market get a grace period until December 2, 2026 to add machine-readable marking. Pre-existing deepfakes aren’t retroactively covered, and personal group chats and “evidently artistic” satirical or fictional works are exempt.

The Commission also published three optional icons, covering AI-assisted, fully AI-generated, and human-with-AI-edits content. Use is voluntary, which is its own signal.

The larger news is what didn’t happen. The AI Omnibus, adopted November 19, 2025 and in force since July 27, 2026, pushed the Annex III high-risk use cases to December 2, 2027, a 15-month slip. Annex I high-risk systems embedded in regulated products keep their August 2, 2028 deadline. GPAI model obligations, applicable since August 2, 2025, are now fully enforceable, with the Commission empowered to request documentation, order corrective measures, and impose fines.

So Brussels ships the labels and postpones the rulebook that actually reorders product roadmaps. The pattern rhymes with GDPR’s early years: visible obligations first, structural ones deferred until the lobbying settles.

Sources

Sources