On August 2, the European Commission’s AI Office and national market surveillance authorities began enforcing the AI Act, activating Article 50’s transparency obligations and, more consequentially, the Office’s formal investigative powers over general-purpose AI providers. Chatbots must now identify themselves as machines. Deepfakes must be labeled. Synthetic outputs must carry machine-readable watermarks, and AI-generated text on matters of public interest published without human editorial review has to be disclosed as such.

Non-compliance carries fines up to €15 million or 3% of worldwide annual turnover, whichever is higher. EU institutions face a lower ceiling of €750,000. SMEs get proportionality treatment.

The structural shift isn’t the rulebook, which has been public for months. It’s the enforcement posture. Until August 2, per Wilson Sonsini, the AI Office could only run “technical compliance dialogues” with GPAI providers, a polite fiction of oversight without teeth. It now holds corrective powers. The Office says dialogues remain its preferred first step but “may intensify,” language that reads as prosecutorial throat-clearing.

Brussels has also tried to smooth the landing. On July 20, the Commission adopted implementing guidelines and published a voluntary Code of Practice on Transparency; signatories receive a presumption of conformity, per Cooley. The AI Omnibus package grants legacy generative systems until December 2, 2026 to meet the machine-readable marking requirement, the sole Article 50 transition on offer. The same date activates the ban on AI-generated CSAM and non-consensual sexual imagery. High-risk system rules follow on December 2, 2027.

Europe has done this before, with GDPR in 2018: pass a sweeping instrument, let the fines catch up. The AI industry now enters the phase where the regulator learns how much it’s willing to use the powers it wrote for itself.

Sources

Sources