Insider Brief
- The European Union began enforcing key AI Act provisions on Aug. 2, requiring disclosure when users interact with AI and labels or machine-readable markings for certain AI-generated and manipulated content.
- General-purpose AI providers must document their models, adopt copyright policies, publish training-content summaries and address systemic risks, while the law also prohibits manipulative systems, harmful exploitation of vulnerabilities and certain social-scoring practices.
- Enforcement is divided among the European Commission’s AI Office, national regulators and the European Data Protection Supervisor, while separate rules for high-risk AI systems have been delayed until 2027 and 2028.
The European Union began enforcing key provisions of its Artificial Intelligence Act on Aug. 2, requiring companies to disclose when people are interacting with AI and to label certain AI-generated or manipulated content.
Acccording to the European Commission, chatbots, AI agents and digital avatars must clearly inform users that they are dealing with an automated system rather than a person. Deepfake images, video and audio must also be labeled, while covered content must include machine-readable markings that allow automated detection.
The rules are intended to reduce fraud, impersonation, misinformation and other forms of deception as synthetic content becomes harder to distinguish from authentic material, according to the commission. They also establish more specific compliance requirements for developers and businesses using AI systems in the European Union.
The commission said more than 180 organizations have signed a voluntary Code of Practice designed to help companies apply the transparency rules for AI-generated content.
New Rules and Obligations
The requirements taking effect include:
Prohibited practices: The law bans certain systems that manipulate people, exploit vulnerabilities or use social scoring in ways that threaten individual rights.
Disclosure of AI interactions: Chatbots, AI agents, digital avatars and other interactive systems must clearly inform users that they are dealing with AI rather than a person.
Deepfake labeling: AI-generated or manipulated images, video and audio that resemble real people, places, objects or events must be visibly identified.
Machine-readable markings: Covered AI-generated or altered content must include technical markers that allow platforms and automated tools to detect it.
Public-interest text: AI-generated text published to inform the public on matters of public interest must be disclosed when it has not received human review or editorial oversight.
Model documentation: Providers of general-purpose AI models must document required information and make it available to regulators and companies building products on top of their systems.
Copyright policies: General-purpose model providers must establish policies for complying with EU copyright law.
Training-data summaries: Providers must publish sufficiently detailed summaries describing the material used to train their models.
Systemic-risk safeguards: Developers of the most capable general-purpose models must address risks involving cyberattacks, harmful manipulation, loss of control and chemical, biological, radiological or nuclear threats.
Divided Enforcement
Responsibility for enforcing the rules is divided among the commission’s AI office, national authorities and the European Data Protection Supervisor.
The AI office will supervise systems offered by providers of general-purpose AI models. It will also oversee certain AI services integrated into the largest online platforms and search engines covered by the Digital Services Act. National regulators will enforce the rules for other AI systems used within their jurisdictions and the European Data Protection Supervisor will oversee systems used by EU institutions, bodies and agencies.
The commission said effective enforcement will depend partly on member states properly designating and funding their national authorities.
General-Purpose AI Oversight
The AI Office can now enforce requirements covering general-purpose AI models, which can perform a wide range of tasks and serve as the foundation for chatbots, agents and other applications, the commission noted.
More advanced models considered capable of creating systemic risks face additional obligations and the commission said those risks include large-scale cyberattacks, harmful manipulation, loss of human control and threats to fundamental rights or European cybersecurity.
Providers of those systems will be expected to assess risks, put safeguards in place and cooperate with regulators.
Complaints and Scientific Review
The AI Office has introduced tools for reporting suspected violations. Individuals and companies can submit complaints involving systems supervised by the office, while workers at AI companies can use a confidential whistleblower channel.
A separate reporting route is available to businesses that rely on general-purpose models and believe a model provider has violated the law. The commission indicated information submitted through the tools will be handled confidentially.
Regulators will receive technical support from a 60-member Scientific Panel of independent AI experts, which recently held its first meeting.
The AI Office also appointed Alessandro Abate, a professor in the University of Oxford’s Department of Computer Science, as its lead scientific adviser. The commission said Abate will support work on model testing, safety, evaluation, innovation and adoption.
High-Risk Rules Delayed
Other parts of the AI Act will take effect later. The commission said the AI Omnibus postponed requirements for high-risk AI systems until Dec. 2, 2027. Rules covering high-risk AI embedded in regulated products were delayed until Aug. 2, 2028. Those systems can include AI used in areas where failures could create significant risks to safety or individual rights.
The commission pointed out that the EU plans to introduce additional prohibitions on Dec. 2, 2026, including bans on systems that generate nonconsensual sexually explicit material or child sexual abuse content.




