On August 2, 2026, the European Commission's AI Office and national market surveillance authorities began enforcing two pieces of the AI Act that survived a year of political retreat: Article 50's transparency duties and the Commission's supervisory powers over general-purpose AI (GPAI) models. The Commission's own announcement frames it plainly — chatbots and other interactive systems must now tell users they are dealing with AI, deepfakes have to be labeled, and AI-generated images, video, audio, and public-interest text need machine-readable marks (digital-strategy.ec.europa.eu). This is the AI Act's first genuine live-fire enforcement date since the regulation entered into force two years ago.
It lands in an unusual context. On June 16, 2026, the European Parliament approved the Digital Omnibus on AI by a 423–57 vote, and the measure — formally Regulation (EU) 2026/1744 — was published in the Official Journal on July 24 and entered into force July 27. That instrument deferred the AI Act's most consequential and most expensive obligations: standalone high-risk systems under Annex III (hiring tools, credit scoring, biometric ID) now have until December 2, 2027, a 16-month reprieve, and AI embedded in already-regulated products under Annex I moves to August 2, 2028. Article 50 and the GPAI enforcement regime were deliberately left untouched (gibsondunn.com).
What actually changed on August 2
Three things are now live. First, the chatbot-disclosure and deepfake-labeling duties in Article 50: users must be told when they're interacting with AI "unless obvious to a reasonably informed person," and manipulated audio, image, or video content must be marked as artificially generated, with narrow carve-outs for clearly-flagged art, satire, and fiction (ai-act-service-desk.ec.europa.eu). Systems already on the market before August 2 get a four-month grace period, until December 2, 2026, specifically for the machine-readable watermarking piece — a sensible concession to the fact that retrofitting provenance metadata into existing pipelines takes real engineering time.
Second, the Commission's AI Office now has active enforcement authority over GPAI model providers: it can compel technical documentation under Article 91, demand model access to run evaluations under Article 92, order risk-mitigation measures under Article 93, and — in the most severe cases — restrict a model's availability in the EU market. Third, the penalty regime attached to both tracks is real money: up to €15 million or 3% of global annual turnover, whichever is higher (digital-strategy.ec.europa.eu).
The steelman for keeping this on schedule
Regulators have a genuine case here, and it's worth stating without caricature. Transparency obligations are comparatively cheap to implement relative to full high-risk conformity assessments — disclosing that a chatbot is a chatbot, or tagging a synthetic image, doesn't require the kind of technical documentation, human-oversight architecture, and third-party auditing that Annex III compliance does. Meanwhile the harm these rules target — undisclosed AI manipulation in elections, fraud, and non-consensual synthetic media — is already occurring at scale and doesn't wait for a compliance calendar. Decoupling transparency from the delayed high-risk track lets Brussels address the most visible, least contestable harms first while giving industry the runway it asked for on the genuinely burdensome parts of the regulation. That the Digital Omnibus also added a new prohibition on AI-generated non-consensual intimate imagery and CSAM into Article 5 (gibsondunn.com) reflects the same triage logic: act fastest where the case for intervention is least ambiguous.
Where the caution still applies
That said, this is exactly the kind of proportionate sequencing this publication has argued for since the Digital Omnibus first surfaced — and the fact that Brussels landed here after a bruising legislative fight, rather than by original design, is itself informative. The Commission's original 2024 text bundled disclosure duties with the far heavier Annex III and Annex I machinery on a single clock; it took sustained industry pushback, a 423–57 parliamentary vote, and sixteen months of deferral to arrive at a sequencing that most compliance lawyers now describe as sensible. The lesson is not that regulators got it right the first time. It's that a rule calibrated to actual, demonstrable harm — synthetic media deception — survived scrutiny, while a rule built around abstract risk categories for systems not yet shown to cause comparable harm did not.
The residual risk is enforcement discipline. "Machine-readable and detectable" marking has no single technical standard yet — the Commission is still finalizing a Code of Practice on marking and labelling, which over 180 organizations have already signed (digital-strategy.ec.europa.eu). If the AI Office applies Article 50 with the same procedural patience it showed on high-risk timelines, transparency compliance will be workable. If it instead treats August 2 as a green light for aggressive early enforcement against ambiguous marking implementations, it risks repeating the same overreach that forced the Digital Omnibus in the first place — just on a narrower front. Proportionality has to survive contact with an actual enforcement docket, not just a press release.