The Rules Are Live, Even If the Enforcer Isn't Fully Armed
As of August 2, 2026, Article 50 of the EU AI Act (Regulation (EU) 2024/1689) is binding law across the bloc. Chatbots and voice assistants must tell users they are talking to a machine. Providers of systems that generate synthetic audio, images, video, or text must embed machine-readable markers. Deployers using emotion-recognition or biometric-categorisation tools must notify the people exposed to them. And AI-generated text published on matters of public interest, without meaningful human editorial review, must say so. The European Commission's implementing guidelines, adopted July 20, confirm the scope and carve out a transition window — providers of systems already on the market before August 2 have until December 2, 2026 to add the machine-readable marking specifically (Commission guidelines).
In the Netherlands, the Autoriteit Persoonsgegevens (AP) — the country's data protection authority — has been positioned as the default supervisor for these transparency duties, alongside prohibited-practice enforcement and most Annex III high-risk applications. That role was set out in an April 20, 2026 government announcement opening public consultation on the national Uitvoeringswet AI-verordening (Uvai), the implementing law that will formally designate market surveillance authorities and their powers; State Secretary Aerdts framed the goal as giving companies "duidelijke regels" — clear rules — while leaving room for innovation (Rijksoverheid).
A Supervisor Ahead of Its Own Statute
Here is the catch: the AI Act is a directly applicable EU Regulation, so the Article 50 obligations bind Dutch companies regardless of domestic legislation. But the consultation on the Uvai — the law that gives the AP its concrete national fining mandate, procedure, and appeals structure — ran only from April 20 to June 1, 2026, and had not been enacted by the time Article 50 became enforceable. Legal commentary tracking the bill's progress is blunt about the gap: "Until the bill is adopted, a Dutch regulator cannot yet impose a fine under the AI Act" (Praxikon). The substantive duty exists; the domestic machinery to punish its breach does not — yet.
That sequencing is not unique to the Netherlands, but it is a real feature of how the AI Act rolls out: Brussels sets an EU-wide compliance date, and each member state races to stand up its own enforcement plumbing on a separate, slower clock. Companies operating in the Netherlands are legally on the hook from August 2, while the entity meant to hold them accountable is still waiting on Parliament.
The Code of Practice as a Workaround
Into that gap, the AP has pushed a softer lever: it is advising organizations to sign the EU's Code of Practice on Transparency of AI-generated Content, a voluntary framework the Commission published on June 10, 2026, and which the Commission and the AI Board have jointly assessed as adequate for demonstrating compliance with the marking and labelling obligations (Commission news). By the end of July, roughly 190 organizations had signed — 82 as providers, 152 as deployers, with about half described by the Commission as small or recently founded firms. Dutch legal press reported the AP explicitly steering companies toward signing ahead of the deadline, since it "demonstrates to consumers, end-users and other stakeholders" how a company meets its obligations (Governance-web.nl).
That is a sensible use of soft law: the Code gives smaller firms a template instead of a blank legal duty to interpret from scratch. But it also underscores the practical reality — with formal fining power still pending, encouraging voluntary sign-up is one of the AP's few real levers this month.
Steelmanning the Rules
The case for Article 50 is genuinely strong, and skeptics of AI regulation should not wave it away. Synthetic media has already been used to fabricate the voices of officials and to circulate fake video of public figures during elections elsewhere in Europe. A baseline duty to disclose — this is a bot, this image was generated, this text was not edited by a human — is a low-cost, content-neutral rule: it does not restrict what AI can say, only requires labeling of how it was made. That is closer to a nutrition label than a speech restriction, and outlets like this one, which depend on readers trusting that a byline reflects real editorial review, have a direct stake in deepfakes and synthetic text not passing silently as authentic.
Where the Balance Tips
The problem is not the transparency requirement itself; it is the execution gap. Firms face a hard compliance deadline, a €15 million-or-3%-of-global-turnover penalty ceiling under the Act's Article 99 fining framework, and genuine uncertainty about which Dutch body will actually investigate them and under what procedure, because the enabling statute is still in the legislative pipeline. That is the kind of regulatory whiplash — binding duty, unfinished enforcement architecture — that erodes trust in "risk-based" EU tech regulation more than the substance of the rule does. A better sequencing would tie a Regulation's compliance date to member states having their enforcement statute in force, not the other way around.
For now, Dutch companies get a de facto reprieve: the legal duty to disclose is real, but the fine that would make ignoring it costly is not, at least not yet. Reasonable firms should sign the Code of Practice and comply anyway — reputational risk and the eventual arrival of AP fining power both argue for it. But regulators should not mistake a voluntary signature list for enforcement, and Brussels should take the lesson that phased national implementation timelines need to be genuinely synchronized with EU-level compliance dates, not just aspirationally aligned.