August 3 Update Explained

What Changed When EU AI Act Enforcement Began?

August 2, 2026 was an important date for the European Union’s AI Act, but not because one single rule suddenly covered every AI product. Two different changes happened at the same time: transparency duties began applying to certain AI systems and content, while the European Commission gained active enforcement powers over providers of general-purpose AI models.

The direct answer

August 2 did not create one universal AI licence or one rule for every AI tool

Instead, it activated different parts of the EU AI Act for different actors.

Change one

Certain AI providers and professional deployers must now give people clearer information when they interact with AI or encounter particular forms of AI-generated or manipulated content.

Change two

The European Commission can now actively enforce the AI Act obligations that already applied to providers of general-purpose AI models, including the most advanced models that may create systemic risks.

These changes are connected because both concern trust and accountability, but they are not the same legal duty. A small company using a customer-service chatbot faces a different set of questions from a company developing a frontier general-purpose model.

The easiest way to understand the update is to separate the two tracks

Track A

Transparency for AI systems and content

Main question: Are people being told when AI is interacting with them or producing particular content?

Relevant actors: providers and professional deployers of certain AI systems.

Typical controls: chatbot notices, machine-readable marking, deepfake disclosures and notices for emotion-recognition or biometric-categorisation systems.

Track B

Enforcement for general-purpose AI models

Main question: Are model providers meeting their documentation, copyright, information-sharing and systemic-risk obligations?

Relevant actors: providers that place general-purpose AI models on the EU market, with additional duties for models classified as having systemic risk.

Typical controls: technical documentation, downstream information, copyright policy, model evaluations, incident reporting and risk mitigation.

A company can fall under one track, both tracks or neither, depending on what it builds, sells and uses.

Track A

Article 50 transparency duties now apply to several situations where AI could be mistaken for a person or authentic content

The European Commission says Article 50 applies from August 2, 2026. Its purpose is to help people recognise certain AI interactions and synthetic material before they make decisions based on them.

1

Direct AI interaction

People should generally be informed when they are interacting directly with an AI system, unless that fact is already obvious in the circumstances.

Example: A support bot should not quietly pretend to be a human employee.

2

AI-generated or manipulated material

Providers of relevant generative systems must support reliable detection through machine-readable marking, subject to the Act’s scope and exceptions.

Example: An image generator may embed provenance information that compatible tools can inspect.

3

Deepfakes and public-interest text

Professional deployers must disclose covered deepfakes and certain AI-generated public-interest text when it has not received human review or editorial control.

Example: A realistic synthetic video of a public official should not be presented as authentic footage.

4

Emotion and biometric systems

People exposed to in-scope emotion-recognition or biometric-categorisation systems must receive appropriate information.

Example: An organisation should not operate a covered emotion-inference system as invisible background software.

A disclosure explains AI involvement. It does not prove that the content is true, safe, lawful or unbiased.

Track B

The Commission can now enforce obligations for general-purpose AI model providers

The underlying obligations for providers of general-purpose AI models started applying on August 2, 2025. The following year was not a year in which the rules did not exist. It was a preparation and compliance period before the Commission’s enforcement powers became active on August 2, 2026.

General-purpose AI models are models capable of performing a broad range of tasks and being integrated into many downstream systems. Some of the most capable models may be classified as general-purpose AI models with systemic risk.

Technical documentation

Providers must maintain information about the model, its development and its capabilities so regulators and downstream providers can understand important characteristics and limitations.

Information for downstream providers

Businesses building services on top of a general-purpose model need enough information to understand capabilities, limits and integration requirements.

Copyright compliance policy

Providers must maintain a policy intended to comply with EU copyright law, including rules concerning rights reservations.

Training-content summary

Providers must make available a sufficiently detailed summary of the content used to train the model, using the required framework.

Systemic-risk evaluation

Providers of models with systemic risk face additional duties involving model evaluation, adversarial testing and assessment of serious risks.

Risk mitigation and incident reporting

Advanced-model providers may need to reduce identified systemic risks, document serious incidents and maintain appropriate cybersecurity protections.

Models already on the EU market before August 2, 2025 have a separate compliance deadline of August 2, 2027. That does not remove current obligations for newer models placed on the market after the 2025 start date.

What can the Commission and AI Office do now?

The Commission’s AI Office says technical compliance discussions remain its preferred first tool. Enforcement does not necessarily begin with a fine. Regulators can request evidence, investigate gaps and require corrective action.

  1. 1
    Request information and documents

    A provider may be required to supply technical, governance or risk-management evidence.

  2. 2
    Request access for model evaluation

    Regulators can seek access needed to assess capabilities, systemic risks or compliance.

  3. 3
    Require corrective or risk-mitigation measures

    A provider may be directed to address identified failures rather than merely explain them.

  4. 4
    Restrict, withdraw or recall a model

    In serious circumstances, the Commission can seek limits on making a model available in the EU market.

  5. 5
    Impose administrative fines

    For general-purpose AI model providers, fines can reach up to €15 million or 3% of total worldwide annual turnover, whichever is higher, subject to the Act’s conditions.

Article 50 transparency rules are mainly supervised by national market-surveillance authorities. The AI Office has a narrower direct role for certain systems based on general-purpose models and for designated very large platforms or search engines in the situations described by the Act.

Who should pay attention?

Frontier and general-purpose model providers

They should be ready to demonstrate compliance, not merely point to internal plans or voluntary commitments.

Companies building products on foundation models

They need to know whether they are only downstream deployers or whether their modifications and branding make them a provider of a new system or model.

Businesses using chatbots or synthetic media

They should review customer notices, labels, machine-readable marking and editorial-review records.

Publishers and public-information services

They should separate AI-assisted work that receives genuine editorial control from content published automatically without meaningful human review.

Platforms and marketplaces

They may need processes for reading provenance signals, applying disclosures and responding to regulator requests.

Organisations outside Europe

Location alone does not remove EU obligations when a relevant model or system is placed on the EU market or put into service there.

What may ordinary users notice?

  • More visible chatbot disclosures before or during automated conversations.
  • More labels on realistic synthetic images, audio and video when professional deployers publish covered material.
  • More platform notices generated from embedded provenance or machine-readable signals.
  • Clearer information around emotion or biometric categorisation tools in situations where those systems are legally permitted and Article 50 applies.
  • More public compliance explanations from major model providers, especially concerning risk evaluations, incidents and model governance.

Users should not expect every AI-created sentence or every edited photograph to carry the same label. The legal scope depends on the system, actor, content and context.

Use this now

A first-business-day checklist

  1. 1
    Inventory every externally facing AI system.

    Include chatbots, content generators, synthetic-media tools and model-powered workflow applications.

  2. 2
    Identify your legal role for each system.

    Record whether the organisation is acting as a model provider, system provider, deployer, importer, distributor or more than one role.

  3. 3
    Map the relevant obligation.

    Do not use one generic “AI policy” as a substitute for system-specific notices, documentation and controls.

  4. 4
    Test notices and technical marks.

    Confirm that visible disclosures appear at the right moment and that provenance signals survive normal export and publishing workflows.

  5. 5
    Preserve evidence.

    Keep screenshots, version records, test results, responsible owners, review logs and the reasoning behind any exception.

  6. 6
    Prepare for regulator questions.

    Know who will respond, where documents are stored and how quickly technical access or risk evidence can be provided.

  7. 7
    Review vendor contracts.

    Confirm that model and system suppliers provide the information, marking support and cooperation needed for your own compliance.

What the August 2 change does not mean

It does not mean every AI tool is now “approved by the EU.”

The AI Act creates obligations and oversight. It does not provide one universal quality certificate for all AI products.

It does not mean every company faces the same regulator.

National authorities, the AI Office and the European Data Protection Supervisor have different responsibilities.

It does not mean all enforcement starts with punishment.

Information requests, technical dialogue and corrective measures may come before financial penalties.

It does not mean transparency proves accuracy.

An AI label identifies origin or involvement; it does not verify the claim being made.

It does not mean older models have no obligations.

Different transition dates apply, and the exact date depends on when a model or system entered the EU market and which duty is involved.

It does not mean only European companies are affected.

Non-EU providers can be covered when their relevant models or systems are offered or used in the European Union.

Verified sources

Official European Union material

Verification note: This explainer was checked against official European Commission, AI Act Service Desk and EUR-Lex material on August 2, 2026. It provides general information and is not legal advice.

The bottom line

The EU AI Act has moved further from policy preparation into operational accountability

For ordinary users, the most visible change should be better notice when AI is interacting with them or producing particular synthetic material. For general-purpose model providers, the more important change is behind the interface: the Commission can now demand evidence, evaluate models, require risk controls and impose sanctions when obligations are not met.

The practical lesson is straightforward. Organisations should stop treating AI compliance as one generic policy document. They need to know which system they operate, which legal role they occupy, which authority may ask questions and what evidence proves that the required control actually works.

Continue learning

Related explainers

More in Trust and Safety