The countdown ended today. As of August 2, 2026, the European Commission has activated enforcement of the EU AI Act — and what was “forthcoming regulation” is now a live legal reality for any business using AI that touches European users.
The European Commission published an official press release today confirming enforcement has started. The AI Office, the Commission’s dedicated AI supervisory body, now holds full enforcement powers over general-purpose AI (GPAI) model providers. Simultaneously, the Article 50 transparency obligations — requiring businesses to disclose when users are interacting with AI — are enforceable from this date.
The penalties are real: fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
What Switched On Today
There are two distinct enforcement tracks that activated today.
Track 1: AI Office powers over GPAI providers. The AI Office can now request technical documentation, access models directly, require corrective measures, and impose fines on providers of large AI models — think the companies building the underlying models that businesses plug into their products. If you’re a business deploying GPT-5.6, Claude Sonnet 5, or Gemini via API to serve EU customers, the providers of those models are now under active regulatory supervision. That scrutiny doesn’t stay with the providers; it flows downstream through their terms of service and usage policies.
Track 2: Article 50 transparency for deployers. Four categories of AI use now require disclosure:
- Direct AI interaction — If you run a chatbot, voice agent, or AI assistant that converses with EU users, the user must be told they are talking to an AI at the start of the interaction. An AI voice agent that introduces itself as “Sarah from customer support” without disclosing its nature is now non-compliant.
- AI-generated content — Content generated by AI and presented to users in contexts relating to public interest must be labeled.
- Emotion recognition and biometric categorisation — Systems that assess emotional states or categorise users by biometric data must disclose this.
- Deepfake labeling — AI-manipulated images, video, and audio must be marked as synthetically generated.
Pre-existing AI systems get a grace period on the content marking and watermarking requirements until December 2, 2026. The disclosure obligation for interactive AI — telling people they’re talking to a machine — applies immediately to all systems regardless of when they were deployed.
The Gap That’s Now a Liability
For businesses that have been watching and waiting, today marks a hard line. As of spring 2026, roughly 78% of organisations had taken no meaningful compliance steps. More than half could not produce a basic inventory of the AI systems they operate.
That’s not a preparation gap anymore — it’s an enforcement exposure.
The practical reality is that regulators don’t begin enforcement by targeting every violation simultaneously. They begin with high-profile cases and sectors where the public interest is highest. Financial services, healthcare, employment, and legal communication have all been flagged by EU national authorities as early enforcement priorities. Germany, France, and the Netherlands have already signalled active intent.
If your business operates AI that handles customer enquiries, processes EU applicants, delivers health information, or produces financial communications to European clients, you are inside the highest-priority enforcement perimeter.
What Businesses Need Right Now
There are three things businesses should have completed by today, and if they haven’t, they need to move quickly.
Disclosure language active. Every AI-powered touchpoint with EU users — chatbot, voice agent, AI email assistant, AI-generated reports — should have a clear, upfront disclosure that users are interacting with AI. Not buried in your privacy policy. Visible at the point of interaction.
AI system inventory documented. Regulators in enforcement proceedings look for evidence of intent. A documented audit of where AI touches your EU operations — even one that lists gaps you’re actively fixing — demonstrates good faith. Silence does not.
Vendor compliance checked. If you use third-party AI APIs or platforms, verify your vendors’ own compliance posture. Under the AI Act, obligations cascade: a non-compliant provider creates downstream exposure for every deployer relying on their outputs.
What This Means for Business
This regulation is not asking businesses to stop using AI. It’s asking them to be honest about it.
The transparency obligations under Article 50 align with what customers already expect. Research consistently shows users accept AI interactions when they’re disclosed upfront — the trust damage comes from discovering they were misled. A voice agent that opens with “Hi, I’m an AI assistant with Enterprise X” loses nothing and gains regulatory safety.
The businesses with the most to lose today are those running AI at scale with EU exposure who have done nothing. For them, the question has shifted from “when do we need to do this?” to “how fast can we document what we have?”
If you need help mapping your AI operations against these obligations — what’s in scope, what needs updating, and how to document your position — our advisory team works through exactly this with businesses navigating AI compliance in regulated environments.
Source
European Commission
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible