Since 2 August, the European Commission’s AI Office and national authorities across the EU have had the power to enforce the Artificial Intelligence Act. On the same date, a set of transparency obligations began to apply — the ones most likely to be visible to ordinary users rather than to compliance departments.

Advertisement — ad space reserved

What changes for users

Three requirements do most of the work.

  • Chatbots and other interactive systems must tell people they are dealing with a machine rather than a human.
  • Deepfakes — images, video or audio generated or altered with AI — must be labelled as such.
  • AI-generated or modified content must carry machine-readable marks so it can be detected automatically rather than by eye.

The third is the technically ambitious one. A visible label can be cropped out; a machine-readable mark is meant to survive ordinary handling and let platforms, search engines and verification tools identify synthetic material at scale. Whether current watermarking and provenance techniques are robust enough to do that reliably is disputed among researchers, and the Commission has said it will build up EU capacity to evaluate models, with a third-party assessment capability expected to be operational by 2027.

How the law is structured

The AI Act entered into force in August 2024 and has been arriving in stages. It sorts applications by risk: a small number of uses are prohibited outright, a defined set is treated as high-risk and carries substantial obligations, and the rest face lighter or no requirements. There are exemptions for military and national-security uses, for research, and for purely personal use.

It is product regulation rather than a rights instrument. It does not give an individual a new right to sue; it places duties on the organisations that build and deploy these systems. The AI Office holds enforcement powers over general-purpose AI models specifically — the large models that sit underneath many separate products.

Member states were also required to have at least one national regulatory sandbox in place by 2 August, intended to let developers test systems under supervision rather than in the dark.

Advertisement — ad space reserved

The arguments about it

Supporters, including the Commission, argue that the technology has been deployed into consequential decisions — credit, hiring, education, biometrics — with no obligation to explain anything, and that a baseline of documentation and disclosure is the minimum a functioning market requires. They also point out that a single European rulebook is simpler for companies than twenty-seven national ones.

Critics make two distinct arguments that are often blurred together. The first is about burden: that compliance costs fall hardest on small companies, and that documentation obligations favour firms large enough to employ policy teams. The second is about pace: that the law was drafted for a technology that has changed substantially since, and that a rulebook fixed in 2024 will be enforcing categories that no longer describe what is being built.

There is a jurisdictional argument running alongside. The United States has moved in a different direction, with a December 2025 executive order pushing towards a single federal framework and away from a patchwork of state AI rules. The practical result for anyone building AI products is that the same system can face materially different obligations depending on which market it enters.

What to watch

Enforcement powers existing and enforcement happening are not the same thing. The meaningful indicators over the coming months are the first formal proceedings against a named provider, whether the labelling requirements produce visible changes in consumer products, and whether the machine-readable marking obligation turns out to be technically satisfiable at the scale the text assumes.

Sources

Advertisement — ad space reserved


Leave a Reply

Your email address will not be published. Required fields are marked *