EU AI Act Officially Enforced Today: Chatbots Must Disclose AI Identity, Deepfake Content Mandatory Labeling

2026-08-02·10 min read

August 2, 2026, is a historic day for the global AI industry. The European Commission's AI Office officially announced that from today, the core transparency provisions of the Artificial Intelligence Act (AI Act) begin full enforcement. This means all AI systems operating across the EU's 27 member states — whether from American tech giants or Chinese AI companies — must comply with these binding regulations. The EU AI Office simultaneously announced the appointment of Professor Alessandro Abate from the University of Oxford's Department of Computer Science as Lead Scientific Adviser, supporting the Office's scientific work on general-purpose AI models, including innovation, adoption, model testing, and evaluation. The European Commission also published the first list of over 180 organizations that have signed the Code of Practice on transparency of AI-generated content, with these organizations committing to take active measures in labeling and transparency of AI-generated content.

Under the new rules, chatbots and other interactive AI systems must clearly inform users that they are interacting with AI rather than humans. This requirement may seem simple, but in practice involves numerous technical details. For example, when users consult through a customer service phone system, the system must clearly inform users at the start of the interaction that they are speaking with an AI assistant, rather than disclosing this during or after the interaction. For deepfake content — including images, videos, or audio edited or generated using AI — clear labeling is mandatory. More importantly, AI-generated or modified content must also carry machine-readable marks so that automated systems can more easily detect and identify this content. The purpose of these measures is to reduce deception and manipulation, help people make informed choices, while also providing businesses with clearer compliance obligations and practical methods to demonstrate compliance.

Notably, the 'high-risk AI systems' provisions originally scheduled to take effect today have been postponed. Under revisions in the Digital Omnibus package, Annex III high-risk AI system compliance requirements — covering recruitment tools, credit scoring, education, law enforcement, border control, and critical infrastructure — originally set for full enforcement on August 2, 2026, are now delayed to December 2, 2027, an extension of 17 months. Legislators recognize that compliance requirements can only be effective when necessary infrastructure is in place. This adjustment is not simply granting more time, but aims to align rule implementation with the actual availability of systems and structures needed to support the rules, ensuring more coherent and legally certain implementation across the EU. However, the AI Office's supervisory powers over general-purpose AI models (GPAI) have been strengthened — for vertically integrated providers (which describes most frontier labs), supervisory authority is centralized in Brussels rather than dispersed across 27 national regulators.

For generative AI systems already on the market, legislators introduced a four-month 'grace period.' The watermarking obligation under Article 50(2) of the AI Act was originally set to apply from August 2, but for generative AI systems already on the market before August 2, 2026, the compliance deadline is extended to December 2, 2026. This arrangement gives existing AI service providers a buffer period to implement watermarking technology. Simultaneously, the AI Act introduces a new prohibited practice: banning AI systems designed to generate non-consensual intimate imagery (so-called 'nudifier' applications) and child sexual abuse material. This ban takes effect on December 2, 2026, representing an important addition to the existing prohibited practices list. The European Parliament pushed for this provision during trilogue negotiations, responding to concerns about online harms caused by 'nudifier' tools and intimate deepfakes.

The global AI industry's reaction to these new regulations is mixed. Large tech companies like Google, Microsoft, and Meta mostly expressed support, believing clear regulatory frameworks help build public trust and promote healthy industry development. However, some startups and open-source AI communities expressed concerns that compliance costs may impose excessive burdens on smaller businesses. The European Commission responded that it is developing simplified compliance guidelines for SMEs and startups. In the United States, federal AI legislation is also accelerating, but the two parties still have significant disagreements on AI regulation direction. Meanwhile, China is also actively improving its AI regulatory framework. Global AI regulation is forming three major systems — the 'EU model,' 'US model,' and 'China model' — posing significant challenges to multinational AI companies' compliance strategies. For AI companies operating in the EU, today's regulation taking effect means they must immediately adjust products and services, or face fines of up to 6% of global annual revenue.

🤔 Frequently Asked Questions

Q1: What impact does the EU AI Act have on Chinese AI companies?

The EU AI Act adopts a 'territorial principle' — any company providing AI products or services in the EU market, regardless of headquarters location, must comply with these regulations. This means Chinese AI companies providing services to EU users (including services provided via the internet) must meet transparency requirements, labeling obligations, and prohibited practice provisions. For large Chinese AI companies like Baidu, Alibaba, ByteDance, etc., they need to immediately review whether their EU-facing products comply with new regulations. For smaller companies, they may need to consider whether to continue serving the EU market, as compliance costs may be relatively high. However, the EU has also promised simplified compliance pathways for SMEs.

Q2: How are deepfake labeling requirements specifically implemented?

Deepfake labeling has two layers: first is 'human-readable labeling' — adding visible or audible identifiers to the content itself, informing viewers that this is AI-generated or modified content. For example, AI-generated videos should display watermarks or text descriptions on screen. Second is 'machine-readable marks' — embedding metadata or digital watermarks in content so automated systems can detect and identify AI-generated content. This is similar to EXIF data in photos, but more secure and difficult to remove. The EU is working with technical standards organizations to develop specific technical implementation standards. The 180+ organizations that have signed the Code of Practice will be first to implement these labeling requirements.

Q3: What penalties do violations of the AI Act face?

The AI Act establishes a tiered penalty system. For violations of prohibited practices (such as using banned AI systems), fines can reach up to €35 million or 7% of global annual revenue (whichever is higher). For violations of transparency obligations (such as failing to label deepfake content), fines can reach up to €15 million or 3% of global annual revenue. For supplying incorrect, incomplete, or misleading information to the AI Office, fines can reach up to €750,000 or 1% of global annual revenue. These penalty levels are comparable to GDPR, demonstrating the EU's seriousness about AI regulation. National regulatory authorities in each member state will be responsible for enforcing these penalties.

Q4: How do ordinary users benefit from these new regulations?

These new regulations provide multiple protections for ordinary users. First, when you interact with 'customer service' or 'consultants' online, you will clearly know whether the other party is AI or human, avoiding deception. Second, when browsing social media or news sites, AI-generated images, videos, and audio will be labeled, helping you distinguish real content from synthetic content and reducing the risk of being deceived by false information. Third, machine-readable marks enable fact-checking tools and platforms to more effectively detect and flag AI-generated false content. Overall, these regulations aim to create a more transparent and trustworthy digital environment, enabling users to make informed judgments and choices.

🛠️ Recommended Tools

Summary

August 2, 2026, marks the entry of global AI regulation into a new phase. The EU AI Act's transparency provisions officially taking effect is not only an important milestone within the EU but also has profound implications for the global AI industry. Chatbots must disclose AI identity, deepfake content must be labeled, AI-generated content must carry machine-readable marks — these requirements will reshape how humans interact with AI and the trustworthiness of digital content. Although full compliance for high-risk AI systems is delayed to late 2027, today's transparency requirements already have immediate impact on all AI systems operating in the EU. For AI companies and developers, compliance is no longer optional but a reality that must be faced. Meanwhile, the new prohibition on AI-generated non-consensual intimate imagery also demonstrates the EU's firm stance on protecting citizens' rights. The 'Brussels effect' of global AI regulation is emerging — just as GDPR changed global data protection standards, the AI Act may become the benchmark for global AI regulation.