The Agentic Review

Incidents — AUGUST 1, 2026

EU AI Act transparency rules go live, putting every chatbot and agent deployer in Europe on the clock

From August 2, the AI Office can fine GPAI providers up to 3% of global turnover and Article 50 disclosure obligations apply to any AI system whose outputs reach the EU's 450 million users.

The European Commission’s AI Office assumed full enforcement powers over general-purpose AI providers on August 2, and Article 50 of the AI Act went live in all 27 member states the same day, closing a one-year grace period and drawing a compliance perimeter around the roughly 450 million people in the EU single market.

The mechanics are now legible. Per the Commission’s July 31 press release, chatbots and other interactive systems must tell users they’re talking to a machine; deepfake images, video and audio must be labelled; and AI-generated or altered content must carry machine-readable marks. Fines run to €15 million or 3% of worldwide annual turnover, whichever is higher. Providers of GPT, Claude, Gemini, Llama and other GPAI models can now be sanctioned retroactively for violations dating to August 2025, when the substantive obligations (technical documentation, copyright policies, training-data summaries, systemic-risk assessments above 10^25 FLOPs) first took legal effect.

Guidelines the Commission adopted on July 20 split Article 50 into four disclosure categories: direct-interaction notice for conversational systems, machine-readable marking of synthetic audio, image, video and text, notification when emotion recognition or biometric categorisation is in use, and prominent labelling of deepfakes and AI-generated text on matters of public interest. The guidelines are non-binding. Stibbe notes they’ll nonetheless serve as the primary reference for national market surveillance authorities, which is the operative point.

The scope is where things get uncomfortable for deployers. Per Data Protection Report, the transparency obligations bind any organisation applying its own branding to a chatbot or generative tool, not just the underlying labs, and open-source releases aren’t exempted. A grace period on the marking obligation for systems placed on the market before August 2 runs to December 2, 2026.

Approximately 24 organisations, including Amazon, Anthropic, Google, IBM and Microsoft, had signed the voluntary GPAI Code of Practice as of June, a pre-emptive alignment familiar from earlier regulatory cycles like GDPR’s 2018 rollout. Meanwhile the AI Omnibus, which entered force on July 27, pushed high-risk regime enforcement out to December 2, 2027. Brussels is sequencing its fights: transparency first, systemic risk next, the high-risk stack later. The industry now knows the order.

Sources

— END —