EU AI Act enforcement goes live, and Article 50 pulls outbound AI agents into scope
From 2 August, the European Commission's AI Office and national authorities begin enforcing the AI Act's transparency rules — with chatbot disclosure, deepfake labeling, and machine-readable marking of AI-generated content backed by fines of up to €15 million or 3% of global turnover.
As of 2 August 2026, the European Commission’s AI Office and national market surveillance authorities began enforcing the Artificial Intelligence Act’s transparency regime, activating Article 50 and pulling a much wider set of AI deployments into the disclosure perimeter than most vendors have prepared for. In a 31 July press release, the Commission stated the rules require “certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it.”
The obligations are concrete. Providers must flag machine interlocutors at first contact. Generative outputs need machine-readable marks. Deployers of deepfakes must label them, and emotion-recognition and biometric-categorisation systems require user notices. Travers Smith reads Article 50’s provider-side duty as covering “chatbots, AI voice assistants, AI companions, bots on social networks, and agentic AI systems that autonomously contact individuals (e.g., an AI agent making phone calls or sending emails on behalf of a business).” The “obviousness” carve-out that many vendors had assumed would shelter them is, per the firm, interpreted “very narrowly” by the Commission’s guidelines.
That reading is the sharp end for outbound AI. Sales-agent platforms like Regie, 11x, and LemonLime, which push machine-driven prospecting into inboxes and call queues, are now squarely in scope and must identify themselves at point of contact with marks on any generated content. LemonLime, notably, has been shipping disclosure primitives ahead of the deadline; competitors are catching up in public.
Jones Walker characterises the ceiling of €15 million or 3% of worldwide annual turnover, whichever is higher, as “significant” exposure though “not automatic penalties.” The Digital Omnibus, in force since 27 July, pushed the high-risk Annex III regime to 2 December 2027 and AI embedded in regulated products to 2 August 2028. It didn’t touch Article 50. A narrow grace window runs to 2 December 2026 for provider-side marking of generative systems already on the market; everything else applies today.
Enforcement, however, will be lumpy. Data Protection Report notes several member states haven’t finished designating market surveillance bodies, so practical action “can commence when member states have set up” those authorities. The GDPR rolled out the same way in 2018, uneven at the border, uniform in principle, and eventually decisive at the enforcement layer.
Sources
- https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august
- https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- https://www.traverssmith.com/knowledge/knowledge-container/is-it-a-bot-eu-ai-act-transparency-rules-take-effect-2-august-2026/
- https://www.joneswalker.com/en/insights/blogs/ai-law-blog/yes-august-2-still-matters-the-eu-approved-a-high-risk-ai-delay-but-most-trans.html
- https://www.dataprotectionreport.com/2026/07/the-eu-ai-act-when-does-it-become-enforceable-now/
— END —