EU’s AI Act Enforcement Era Begins: What Businesses and Users Need to Know Now
Europe has officially entered a new phase of artificial intelligence regulation. Since the start of this month, the European Commission’s dedicated AI Office, working alongside national regulators, has begun actively enforcing key provisions of the bloc’s landmark AI Act — a shift that transforms years of legislative groundwork into real-world legal obligations for companies operating across the continent.
What Changed and When
The centrepiece of this new enforcement phase is a set of transparency obligations that require certain AI systems to clearly disclose their nature to users. Chatbots and other AI tools that interact directly with people must now make it obvious that users are dealing with a machine rather than a human, unless that fact is already self-evident from the context. Deepfake content — images, audio, or video that has been synthetically generated or manipulated — must be clearly labelled, and AI-generated content more broadly is required to carry machine-readable markings that make it easier to detect and trace.
These obligations apply immediately to any qualifying system operating on the EU market, regardless of when that system was originally deployed, though content published before the rules took effect does not need retroactive labelling. A short transitional window has been granted specifically for the technical marking and detection requirements applied to generative AI tools already in circulation, giving providers extra time to implement compliant systems.
The Long Road to This Moment
The AI Act’s journey to enforcement has been anything but simple. The regulation formally entered into force back in 2024, but its rollout has occurred in stages, with different categories of obligations activating at different points. Prohibited practices and AI literacy requirements were among the first to apply, followed by a lengthy and, at times, contentious negotiation process over how to simplify and refine the framework’s more complex provisions.
That process culminated in a package of amendments — sometimes referred to as a digital omnibus — that reached political agreement earlier this year following a collapsed negotiation round in the spring. The revised text was formally adopted by the European Parliament in June and received final Council approval shortly after, before being signed into law and prepared for enforcement.
One notable late addition to the framework is a new outright prohibition on AI systems specifically designed to generate non-consensual intimate imagery, closing a gap that campaigners had long flagged as a serious safety concern, particularly given the proliferation of so-called “nudifying” applications powered by generative AI.
What About High-Risk AI Systems?
While transparency rules are now live, the more demanding obligations tied to “high-risk” AI systems — those used in sensitive areas like employment, credit scoring, or critical infrastructure — have not yet arrived. Standalone high-risk systems falling under a specific annex of the regulation now have until December 2027 to achieve compliance, while AI embedded within already-regulated products, such as medical devices or vehicles, has been given until August 2028. This phased timeline gives both regulators and industry additional runway to build out the technical standards and assessment infrastructure needed to police more complex AI applications.
How the AI Office Plans to Enforce the Rules
Beyond the transparency requirements, the AI Office has begun applying stricter obligations to providers of the most powerful general-purpose AI models — specifically those whose training computation exceeds a defined threshold. A small number of foundation model providers now fall into this category and are required to submit regular assessments of systemic risk. Non-compliance with these systemic risk provisions can trigger fines running into the tens of millions of euros, or a percentage of a company’s global annual turnover, whichever proves higher — a penalty structure clearly modelled on the enforcement approach used for GDPR violations.
The Commission has also published voluntary guidance and a code of practice aimed at helping companies demonstrate compliance with the new marking and detection obligations, alongside broader guidelines clarifying how the transparency rules should be interpreted in practice.
Why This Matters Beyond Europe’s Borders
Much like the GDPR before it, the AI Act’s reach extends well beyond companies physically based in the EU. Any provider, deployer, importer, or distributor whose AI systems are used within the European Union — or whose AI-generated outputs circulate there — falls within scope, regardless of where the company itself is headquartered. That extraterritorial reach means global technology firms, not just European ones, are now recalibrating their compliance strategies.
For everyday users across Europe, the most visible impact will likely be seeing more explicit disclosures when interacting with chatbots, virtual assistants, and AI-generated media — small but meaningful signals intended to help people navigate an increasingly synthetic information environment with greater confidence and clarity. Next Article