THE RULES ARRIVING
The EU AI Act became broadly applicable on 2 August 2026. The EU AI Act became broadly applicable on 2 August 2026. What changed, when, and what it actually means.
- Transparency obligations. Tell people when they are interacting with an AI system unless it is obvious; mark synthetic audio, image and video in a machine-readable format; disclose emotion recognition and biometric categorisation.Article 50. Practical detail on how AI content gets labelled.
- Enforcement powers over general-purpose model providers, held by the European AI Office — including the ability to request technical documentation, evaluate models and require corrective measures.
- The penalty regime. The ceiling for the most serious violations — deploying a prohibited practice — is €35 million or 7% of global annual turnover, higher than the GDPR. The tier now actively enforced against general-purpose model providers is lower: €15 million or 3%.
The staircase, in order
Binding law, no substantive obligations yet. This date started every clock below it.
Prohibited practices became enforceable, alongside an obligation on organisations to ensure staff have a working understanding of the AI they deploy.
Duties on providers of foundation models — technical documentation, a summary of training-data copyright compliance, and additional assessment and incident-reporting expectations for models above a systemic-risk compute threshold.
The main body of the Act applies. Member State authorities and the AI Office take up enforcement. This is the date that matters for ordinary readers, because it is when labelling and disclosure became legal duties rather than good practice.
Content-marking duties extend to AI systems placed on the market before 2 August 2026 — earlier than the February 2027 date the Commission originally proposed. Providers of systems caught by the new prohibition below have the same deadline to implement technical safeguards.
Obligations for high-risk applications in sensitive areas — hiring, credit, education, essential services — pushed back from the original date by the 2026 simplification package.
AI embedded in medical devices, machinery and similar products, where existing sectoral regimes already apply.
The amending instrument has a name worth knowing: the Digital Omnibus on AI, Regulation (EU) 2026/1744, agreed politically on 7 May 2026 after a first negotiation collapsed in April, adopted by Parliament on 16 June and Council on 29 June, and in force from 27 July 2026. It postponed the most operationally demanding requirements: conformity assessments, risk-management files and registration for high-risk systems. It did not postpone transparency, enforcement powers over model providers, or penalties.
So "the AI Act was delayed" describes the compliance burden on companies building hiring or credit systems. It does not describe the rules governing whether AI content gets labelled — those are live now. Reporting that collapses the two is telling you something false about the thing most readers care about.
Regulation is only half of the law arriving. The other half is copyright litigation — more than 35 active training-data cases by mid-2026, one settled for roughly $1.5 billion, and an emerging distinction that turns on how training data was obtained rather than whether training itself is copying. Covered on AI and the open web, because it is ultimately the same question as the traffic collapse: if a publisher's work ends up inside an answer, what is owed?
Coverage of this instrument has concentrated almost entirely on the deferral. Two additions deserve equal attention.
A new prohibition. AI systems used to generate child sexual abuse material, or non-consensual sexual or intimate content, are now banned outright — both placing them on the market and using them. Providers of in-scope systems have until 2 December 2026 to implement the required technical safeguards, including refusal training, output controls and content filtering.
Centralised enforcement. The AI Office gained exclusive supervisory competence over AI systems built on a general-purpose model by the same provider or group, and over AI systems integrated into very large online platforms and search engines. It also receives serious-incident reports directly. That is a meaningful shift of power from member-state authorities to Brussels — and it matters because a fragmented regulator is a weak one.
Beyond Europe
No comparable federal law exists in the United States. What exists is a patchwork of state legislation — California's transparency requirements for AI-generated content and its companion-chatbot rules both took effect on 1 January 2026 — alongside an unsettled and ongoing argument about whether federal action should override state rules. The prudent reading, and the one most compliance guidance gives, is that state law applies until something displaces it.California SB 942 and SB 243, both effective 1 Jan 2026. Companion-chatbot detail on AI companions.
Which produces the practical situation worth understanding: a European rule tends to become the global default, because building one compliant product is cheaper than building two. The labelling you will encounter was probably written for Brussels regardless of where you live.
What it means if you are not a company
- Expect labels, and read them correctly. A label is now a legal duty for providers in the EU — but as the provenance page explains at length, an absent label still proves nothing, because marks can be stripped and most tools worldwide are not covered.
- Chatbot disclosure is now required where it is not obvious you are talking to a machine. If a service is coy about this, that is now a compliance question rather than a style choice.
- Text remains the gap. The marking duties centre on audio, image and video. The highest-volume category — written words — has no equivalent workable requirement.
- Enforcement is new, and unevenly staffed. Rules taking effect is not the same as rules being enforced. Independent tracking of the EU-27 shows member states at markedly different stages of designating the national authorities who are supposed to do the enforcing — so the first significant actions will tell you more than the statute does, and where they happen will tell you something too.National-authority readiness tracked by the Future of Life Institute, status as of August 2026.
This is the most encouraging development this site covers and it is arriving years after the harms it addresses were measurable — voice cloning was demonstrated in 2023 and first counted as a fraud category in 2026; automated traffic passed half the web in 2024 and the first broad transparency duty took effect in August 2026. That lag is the normal speed of law, not a scandal. But it means the rules will always describe the previous problem, which is why the habits on this site are not made redundant by legislation — they are what covers the gap.The full lag, dated: the timeline.