Replio · AI customer support
Never lose a customer to a missed message
An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.
The EU AI Act transparency rules became enforceable across the European Union on 2 August 2026, requiring companies to tell people when they are dealing with a machine, to mark AI-generated audio, images, video and text in a machine-readable format, and to label deepfakes. The same date had long been billed as the moment the Act’s heavier obligations for high-risk systems would bite. That did not happen. A separate regulation adopted weeks earlier pushed those duties back by more than a year, leaving Europe with a narrower set of requirements that are nonetheless binding right now.
The distinction matters, because the two tracks are often described together and they have now separated. Disclosure duties apply today, to any provider or deployer within scope, regardless of how the underlying system is classified. The documentation, risk management and human oversight obligations attached to high-risk classification do not.
What the EU AI Act transparency rules actually require
Article 50 of the Act sets out three groups of duties, and none of them depend on a risk classification.
First, providers of AI systems designed to interact directly with people, such as chatbots and virtual assistants, must ensure that individuals are informed they are interacting with an AI system, unless that is obvious from the context to a reasonably well-informed person.
Second, providers of systems that generate synthetic audio, image, video or text must mark the outputs in a machine-readable format that allows them to be detected as artificially generated or manipulated. Deployers who produce or manipulate content that constitutes a deepfake of real persons, places or events must disclose that the content is artificial. A parallel duty applies to AI-generated or manipulated text published to inform the public on matters of public interest.
Third, deployers of emotion recognition and biometric categorisation systems must inform the people exposed to them and process any personal data in line with EU data protection law. Narrow exceptions apply where such systems are permitted by law to detect, prevent or investigate criminal offences.
Breaches fall under Article 99(4), which provides for administrative fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. Enforcement sits with national competent authorities rather than with Brussels.
Two supporting instruments arrived shortly before the deadline. The European Commission adopted final guidelines on transparency obligations on 20 July 2026. A voluntary Code of Practice on Transparency of AI-generated Content, published in June, was confirmed by the Commission and the AI Board as an adequate route to demonstrating compliance; the Commission has said roughly 190 organisations had signed it by the end of July. Signing creates no new legal duty and does not displace the obligation in the Regulation itself.
One narrow carve-out survives. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2). Everything else applied on the day.
Why the high-risk deadline moved to December 2027
The instrument responsible is Regulation (EU) 2026/1744, known as the AI Omnibus. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July, days before the deadline it amended.
The central change is timing. Obligations for standalone high-risk systems listed in Annex III, which cover recruitment, credit scoring, education, law enforcement, border control and critical infrastructure, now apply from 2 December 2027. High-risk AI embedded in products already regulated under Annex I product safety legislation, such as medical devices and lifts, applies from 2 August 2028.
The Omnibus made other adjustments. The AI literacy duty in Article 4 was softened, database registration was streamlined for systems assessed as not high-risk, and the post-market monitoring template became voluntary guidance. It also added a prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material, carrying fines of up to 35 million euros or 7 percent of worldwide turnover from 2 December 2026.
Governance shifted too. The European AI Office, rather than national regulators, now holds direct supervisory authority over AI systems built on general-purpose AI models by the same provider, and over AI features embedded in very large online platforms designated under the Digital Services Act.

Replio · AI customer support
Your customers message at 2am. Answer them anyway.
An AI agent trained on your own business replies in seconds on WhatsApp, Instagram, Telegram and your website, in your customer’s language.
Who is actually enforcing the new duties
Enforcement depends on national authorities, and the map is incomplete. Member states were required under Article 70 to designate a market surveillance authority and a notifying authority by 2 August 2025. Many did not.
According to the AI Act implementation tracker maintained by the Future of Life Institute, updated in June 2026, nine member states had designated both authorities, twelve had pending legislative proposals or had appointed only one, and six had designated neither. Fundamental rights authorities under Article 77 are in better shape: all 27 member states have published those.
France illustrates the pattern. A published scheme proposes a decentralised model, with the DGCCRF acting as coordinating market surveillance authority and single point of contact and sectoral regulators handling specific use cases. It has not completed its passage. Germany’s federal cabinet adopted a draft AI market surveillance bill in February 2026 naming the Bundesnetzagentur, but that text still requires approval by both chambers.
The obligations therefore bind companies everywhere in the single market from 2 August 2026, while the machinery for policing them is uneven. The Regulation is directly applicable, and where authorities exist they can act, so early enforcement is likely to be concentrated in the jurisdictions that finished their preparations.
Companies running customer-facing assistants are among the most immediately exposed, since chatbot disclosure is the simplest duty to check and the easiest to fail. Our earlier reporting on AI customer support on WhatsApp and Instagram sets out how quickly those tools have spread through small businesses.
The road ahead for AI compliance in Europe
The next fixed date is 2 December 2026. The marking grace period for pre-existing generative systems ends, so legacy tools must carry machine-readable provenance signals, and the new prohibition on nudification tools and CSAM-generating systems begins to apply at the Act’s highest penalty level.
After that, 2 August 2027 is the deadline for member states to establish AI regulatory sandboxes. Commission guidance on post-market monitoring is due by 2 September 2027. The deferred Annex III high-risk obligations arrive on 2 December 2027, and the Annex I obligations on 2 August 2028.
For businesses outside Europe, the reach is the familiar one. The Act applies to providers placing systems on the EU market and to deployers established in the Union, wherever the developer sits. A chatbot built anywhere that serves European users falls within scope.
Common questions about the new obligations
Which EU AI Act obligations became enforceable on 2 August 2026?
The transparency duties in Article 50. Providers of AI systems that interact directly with people must make clear users are dealing with a machine unless it is obvious from context. Providers and deployers of systems generating synthetic audio, image, video or text must mark those outputs in a machine-readable format, and deployers must disclose deepfakes of real people, places or events.
Did the high-risk AI system rules take effect on the same date?
No. Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026 and moved the obligations for standalone high-risk systems listed in Annex III to 2 December 2027. High-risk AI embedded in products regulated under Annex I moves to 2 August 2028.
What are the penalties for breaching the transparency duties?
Article 99(4) sets administrative fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. National competent authorities enforce them.
Is there a grace period for existing generative AI systems?
A narrow one. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation in Article 50(2). The other duties applied immediately.
Does signing the Code of Practice guarantee compliance?
No. The Code is voluntary and creates no new legal duties. The Commission and the AI Board have confirmed it is adequate for demonstrating compliance with Article 50, so following it is a recognised route, but the obligation sits in the Regulation itself.
For related coverage of how European regulators are applying digital and financial rules in practice, see our report on the Noones shutdown and the handling of user funds under EU sanctions.
Replio · AI customer support
Running a business while you study abroad?
Replio answers your customers on WhatsApp, Instagram and Telegram while you are in class, asleep, or five time zones away.

