Tag Archives: AI regulation Europe

One Month Into the EU’s New AI Rules, Here’s Who’s Actually Complying

The European Union’s AI rulebook has had a month to bite. EU AI Act transparency obligations took effect August 2. The European Commission’s AI Office and national regulators began enforcing rules that require AI systems to disclose their own involvement. Four areas are covered: direct interaction with people, AI-generated content, emotion recognition and biometric categorization, and deepfakes or AI-generated text on public-interest matters.

In practice, that means chatbots must tell users they are talking to a machine. Deepfakes need visible labels. AI-generated or altered content must carry machine-readable marks so platforms and researchers can detect it. Companies that don’t comply face fines up to €15 million or 3% of global annual turnover, whichever is larger. National market surveillance authorities, the European AI Office and the European Data Protection Supervisor enforce the penalty structure in parallel.

EU AI Act transparency

What EU AI Act transparency actually requires day to day

The rule’s four categories cover most consumer-facing AI use cases already in wide circulation. A customer-service chatbot on a European retail site now needs a clear disclosure at first contact. A marketing image generated or substantially altered by AI needs a machine-readable mark, not just a small watermark a user might miss. Emotion-recognition and biometric categorization systems, used in some retail and workplace settings, now require explicit disclosure to the people being monitored.

The AI Office has also published a voluntary Code of Practice on Transparency of AI-Generated Content. Several major AI providers have already signed on. That gives companies a template for compliance, rather than requiring each to interpret the regulation from scratch.

How this compares to the US approach to AI regulation

The EU’s transparency-first approach contrasts with Washington’s posture. The Commerce Department has signaled new rules are coming for AI chips and semiconductors, not for AI-generated content disclosure. That US regulatory track targets hardware supply chains. Brussels is regulating the output layer instead — what users see and interact with, rather than what powers it underneath.

China has taken a third approach. It recently fined AI companion apps for what regulators called inappropriately close engagement with users, a move covered in our reporting on Beijing’s AI companion crackdown. Three major regulatory blocs are now pursuing three distinct enforcement philosophies for the same underlying technology.

What happens next for companies still catching up

National regulators have signaled a phased enforcement approach. They are prioritizing the largest platforms and most visible violations first, rather than pursuing every noncompliant chatbot at once. Legal advisers tracking the rollout expect the first public fines to land in the coming months. Those are likely to target companies that ignored disclosure requirements entirely, rather than those that made good-faith but imperfect attempts at compliance.

Smaller companies building on top of major AI providers face a practical question. Does their chosen model provider’s compliance cover their own product, or do they need separate disclosure measures? Legal guidance from law firms including Cooley and Stibbe generally advises deployers not to assume upstream compliance protects them. The obligation applies at the point of user interaction, not just at the model level.

What compliance looks like for a small business

A small e-commerce site running an AI chatbot for customer support does not need a legal department to comply. It does need a few concrete changes. Those include a visible statement at the start of a chat session that the user is talking to an AI system, a process for labeling AI-generated product images or marketing copy, and a documented record of which disclosure measures are in place in case a regulator asks. Firms building on top of major providers’ APIs generally still carry this obligation themselves. The rule targets the point of interaction with the end user, not the underlying model.

Industry advisers say the most common compliance gap so far is not malicious evasion but simple oversight. Companies adopted AI tools for internal efficiency and only later realized customer-facing outputs also fall under the transparency rule. The Code of Practice published by the AI Office is designed to close that gap. It gives smaller companies language and formatting they can adopt directly, rather than drafting disclosure text from scratch.

Companies operating only outside the EU are not automatically exempt either. The rule applies based on where users are located, not where the company is headquartered. A US or Asia-based platform with European customers still needs to meet the same disclosure standard for the portion of its user base interacting from within the bloc. Legal teams at global platforms are treating that geographic split as a genuine engineering requirement, not just a policy footnote.

FAQ

When did the EU AI Act transparency rules take effect?

August 2, 2026.

What four areas do the rules cover?

Direct interaction with individuals, AI-generated content, emotion recognition and biometric categorization, and deepfakes or AI-generated public-interest content.

What are the penalties for noncompliance?

Fines up to €15 million or 3% of global annual turnover, whichever is greater.

Who enforces the transparency rules?

National market surveillance authorities, the European AI Office, and the European Data Protection Supervisor.

Is there a compliance template companies can follow?

Yes, the AI Office published a voluntary Code of Practice on Transparency of AI-Generated Content that several major providers have signed.

Does using a compliant AI model automatically make my product compliant?

Not necessarily. Legal advisers say the disclosure obligation applies at the point of user interaction, so deployers generally need their own compliance measures.