Europe just switched on the AI Act's transparency rules. The line every chatbot now has to say is the part that will travel furthest.
The reported deadline covered the whole law. The binding text covers three narrow duties, a 'voluntary' code that isn't really voluntary, and a watermark no one builds for Europe alone.

Image: David Iliff / Wikimedia Commons (CC BY-SA 3.0)
The reported version is that Europe's AI law arrived on the second of August. Headlines said the AI Act "took effect," that the EU was now "regulating AI," that the deadline everyone had been warned about had finally landed. Read the text and a narrower, more precise thing happened. What switched on that Sunday was one article — the transparency obligations of Article 50 — plus the authority of the Commission's new AI Office over the largest general-purpose models. The heavy part of the statute, the high-risk regime that governs AI in hiring, credit, medical devices and critical infrastructure, did not arrive. It was moved, by a late amendment, to December 2027 and, for systems built into regulated products, to August 2028.
So the useful question is not "did the AI Act take effect" — parts of it have been in force since 2025, quietly — but which clause became binding on whom, and what it actually requires them to do. The answer is that the cheapest, narrowest, hardest-to-enforce slice of the law went live, and it happens to be the slice most likely to become a global default. Both of those things are true at once, and neither is in the headline.
What the operative clause actually says
Article 50 is not one obligation. It is three, resting on different parties, and the distinctions are the whole of it.
- Providers of AI systems that interact with people — chatbots, voice assistants, agents — must ensure the person is informed they are dealing with a machine, unless that is already obvious from the circumstances.
- Providers of generative AI that produces synthetic audio, image, video or text must mark the output in a machine-readable format and provide a way to detect that marking — a watermark and a reader for it — subject to exceptions for standard editing and non-substantial changes.
- Deployers who publish deepfakes, or AI-generated text on matters of public interest, must disclose that the content is artificially generated or manipulated — unless it has undergone substantive human editorial review and a person has assumed editorial responsibility for it.
- Deployers of emotion-recognition or biometric-categorisation systems must tell the people exposed to them that the system is in use.
A lawyer reads a list like that for the exemptions, because the exemptions are where the obligation is actually set. "Unless it is obvious" decides how many chatbots ever have to announce themselves. And the deepfake rule's carve-out — no disclosure required where a human took "editorial responsibility" — is the clause a newsroom, a studio or an advertising agency drives straight through: put a named editor behind the synthetic content and the labelling duty lifts. That is not a loophole in the pejorative sense; it is a deliberate line between an automated feed and an edited publication. But it means the rule bites hardest on the anonymous and the automated, and barely at all on the institutional, which is close to the opposite of how the coverage describes it.
There is also a grace period the summaries skip. The marking obligation on generative systems already on the market does not bite until the second of December 2026; content generated and published before the August date does not have to be retroactively labelled. "In force" and "enforced against you today" are, as ever, two different states.
Who it binds, which is nearly everyone
The most common misreading of any EU digital statute is that it governs European companies. It governs the European market. Article 50 binds any provider placing a covered system on that market, which means the American and Chinese labs — OpenAI, Anthropic, Google, xAI and the rest — are squarely in scope the moment their models are available to someone in the Union. A firm with no office in Europe still has to mark its outputs if Europeans can use it.
That is the mechanism by which a rule written in Brussels becomes a feature everywhere. No lab is going to build one model that watermarks its output for European users and a second, unmarked model for everyone else; the marking goes into the model, and the model ships worldwide. The obligation is technically a European one and practically a global one, for the same undramatic reason every previous EU digital rule became the default: no one maintains a separate product for one market when compliance is cheaper to build once. The fine stops at the Union's border. The watermark does not.
The fine stops at the Union's border. The watermark does not. — On why a European labelling rule becomes a global default
The rulebook is the code, and the code is 'voluntary'
The Commission did something with this article that is easy to miss and worth stating plainly: it published a Code of Practice on the transparency of AI-generated content, and more than 180 organisations signed it as the obligations went live. Signatories, the Commission says, receive a presumption of conformity and a more favourable enforcement posture. Non-signatories face closer scrutiny and have to demonstrate compliance some other way.
Translate that. A voluntary code to which the regulator has attached a presumption of conformity is not, in any operational sense, voluntary. It is the operative standard, wearing softer clothing. Sign it and you are presumed to comply; decline and you carry the burden of proving you comply without it, before an authority the code has told you is watching you more closely. The article says what must be achieved — marking, detection, disclosure — in general terms; the code says how, in specific ones, and the specifics are where a compliance department actually lives. This is a familiar Brussels move, and a legitimate one: it lets the detailed rules evolve with a technology faster than a statute can. But it means the document that binds you in practice is the one that was never voted on, and that is worth knowing before you call the regime light-touch.
In force is not enforced
Here the gap between the reported and the binding runs the other way, in industry's favour. Transparency duties are live on paper, but enforcement runs through machinery that is not fully assembled. The AI Office enforces the rules for general-purpose models directly — it can demand documentation, run evaluations, order corrections and levy fines. Everything else runs through national competent authorities, and member states were supposed to have designated those authorities by the same second of August. A number of them have not. Until each capital has stood up a regulator with staff and a mandate, the same clause is enforceable in one member state and merely aspirational in the next.
So the load-bearing date is not the second of August. It is whenever the last member state names its authority, and whenever the AI Office issues its first real demand to a large model provider — because that is the day the market learns what the text means in practice rather than in principle. A deadline that arrives before its enforcers do is a commitment, not yet a constraint. The Commission's own framing — Executive Vice-President Henna Virkkunen said the Act gives "innovators legal certainty while protecting the public interest" — is doing quiet work in that sentence: certainty is exactly what a half-designated enforcement system does not yet provide.
What the penalties are, and why they're the least of it
The numbers, precisely, because they are usually reported vaguely. Breach of the transparency obligations carries fines of up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher. The same ceiling applies to the general-purpose-model obligations the AI Office oversees. The Act's heaviest tier — up to 35 million euro or 7 percent of turnover — is reserved for the prohibited practices, the uses Europe has banned outright, and those are a separate part of the statute from the transparency rules that just went live.
But the fine is the least consequential part of this article, for the reason already given: the marking standard travels regardless of whether anyone is ever fined. A company weighing a 3 percent penalty it might one day face in one jurisdiction against the cost of re-architecting a global model will, in most cases, simply build the watermark. The behaviour changes not because the fine is large but because the cheapest path to compliance is a product change that then ships everywhere. That is the Brussels Effect doing its work through engineering budgets rather than courtrooms.
The honest limit: a watermark you can rub off
It would be a poor reading of this law to pretend it does what its supporters hope. The obligation is to mark synthetic content in a machine-readable way and to make the mark detectable. For images, audio and video that is technically meaningful, if imperfect. For text it is close to wishful: a watermark on generated prose is fragile, and a determined actor strips it by paraphrasing, re-typing, or running the passage through a second model. The rule therefore protects the honest platform — which will mark, disclose and sign the code — and waves at the malicious deepfaker, who was never going to label anything and now simply removes the label the compliant tools apply.
This is the standard shape of a transparency mandate: it raises the floor for the law-abiding and does little to the lawbreaker, and it is worth being honest in both directions about that. The law is not theatre — a default that makes most synthetic content on mainstream platforms detectable is a real public good, and the disclosure duties on interactive systems and biometric tools are enforceable in a way the text watermark is not. But anyone told this rule ends the deepfake problem has read the press release, not the clause. The one place the law moved faster rather than slower is telling: the generation of non-consensual sexual imagery and child sexual abuse material is being pushed to a December 2026 prohibition, ahead of the rest — an acknowledgement that for the worst harms, disclosure was never going to be enough, and only a ban would do.
The line that travels
Strip it back and Europe did something small and durable at once. It did not build the models, and it did not, this month, switch on the parts of its law that will most change how AI is used in the decisions that matter. What it did was write a single sentence that every general-purpose model sold into its market now has to be able to speak — in effect, "I am not a person, and this was made by a machine" — and attach to that sentence a code of practice that defines, in operational detail, how the sentence must be said. Because no one ships a separate model for one market, that sentence becomes the global default, enforced less by the Commission's fines than by the labs' own preference to build a thing once.
The deadline was the announcement. The operative clause, its exemptions, and the code that fills them in are the achievement, and they will outlast the news cycle that misdescribed them. The date to watch now is not the one that just passed but the two still ahead: the December grace period, when the marking duty actually bites, and the first enforcement action the AI Office brings against a model provider. Until then the rule is in force, unevenly enforced, and already, quietly, being built into products a long way from Brussels.
References
- European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August
- Cooley — EU AI Act: Transparency Obligations Take Effect 2 August 2026
- Wilson Sonsini — EU AI Act Enforcement Phase Begins
- Help Net Security — EU begins enforcing AI Act, putting AI models under the microscope
- European Commission — Safer and more transparent AI


