As of August 2, the EU’s AI Act moved from legislation to active enforcement. The same deadline brought new transparency rules into effect. These require certain AI systems to tell users when they’re interacting with AI, flagging any content that has been generated or altered by AI.
Chatbots are one of the main areas that are affected. They have to show that they are automated systems. The legislation goes further. Deepfake images must carry a machine-readable tag, marking them as machine-made or edited.
For any company that falls foul of these regulations, they could be facing a fine of up to €15 million or 3% of their worldwide annual turnover, whichever is higher.
The International Picture
This increased scrutiny on AI systems within Europe clashes with recent comments made at Black Hat, where the National Cyber Director Sean Cairncross said that the administration will lead on industry collaboration, rather than regulation.
In his keynote speech, Cairncross said that a regulatory regime “would not only strangle growth, development and innovation… but it would be obsolete 48 hours after” it was written.
This is perhaps the starkest difference in policy terms between the US and Europe, with another key player in the AI development market being China.
China represents a third policy area. Rather than a single blanket law, Beijing has regulated AI sector by sector. There are separate rules cover recommendation algorithms, generative AI content, and synthetic media. Its Generative AI Regulation, in effect since 2023, already requires providers to label AI-generated content, though the obligation is framed around preventing content that undermines state authority rather than protecting individual rights.
China announced plans for its first unified AI law in 2026, which would consolidate that patchwork. The policy distance from Brussels remains wide: where the EU ties regulation to transparency and rights, Beijing anchors it to content control and national security.
The Act imposes additional obligations on providers of the most powerful AI models (defined as general-purpose AI (GPAI) systems trained above 10²⁵ floating point operations). These providers must conduct adversarial testing, assess and mitigate systemic risks, and report serious incidents to the EU AI Office.
The risk categories the Act identifies include chemical, biological, radiological, and nuclear threats, cyber offence, harmful manipulation, and fundamental rights. The European Commission has also published a code of best practice to help ensure that organizations are operating in accordance with the public’s expectations.