For most of its life, the European Union's Artificial Intelligence Act has been a law on paper — a sprawling framework that companies read about, debated, and prepared for, but rarely had to answer to. That changed on August 2, 2026. On that date the Act crossed from drafting and guidance into something with teeth: a set of obligations that regulators can now investigate, demand documents about, and fine companies for ignoring. It is the moment the world's first comprehensive AI law stopped being a promise and became an enforcement regime.
What Happened
Two things switched on at once. The first is a bundle of transparency duties under Article 50 of the Act. From August 2, providers and deployers of certain AI systems have to be honest, in plain terms, about the fact that a machine is involved. People interacting with a chatbot must be told they are talking to software rather than a human. Synthetic images, audio, and video — the raw material of deepfakes — have to be marked in a machine-readable way so that platforms and downstream tools can detect them. Systems that recognize emotions or sort people into biometric categories must disclose that they are doing so. And AI-generated text published to inform the public on matters of public interest has to be labeled as such. None of this depends on whether a system is formally "high-risk"; the transparency rules apply across the board.
The second change is about who can now act. The European Commission's AI Office, which became operational back in August 2025, formally gained the power to enforce the rules governing general-purpose AI models — the large foundation models that sit underneath most consumer AI products. As several law firms tracking the rollout have noted, the Office can request technical documentation from model providers, evaluate the models themselves, demand risk-mitigation measures, and levy penalties. National market-surveillance authorities, meanwhile, can enforce the Article 50 transparency rules within their own borders. The penalty tiers are not symbolic: violations of the GPAI and transparency provisions can reach the greater of fifteen million euros or three percent of a company's total worldwide annual turnover.
Why It Matters
The significance of August 2 is less about any single rule than about a shift in posture. Until now, the AI Act's most demanding requirements lived in the future tense. Companies could point to a compliance roadmap and a distant deadline. With enforcement powers live, the conversation moves from intention to evidence — regulators can knock, and the answer has to be more than a slide deck.
The transparency obligations in particular reflect a distinctly European bet about how to govern a technology that is moving faster than any legislature. Rather than trying to certify every model as safe up front, the Act starts by insisting that people know when they are dealing with a machine and when content has been synthesized. It is a disclosure-first philosophy, closer in spirit to food labeling than to pharmaceutical approval. The wager is that a well-informed public and a traceable trail of synthetic media will do more, sooner, than a thicket of technical mandates that arrive years late.
There is also a gravitational effect that reaches well beyond Europe. Because the largest AI providers are global, and because rebuilding a product for a single market is expensive, obligations written in Brussels tend to become de facto defaults elsewhere — the same "Brussels effect" that made European privacy rules a worldwide template. A watermarking or disclosure standard that a company builds to satisfy the AI Office is unlikely to be switched off for users in other regions. In that sense, a rule that formally binds only inside the EU quietly sets expectations for how AI content should behave everywhere.
The Reaction
The mood among companies has been a mixture of scramble and relief, and the relief has a specific cause. In the months before the deadline, it became clear that the regulatory scaffolding needed to make the Act's toughest provisions workable had not been built on time. In response, EU institutions negotiated a package known informally as the Digital Omnibus, reaching a provisional political agreement in early May 2026 and confirming it among member states shortly after. As Gibson Dunn's analysis of the deal explains, the Omnibus pushes the most burdensome obligations — those covering "high-risk" AI systems used in hiring, credit scoring, education, and border control — out to late 2027 and 2028.
That deferral took real pressure off compliance teams who had feared a cliff edge on August 2. But it also drew criticism from the other direction. Digital-rights advocates and some lawmakers argued that repeatedly moving the goalposts risks hollowing out a landmark law before it has been tested, and that a deferral, however pragmatic, sends a signal that deadlines are negotiable. The counter-argument, offered by many in industry and by officials sympathetic to it, is that rules no one can actually implement do more harm than good, and that a workable law arriving a year late beats an unworkable one arriving on time. What almost everyone agrees on is that the underlying architecture of the Act — its risk tiers, its governance bodies, its core duties — remains intact. The Omnibus rescheduled the hardest parts; it did not repeal them.
What Comes Next
The immediate future is a set of dates that stretch across the next two years. The Omnibus changes only bind once they are formally adopted and published in the EU's Official Journal, so the first thing to watch is that publication landing on schedule. Assuming it does, a four-month grace period runs until December 2026 for the watermarking requirement as it applies to AI systems already on the market before August, giving existing products time to retrofit machine-readable markers into their output.
December 2026 also brings the end of a transitional window for a newly added prohibition — a ban, written into the Act's list of forbidden practices, on AI systems whose purpose or foreseeable use is generating non-consensual intimate imagery or child sexual abuse material. Further out, member states now have until August 2027 to stand up the regulatory "sandboxes" where startups can test AI under supervision, and the deferred high-risk obligations arrive in December 2027 for standalone systems and August 2028 for AI baked into regulated products like medical devices and vehicles. The practical guidance most compliance experts are giving is blunt: treat the extra time as room to build properly, not as a reason to stop. A governance framework for AI is not something a company can assemble in the final quarter before a deadline.
Closing Thoughts
It is tempting to read the story of August 2 as a familiar contest between regulation and innovation, with Europe cast as the cautious continent and its rules as a drag on progress. But the more interesting reading is about sequencing. The EU has chosen to make transparency the first obligation with real enforcement behind it, and to let the heavier machinery of high-risk certification arrive later, once the tools to support it exist. Whether by design or by necessity, that ordering says something about what is enforceable today: we may not yet know how to certify a foundation model as safe, but we can insist that a deepfake be labeled and that a person know when they are talking to a machine.
The deeper question the Act poses is one every jurisdiction will eventually face. As synthetic media becomes indistinguishable from the real thing and as general-purpose models seep into daily life, how much of governing AI is about controlling what the technology can do, and how much is simply about preserving people's ability to know what they are looking at? Europe has placed an early bet that disclosure is the foundation everything else rests on. The years between now and 2028 will test whether a law that starts with honesty — and only later reaches for harder guarantees — can keep pace with the thing it is trying to govern.
한국어 요약
2026년 8월 2일, 세계 최초의 포괄적 인공지능 규제인 EU 인공지능법(AI Act)이 '문서상의 법'에서 '집행되는 규제'로 전환됐다. 이날부터 AI법 제50조의 투명성 의무가 적용된다. 챗봇 등과 대화할 때는 상대가 사람이 아닌 AI임을 알려야 하고, 딥페이크를 포함한 합성 이미지·영상·음성에는 기계가 판독할 수 있는 표식을 넣어야 하며, 감정 인식·생체 분류 시스템과 공익적 사안을 다루는 AI 생성 텍스트도 그 사실을 밝혀야 한다. 동시에 유럽연합 집행위원회 산하 AI사무국(AI Office)은 대다수 AI 제품의 기반이 되는 범용 AI(GPAI) 모델에 대한 집행 권한을 공식적으로 갖게 됐다. 기수 문서 요구, 모델 평가, 위험 완화 조치 요구가 가능하며, 위반 시 최대 1,500만 유로 또는 전 세계 연매출의 3% 중 큰 금액의 과징금이 부과될 수 있다.
이번 조치의 핵심은 개별 규정보다 '태도의 전환'에 있다. 그동안 AI법의 가장 무거운 요구사항은 미래의 이이었고 기업은 로드맵과 먼 마감일을 제시하면 됐지만, 이제 규제 당국이 실제로 자료를 요구하고 제재할 수 있게 됐다. 특히 투명성 우선 접근은 모든 모델을 사전에 '안전'으로 인증하기보다, 사람들이 기계와 상호작용하는 시점과 콘텐츠가 합성됐다는 사실을 알 수 있게 하는 데서 출발한다. 의약품 습인보다 식품 라벨링에 가까운 철학이다. 글로벌 사업자들이 EU 기준에 맞춰 구축한 표식·고지 방식은 다른 지역에서도 사실상 기본값이 되는 '브룤셀 효과'로 이어질 가능성이 크다.
다만 마감 직전, 채용·신용평가·교육·국경관리 등에 쓰이는 '고위험' AI 의무는 '디지털 옴니버스(Digital Omnibus)' 합의를 통해 2027년 말과 2028년으로 미룄조다. 기업의 부담은 덜었으나, 디지털 권리 단체와 일부 의무들은 시행 전부터 법을 무르게 만든다고 비판했다. 앞으로는 옴니버스의 관보 게재, 2026년 12월까지의 워터마킹 유예와 비동의 성적 이미지·아동 성착취물 생성 금지의 경과기간 종료, 2027년 규제 샌드박스 구축 마감 등이 이어진다. 전문가들의 조언은 명확한다. 늘어난 시간은 준비를 제대로 할 여유이지 미룰 이유가 아니라는 것이다. 참고: Wilson Sonsini, Gibson Dunn, Stibbe.