Omi Iyamu · Personal DossierVol. XVII · 2026 Edition
Omi Iyamu.
← All essays
2026 · 08 · 034 min read

Commission starts enforcing AI Act rules and new transparency requirements on 2 August

# The EU AI Act stopped being a deadline this weekend

Sunday, August 2, was the day the European Commission's supervision and enforcement powers over general-purpose model providers came into force. The obligations on GPAI providers have been in law since August 2, 2025; what changed this weekend is that the AI Office can now request documentation, conduct model evaluations, order recalls, and levy fines of up to 3% of global turnover or 15 million euros, whichever is higher. Article 50 transparency duties for chatbots, voice agents, and AI-generated content landed the same day, with the machine-readable-marking obligation getting a grace period until December 2 for systems already on the market.

Two things happened at once, and it is worth pulling them apart.

**The GPAI supervision half.**

If you provide a general-purpose model to the EU market — and "provide" here is broad, meaning make available, not just sell — the Commission can now ask you for your training-data summary, your evaluation results, and your incident-reporting posture, and hand out fines if you do not deliver. About 24 organizations signed the GPAI Code of Practice, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral, and Aleph Alpha. Meta declined. A larger group — around 190 organizations by end of July, per public reporting — signed the separate Code on marking and labeling AI-generated content.

Signing the Code buys presumption of conformity, which the AI Office has said is weighed when a fine is calculated. Not immunity. A documented mitigating factor.

If you are a US or Middle East AI company doing business in the EU and you have not decided whether to sign, the decision was for last month, not this one. If you did decide not to sign — Meta's position — you need a defensible written record of why your bespoke compliance approach meets the Act's substantive requirements. Not a memo. A record you would show a regulator on 24 hours' notice.

**The transparency half.**

Article 50 is the piece that reaches most product teams, not just labs. From Sunday:

- Chatbots and voice agents that interact with people have to disclose they are AI, at the first interaction, in a clear and distinguishable way. Burying it in the terms of service does not count. - Deepfakes and AI-manipulated content have to be labeled. - AI-generated or manipulated content has to carry machine-readable marks so downstream systems can detect it.

If you ship a customer-facing agent in the EU, that first bullet is your immediate work. If you are wondering whether a voice interviewer, a support chatbot, a legal intake bot, or a scheduling assistant needs disclosure — yes. If it interacts with a person and there is any chance the person would think they were talking to a human, disclose.

The one nuance that comes up a lot: "obvious from context" is a get-out clause in the text. Do not lean on it. Any regulator who has to argue about whether it was obvious in your case is already halfway to a fine. Just disclose, cleanly, in a place the user reads.

**What actually moves this week for a team shipping into the EU.**

Three things, in order.

One: write down whether your product touches the EU in a way that triggers GPAI provider obligations, deployer obligations, or the Article 50 duties. If you touch users in the EU, the transparency duties apply to you whether you are a GPAI provider or not. Write this down; do not carry it in someone's head. If you are ever asked, you want to show a document, not a Slack thread.

Two: audit your customer-facing surfaces for disclosure. Every chatbot. Every voice agent. Every assistant flow that is not clearly a human. Add a first-interaction disclosure, log it, and pull it into your compliance evidence pack.

Three: if you generate or modify content, decide how you are marking it. C2PA, watermarks, both. There is a grace period on the machine-readable marking until December 2 for pre-existing systems, but that is a smaller runway than it looks. Start now.

**The things I would not do this week.**

I would not panic-sign the Code of Practice without reading it. If you are not a frontier-model provider, the Code's substantive commitments may not fit your posture, and signing a document you cannot honor is worse than not signing one.

I would not treat Sunday's date as a cliff. The enforcement powers came into force; the enforcement actions will take months. What arrives this year is information requests, model access requests, and the occasional public warning. The Commission is not going to open with a 15 million euro fine on a company that answers its emails.

I would not defer this to legal. If you are a technical leader shipping AI, the disclosure text, the training-data documentation, and the eval evidence are your work as much as anyone's. Legal writes the contract; you write the facts.

**What I am doing.**

The two projects on my desk that touch EU users are getting a disclosure audit this week. Same first-interaction disclosure pattern in both. Same log line. Same evidence bundle. Cheap to do once, expensive to retrofit under a regulator's clock.

If you have written a disclosure line you are proud of — the one where the tone matches the product and the words survive a five-second glance — reply and send it. I am collecting a small library of ones I would cite.

If this was useful, the weekly Brief covers shorter ideas like this every Wednesday.
Read the Briefs →
© Omi Iyamu · MMXXVIContact → · linkedin.com/in/omiiyamu