← All posts / Policy

The EU AI Act's Transparency Rules Are Now Law — Most Companies Aren't Ready

Article 50 transparency obligations and high-risk system requirements under the EU AI Act became enforceable on August 2, 2026. Fines reach €35M or 7% of global revenue — yet 78% of organizations have done nothing.

The EU AI Act's Transparency Rules Are Now Law — Most Companies Aren't Ready

On August 2, 2026, a regulatory clock that had been ticking for over two years finally struck zero. The European Union’s AI Act — the world’s first comprehensive legal framework for artificial intelligence — entered its most consequential enforcement phase. Two massive categories of obligations kicked in simultaneously: the full requirements for high-risk AI systems under Articles 9 through 15, and the transparency duties of Article 50 that touch virtually every business using generative AI.

The stakes are enormous. Maximum penalties reach €35 million or 7% of a company’s worldwide annual turnover, whichever is higher — exceeding even the famously steep fines under GDPR. And yet, according to compliance tracking from Responsible AI Labs, roughly 78% of affected organizations have taken no meaningful steps toward compliance. The gap between legal obligation and operational reality has rarely been wider.

What Actually Changed on August 2

The August 2 deadline activates two distinct but overlapping sets of rules. Understanding both is essential for any organization deploying AI in or into the European market.

Article 50: Transparency Obligations

Article 50 imposes four core transparency duties on both providers and deployers of AI systems. Unlike the high-risk regime, these rules are not limited to a narrow set of applications — they apply broadly to any AI system that meets their triggers.

1. AI Interaction Disclosure. Providers must ensure that AI systems designed to interact with humans — chatbots, virtual assistants, customer service bots — are built so that users are aware they are communicating with a machine, not a person. This obligation rests on the provider (the entity that develops the system), but deployers share responsibility for ensuring the disclosure functions in practice.

2. Emotion Recognition Systems. Deployers of AI systems that detect emotions or intentions based on biometric data must inform the people being analyzed. This covers workplace monitoring tools, retail analytics, and educational assessment platforms that infer emotional states from facial expressions, voice patterns, or physiological signals.

3. AI-Generated Text on Public Interest Matters. Deployers who use AI to generate or manipulate text published on matters of public interest — news articles, policy commentary, public-facing reports — must disclose that the content was artificially produced or substantially modified. This provision targets the erosion of public trust in media and information ecosystems.

4. Deepfake Disclosure. Deployers of AI that generates or manipulates images, audio, or video constituting a deepfake must disclose that the content has been artificially created or altered. This obligation carries notable exceptions: content created for artistic, creative, satirical, or analogous legitimate purposes is exempt, provided the disclosure doesn’t interfere with the work’s enjoyment. Law enforcement and judicial uses are also carved out.

High-Risk AI Systems: Articles 9–15

The second wave of obligations covers the AI Act’s high-risk category — systems used in sensitive domains that could significantly affect health, safety, or fundamental rights. Annex III enumerates these domains: recruitment and employment, credit scoring, education, critical infrastructure management, law enforcement, migration and border control, and democratic processes.

For these systems, providers and deployers must implement a comprehensive risk management framework (Article 9), ensure data governance and training data quality (Article 10), maintain technical documentation (Article 11), enable logging and auditability (Article 12), provide instructions for use (Article 13), design for human oversight (Article 14), and meet accuracy, robustness, and cybersecurity standards (Article 15). Each obligation carries its own detailed technical requirements — Article 9 alone runs to multiple sub-paragraphs defining iterative risk identification, mitigation, and residual risk evaluation.

A conformity assessment is required before a high-risk system can be placed on the EU market. For systems already deployed before August 2, 2026, operators must bring them into compliance — though the transitional framework provides some breathing room for certain embedded systems, with extended deadlines running through August 2, 2027, and even December 31, 2030, for specific legacy systems.

The Code of Practice and Technical Standards

On July 31, 2026 — just two days before enforcement began — the European Commission’s AI Office published the Code of Practice on Transparency of AI-Generated Content. This document provides practical guidance on how to satisfy Article 50’s marking and labeling requirements. It complements the broader regulatory framework and signals the Commission’s expectation that technical solutions like C2PA (Coalition for Content Provenance and Authenticity) provenance certificates, invisible watermarks, and machine-readable metadata labels will form the backbone of compliance.

For companies like OpenAI, Google, Anthropic, and Meta, the Code of Practice is particularly significant. These providers must ensure their models’ outputs can be reliably marked — a technical challenge that has already driven investment in watermarking infrastructure across the industry. Anthropic’s invisible text watermark for Claude, Google’s SynthID, and OpenAI’s C2PA-based image provenance system all predate the deadline, but the August 2 enforcement date transforms these features from voluntary good practices into legal expectations.

Who Is Affected — and How Wide the Net Reaches

A common misconception is that the AI Act only applies to EU-based companies. In reality, the regulation has extraterritorial reach: any provider or deployer whose AI system’s output is used in the European Union falls within its scope. This means U.S., UK, and Asian companies that serve European users are subject to the same obligations.

Holland & Knight’s legal analysis, published in April 2026, emphasized that American companies operating high-risk AI systems — in hiring, lending, or healthcare — face the same compliance measures as their European counterparts. The law firm noted that the industry pressure that delayed certain provisions of the original timeline did not delay the August 2 deadline for Article 50 transparency or the core high-risk obligations. That date arrived regardless.

The breadth of impact is striking. Marketing agencies using generative AI for ad copy, media organizations publishing AI-assisted articles, HR departments deploying algorithmic screening tools, financial institutions using AI for credit decisions, and retailers employing emotion-detection analytics all fall under the new rules. Small and mid-sized businesses — not just tech giants — are squarely in scope.

The Readiness Gap

Perhaps the most alarming data point comes from compliance surveys conducted in the weeks before the deadline. Responsible AI Labs reported that 78% of organizations subject to the high-risk requirements had not begun compliance work as of early August. The Cloud Security Alliance’s research noted a similar pattern: while large enterprises had invested in AI governance programs, the vast majority of mid-market companies were unprepared.

The reasons are understandable. Article 50’s deepfake disclosure provision sounds simple in principle but raises thorny questions in practice: What counts as “artistic”? How should disclosure be implemented for audio content played on the radio versus a social media clip? Must every AI-assisted photo edit be labeled, or only fully synthetic images? The Code of Practice offers guidance, but many edge cases will only be resolved through enforcement actions and eventual court decisions.

For high-risk systems, the challenge is even steeper. Building a risk management system that satisfies Article 9, maintaining the technical documentation required by Article 11, and ensuring human oversight under Article 14 are not checkbox exercises — they demand sustained engineering and governance investment. Companies that treated GDPR as a one-time compliance project are learning that the AI Act’s obligations are even more deeply embedded in product development workflows.

Fines That Bite

The penalty structure under Article 99 of the AI Act is deliberately punitive. Violations of prohibited AI practices carry fines up to €35 million or 7% of global annual turnover — whichever is higher. Breaches of high-risk obligations result in fines up to €15 million or 3%. Supplying incorrect or misleading information to authorities can trigger fines of €7.5 million or 1%.

These figures exceed GDPR’s maximum of 4% of global turnover, which itself produced record-breaking fines against Meta, Amazon, and others. The AI Act’s higher ceiling reflects the European legislature’s view that AI poses risks of a fundamentally different order than data privacy violations alone.

What Comes Next

The August 2 deadline is not the end of the AI Act’s rollout. Additional obligations phase in through 2027 and beyond. GPAI (general-purpose AI) model requirements took effect in August 2025, and certain high-risk systems embedded in regulated products have until August 2, 2027. The transitional framework for legacy systems extends to 2030 for specific categories.

But for the vast majority of organizations, August 2, 2026 was the line in the sand. The transparency rules are live. The high-risk obligations are enforceable. The fines are real. And the European Commission has signaled it intends to enforce aggressively, drawing on lessons from GDPR’s early years when enforcement was perceived as slow.

For any organization using AI in ways that touch European users, the message is clear: the era of voluntary AI safety principles is over. The era of legally binding, financially consequential AI regulation has begun — and the clock is already running.


This article is based on reporting from Cooley LLP, the European Commission’s Digital Strategy portal, Responsible AI Labs, the Cloud Security Alliance, and the EU AI Act’s official text. It was researched and written on August 12, 2026.