TLDRocket
Sign in

Europe starts enforcing AI Act rules

Sifted Covered by 58 sources

Brussels just flipped the switch on AI Act enforcement. Chatbots must confess they're bots, deepfakes need labels, or firms risk fines up to 3% of global revenue.

The EU's AI Act stopped being a policy document on August 2 and became something companies actually have to answer to. The European Commission's AI Office, working alongside national regulators across the bloc, began enforcing a new batch of transparency rules that touch everything from customer service chatbots to viral deepfake videos.

The core idea is simple enough: people deserve to know when they're talking to a machine instead of a human, and AI-generated content that could pass as real needs some kind of tag. Certain categories of manipulated media now require machine-readable markers, the digital equivalent of a watermark that software can detect even if a human eye misses it. General-purpose AI models, the kind powering most chatbots on the market, fall under the AI Office's direct watch, while national authorities take on enforcement for the rest.

Lawyers are already warning clients that this net is wider than most executives assume. Marcus Evans at Norton Rose Fulbright points out that the obligations don't stop at OpenAI or Google — any company slapping its own branding on a third-party AI tool can find itself on the hook too. That's a meaningful shift for the mid-size software vendors and retailers who've spent the last two years bolting AI features onto their products without much thought about who's legally responsible for the label on the box.

The money at stake is real: fines can reach 3% of a company's global annual turnover, a number large enough to get a general counsel's attention regardless of where that company is headquartered. Peter Van Dyck at A&O Shearman says US AI labs are particularly rattled, since the rule applies based on where outputs land, not where the model was built. If a chatbot's answers reach a user in Berlin or Warsaw, Brussels considers it fair game.

Still, nobody expects raids on day one. Van Dyck's read is that regulators will start by asking for evidence of good-faith compliance efforts rather than dropping maximum penalties immediately. That grace period, however, has a shelf life, and companies that treat this week as a formality rather than a deadline are the ones most likely to get made an example of once enforcement matures.

My take

I've watched enough US labs treat 'we'll figure out compliance later' as an actual strategy to find this refreshing — Brussels finally has teeth, not just a white paper. The real test isn't the fine print, it's whether regulators go after the small companies slapping AI branding on borrowed models, because that's where the actual confusion for users lives, not in OpenAI's terms of service.

Read more about this at: Sifted

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads 60+ sources, removes duplicate coverage, and summarises the day in two minutes. Free, no spam, unsubscribe anytime.