On 2 August, a small honesty requirement quietly switched on across the European Union. If a piece of software is talking to you and it is an AI, it now has to tell you so. Not in the terms of service. To your face, in the conversation.

That is the most human-sized part of a much larger event. The same date is when the European Commission’s AI Office, working with authorities in each member state, began actually enforcing the AI Act, the sweeping law the EU passed to govern artificial intelligence. The text of the law is not new. What is new is the machinery behind it, the offices and the powers that turn a written rule into one that can be checked and fined.

Screenshot of the European Commission press release headlined 'Commission starts enforcing AI Act rules and new transparency requirements on 2 August', dated 31 July 2026.
The announcement, on the Commission's own Shaping Europe's digital future site.

What actually changes for a person

Three obligations start to bite, and they are unusually easy to explain.

A chatbot or other interactive AI has to disclose that it is an AI and not a person. A deepfake, meaning an image, a video or audio that has been generated or meaningfully altered by AI, has to be labelled as such. And AI-generated content more broadly has to carry a machine-readable mark, an invisible tag baked into the file so that other software can recognise it as synthetic even after a human eye has been fooled.

The stated goal is narrow and sensible: reduce deception, and give people a fair chance to know what they are looking at. The Commission frames it as good for business too, on the logic that clear obligations are easier to comply with than vague ones. More than 180 organisations have already signed a voluntary Code of Practice on labelling AI-generated content, which is the industry’s attempt to agree on how the marking actually gets done.

The office behind it now has powers

The quieter half of the story is enforcement. From this date the AI Office can demand technical documentation from the companies behind the largest general-purpose models, evaluate those models itself, order corrective measures and levy fines when a provider does not comply. National market surveillance authorities handle the rest. For a field that spent years governed mostly by its own press releases, a regulator that can ask to see inside the model is a real shift.

Where the honesty gets hard

It is worth being clear-eyed about the parts that are going to be difficult, because the gap between a clean rule and a working one is where this will actually be decided.

Machine-readable marks are the obvious pressure point. A watermark or provenance tag is only useful if it survives the ordinary life of a file, and the ordinary life of a file involves screenshots, re-compression, cropping and being run back through another model. Marks that are easy to add are often easy to strip, and the people most motivated to strip them are exactly the ones the rule is aimed at. The labelling requirement leans on standards for signing content at the point of creation, but a standard only helps for content created by companies that chose to follow it.

Then there is reach. The rule applies to AI systems used in the EU, not only to those built there, which means a model trained anywhere is in scope the moment a European talks to it. Enforcing that against a provider with no European offices is a question the AI Office will be answering in practice for years, not one the law settles on paper.

None of that makes the requirement pointless. A chatbot that has to say it is a chatbot is a genuine improvement over one that lets you assume otherwise, and a labelling regime does not need to be perfect to raise the cost of casual deception. But the honest framing is that 2 August was the start of the enforcement, not the end of the argument. The text was always the easy part.

Photograph: Thijs ter Haar, CC BY 2.0. Screenshot: European Commission.