Article · 8 min read

The EU just started enforcing its AI law. Here's what actually changed.

Published August 2026

For the past couple of years, the EU AI Act has mostly been something tech lawyers argued about. It was passed, it was coming, it was the world's first major AI law, and then nothing obviously changed for ordinary people using ChatGPT or Gemini. That ended last weekend.

On 2 August 2026, the European Commission's AI Office and national authorities began enforcing the AI Act. Real enforcement, with real fines. If you use AI tools of any kind, for work, for fun, to handle customer queries, this is worth understanding, because the rules reach well beyond Europe's borders.

What the EU AI Act actually is

The EU AI Act is the world's first comprehensive law on artificial intelligence, formally Regulation (EU) 2024/1689. The basic idea is that not all AI is equally risky. A chatbot that helps you write birthday cards is not in the same category as an algorithm that decides whether you get a job interview or a bank loan. So rather than one blanket rule, the law sorts AI into tiers.

It sorts AI systems into four risk tiers, unacceptable, high, limited, and minimal, then sets rules, transparency duties, and fines based on how risky each system is. And critically, the AI Act applies globally to providers, deployers, importers and distributors of AI systems that place AI on the EU market or whose AI outputs are used within the European Union. That last part is the reason a startup in California or a tech giant in Tokyo has to care about a Brussels regulation.

Think of it like food labelling law. The EU decided that if you want to sell food to European consumers, you meet European standards, regardless of where your factory is. The AI Act works the same way. Serve EU residents? You're in scope.

What came into force this week

The Act didn't switch on all at once. It has been rolling out in stages, and what started on 2 August is primarily about two things: transparency obligations and enforcement powers over the biggest AI model providers.

New transparency rules took effect, requiring certain AI systems to tell users when they're interacting with AI and when content has been generated or altered by it. Under these rules, chatbots have to identify themselves as automated systems, deepfakes need a label, and machine-made or edited content must carry machine-readable marks so it can be detected automatically.

In plain terms: if you're chatting with a bot, the bot has to say so upfront. It requires that anyone deploying a chatbot or similar conversational AI disclose "you are talking to an AI" at the start of the interaction, in plain and accessible language, and that synthetic or deepfake content be labelled as such.

This matters more than it sounds. Huge numbers of customer service interactions, appointment bookings, and sales conversations now happen through AI, and many of the people on the other end of those conversations have no idea. The EU has decided that deception by omission is still deception.

There's more where this came from. New articles most weeks.Browse all articles →

The other switch that flipped: fining power over AI model makers

The second big change is less visible to ordinary users but more significant for the industry. The EU's AI Office has now gained the ability to actually fine the companies behind large AI models.

Providers of foundation models such as GPT-4, Claude, Gemini, and Llama have been legally subject to obligations since August 2025: publishing technical documentation, maintaining copyright compliance policies, providing training data summaries to downstream users, and conducting systemic risk assessments for models trained on compute above a certain threshold. The European Commission could not issue fines during that first year. Beginning August 2, it can, retroactively for violations dating back to August 2025.

That retroactive element is the part that will have got attention in legal teams across Silicon Valley. A whole year of potential non-compliance is suddenly on the table.

The fines themselves are not trivial. Companies that ignore these obligations risk fines of up to €15 million or 3% of their worldwide annual turnover, whichever is higher. For a company with tens of billions in revenue, 3% is a very large number.

What isn't changing yet

Here's where it gets a bit complicated. What started this week is not the full Act, it's the first major enforcement phase. The heavier obligations, the ones that apply to AI used in high-stakes decisions, are still coming.

The AI Omnibus, a package of amendments to the Act, pushed back the rules for high-risk AI systems to 2 December 2027, and those for high-risk systems built into regulated products to 2 August 2028.

"High-risk" here has a specific legal meaning. High-risk Annex III systems cover recruitment, credit scoring, law enforcement, education, and border control. So an AI that screens job applications, for example, faces stricter scrutiny than a general-purpose chatbot, but that scrutiny won't fully kick in until late 2027.

And at the far end of the scale, some AI uses are simply banned. The landmark regulation bans manipulative AI practices, social scoring, and real-time biometric surveillance in public spaces. Systems deemed 'unacceptable risk' are outright prohibited. As of August 2026, these bans, which first took effect in February 2025, are fully enforceable with the maximum penalty tier.

The "Brussels Effect" and why it applies to you even outside Europe

One of the more interesting consequences of a law this large is that it tends to reshape products globally, not just in Europe. The same thing happened with GDPR, almost every website now has a cookie consent pop-up, worldwide, because companies decided it was easier to apply one standard everywhere than to maintain separate versions for European users.

With extraterritorial reach affecting any company whose AI systems serve EU residents, the Act creates a powerful 'Brussels Effect' that is forcing tech giants from Silicon Valley to Beijing to redesign their compliance architectures or risk losing access to the EU's 450-million-consumer market.

In practice, this means the disclosure rules, chatbots identifying themselves, deepfakes being labelled, are likely to become standard features in most major AI products, not just European ones. It's cheaper to build one product than two.

What about the AI companies that signed the Code of Practice?

You may have seen references to a "Code of Practice" alongside the enforcement news. This is a voluntary transparency code that AI providers were invited to sign. The window for AI providers to sign the EU's Code of Practice on Transparency of AI-Generated Content closed on 22 July 2026. Eleven days later, the obligations that Code was written to help with became enforceable anyway, whether a company signed or not.

Signatories benefit from a degree of presumption of conformity and a more favourable enforcement posture; non-signatories face closer scrutiny and must demonstrate compliance through other means. So signing was worth doing, but it wasn't a way to avoid the underlying rules.

From Telltale
Keep reading

If this one was useful, there's plenty more on the site. Pieces on how AI works, plus coverage of AI news, the downsides included. All free to read, no account needed.

See all articles →

So what does this mean in practice for ordinary users?

If you're a consumer, the most immediate change you should notice is better disclosure. Any AI system deployed in Europe now has to make clear it's an AI before you get deep into a conversation. AI-generated images, videos, and audio, including deepfakes, need to carry labels. And the watermarking requirement (machine-readable marks on AI content) ties into a broader push, including similar rules in the US, to make AI-generated content traceable.

If you work at a company that uses AI in customer-facing products, this is the moment to check how your tools handle disclosure. This isn't a footnote requirement. It touches every customer-facing assistive AI deployment an enterprise runs, and the general penalty ceiling, €15 million or 3% of global turnover, applies to non-compliance.

And if you're simply a curious person trying to understand why this matters: the honest answer is that the EU AI Act is an experiment in whether democratic governments can set meaningful rules for a technology moving faster than any regulator has previously had to handle. The measures are intended to reduce deception and manipulation and help people make informed choices. Whether they succeed at that is a question that will take years to answer. But as of this week, at least, the fines are real.

Published August 2026 · telltale-ai.com
All articles · Privacy · Terms