The EU Started Enforcing AI Labelling on August 2. Almost Nobody Noticed.
The EU AI Act's transparency obligations took effect on 2 August 2026: chatbots must disclose they are chatbots, and three named categories of AI content must be labelled and machine-readably marked. Fines reach EUR 15 million or 3% of global turnover. What is actually required, who enforces it, the December grace period that applies to only part of it, and why a labelling rule may not do much yet.
DrafterDaily Editorial··8 min readAITechnologyEnterprise
The EU AI Act has been covered as a permanent future event for two years — always about to bite, never biting. On 2 August 2026 a specific slice of it actually did. The coverage was near-silent, largely because the newsworthy part is not a ban on anything glamorous. Article 50's transparency obligations are now live and enforceable, and they are the first AI rules that reach the ordinary product surface rather than the frontier lab.
This is a meaningful shift in what EU AI regulation is for. The rules that got the attention asked whether a model is dangerous. These ask something much more mundane: does a chatbot tell you it is a chatbot, and does synthetic media carry a mark a machine can read. That is a compliance obligation landing on essentially every consumer product with a conversational interface or a generation feature — not on a dozen frontier developers.
What actually became enforceable on 2 August
There are two obligations, and the Commission's own scoping is worth quoting rather than paraphrasing, because it is the most-misreported part of the rule.
The first is marking and labelling. Certain AI-generated or manipulated content must be clearly and visibly labelled and include machine-readable marks. Per the Commission, this applies to three named categories: images, audio and video content that resemble existing persons, objects, places, entities or events — deepfakes; emotion recognition and biometric categorisation tools; and text published to inform the public on matters of public interest where there has been no human review or editorial control.
The second is disclosure in interaction. Users must be clearly informed when they are not interacting with a real person but an AI system — the Commission names chatbots, AI agents and avatars.
Note what is not in that list. There is no general obligation to label every AI-assisted output. A marketing email drafted with a model and edited by a person is not covered by the text clause, because there was human review. An illustration that does not resemble an existing person, place or event is not a deepfake. The rule is narrower than the headlines implied, and stranger.
The clause publishers should read twice
Text published to inform the public on matters of public interest where there has been no human review or editorial control is a media-industry rule hiding inside an AI regulation. It does not care whether a model wrote the piece. It cares whether a person checked it before publication.
That is a deliberate and defensible line — editorial control is the thing that historically made publication accountable — but it puts a legal weight on newsroom workflow that most publishers have never had to document. An outlet running an automated feed of AI-summarised council decisions is squarely inside the clause. An outlet where a human editor signs off on the same output is not. The difference is a process, and processes have to be evidenced.
The Commission has also published a set of official EU icons for this purpose, released on 10 June 2026 alongside a Code of Practice on marking and labelling. Three icons, in SVG and PNG, covering image, video, audio and text. A standard symbol is a small detail with outsized consequences: it is how a legal obligation becomes a user expectation, and eventually how the absence of a label becomes conspicuous.
Who enforces it and what it costs
The enforcement architecture is genuinely tri-partite. National market surveillance authorities handle most of it. The European AI Office covers systems under its supervision. The European Data Protection Supervisor takes over where EU institutions, bodies or agencies are the provider or deployer.
Up to EUR 15 million, or 3% of global annual turnover, for companies
Up to EUR 750,000 for EU institutions, bodies and agencies
Proportionality explicitly taken into account for SMEs and small mid-cap companies
There is also a grace period, and it is narrower than most summaries suggest. It applies only to AI systems placed on the market before 2 August 2026, and only to the marking and detection obligation for AI-generated content, with compliance required from 2 December 2026. The disclosure duties for interactive systems and the deployer-side deepfake obligation took effect immediately on 2 August. Content generated before 2 August does not have to be labelled retroactively.
The AI Act itself entered into force on 1 August 2024 and applies in stages. This is one stage, not the whole thing.
Why a labelling rule may not do much yet
The sceptical case deserves to be stated plainly rather than buried. A labelling rule is only as good as its detection and its enforcement appetite, and both are unproven.
Machine-readable marks are the weak link. Watermarks and provenance metadata are frequently stripped by ordinary operations — re-encoding a video, screenshotting an image, copying text out of a page. A mark that does not survive the normal life of a file on the internet is a compliance artefact rather than a consumer protection. The industry is working on more durable marking, but nothing deployed today survives a determined adversary, and the rule does not require that it does.
The compliance path also points towards voluntary adherence rather than enforcement. The Commission has published guidelines explaining how compliance can be demonstrated, including through adherence to a Code of Practice — which is itself voluntary. The realistic near-term outcome is that large providers sign the code, document their marking, and are largely left alone. A first enforcement action would require a national authority to identify unlabelled content, attribute it to a specific provider or deployer, and demonstrate the obligation applied. None of those steps is trivial.
So the accurate framing is not that the EU is now fining companies for unlabelled AI. It is that the EU can now fine companies, the legal basis exists, the scope is defined, and the symbols are published. What happens next depends on whether any authority decides to test it — and until one does, the practical effect of 2 August will be felt in compliance departments rather than in what users actually see.
Frequently Asked Questions
The AI Act applies based on where an AI system is placed on the market or put into service, and where its output is used, not on where the company is incorporated. A US-based product with EU users generally falls within scope. This mirrors how GDPR works and is the reason non-EU firms ended up complying with it. Take specific legal advice for your situation — this is a summary, not counsel.
Regulation, without the summary-of-a-summary
DrafterDaily reads the primary source so you don't have to — what a rule actually says, who it binds, and what would need to happen before it bites.
Claude Fable 5.1 costs exactly what Fable 5 cost per token. The 25-to-45% saving Anthropic advertises comes from one repriced line item — cached input, now billed at 2.5% of list instead of 10%. That is a discount you only collect if you keep the agent running.
Anthropic was not breached. The malware was already on the customer's machine, and it took a session cookie rather than a password — which is why two-factor authentication did nothing and why server-side revocation is the only lever the vendor has.
OpenAI's incident report on the Hugging Face breach leads on a security failure. The remarkable part is a verbatim chain-of-thought in which a model identifies its action as unauthorised and proceeds anyway — and an escape route that was a package manager, not a superintelligence.