ONLINEAGENT_OPS 2026.Q3 HOME ARTICLES CRAFT RECORD BLOG MAP HUBS FAQ SEARCH
HOMEBLOGAi Rules
BLOG · DATED PIECE

THE RULES ARRIVING

The EU AI Act became broadly applicable on 2 August 2026. The EU AI Act became broadly applicable on 2 August 2026. What changed, when, and what it actually means.

READ8 min
WORDS1,695
SECTIONS4
SOURCES6
TYPEDATED
CHECKED25 AUG 26
TL;DR — THE SHORT VERSION

Under the AI Act, transparency rules, the AI Office’s enforcement powers and fines on general-purpose model providers apply from 2 August 2026; the rest of the penalty chapter has applied since 2 August 2025, and the heaviest high-risk duties were deferred.

  • Transparency is live now. Chatbots must be disclosed and synthetic audio, image, video and text marked in machine-readable form.
  • High-risk duties were deferred. Hiring, credit and education systems now face obligations from 2 December 2027.
  • Publishers face a narrow rule. AI text on public-interest matters needs labelling only without human editorial control.
  • Penalties are large. Fines are set as a share of worldwide turnover, and prohibited practices carry the highest ceiling.
  • A missing label proves nothing. Marks can be stripped, and most tools worldwide are not covered.
◈ UPDATE — 22 AUGUST 2026 · ENFORCEMENT IS LIVE

Since this page was written, the enforcement machinery has actually switched on and the deferral dates have been fixed in law rather than proposed. Three things changed.

1 · The AI Office now has powers, not just a mandate. From 2 August 2026 the European Commission's AI Office and national authorities can investigate and enforce — requesting documentation, obtaining model access for evaluation, requiring corrective measures, and fining.European Commission press release IP/26/1714, Commission starts enforcing AI Act rules and new transparency requirements on 2 August, 31 Jul 2026, read at source 17 Sep 2026: “From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act.”

2 · The Digital Omnibus is law. Regulation (EU) 2026/1744 entered into force 27 July 2026. High-risk obligations for stand-alone Annex III systems — hiring, credit scoring, education, critical infrastructure — moved to 2 December 2027. High-risk AI embedded in already-regulated products under Annex I moved to 2 August 2028. Neither date is conditional on further Commission decisions; the earlier "months after standards are confirmed" mechanism was dropped.Digital Omnibus on AI — Regulation (EU) 2026/1744, signed 8 July 2026, published in the Official Journal 24 July and in force 27 July 2026. Read at source 11 Sep 2026; also reported by Goodwin, Latham & Watkins and DLA Piper, Aug 2026.

3 · A new prohibition arrives 2 December 2026 — AI systems designed to generate non-consensual intimate imagery ("nudifier" applications) and child sexual abuse material, added to Article 5.Digital Omnibus, Art. 5 amendment, read at source 11 Sep 2026: “a new prohibition on AI-generated non-consensual intimate imagery (“nudifiers”) and child sexual abuse material is introduced into Article 5 of the AI Act”.

What Article 50 actually requires of a publisher

This is the part that applies to sites rather than to model labs, and it is narrower than most summaries suggest.

€15M
or 3% of worldwide annual turnover, whichever is higher — the ceiling for breaching obligations other than the Article 5 prohibitionsAI Act Article 99(4), read at source 16 Sep 2026 via artificialintelligenceact.eu: “shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher”. On enforcement beginning: European Commission press release IP/26/1714, Commission starts enforcing AI Act rules and new transparency requirements on 2 August, 31 Jul 2026, read at source 17 Sep 2026: “From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act.”
€35M
or 7% of turnover — the separate, higher ceiling for prohibited practices under Article 5Regulation (EU) 2024/1689 (the AI Act), Article 99(3), read at source 16 Sep 2026 via artificialintelligenceact.eu, which reproduces the regulation: “Non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.” Official text: EUR-Lex.
2 DEC 2026
deadline for machine-readable marking on generative systems that were already on the market before 2 August 2026AI Act Art. 111 as amended, Article 111, read at source 22 Sep 2026: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.” Also summarised by Cooley, 3 Aug 2026.

Article 50(4) is the one that reaches publishers. It requires labelling of deepfakes, and of AI-generated text published to inform the public on matters of public interest — but only where no human editorial control has been exercised. A page an editor commissioned, checked and takes responsibility for falls outside that requirement.AI Act Art. 50(4); Commission Guidelines on transparency obligations, adopted 20 Jul 2026, read at source 11 Sep 2026 — synthetic outputs generated before 2 August 2026 need not be marked retroactively; the relevant date is the date of generation.

The obligations apply from 2 August 2026. Generators already on the market before that date have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).Regulation (EU) 2024/1689 as amended, Article 111, read at source 22 Sep 2026 via artificialintelligenceact.eu: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.” Until 22 Sep 2026 this line said the obligations applied from 2 August 2026 “to all in-scope systems regardless of when they were placed on the market”, which contradicted the 2 December date in the box above it. Content published before that date does not need retroactive labelling.Commission Guidelines on transparency obligations, adopted 20 Jul 2026, read at source 11 Sep 2026 — 51 pages, non-binding, but national market surveillance authorities and the AI Office can be expected to follow them.

◈ THE VOLUNTARY CODE, AND WHY IT MATTERS

The AI Office has published a Code of Practice on Transparency of AI-Generated Content, including a standard icon set for labelling synthetic images, audio and text. Signatories get a degree of presumption of conformity and more favourable treatment in enforcement.European Commission, Commission publishes Code of Practice on marking and labelling AI-generated content, read at source 22 Sep 2026: “Publication 10 June 2026” and “The Code is voluntary”. Until 22 Sep 2026 this citation dated the Code July 2026.

It is voluntary. The underlying obligation is not.

◈ LIVE AS OF 2 AUGUST 2026
  • Transparency obligations. Tell people when they are interacting with an AI system unless it is obvious; mark synthetic audio, image, video and text in a machine-readable format; disclose emotion recognition and biometric categorisation.EU AI Act Article 50(2), read at source 22 Sep 2026 via artificialintelligenceact.eu: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs” … “are marked in a machine-readable format and detectable as artificially generated or manipulated.” Practical detail on how AI content gets labelled.First-hand: until 23 Sep 2026 this line, and the summary at the top of the page, listed only “audio, image and video”. Article 50(2) names text as well.
  • Enforcement powers over general-purpose model providers, held by the European AI Office — including the ability to request technical documentation, evaluate models and require corrective measures.
  • Fines on general-purpose model providers. Most of the penalty chapter has applied since 2 August 2025. What began on 2 August 2026 is Article 101, the fines for providers of general-purpose AI models. The ceiling for the most serious violations — deploying a prohibited practice — is €35 million or 7% of global annual turnover, higher than the GDPR. The tier for general-purpose model providers is lower: €15 million or 3%.Regulation (EU) 2024/1689 as amended, Article 113, read at source 22 Sep 2026 via artificialintelligenceact.eu: the Regulation “shall apply from 2 August 2026”, but “Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101”. Chapter XII is the penalties chapter. Until 22 Sep 2026 this item was headed “The penalty regime” and listed it as live from 2 August 2026.

The staircase, in order

1 AUG 2024
Entered into force

Binding law, no substantive obligations yet. This date started every clock below it.

2 FEB 2025
Bans and AI literacy

Prohibited practices became enforceable, alongside an AI-literacy duty on providers and deployers. The Digital Omnibus has since softened that duty: Article 4 now says they “shall take measures to support the development of AI literacy” of their staff, and that this “does not require providers or deployers to guarantee any specific level of AI literacy” in any individual.Regulation (EU) 2024/1689 as amended, Article 4, read at source 22 Sep 2026 via artificialintelligenceact.eu: “Providers and deployers of AI systems shall take measures to support the development of AI literacy” and “This obligation does not require providers or deployers to guarantee any specific level of AI literacy”. Until 22 Sep 2026 this row described the duty as an obligation “to ensure staff have a working understanding of the AI they deploy”, the wording before the Omnibus.

2 AUG 2025
General-purpose model obligations · penalties

The penalty chapter applied from this date, apart from the fines on general-purpose model providers, which followed a year later.AI Act Article 113(b), read at source 22 Sep 2026: “Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101”. Duties on providers of foundation models — technical documentation, a summary of training-data copyright compliance, and additional assessment and incident-reporting expectations for models above a systemic-risk compute threshold.

2 AUG 2026
General application · transparency · model-provider fines

The main body of the Act applies. Member State authorities and the AI Office take up enforcement. This is the date that matters for ordinary readers, because it is when labelling and disclosure became legal duties rather than good practice.

2 DEC 2026
Marking obligations for systems already on the market

Content-marking duties extend to AI systems placed on the market before 2 August 2026 — earlier than the February 2027 date the Commission originally proposed. The new prohibition described below applies from the same date.AI Act Article 113(a), read at source 22 Sep 2026: the new Article 5 “points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026”.

2 DEC 2027
High-risk use cases (deferred)

Obligations for high-risk applications in sensitive areas — hiring, credit, education, essential services — pushed back from the original date by the 2026 simplification package.

2 AUG 2028
High-risk AI in regulated products (deferred)

AI embedded in medical devices, machinery and similar products, where existing sectoral regimes already apply.

◈ WHAT ACTUALLY GOT DEFERRED, AND WHAT DID NOT

The amending instrument has a name worth knowing: the Digital Omnibus on AI, Regulation (EU) 2026/1744, agreed politically on 7 May 2026 after a first negotiation collapsed in April, adopted by Parliament on 16 June and Council on 29 June, and in force from 27 July 2026. It postponed the most operationally demanding requirements: conformity assessments, risk-management files and registration for high-risk systems. It did not postpone transparency, enforcement powers over model providers, or penalties.

So "the AI Act was delayed" describes the compliance burden on companies building hiring or credit systems. It does not describe the rules governing whether AI content gets labelled — those are live now. Reporting that collapses the two is telling you something false about the thing most readers care about.

WHAT WAS DEFERRED · WHAT WAS NOT
“The AI Act was delayed” is true of the left column only. The dates are on the staircase above.
DEFERRED BY THE DIGITAL OMNIBUS
No: High-risk obligations for stand-alone systems: hiring, credit scoring, education, critical infrastructure
No: High-risk AI embedded in already-regulated products, such as medical devices and machinery
No: Conformity assessments, risk-management files and registration for high-risk systems
LIVE FROM 2 AUGUST 2026
Yes: Transparency: disclose chatbots, mark synthetic audio, image, video and text
Yes: Enforcement powers for the AI Office and national authorities
Yes: Fines on general-purpose model providers (Article 101); most other penalties have applied since 2 August 2025
European Commission press release IP/26/1714, Commission starts enforcing AI Act rules and new transparency requirements on 2 August, 31 Jul 2026, read at source 17 Sep 2026: “From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act.” Deferrals: Digital Omnibus on AI — Regulation (EU) 2026/1744, in force 27 July 2026, read at source 11 Sep 2026. Penalty dates: AI Act Article 113(b), read at source 22 Sep 2026: “Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101”.
◈ THE OTHER LEGAL FRONT

Regulation is only half of the law arriving. The other half is copyright litigation — training-data cases including one US class action, Bartz v. Anthropic, that reached a $1.5 billion settlement, and an emerging distinction that turns on how training data was obtained rather than whether training itself is copying. Covered on AI and the open web, because it is ultimately the same question as the traffic collapse: if a publisher's work ends up inside an answer, what is owed?Authors Guild, Bartz v. Anthropic Settlement: What Authors Need to Know, updated 4 Sep 2026, read at source 17 Sep 2026: “The $1.5 billion award will be split among the rightsholders—which includes both authors and publishers—of all of the books included in the class after administration fees, lawyers’ fees, and expenses are paid.” An earlier version also said more than 35 training-data cases were active by mid-2026; no source was given for that count, and it was removed.

◈ WHAT THE OMNIBUS ADDED, NOT ONLY WHAT IT DELAYED

Coverage of this instrument has concentrated almost entirely on the deferral. Two additions deserve equal attention.

A new prohibition. AI systems used to generate child sexual abuse material, or non-consensual sexual or intimate content, are banned from 2 December 2026 — both placing them on the market and using them. A system built for something else is caught if it can readily produce such material and lacks “reasonable and adequate technical safety measures and other safeguards” to prevent it.AI Act Article 5(1)(ba), (bb) and 5(1a), read at source 22 Sep 2026 via artificialintelligenceact.eu, which notes against the new points: “Comes into force 2 December 2026, according to Article 113(a)”. Until 22 Sep 2026 this paragraph said these systems “are now banned outright”, contradicting the update box at the top of this page, and listed safeguards (refusal training, output controls, content filtering) that the text does not name; that list was removed.

Centralised enforcement. The AI Office gained exclusive supervisory competence over AI systems built on a general-purpose model by the same provider or group, and over AI systems integrated into very large online platforms and search engines. It also receives serious-incident reports directly. That is a meaningful shift of power from member-state authorities to Brussels — and it matters because a fragmented regulator is a weak one.

Beyond Europe

At federal level the United States has a narrow law rather than a broad one. The TAKE IT DOWN Act requires platforms to remove non-consensual intimate images within 48 hours of a valid request, and the Federal Trade Commission began enforcing it on 19 May 2026.Federal Trade Commission, FTC Begins Enforcing the TAKE IT DOWN Act, 19 May 2026, read at source 22 Sep 2026: covered platforms must give people a way to request removal and “remove those intimate images, and known identical copies, within 48 hours of a valid request.” Until 22 Sep 2026 this paragraph opened “No comparable federal law exists in the United States”. Beyond that, what exists is a patchwork of state legislation — California's companion-chatbot rules took effect on 1 January 2026 and its transparency requirements for AI-generated content on 2 August 2026 — alongside an unsettled and ongoing argument about whether federal action should override state rules. The prudent reading, and the one most compliance guidance gives, is that state law applies until something displaces it.California SB 942 and SB 243not both 1 Jan 2026, as an earlier version of this page said. SB 243 took effect 1 January 2026; SB 942 was pushed to 2 August 2026 by AB 853 to line up with EU AI Act Article 50. Both re-read at source 11 Sep 2026. Companion-chatbot detail on AI companions. Until 22 Sep 2026 the sentence above still said both laws “took effect on 1 January 2026”, although this note had already been corrected.

California added two chatbot laws on 10 September 2026. SB 1119, which the Governor’s office calls “Adam’s Law”, requires companion-chatbot operators to carry out a child-safety risk assessment before offering a new or substantially modified chatbot from 1 July 2027, and to have an independent child-safety audit by 1 January 2029 or before launch, whichever is later. SB 867 bans the sale of toys that include a companion chatbot until 1 January 2031.California Legislature, SB-1119 Companion chatbots: children’s safety, chaptered text, read at source 22 Sep 2026: “Approved by Governor September 10, 2026”; operators must, “beginning July 1, 2027, before making a new or substantially modified companion chatbot available to users in the state”, carry out a risk assessment; and “On or before January 1, 2029, or before an operator first makes a companion chatbot publicly available, whichever is later, an operator shall ensure the performance of a child safety audit.” SB-867 Toys: companion chatbots, chaptered text, read at source 22 Sep 2026: “No person shall manufacture, sell, or exchange, possess with intent to sell or exchange, or expose or offer for sale or exchange to any retailer any toy that includes a companion chatbot.” and “This section shall remain in effect only until January 1, 2031, and as of that date is repealed.” The name comes from the Office of the Governor of California, 10 Sep 2026, read at source 22 Sep 2026: “Named after Adam Raine”.

The UK has taken a power rather than a rulebook. The Crime and Policing Act 2026 inserts a section 216A into the Online Safety Act 2023, letting the Secretary of State amend that Act by regulations to deal with illegal AI-generated content and AI services. The government said the aim was to bring chatbots that the Online Safety Act does not yet cover under its illegal-content duties. If no draft regulations are laid first, the Secretary of State must report progress to Parliament by 31 December 2026.legislation.gov.uk, Crime and Policing Act 2026, sections 248–249, read at source 22 Sep 2026: new section 216A provides that “the Secretary of State may by regulations amend any provision of this Act” to reduce the risks from “illegal AI-generated content”; section 249: “no later than 31 December 2026, lay before Parliament a report about the progress that has been made towards making regulations under section 216A”. UK Government, PM: “No platform gets a free pass”, 15 Feb 2026, read at source 22 Sep 2026: an amendment “to allow the government to require chatbots not currently in scope of the Online Safety Act to protect their users from illegal content.”

Which produces the practical situation worth understanding: a European rule tends to become the global default, because building one compliant product is cheaper than building two. The labelling you will encounter was probably written for Brussels regardless of where you live.

TAKEAWAY

A narrow US federal law, and state laws. The TAKE IT DOWN Act covers intimate images; for most other AI questions state laws such as California's apply, and EU rules tend to become the global default because one compliant product is cheaper than two.

What it means if you are not a company

  • Expect labels, and read them correctly. A label is now a legal duty for providers in the EU — but as the provenance page explains at length, an absent label still proves nothing, because marks can be stripped and most tools worldwide are not covered.
  • Chatbot disclosure is now required where it is not obvious you are talking to a machine. If a service is coy about this, that is now a compliance question rather than a style choice.
  • Text is covered, but hard to check. Article 50(2) names “synthetic audio, image, video or text content”, and text watermarks already exist: Anthropic marks text from its newest Claude models, and Google marks text from the Gemini app. What is missing is a shared public standard for text marks and a public checker. Each company’s mark is read with its own key, and access to the checkers is limited.EU AI Act Article 50(2), read at source 22 Sep 2026 via artificialintelligenceact.eu: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs” … “are marked in a machine-readable format and detectable as artificially generated or manipulated.”Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “Generated text will carry embedded watermarks”; “Watermark detection is currently in private preview, available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups)”; “A detected mark provides a signal that content was processed by Claude, but is not fully conclusive.” Its model table, read the same day, ticks text watermarks for Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5, and says “Anthropic is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026.”Google DeepMind, SynthID, read at source 22 Sep 2026: “We’ve expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience.” Of its SynthID Detector portal: “Just upload an image, video or audio file.”Anthropic, How Claude’s text watermark works, 14 Aug 2026, read at source 22 Sep 2026, on another company’s watermark: “it would have a different key; it might also use a different watermarking method altogether”.First-hand: until 23 Sep 2026 this item was headed “Text remains the gap” and said the marking duties “centre on audio, image and video”, with written words having “no equivalent workable requirement”. The text of Article 50(2) says otherwise. More on Claude’s text watermark.
  • Enforcement is new, and unevenly staffed. Rules taking effect is not the same as rules being enforced. Independent tracking of the EU-27 shows member states at markedly different stages of designating the national authorities who are supposed to do the enforcing — so the first significant actions will tell you more than the statute does, and where they happen will tell you something too.Future of Life Institute, National implementation plans, last updated 17 June 2026, read at source 23 Sep 2026: “9 Member States have designated both market surveillance and notifying authorities”, 12 have “partial clarity”, “whereas 6 Member States have yet to designate or establish any competent authority”.
◈ WHERE THIS SITE STANDS

This is the most encouraging development this site covers and it is arriving years after the harms it addresses were measurable — voice cloning was demonstrated in 2023 and first counted as a fraud category in 2026; automated traffic passed half the web in 2024 and the first broad transparency duty took effect in August 2026. That lag is the normal speed of law, not a scandal. But it means the rules will always describe the previous problem, which is why the habits on this site are not made redundant by legislation — they are what covers the gap.Site data: the full lag, dated, is on the timeline, last revised 16 Sep 2026.

TAKEAWAY

Expect labels, read them carefully. An absent label proves nothing, the public cannot yet check a text watermark, and enforcement is new and uneven across member states.First-hand: until 23 Sep 2026 this takeaway said “text has no workable marking rule”. Article 50(2) covers text; see the list above.

ABOUTMETHODVERIFYPRIVACYCONTACTINDEXAI PROMPT GENEER · EVERY ARTICLE CARRIES ITS OWN CHECKED DATE