{"id":128814,"date":"2026-08-04T07:20:11","date_gmt":"2026-08-04T07:20:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/128814\/"},"modified":"2026-08-04T07:20:11","modified_gmt":"2026-08-04T07:20:11","slug":"eu-begins-enforcing-ai-act-putting-ai-models-under-the-microscope","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/128814\/","title":{"rendered":"EU begins enforcing AI Act, putting AI models under the microscope"},"content":{"rendered":"<p>Europe\u2019s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission\u2019s AI Office and national authorities began enforcing the <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/04\/16\/eu-ai-act-logging-requirements\/\" rel=\"nofollow noopener\" target=\"_blank\">AI Act<\/a>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/eu-people-650.webp\" class=\"aligncenter\" alt=\"EU AI Act enforcement\" title=\"EU\"\/><\/p>\n<p>On the same date, new transparency rules took effect, requiring certain AI systems to tell users when they\u2019re interacting with AI and when content has been generated or altered by it.<\/p>\n<p>Under these rules, chatbots have to identify themselves as automated systems, <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/05\/15\/research-deepfake-detection-limitations\/\" rel=\"nofollow noopener\" target=\"_blank\">deepfakes<\/a> need a label, and machine-made or edited content must carry machine-readable marks so it can be detected automatically.<\/p>\n<p>Companies that ignore these obligations risk fines of up to \u20ac15 million or 3% of their worldwide annual turnover, whichever is higher.<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/henna-virkkunen\/\" target=\"_blank\" rel=\"nofollow noopener\">Henna Virkkunen<\/a>, Executive Vice-President for Tech Sovereignty, Security and Democracy, called AI \u201ca transformative technology\u201d with benefits for people and businesses, but warned that the most advanced models \u201ccreate risks on an entirely new scale.\u201d<\/p>\n<p>The goal of these measures, according to the Commission, is to cut down on deception and manipulation and help people make informed choices. They\u2019re also meant to give businesses clearer obligations and a practical way to show compliance.<\/p>\n<p>These enforcement powers could add fuel to an already <a href=\"https:\/\/www.euronews.com\/my-europe\/2026\/07\/24\/eu-seeks-dialogue-with-us-as-tensions-rise-after-google-fine\" target=\"_blank\" rel=\"nofollow noopener\">tense<\/a> relationship between major U.S. companies like OpenAI, Anthropic and <a href=\"https:\/\/www.reuters.com\/world\/google-hit-with-1-billion-eu-fine-first-under-landmark-rules-2026-07-23\/\" target=\"_blank\" rel=\"nofollow noopener\">Google<\/a>, and the European Commission, which has been pushing hard on <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/04\/20\/eu-sovereign-cloud-tender-180-million-eu\/\" rel=\"nofollow noopener\" target=\"_blank\">tech sovereignty<\/a>.<\/p>\n<p>GPAI providers face new scrutiny<\/p>\n<p>The AI Office\u2019s new enforcement power covers providers of general-purpose AI (GPAI) models, the versatile systems behind many tools and services, including <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/09\/securing-autonomous-ai-agents-rules\/\" rel=\"nofollow noopener\" target=\"_blank\">AI agents<\/a>.<\/p>\n<p>The Commission said providers of the most advanced GPAI models must address risks of large-scale harm, including chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, harmful manipulation and threats to fundamental rights. <\/p>\n<p>\u201cAll providers of GPAI models must document certain information and provide it to competent authorities or downstream providers. They must also put in place a copyright policy and publish a sufficiently detailed summary of the content used to train their models,\u201d the Commission explained.<\/p>\n<p>Industry compliance and what\u2019s still ahead<\/p>\n<p>Alongside enforcement, the Commission released a first list of over 180 organizations that signed the Code of Practice on transparency of AI-generated content, a voluntary framework meant to give companies a concrete way to show they\u2019re meeting the labelling and marking requirements. <\/p>\n<p>The Code of Practice itself is voluntary, though the transparency obligations behind it are legal requirements under <a href=\"https:\/\/ai-act-service-desk.ec.europa.eu\/en\/ai-act\/article-50\" target=\"_blank\" rel=\"nofollow noopener\">Article 50<\/a> either way. Signing gives providers a documented way to demonstrate compliance.<\/p>\n<p>Not every part of the AI Act is moving at the same speed. The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/news\/ai-omnibus-enters-force\" target=\"_blank\" rel=\"nofollow noopener\">AI Omnibus<\/a>, a package of amendments to the Act, pushed back the rules for high-risk AI systems to 2 December 2027, and those for high-risk systems built into regulated products to 2 August 2028. The same package moves faster on the harm side. From 2 December 2026, it bans AI systems that generate non-consensual sexually explicit content or child sexual abuse material.<\/p>\n<p>The Commission has already used other EU digital laws to scrutinise risks associated with generative AI. In January 2026, the Commission opened a formal <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/01\/26\/european-commission-grok-x-investigation\/\" rel=\"nofollow noopener\" target=\"_blank\">investigation into X <\/a>under the Digital Services Act over its Grok tool, after manipulated sexually explicit images and possible child sexual abuse material appeared on the platform.<\/p>\n<p>Who enforces what<\/p>\n<p>Enforcement responsibility is split among several bodies. The AI Office handles general-purpose AI models directly, with power to request technical documentation, run evaluations, demand corrective steps and issue fines. <\/p>\n<p>National competent authorities take on other AI systems operating within their borders. The European Data Protection Supervisor oversees compliance among EU institutions themselves.<\/p>\n<p>Virkkunen <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_26_1714\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> the Act gives \u201cinnovators legal certainty while protecting the public interest,\u201d and called enforcement \u201can important step towards AI that people and businesses can understand and trust.\u201d<\/p>\n<p>Not everyone is convinced this will change much. In a May interview with Help Net Security at the Span Cyber Security Arena conference, <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/01\/antonija-vojnovic-span-cybersecurity-governance-challenges\/\" rel=\"nofollow noopener\" target=\"_blank\">Antonija Vojnovi\u0107<\/a>, Governance, Risk and Compliance Department Manager at Span, said she isn\u2019t convinced the AI Act will bring major change. She argued that awareness of how AI tools handle data may matter more than the rules themselves.<\/p>\n","protected":false},"excerpt":{"rendered":"Europe\u2019s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European&hellip;\n","protected":false},"author":2,"featured_media":128815,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,719,9955,779,6861,597,1715],"class_list":["post-128814","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-compliance","tag-data-protection","tag-eu","tag-european-commission","tag-government","tag-regulation"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/128814","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=128814"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/128814\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/128815"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=128814"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=128814"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=128814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}