On 2 August 2026, the third major wave of requirements under the EU AI Act (the “Act”) entered into force. For many businesses, the most relevant changes fall into two key areas: (1) the AI transparency requirements under Article 50; and (2) the Act’s now-operational market surveillance and regulatory enforcement regime.
This wave of requirements is, however, narrower than originally anticipated. The Digital Omnibus on AI, adopted in July 2026, delayed the high-risk AI system requirements – which account for many of the Act’s most substantive requirements – until 2 December 2027 (for stand-alone high-risk AI systems) or 2 August 2028 (for high-risk systems embedded in certain regulated products). See our previous blog post for more information.
Nevertheless, we summarise the main new requirements below.
EU AI Act Background
As we have previously discussed, the Act is the EU’s flagship AI regulation. It takes a risk-based approach, imposing different requirements on: (i) prohibited or “unacceptable risk” systems; (ii) high-risk systems; (iii) systems that trigger specific transparency obligations; and (iv) general-purpose AI models.
The Act entered into force on 1 August 2024, but its provisions apply in stages. The first wave, including the prohibited-practices and AI-literacy provisions, applied from 2 February 2025. The second wave, principally covering general-purpose AI models and the EU’s AI governance framework, applied from 2 August 2025. The third wave of requirements is now in effect.
- The Article 50 Transparency Requirements
Article 50 imposes four main categories of transparency requirements on providers and deployers of certain AI systems: (1) informing individuals when they are interacting directly with an AI system; (2) technically marking AI-generated or AI-manipulated content so that outputs can be reliably detected and traced as AI-generated or altered; (3) disclosing the use of emotion-recognition or biometric-categorisation systems; and (4) labelling deepfakes and certain AI-generated text relating to matters of public interest.
In parallel, the European Commission has now published both a final Code of Practice on Transparency of AI-Generated Content and official Guidelines on Article 50. The Code is voluntary, but provides a recognised route for demonstrating compliance with the content-marking and labelling obligations.
For many businesses, two issues are likely to be particularly relevant:
- Deepfake labelling. Deployers of AI systems that generate or manipulate deepfakes must disclose that the content has been artificially generated or manipulated. Determining whether content is a “deepfake” can be complex, particularly where AI is used to edit otherwise authentic content or to create realistic but fictional material. We discuss these issues in more detail in our separate post, When Does AI-Generated Content Become a Deepfake, and Why Does It Matter?
- AI content metadata labelling and watermarking. Providers of AI systems that generate synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as AI-generated or manipulated. This may include the use of metadata identifiers, such as embedded provenance information or cryptographic watermarks, or other technical solutions that allow the output to be reliably identified as artificially generated or manipulated in accordance with the Act. The Commission’s guidance and Code of Practice also provide illustrative examples of how these requirements may be implemented in practice, including through different forms of watermarking and provenance-tracking techniques.
This obligation may be relevant not only to major AI vendors, but also to businesses that develop or commission their own chatbots, assessment tools or other AI applications and put them into service under their own name, where those systems generate synthetic content. The requirement contemplates technical measures, such as metadata and watermarking; an overt statement that an output is “AI-generated” may be useful, but is not by itself a substitute for machine-readable marking.
A limited transition period applies: providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the Article 50(2) machine-readable marking requirement.
- The Act’s Market-Surveillance and Regulatory Enforcement Framework Is Now Operational
The Act’s dedicated market-surveillance and enforcement provisions now apply.
- National market-surveillance authorities may investigate potentially non-compliant AI systems, require access to information and documentation (and, in defined circumstances, data or source code) and order corrective action, restriction, withdrawal or recall.
- The European Commission, acting through the AI Office, now has its full investigatory and enforcement powers in relation to general-purpose AI models and certain AI systems under its supervision. These include powers to request information, conduct model evaluations, require mitigations and restrict or withdraw models or systems from the EU market. This is particularly important for the prohibited AI practices under Article 5, which have applied since 2 February 2025. The Act’s dedicated enforcement machinery is now available for those prohibitions, and breaches may attract fines of up to €35 million or 7% of worldwide annual turnover.
- In addition, any individual or organisation may submit a complaint to a market surveillance authority regarding an alleged breach of the Act, and reports of suspected infringements are also brought within the scope of the EU Whistleblowing Directive. Businesses should therefore ensure that internal reporting channels and policies appropriately capture AI-related concerns.
Key Upcoming Milestones
Due to the Omnibus delays, the next relevant milestones in the Act’s implementation are as follows:
- 2 December 2026: This date marks the end of the transition period for the machine-readable marking requirements for AI-generated content. It is also when the new prohibition on AI systems that generate or manipulate non-consensual intimate imagery or child sexual abuse material comes into effect.
- 2 December 2027 and 2 August 2028: The principal high-risk AI system obligations will come into force. However, under the Article 111 grandfathering clause, these requirements generally apply only to high-risk systems placed on the market or put into service after the relevant date, unless an existing system undergoes a significant design change thereafter.
Key Takeaways
Assess Article 50 touchpoints and prioritise machine-readable labelling. Businesses should identify systems that generate or materially manipulate synthetic content (such as AI chatbots that generate written responses, or tools that create AI-generated images or alter audio and video content) and determine which Article 50 obligations apply, particularly for chatbots, embedded assistants and content-generation tools. Providers should assess how machine-readable identifiers, metadata or watermarking will operate across APIs and downstream distribution. Although systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2), implementation should begin now given the technical complexity of this area. In practice, monitoring how other market participants are approaching compliance may also help reduce regulatory exposure, as alignment with emerging market practice is likely to be an important factor in supervisory expectations.
Operationalise enforcement readiness under the newly applicable supervisory regime. Regulators can now investigate and sanction breaches of provisions already applicable, including Article 5 prohibitions and relevant Article 50 transparency obligations. Businesses should assign responsibility for regulatory engagement, establish document-production and escalation procedures, and ensure whistleblowing channels capture potential AI Act breaches.
****
To subscribe to the Data Blog, please click here.
The cover art used in this blog post was generated by ChatGPT.
The Debevoise STAAR (Suite of Tools for Assessing AI Risk) is a monthly subscription service that provides Debevoise clients with an online suite of tools to help them responsibly fast-track their AI adoption. Please contact us at STAARinfo@debevoise.com for more information.