
Regulation · 12 min read
The AI Act Is Here — What the First Enforcement Wave Means for Ordinary Users
The European Union began enforcing core rules of the AI Act on 2 August 2026. This article explains what the new transparency obligations mean for how you encounter AI-generated content, what the law requires, and where it still falls short.
On 2 August 2026, the European Commission began enforcing the first major tranche of rules under the European Union Artificial Intelligence Act (EU AI Act) — the world's first comprehensive regulatory framework for artificial intelligence. For the first time, providers of AI systems that generate or manipulate content must clearly label their output as AI-generated. This changes what you can assume about the text, images, audio, and video you encounter online.
Key Takeaways
- The EU AI Act entered force on 1 August 2024, with phased enforcement starting 2 August 2026 for transparency obligations.
- AI systems that generate or manipulate content must now label output as AI-generated.
- Real-time biometric surveillance in public spaces is banned, with limited exceptions.
- Enforcement is shared between the European Commission's AI Office and national regulators across 27 member states.
- The Act's definition of "high-risk" systems remains broad, and general-purpose AI models still occupy regulatory grey areas.
What the AI Act Actually Does
The EU AI Act (Regulation (EU) 2024/1689) takes a risk-based approach that classifies AI systems into four categories: unacceptable risk, high risk, limited risk, and minimal risk. The most severe category — unacceptable risk — includes systems that are banned outright. These include social scoring by governments, real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions), and AI systems that exploit vulnerabilities of specific groups.
High-risk systems face the most extensive regulatory requirements. These include AI used in critical infrastructure, education, employment, access to essential services, law enforcement, border control, and administration of justice. Providers of high-risk systems must implement risk management processes, maintain technical documentation, ensure human oversight, and register their systems in an EU database.
The category most relevant to ordinary users is the transparency obligation that applies to limited-risk systems. As of 2 August 2026, any AI system that generates or manipulates content — including text, images, audio, or video — must clearly and conspicuously label its output as AI-generated. This applies to chatbots, image generators, deepfake tools, and any system whose output is intended to be perceived as human-created content.
The Enforcement Framework
The AI Act created a multi-layered enforcement structure. At the European level, the AI Office, established within the European Commission, oversees the regulation of general-purpose AI models and coordinates enforcement across member states. At the national level, each EU member state must designate a market surveillance authority to enforce rules for individual AI systems.
The European Commission has published guidance on the enforcement framework, including the AI Act complaints tool, which allows individuals and organisations to submit complaints about non-compliance directly to the Commission. The AI Office also operates a whistleblower tool for reporting violations.
Timeline for phased enforcement: - 1 August 2024: AI Act entered into force - 2 February 2025: Rules on prohibited practices took effect - 2 August 2025: Rules on general-purpose AI models took effect - 2 August 2026: Transparency obligations and rules for high-risk systems listed in Annex III began enforcement - 2 August 2027: Full application for all high-risk systems
Why It Matters for Ordinary People
The average person now encounters AI-generated content daily, often without realising it. A support chatbot, a product image, a voice in a video, an article summary — all can be synthetic. The Act's transparency rules aim to restore what researchers call the "attribution baseline": the default assumption that what you see or hear has a known origin.
This matters beyond convenience. Deepfakes have been used for fraud, impersonation, and disinformation. The Federal Trade Commission and other regulators have warned about the growing use of AI-generated content in scams. Without mandatory labelling, there is no practical way for most people to distinguish synthetic content from authentic material.
The AI Act does not solve the detection problem. But it shifts the burden: instead of requiring every user to become an AI-detection expert, it requires providers to disclose the nature of their systems. This is a meaningful change in the default arrangement.
What Is Still Missing
The AI Act is a first step, not a final answer. Several significant gaps remain:
**Enforcement capacity**: The Act depends on 27 national regulators, each with different resources, expertise, and priorities. Smaller member states may struggle to build effective enforcement teams.
**Definitional uncertainty**: The Act's definition of "high-risk" is broad. Critics argue that general-purpose AI models — the kind that power tools like ChatGPT — can fall into regulatory grey areas, particularly when they are used for purposes the original provider did not intend.
**Transparency limits**: The labelling requirement applies to output that is "AI-generated or manipulated," but it does not address the distinction between fully synthetic content and human content that was edited or enhanced by AI. This boundary is increasingly blurred.
**Global fragmentation**: The AI Act applies only within the European Union. While it is likely to influence regulation in other jurisdictions (Canada, Brazil, Japan, and several US states are considering similar frameworks), the internet does not respect national borders. Content generated outside the EU may still reach European users without labelling.
What Happens Next
The European Commission has signalled that further guidance is coming. The AI Office is expected to publish clarifications on the definition of "high-risk" systems and the interaction between the AI Act and other EU digital regulations, including the Digital Services Act and the General Data Protection Regulation.
The next major enforcement milestone is 2 August 2027, when the full requirements for all high-risk AI systems take effect. This will include obligations for conformity assessments, human oversight, and transparency documentation.
Age of Algorithms Perspective
The AI Act represents an important shift: from asking users to detect AI content to requiring providers to disclose it. But disclosure is not the same as understanding. The Act creates a legal obligation to label, but it does not create the literacy that people need to interpret those labels meaningfully.
The deeper question is whether labelling alone is sufficient. Research on privacy policies and cookie consent banners suggests that disclosure without understanding does not change behaviour. The same dynamic may apply to AI labelling: the label is only useful if people know what it means and how to act on it.
For readers of Age of Algorithms, the key takeaway is not the legal detail but the practical effect: the era of completely unmarked AI content is ending within the EU. That changes what we can assume about the media we encounter, and it creates new responsibilities for both providers and users. The question is whether we will use this transparency to become more discerning, or whether it will become another banner we scroll past.