AI Briefing: August 4, 2026 — The EU AI Act's Disclosure Rules Became Enforceable Sunday. The Regulator Meant to Enforce Them Isn't Fully Named in 18 of 27 Countries.

WHAT ACTUALLY LANDED SUNDAY

The July 31 briefing on this site described August 2 as a deadline that had "split in two" — the AI Act's high-risk system rules pushed out to December 2027 and August 2028 by the Digital Omnibus, while Article 50's transparency duties kept their original date. That second half arrived exactly as scheduled. As of Sunday, any AI system built to interact directly with a person — a chatbot, a voice assistant, an automated phone agent — has to be designed so the person is told, perceptibly and inside the interaction itself, that they're talking to a machine; a disclosure buried in terms and conditions or a metadata tag nobody sees does not satisfy the duty. Separately, AI-generated or AI-manipulated audio, image, video, and public-interest text has to be marked as synthetic in a machine-readable format, and systems that perform emotion recognition or biometric categorization have to disclose that to the people they're scanning. The European Commission published its final guidance on Article 50 on July 20, confirming the Code of Practice on Transparency of AI-Generated Content as an adequate compliance path for the marking duty specifically. Providers with generative systems already on the market before Sunday get until December 2 to finish the machine-readable marking piece. Nothing else got a grace period. The fines — up to €15 million or 3% of global turnover, whichever is higher — apply now, to systems already in production, regardless of when they shipped.

A VENDOR'S SIGNATURE ISN'T YOUR SIGNATURE

The Code of Practice's signatory list is genuinely broad — nearly 200 organizations, spanning IT, telecom, education, and retail, with Meta and Google joining OpenAI, Anthropic, and Mistral AI among the model providers on the list. What it covers is the technical side of marking AI-generated output: a mix of machine-readable metadata, watermarking, and provenance tracking, with no single method mandated. What it does not cover is Article 50(1)'s interaction-disclosure duty, and the distinction matters more than most compliance calendars gave it credit for going into this week. The Act assigns that duty to the "deployer" — the company that builds and operates the product a user actually talks to — not to the foundation-model provider whose API sits underneath it. A support bot, sales agent, or voice IVR system built on GPT, Claude, or Gemini inherits none of its underlying provider's compliance work for this specific obligation; OpenAI's Code of Practice signature does not put a disclosure banner in a customer's product, and Anthropic's does not label a customer's chatbot. Coverage in the run-up to Sunday flagged a related trap: businesses that concluded in 2025 they fell outside Article 50's scope, on whatever reading was current then, and never revisited that call as their product evolved are now exposed with no transition window, because the rule doesn't grandfather anything already live.

THE OFFICE MEANT TO TAKE THE COMPLAINT MAY NOT EXIST YET

Article 70 of the Act required every member state to designate at least one market surveillance authority — which also serves as that country's single point of contact — and at least one notifying authority, and to do it by August 2, 2025: a full calendar year of runway, built in specifically so enforcement infrastructure would be ready by the time Article 50's fines went live. It largely wasn't used. As of last month, only 9 of the EU's 27 member states had both required authorities formally designated. Twelve had a legislative proposal pending or had named just one of the two. Six had designated neither. That means in exactly two-thirds of the bloc, the country-level office built to be a person's first stop for reporting an undisclosed chatbot or an unlabeled deepfake is incomplete, or doesn't exist on paper, in the same week the fines behind that complaint became legally enforceable. None of this grants immunity — the Commission's AI Office coordinates centrally, and general product-safety and consumer-protection authorities still have standing in states without a dedicated AI regulator — but it does mean enforcement intensity is set up to vary sharply by member state for as long as the gap persists, which is exactly the regulatory-arbitrage dynamic legal analysts flagged well before this week arrived.

WHAT THIS MEANS FOR TEAMS BUILDING ON AI

If your product includes a chatbot, voice agent, or any AI feature that talks to people in the EU, check today whether the disclosure is visible inside the interaction itself, not tucked into a settings page or a vendor's own compliance documentation — that gap is fineable now, independent of which member state your users sit in. Don't treat your foundation-model provider's Code of Practice signature as coverage for your own product: it addresses how that provider marks its output, not how your interface discloses that a user is talking to AI, and the two obligations sit with different parties under the Act. If you concluded a year or more ago that Article 50 didn't apply to something you've since shipped or expanded, revisit that call this week rather than on your next compliance review — the rule has no grace period for products already in the wild. And don't read a slow or unstaffed national authority as room to wait: the fines are live at the EU level as of Sunday, the enforcement gap is a matter of which office picks up the complaint and how fast, not whether the underlying obligation exists, and a first mover's exposure in a country still building out its AI regulator is genuinely unknown territory — which argues for treating disclosure and labeling as done now, not for treating the gap as cover.