Tomorrow, Not Pretending to Be Human Becomes the Law in Europe

August 2, 2026. On paper it is a Sunday, and there is no press conference scheduled in Brussels. But at midnight, the legal position of every company building or using AI products across the 27 member states of the European Union changes. Article 50 of the EU AI Act — Regulation (EU) 2024/1689 — starts to apply, and national market surveillance authorities gain the power to enforce it.

The substance is almost aggressively common-sense. AI systems that interact directly with people have to make it clear they are AI. Synthetic audio, images, video, and text produced by generative systems have to carry a machine-readable mark. Anyone deploying a deepfake has to disclose that the content was artificially generated or manipulated. People exposed to emotion recognition or biometric categorisation systems have to be told the system is running. Read the text of the article and the reaction is usually some version of "wait, wasn't that already required?"

Here is the deal, though: this is the first time that common sense comes with a price tag. Article 99(4) sets fines for breaches of operator obligations — including Article 50 — at up to €15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs, the arithmetic flips and the lower of the two becomes the cap. The obligations themselves have been sitting in a regulation that entered into force back in August 2024. What was missing was a hand that could reach out and grab you. On August 2, that hand shows up.

Something else switches on the same day. The European Commission and its AI Office gain their enforcement powers over providers of general-purpose AI models. Under Article 91 they can demand documentation and information. Under Article 92 they can evaluate a model directly, including requesting technical access through APIs or source code. Under Article 93, where non-compliance or serious systemic risk is identified, they can require specific measures, up to and including restricting a model on the EU market. GPAI obligations have technically applied since August 2, 2025, but the fining provision — Article 101 — was held back. That releases on August 2 too.

So the real identity of this date is not "the day new rules arrive." It is the day existing rules grow teeth.

Who's Standing on the Field — and Who Still Hasn't Shown Up

The first actor is the AI Office inside the European Commission. For most of the past year its work has not been writing rules but writing documents that explain how to follow the rules already written. It published draft guidelines on implementing Article 50 on May 8, 2026, closed the stakeholder consultation on June 3, and adopted the final guidelines on July 20. That is thirteen days before enforcement begins. Nobody on the receiving end is going to describe that as a generous runway.

The second actor is the set of national market surveillance authorities, and this is the weakest joint in the whole structure. The AI Act required member states to designate market surveillance authorities and notifying authorities by August 2, 2025. According to reporting, only 8 of 27 met that deadline, and as of June 2026 roughly 9 member states had designated both types of body. Finland was reported to be the first member state with full enforcement powers on December 22, 2025, with its Transport and Communications Agency (Traficom) operating as an active enforcer from January 1, 2026. Germany was reported to have designated the Bundesnetzagentur, Spain to have created a dedicated agency in AESIA, and Ireland to have chosen a decentralised model spreading powers across fifteen competent authorities.

Which means the enforcement map of Europe after August 2 is not uniform. The law applies in 27 countries simultaneously; the institutions capable of actually knocking on a door exist in some of them and not others. If you are a regulated company, the correct reading of that is not "we have breathing room." It is "we don't know where the first hit lands." Whichever prepared authority produces the first case will effectively set the interpretive baseline for the entire bloc, and the companies that end up in that case will not have chosen the venue.

The third actor is the regulated companies themselves, and something genuinely interesting happened here. The Commission built a voluntary instrument to help with Article 50 compliance — the Code of Practice on Transparency of AI-generated Content. It began with a public consultation in September 2025, ran a kick-off plenary on November 5, published a first draft on December 17, a second draft on March 3, 2026, and released the final code at the closing plenary on June 10, 2026. It was reported that the Commission on July 8 and the AI Board on July 9 concluded the code was adequate to support practical implementation of Articles 50(2), (4) and (5).

Then on July 31 — yesterday — the Commission published the signature tally. About 190 organisations signed. Section 1, for providers, has 83 signatories; Section 2, for deployers, has 152. The named Section 1 examples include Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI, and Synthesia. Section 2 examples include Bulgari, Fastweb, Getty Images, Iberdrola, Lenovo, and Lufthansa. The Commission specifically highlighted that about half of the signatories are small and recently founded companies.

The part not to skip: signing the code is voluntary. Sign it, and you can rely on it to demonstrate compliance with Article 50. Don't sign it, and you have to demonstrate compliance by other adequate means — and the Commission has said plainly that non-signatories can expect a larger number of requests for information. The incentive is not a stick. It is a difference in administrative pain.

What Actually Becomes Mandatory

Let's take the article apart paragraph by paragraph. Article 50(1) binds providers. AI systems intended to interact directly with natural persons must be designed and developed so that people are informed they are interacting with an AI system. The carve-out is where this is obvious to a reasonably well-informed observer, and there is a further exception for systems authorised by law to detect or prosecute crime — although systems made publicly available for reporting crime are pulled back into scope.

Paragraph 2 is the technically nasty one. Providers of AI systems generating synthetic audio, image, video, or text content must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solutions have to be effective, interoperable, robust, and reliable — subject to the qualifier "as far as this is technically feasible." There are exemptions: systems performing an assistive function for standard editing, or not substantially altering the input data, fall outside. Per the Commission's FAQ, a short sequence of numbers, symbols, or letters, and source code, are also outside the marking duty.

Paragraph 4 shifts to deployers. Anyone deploying an AI system that generates or manipulates image, audio, or video content constituting a deepfake has to disclose that the content has been artificially generated or manipulated. Where the content is part of an evidently artistic, creative, satirical, or fictional work, the disclosure obligation is limited to a manner that does not hamper the display or enjoyment of the work. For text the scope is narrower: it covers text published to inform the public on matters of public interest, and it does not apply where the content has undergone human review or editorial control with a person holding editorial responsibility. It was reported that the Commission's final guidelines take the position that deepfake content which is exclusively informative or commercial in nature cannot claim the reduced labelling treatment.

Paragraph 5 is about timing. All of this information has to be provided to the people concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. Small print at the bottom after the conversation ends does not clear that bar.

There is relief, but it is narrow. Generative AI systems already placed on the market before August 2, 2026 get four extra months — until December 2, 2026 — to implement the marking and detection duty. And content generated before August 2, 2026 does not need to be labelled retroactively; the Commission's own material states that "content generated prior to 2 August 2026 does not need to be labelled retroactively," though it encourages doing so anyway.

Here is the timeline and the numbers laid out.

Item What it requires Applies from
Art. 50(1) — chatbot disclosure Inform people they are interacting with an AI system (unless obvious) 2026-08-02
Art. 50(2) — machine-readable marking Watermarks, metadata, or equivalent detectable marks on synthetic output 2026-08-02 (systems already on market: 2026-12-02)
Art. 50(3) — emotion recognition / biometric categorisation Inform exposed persons that the system is operating 2026-08-02
Art. 50(4) — deepfakes and public-interest text Disclose artificial generation or manipulation (artistic/satirical relaxed; human-edited text exempt) 2026-08-02
Art. 99(4) — penalty tier for Art. 50 Up to €15M or 3% of worldwide annual turnover, whichever is higher 2026-08-02
Art. 99(3) — prohibited practices (Art. 5) Up to €35M or 7%, whichever is higher since 2025-02-02
Art. 99(5) — incorrect or misleading information Up to €7.5M or 1%, whichever is higher 2026-08-02
GPAI enforcement (Arts. 91–93, 101) Information requests, model evaluations, required measures, fines 2026-08-02
High-risk systems (Annex III) Reported as deferred by the Digital Omnibus 2027-12-02

That last row may be the most important line in the table. August 2 was originally the day the Annex III high-risk obligations arrived as well. Then on May 7, 2026, negotiators from the Council, Parliament, and Commission reached a provisional agreement on the AI Digital Omnibus, and it was reported that standalone Annex III high-risk obligations moved to December 2, 2027, with AI embedded in regulated products under Annex I moving to August 2, 2028. The Council was reported to have given final approval on June 29. The point that matters here: Article 50 was not on the deferral list. Of everything the AI Act was supposed to switch on this summer, the transparency duties are among the few that arrived on schedule.

What Each Side Is Getting Out of This

For the Commission, this is a credibility play. For the past year the AI Act has been squeezed between industry complaints that it is too early and too heavy, and open hostility from Washington — and the high-risk provisions genuinely did slip. Keeping the transparency obligations on schedule in that environment is a signal: we will bend where bending is warranted, and hold where it is not. It also helps that Article 50 is one of the rare pieces of EU regulation an ordinary citizen can feel. Chatbots saying they are chatbots and deepfakes carrying labels is a form of regulatory output that is easy to explain, which is not something you can say about conformity assessment procedures for Annex III systems.

For the large AI providers the calculation is layered. Google, OpenAI, Meta, Microsoft, Anthropic, and Mistral all appearing in Section 1 means they decided the code was not a thing to fight but a tool for predictability. Watermarking is an area every one of them was already investing in. Following a single code beats being pulled in 27 directions by 27 supervisory authorities applying their own reading of "effective, interoperable, robust and reliable." Sitting in the room where the standard is written beats having the standard applied to you.

But signing is not the same as agreeing. Google announced its signature on July 24 in a post by Karen Massin, its head of government affairs and public policy for EU institutions, and used the same post to register a complaint. The piece leads with SynthID, the company's watermarking technology, and its adoption of the C2PA standard — and then says that "adding more regulatory complexity — as technical solutions are still evolving — could contradict Europe's goals for competitiveness and simplification." It goes on to warn that an excess of AI labels and disclosures risks overwhelming users rather than informing them, which would undercut the very transparency the rules are chasing. That is a company signing the document while laying out its negotiating position for the next round.

The deployer side of the signatory list tells a different story. Bulgari, Lufthansa, Iberdrola, Lenovo, Getty Images, Fastweb. These are not AI companies. They are companies that use AI. The fact that Section 2 has 152 signatories against Section 1's 83 follows the same logic: Article 50(4) reaches every brand that puts a generated image in a campaign or an AI-written piece into public-interest communication. For them the code functions as both a compliance manual and a shield — the ability to say, if something goes wrong later, that they followed the Commission's own code.

There is a real benefit at the small end too. The Commission's note that roughly half the signatories are small and recent companies is not purely promotional. For a company with no in-house legal team trying to interpret what "machine-readable and detectable" means in practice, the code is effectively free compliance consulting. And Article 99(6) matters here more than the headline number does: for SMEs and start-ups, the fine is capped at whichever of the percentage or the fixed amount is lower, not higher, which changes the risk profile substantially.

Mandated disclosure is a tool the EU has been swinging for decades, and the results are not uniform. The success case usually cited is the energy label. Starting in the 1990s, household appliances had to carry a grade from A to G, and it worked on two levels: consumers used it, and more importantly manufacturers began designing products to hit a grade. When grade inflation piled up so many pluses that the scale stopped meaning anything, the EU rescaled the whole thing back to A–G in 2021 — a painful exercise that was itself evidence the mechanism was alive and being used. Disclosure changed behaviour on both sides of the transaction.

The failure case is far more famous, because you click through it every day. Cookie banners. The 2009 revision of the ePrivacy Directive combined with the GDPR in 2018 put a consent pop-up on essentially every website in Europe. The intent was to hand users control. The outcome was a culture of reflexively dismissing a dialog nobody reads, a new vocabulary term in "consent fatigue," and an entire design practice built around dark patterns that nudge people toward accepting. The EU itself has effectively conceded the problem — reforming the cookie rules landed on the Digital Omnibus agenda. What the regulation demanded was notice. What the market produced was the appearance of notice.

For machine-readable signals specifically there is an even sharper cautionary tale: Do Not Track. Around 2011, browsers began sending a header telling servers not to track the user. Technically it worked perfectly. The problem was that nobody was obliged to honour it, and so almost nobody did. The W3C abandoned the standardisation effort in 2019, leaving behind a header that exists and means nothing. If Article 50(2) is going to avoid that fate, the incentive has to exist on both sides — not just for the party attaching the mark, but for the platforms that have to read it and surface it to users. The AI Act mandates the first half. It has not yet mandated the second.

So the fate of Article 50 will probably be decided in the ecosystem rather than in the text. Does a watermark survive a screenshot, a re-encode, a crop? Do marks from different vendors interoperate, or does each company build a detector that only reads its own signal? Do social platforms actually put the disclosure in the interface where a scrolling user sees it? Google's statement that it is working with Apple, Eleven Labs, Kakao, Nvidia, and OpenAI to push adoption of interoperable watermarking tools is a direct acknowledgment of exactly this problem. Solve it and you get the energy label. Don't and you get the cookie banner, at planetary scale.

What Washington and Beijing Are Calculating Right Now

The most striking parallel is in California. The California AI Transparency Act (SB 942) was originally due to take effect on January 1, 2026. Then AB 853, signed by Governor Gavin Newsom on October 13, 2025, pushed the existing provisions to August 2, 2026 — the same day as the EU — while setting new obligations for large online platforms and generative AI hosting platforms to become operative on January 1, 2027. Whether that alignment was coincidence or coordination has not been made public, but the practical result is that provenance-marking duties start on both sides of the Atlantic on the same date. For a company shipping a global product, that is a small mercy: one date, two rulebooks, beats two dates and two rulebooks.

China has been ahead of both for nearly a year. Its Measures for Labeling of AI-Generated Synthetic Content took effect on September 1, 2025, and they require both explicit and implicit labels on AI-generated text, images, audio, video, and virtual scenes distributed on Chinese platforms. Implicit labels go into file metadata. The rules also prohibit maliciously deleting, altering, forging, or concealing labels, and prohibit providing tools or services that help others do so. Where the EU wrote "as far as this is technically feasible," China simply nailed the requirement down. On raw stringency Beijing is out front, and any serious conversation about interoperable marking standards now has to account for compatibility with the Chinese approach whether or not anyone says so out loud.

Federal policy in the United States runs the other direction. There is no comprehensive federal AI marking mandate, and there has been sustained discussion of federal preemption of state AI laws. Which makes the sight of American AI companies signing an EU code in large numbers mildly ironic — arguing for minimal regulation at home while helping design the regulation abroad. It reads less like hypocrisy than like market-by-market optimisation. If you cannot walk away from the European market, being in the room where its rules are drafted is simply the rational move.

The genuinely awkward position belongs to the open-source ecosystem. The Commission's GPAI guidelines establish that only those making significant modifications to a model take on provider obligations, not those making minor changes, and they set out conditions under which open-source providers are exempt from certain duties. But the Article 50(2) marking obligation attaches to the output of a system, not to a model. Whoever takes the weights and stands up a service ends up carrying the marking responsibility. For a large provider that is solved by baking watermarking into the API. For a small fine-tuner or an app developer running open weights locally, it is a real engineering task with a real deadline, and there is no API vendor to hand it to.

Then there are the platforms. For AI systems integrated into very large online platforms or search engines designated under the Digital Services Act, the AI Office has direct oversight, and DSA obligations stack on top. Which means the largest platforms are squeezed from two directions at once: a duty to attach marks, and a separate set of pressures about what to do with marked content once it is flowing through their feeds. In practice they hold the key to whether Article 50 ends up as an energy label or a cookie banner — and the regulation does not give the Commission a clean way to force that hand.

So What Actually Changes for You

If you are a developer — if you serve users in the EU, there are three things to check this week. One: does your chatbot, voice agent, or automated support flow disclose that it is AI at the point of first interaction, clearly enough that a user notices? Two: does your generated image, video, audio, or text carry a machine-readable mark — and if you are calling a commercial API, is the provider attaching it, or did you assume they were? Three: if the system was already on the market before August 2, you have until December 2 for the marking duty, and that grace period does not extend to anything you launch after August 2. Building the marking pipeline against the December date while shipping new features under the August one is a scheduling trap worth naming now.

If you work in content or marketing — your exposure here is larger than you probably think. If your campaign uses an AI-generated person, or video that resembles a real individual, place, or event, you may be deploying a deepfake within the meaning of Article 50(4). The artistic and satirical relaxation exists, but it was reported that the final guidelines treat purely informative or commercial content as unable to claim it. And if you publish AI-written text on matters of public interest, the exemption depends on human review with someone holding editorial responsibility — so document that review process, because the process is the exemption. An undocumented editorial workflow is not much of a defence when an authority asks how the text was produced.

If you are in legal or compliance — the first question to answer after August 2 is whether you are a provider or a deployer, because the obligations differ and it is extremely common for one company to be both at once for different products. The second decision is whether to sign the Code of Practice. It is not required, but skipping it means, in the Commission's own words, fielding more requests for information and designing your own evidence of compliance from scratch. The third is to put the uneven readiness of the 27 national authorities on your risk map rather than treating the EU as one jurisdiction. The first enforcement actions are most likely to originate where the institutions actually exist, and that geography is knowable today.

If you are a regular user — over the next few months you will see small markers appearing across the services you use in Europe. Banners saying you are talking to an AI. Labels tucked into the corner of generated images. Disclosure lines in video descriptions. Honestly, whether any of it proves useful is still unknown. It could become background noise you learn to ignore the way you ignore cookie dialogs, or it could become a genuine input to how you judge what you are looking at. The fork in the road is not whether the marks exist. It is how well the platforms choose to show them to you.

🥄 Three Things You're Probably Wondering

— So who actually gets fined on August 2? Probably nobody. Only a minority of member states were reported to have fully stood up their market surveillance authorities, and penalties require investigation and a right to be heard, so nothing lands in days. What changes is that the clock starts. Conduct from tomorrow onward is conduct that can be examined later, which is a different thing from being safe.

— Can't you just strip the watermark off? There is no fully robust marking method yet. Resistance to re-encoding, cropping, and screenshotting varies a lot by technique, which is exactly why Article 50(2) carries the "as far as this is technically feasible" qualifier. Worth noting that the EU does not have an equivalent to China's explicit ban on maliciously removing labels. Whether this becomes a meaningful safeguard or a cosmetic one is too early to call.

— Does this apply to companies outside the EU? If you place an AI system on the EU market or serve people inside the EU, you can be in scope — the AI Act has extraterritorial reach in a similar shape to the GDPR. But whether a given service counts as provider or deployer, and which paragraph bites, varies case by case in ways that resist a general answer. If you have EU revenue, there is no good reason to keep postponing the legal review.

Further Reading

Numbers are as of announcement and may change.