Data Privacy Alerts

EU Begins Enforcement of AI Act Transparency and GPAI Rules

EU enforcement of the AI Act has begun. Learn how mandatory transparency obligations and new general-purpose AI rules impact your organization's compliance strategy and operational governance in European markets.
Why This Alert Is Important

The European Commission's enforcement of the AI Act beginning August 2, 2026, marks a pivotal compliance milestone with mandatory transparency obligations and strict general-purpose AI rules. Privacy and legal professionals must align their AI governance and disclosure frameworks to mitigate regulatory exposure across European markets.

Overview Text

On August 2, 2026, the European Commission’s AI Office and national competent authorities began enforcing key provisions of the landmark Artificial Intelligence (AI) Act. This phase introduces mandatory transparency requirements designed to prevent deception and ensure informed user consent. Under the new rules, interactive systems such as chatbots must explicitly inform users when they are interacting with AI rather than a human. Additionally, deepfakes must be clearly labeled, and AI-generated or altered content must carry machine-readable marks to assist in automated detection.

Enforcement also extends to providers of General-Purpose AI (GPAI) models and bans on prohibited AI practices. All GPAI model providers must document technical information, implement copyright policies, and publish detailed summaries of their training content. Advanced GPAI models posing systemic risks face heightened obligations to address cyber threats, loss of control, and fundamental rights risks. To facilitate compliance and reporting, the AI Office launched dedicated Complaint and Whistleblower Tools alongside appointing a Lead Scientific Adviser to oversee model evaluations. Meanwhile, rules regarding high-risk AI systems have been postponed to late 2027 and 2028 under the AI Omnibus.

What It Covers

Key Implications or Developments

  • The active enforcement of the EU AI Act carries significant operational implications for multinational enterprises, technology vendors, and public sector organizations operating within or serving the EU. Organizations deploying user-facing AI tools must immediately audit their interfaces to integrate explicit disclosure mechanisms and embed machine-readable watermarking into generated media. Failure to comply with transparency rules or continuing prohibited practices could trigger joint enforcement from national supervisory authorities, the European Data Protection Supervisor, or the AI Office.
  • For companies developing or fine-tuning GPAI models, the requirement to publish training summaries and maintain technical documentation demands robust data lineage and copyright management strategies. The introduction of confidential Whistleblower and Complaint tools increases the probability of regulatory scrutiny initiated by internal employees or downstream software integration partners. While high-risk AI system compliance timelines have been extended to December 2027, enterprise privacy teams cannot delay building scalable AI risk governance frameworks. Organizations must coordinate multi-jurisdictional compliance strategies to maintain trust, satisfy reporting obligations, and avoid severe regulatory sanctions.
  • Organizations can find resources to assist with determining their compliance obligations at https://artificialintelligenceact.eu/.
Expert Analysis from

Fahad Diwan, JD, FIP, CIPP/M, CIPP/C, Director of Product, Privacy, Exterro

The active enforcement of the EU AI Act’s transparency and General-Purpose AI (GPAI) rules marks a critical shift from compliance planning to active operational accountability, demanding immediate action even as high-risk system timelines extend into late 2027. To mitigate exposure from mandatory chatbot disclosures, machine-readable watermarking, and GPAI training summaries, privacy and legal leaders must urgently audit user interfaces, map data lineage, and establish a centralized inventory of all internal and vendor-integrated AI models.

Data Privacy Tip

Conduct comprehensive data mapping and AI inventory audits today to ensure compliance with transparency mandates. Learn how the Exterro Data Governance suite automates vendor risk and AI assessments.