
The European Commission's enforcement of the AI Act beginning August 2, 2026, marks a pivotal compliance milestone with mandatory transparency obligations and strict general-purpose AI rules. Privacy and legal professionals must align their AI governance and disclosure frameworks to mitigate regulatory exposure across European markets.
On August 2, 2026, the European Commission’s AI Office and national competent authorities began enforcing key provisions of the landmark Artificial Intelligence (AI) Act. This phase introduces mandatory transparency requirements designed to prevent deception and ensure informed user consent. Under the new rules, interactive systems such as chatbots must explicitly inform users when they are interacting with AI rather than a human. Additionally, deepfakes must be clearly labeled, and AI-generated or altered content must carry machine-readable marks to assist in automated detection.
Enforcement also extends to providers of General-Purpose AI (GPAI) models and bans on prohibited AI practices. All GPAI model providers must document technical information, implement copyright policies, and publish detailed summaries of their training content. Advanced GPAI models posing systemic risks face heightened obligations to address cyber threats, loss of control, and fundamental rights risks. To facilitate compliance and reporting, the AI Office launched dedicated Complaint and Whistleblower Tools alongside appointing a Lead Scientific Adviser to oversee model evaluations. Meanwhile, rules regarding high-risk AI systems have been postponed to late 2027 and 2028 under the AI Omnibus.
Key Implications or Developments
Fahad Diwan, JD, FIP, CIPP/M, CIPP/C, Director of Product, Privacy, Exterro
The active enforcement of the EU AI Act’s transparency and General-Purpose AI (GPAI) rules marks a critical shift from compliance planning to active operational accountability, demanding immediate action even as high-risk system timelines extend into late 2027. To mitigate exposure from mandatory chatbot disclosures, machine-readable watermarking, and GPAI training summaries, privacy and legal leaders must urgently audit user interfaces, map data lineage, and establish a centralized inventory of all internal and vendor-integrated AI models.
Conduct comprehensive data mapping and AI inventory audits today to ensure compliance with transparency mandates. Learn how the Exterro Data Governance suite automates vendor risk and AI assessments.