• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Regulation

The Third Wave of EU AI Act Requirements Are in Force: Transparency Requirements & Supervisory Powers

Coininsight by Coininsight
August 28, 2026
in Regulation
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


by Avi Gesser, Robert Maddox and Martha Hirst

From Left to Right: Avi Gesser, Robert Maddox, and Martha Hirst. Photos courtesy of Debevoise & Plimpton LLP.

On 2 August 2026, the third major wave of requirements under the EU AI Act (the “Act”) entered into force. For many businesses, the most relevant changes fall into two key areas: (1) the AI transparency requirements under Article 50; and (2) the Act’s now-operational market surveillance and regulatory enforcement regime.

This wave of requirements is, however, narrower than originally anticipated. The Digital Omnibus on AI, adopted in July 2026, delayed the high-risk AI system requirements – which account for many of the Act’s most substantive requirements – until 2 December 2027 (for stand-alone high-risk AI systems) or 2 August 2028 (for high-risk systems embedded in certain regulated products). See our previous blog post for more information.

Nevertheless, we summarize the main new requirements below.

As we have previously discussed, the Act is the EU’s flagship AI regulation. It takes a risk-based approach, imposing different requirements on: (i) prohibited or “unacceptable risk” systems; (ii) high-risk systems; (iii) systems that trigger specific transparency obligations; and (iv) general-purpose AI models.

The Act entered into force on 1 August 2024, but its provisions apply in stages. The first wave, including the prohibited-practices and AI-literacy provisions, applied from 2 February 2025. The second wave, principally covering general-purpose AI models and the EU’s AI governance framework, applied from 2 August 2025. The third wave of requirements is now in effect.

Article 50 imposes four main categories of transparency requirements on providers and deployers of certain AI systems: (1) informing individuals when they are interacting directly with an AI system; (2) technically marking AI-generated or AI-manipulated content so that outputs can be reliably detected and traced as AI-generated or altered; (3) disclosing the use of emotion-recognition or biometric-categorization systems; and (4) labelling deepfakes and certain AI-generated text relating to matters of public interest.

In parallel, the European Commission has now published both a final Code of Practice on Transparency of AI-Generated Content and official Guidelines on Article 50. The Code is voluntary, but provides a recognized route for demonstrating compliance with the content-marking and labelling obligations.

For many businesses, two issues are likely to be particularly relevant:

  • Deepfake labelling. Deployers of AI systems that generate or manipulate deepfakes must disclose that the content has been artificially generated or manipulated. Determining whether content is a “deepfake” can be complex, particularly where AI is used to edit otherwise authentic content or to create realistic but fictional material. We discuss these issues in more detail in our separate post, When Does AI-Generated Content Become a Deepfake, and Why Does It Matter?
  • AI content metadata labelling and watermarking. Providers of AI systems that generate synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as AI-generated or manipulated. This may include the use of metadata identifiers, such as embedded provenance information or cryptographic watermarks, or other technical solutions that allow the output to be reliably identified as artificially generated or manipulated in accordance with the Act. The Commission’s guidance and Code of Practice also provide illustrative examples of how these requirements may be implemented in practice, including through different forms of watermarking and provenance-tracking techniques. This obligation may be relevant not only to major AI vendors, but also to businesses that develop or commission their own chatbots, assessment tools or other AI applications and put them into service under their own name, where those systems generate synthetic content. The requirement contemplates technical measures, such as metadata and watermarking; an overt statement that an output is “AI-generated” may be useful, but is not by itself a substitute for machine-readable marking. A limited transition period applies: providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the Article 50(2) machine-readable marking requirement.

The Act’s dedicated market-surveillance and enforcement provisions now apply.

  • National market-surveillance authorities may investigate potentially non-compliant AI systems, require access to information and documentation (and, in defined circumstances, data or source code) and order corrective action, restriction, withdrawal or recall.
  • The European Commission, acting through the AI Office, now has its full investigatory and enforcement powers in relation to general-purpose AI models and certain AI systems under its supervision. These include powers to request information, conduct model evaluations, require mitigations and restrict or withdraw models or systems from the EU market. This is particularly important for the prohibited AI practices under Article 5, which have applied since 2 February 2025. The Act’s dedicated enforcement machinery is now available for those prohibitions, and breaches may attract fines of up to €35 million or 7% of worldwide annual turnover.
  • In addition, any individual or organization may submit a complaint to a market surveillance authority regarding an alleged breach of the Act, and reports of suspected infringements are also brought within the scope of the EU Whistleblowing Directive. Businesses should therefore ensure that internal reporting channels and policies appropriately capture AI-related concerns.

Due to the Omnibus delays, the next relevant milestones in the Act’s implementation are as follows:

  • 2 December 2026: This date marks the end of the transition period for the machine-readable marking requirements for AI-generated content. It is also when the new prohibition on AI systems that generate or manipulate non-consensual intimate imagery or child sexual abuse material comes into effect.
  • 2 December 2027 and 2 August 2028: The principal high-risk AI system obligations will come into force. However, under the Article 111 grandfathering clause, these requirements generally apply only to high-risk systems placed on the market or put into service after the relevant date, unless an existing system undergoes a significant design change thereafter.

Assess Article 50 touchpoints and prioritize machine-readable labelling. Businesses should identify systems that generate or materially manipulate synthetic content (such as AI chatbots that generate written responses, or tools that create AI-generated images or alter audio and video content) and determine which Article 50 obligations apply, particularly for chatbots, embedded assistants and content-generation tools. Providers should assess how machine-readable identifiers, metadata or watermarking will operate across APIs and downstream distribution. Although systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2), implementation should begin now given the technical complexity of this area. In practice, monitoring how other market participants are approaching compliance may also help reduce regulatory exposure, as alignment with emerging market practice is likely to be an important factor in supervisory expectations.

Operationalize enforcement readiness under the newly applicable supervisory regime. Regulators can now investigate and sanction breaches of provisions already applicable, including Article 5 prohibitions and relevant Article 50 transparency obligations. Businesses should assign responsibility for regulatory engagement, establish document-production and escalation procedures, and ensure whistleblowing channels capture potential AI Act breaches.

Avi Gesser and Robert Maddox are Partners, and Martha Hirst is an Associate at Debevoise & Plimpton. This post  first appeared as a Memo for the firm.

The views, opinions and positions expressed within all posts are those of the author(s) alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author(s) and any liability with regards to infringement of intellectual property rights remains with the author(s).

Related articles

Nine in ten compliance professionals lack full confidence they could spot a sanctioned individual hiding behind a shell company

August 28, 2026

Bored Directors? How to Make Sure Board Materials Are Contributing Value

August 26, 2026


by Avi Gesser, Robert Maddox and Martha Hirst

From Left to Right: Avi Gesser, Robert Maddox, and Martha Hirst. Photos courtesy of Debevoise & Plimpton LLP.

On 2 August 2026, the third major wave of requirements under the EU AI Act (the “Act”) entered into force. For many businesses, the most relevant changes fall into two key areas: (1) the AI transparency requirements under Article 50; and (2) the Act’s now-operational market surveillance and regulatory enforcement regime.

This wave of requirements is, however, narrower than originally anticipated. The Digital Omnibus on AI, adopted in July 2026, delayed the high-risk AI system requirements – which account for many of the Act’s most substantive requirements – until 2 December 2027 (for stand-alone high-risk AI systems) or 2 August 2028 (for high-risk systems embedded in certain regulated products). See our previous blog post for more information.

Nevertheless, we summarize the main new requirements below.

As we have previously discussed, the Act is the EU’s flagship AI regulation. It takes a risk-based approach, imposing different requirements on: (i) prohibited or “unacceptable risk” systems; (ii) high-risk systems; (iii) systems that trigger specific transparency obligations; and (iv) general-purpose AI models.

The Act entered into force on 1 August 2024, but its provisions apply in stages. The first wave, including the prohibited-practices and AI-literacy provisions, applied from 2 February 2025. The second wave, principally covering general-purpose AI models and the EU’s AI governance framework, applied from 2 August 2025. The third wave of requirements is now in effect.

Article 50 imposes four main categories of transparency requirements on providers and deployers of certain AI systems: (1) informing individuals when they are interacting directly with an AI system; (2) technically marking AI-generated or AI-manipulated content so that outputs can be reliably detected and traced as AI-generated or altered; (3) disclosing the use of emotion-recognition or biometric-categorization systems; and (4) labelling deepfakes and certain AI-generated text relating to matters of public interest.

In parallel, the European Commission has now published both a final Code of Practice on Transparency of AI-Generated Content and official Guidelines on Article 50. The Code is voluntary, but provides a recognized route for demonstrating compliance with the content-marking and labelling obligations.

For many businesses, two issues are likely to be particularly relevant:

  • Deepfake labelling. Deployers of AI systems that generate or manipulate deepfakes must disclose that the content has been artificially generated or manipulated. Determining whether content is a “deepfake” can be complex, particularly where AI is used to edit otherwise authentic content or to create realistic but fictional material. We discuss these issues in more detail in our separate post, When Does AI-Generated Content Become a Deepfake, and Why Does It Matter?
  • AI content metadata labelling and watermarking. Providers of AI systems that generate synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as AI-generated or manipulated. This may include the use of metadata identifiers, such as embedded provenance information or cryptographic watermarks, or other technical solutions that allow the output to be reliably identified as artificially generated or manipulated in accordance with the Act. The Commission’s guidance and Code of Practice also provide illustrative examples of how these requirements may be implemented in practice, including through different forms of watermarking and provenance-tracking techniques. This obligation may be relevant not only to major AI vendors, but also to businesses that develop or commission their own chatbots, assessment tools or other AI applications and put them into service under their own name, where those systems generate synthetic content. The requirement contemplates technical measures, such as metadata and watermarking; an overt statement that an output is “AI-generated” may be useful, but is not by itself a substitute for machine-readable marking. A limited transition period applies: providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the Article 50(2) machine-readable marking requirement.

The Act’s dedicated market-surveillance and enforcement provisions now apply.

  • National market-surveillance authorities may investigate potentially non-compliant AI systems, require access to information and documentation (and, in defined circumstances, data or source code) and order corrective action, restriction, withdrawal or recall.
  • The European Commission, acting through the AI Office, now has its full investigatory and enforcement powers in relation to general-purpose AI models and certain AI systems under its supervision. These include powers to request information, conduct model evaluations, require mitigations and restrict or withdraw models or systems from the EU market. This is particularly important for the prohibited AI practices under Article 5, which have applied since 2 February 2025. The Act’s dedicated enforcement machinery is now available for those prohibitions, and breaches may attract fines of up to €35 million or 7% of worldwide annual turnover.
  • In addition, any individual or organization may submit a complaint to a market surveillance authority regarding an alleged breach of the Act, and reports of suspected infringements are also brought within the scope of the EU Whistleblowing Directive. Businesses should therefore ensure that internal reporting channels and policies appropriately capture AI-related concerns.

Due to the Omnibus delays, the next relevant milestones in the Act’s implementation are as follows:

  • 2 December 2026: This date marks the end of the transition period for the machine-readable marking requirements for AI-generated content. It is also when the new prohibition on AI systems that generate or manipulate non-consensual intimate imagery or child sexual abuse material comes into effect.
  • 2 December 2027 and 2 August 2028: The principal high-risk AI system obligations will come into force. However, under the Article 111 grandfathering clause, these requirements generally apply only to high-risk systems placed on the market or put into service after the relevant date, unless an existing system undergoes a significant design change thereafter.

Assess Article 50 touchpoints and prioritize machine-readable labelling. Businesses should identify systems that generate or materially manipulate synthetic content (such as AI chatbots that generate written responses, or tools that create AI-generated images or alter audio and video content) and determine which Article 50 obligations apply, particularly for chatbots, embedded assistants and content-generation tools. Providers should assess how machine-readable identifiers, metadata or watermarking will operate across APIs and downstream distribution. Although systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2), implementation should begin now given the technical complexity of this area. In practice, monitoring how other market participants are approaching compliance may also help reduce regulatory exposure, as alignment with emerging market practice is likely to be an important factor in supervisory expectations.

Operationalize enforcement readiness under the newly applicable supervisory regime. Regulators can now investigate and sanction breaches of provisions already applicable, including Article 5 prohibitions and relevant Article 50 transparency obligations. Businesses should assign responsibility for regulatory engagement, establish document-production and escalation procedures, and ensure whistleblowing channels capture potential AI Act breaches.

Avi Gesser and Robert Maddox are Partners, and Martha Hirst is an Associate at Debevoise & Plimpton. This post  first appeared as a Memo for the firm.

The views, opinions and positions expressed within all posts are those of the author(s) alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author(s) and any liability with regards to infringement of intellectual property rights remains with the author(s).

Share76Tweet47

Related Posts

Nine in ten compliance professionals lack full confidence they could spot a sanctioned individual hiding behind a shell company

by Coininsight
August 28, 2026
0

New poll of legal, compliance and financial services professionals also finds almost six in ten organisations have not recently tested...

Bored Directors? How to Make Sure Board Materials Are Contributing Value

by Coininsight
August 26, 2026
0

Board materials should be channeling the board’s energy and effectiveness as strategic advisers, not bogging them down, Protiviti’s Jim DeLoach...

The Supreme Court Clarifies the Scope of the SEC’s Disgorgement Authority

by Coininsight
August 26, 2026
0

by Jonathan J. Rusch Photo courtesy of author Over the past decade, the United States Supreme Court has provided increasing...

A computer cut off their income. Now Uber faces an €825m GDPR fine

by Coininsight
August 25, 2026
0

Uber has been fined almost €825 million by the Dutch Data Protection Authority (AP) in one of the largest GDPR...

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

by Coininsight
August 24, 2026
0

NIST’s new draft framework for evaluating AI systems, TEVV-Athlon, should provide a useful reframe for leaders who rely on checklist-style...

Load More
  • Trending
  • Comments
  • Latest
What’s Actually Going On With Ripple’s Blockchain?

What’s Actually Going On With Ripple’s Blockchain?

January 12, 2026
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Easy methods to Host a Storj Node – Setup, Earnings & Experiences

Easy methods to Host a Storj Node – Setup, Earnings & Experiences

March 11, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1

Nektar Therapeutics’ Billion-Dollar Balance Sheet Faces a Multi-Year Test

August 28, 2026

The Third Wave of EU AI Act Requirements Are in Force: Transparency Requirements & Supervisory Powers

August 28, 2026

Bitcoin Gained $14,264 in a Week, Galaxy Says Next Bottom Signal Is Close

August 28, 2026

Visa Partners With Upbit Parent on Stablecoin Payments

August 28, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

Nektar Therapeutics’ Billion-Dollar Balance Sheet Faces a Multi-Year Test

August 28, 2026

The Third Wave of EU AI Act Requirements Are in Force: Transparency Requirements & Supervisory Powers

August 28, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights