The EU AI Act has entered a new phase, and for many businesses, the compliance countdown is over.
From 2 August, regulators have begun enforcing transparency obligations that require organisations to tell users when they are interacting with AI and to label AI-generated content, including text, images, audio, video and deepfakes. Companies that fail to comply could face fines of up to 3% of their annual global turnover.
For many organisations, the biggest surprise is not the size of the penalties. It’s discovering that the rules apply to them at all.
The AI Act isn’t just about Big Tech
For months, many businesses have assumed the AI Act was primarily aimed at developers of foundation models such as OpenAI, Google, Anthropic or DeepSeek, or that the most significant obligations had been postponed until 2027.
Neither assumption is correct.
While some provisions affecting high-risk AI systems have been delayed under the EU’s Omnibus reforms, the transparency obligations were not. They are already in force.
Even more importantly, organisations do not have to build their own AI models to fall within scope. If your business integrates AI into its own products or services and those outputs reach users in the EU, your organisation may be considered a deployer under the AI Act. That means the compliance responsibilities are yours, not your AI vendor’s.
OpenAI cannot add a disclosure notice inside your branded application. Anthropic cannot label content generated within your customer portal. Those obligations remain with the organisation presenting the AI to users.
Brussels is moving from legislation to enforcement
To coincide with the latest phase of the legislation, the European Commission (EC) has expanded its AI office with an additional 38 specialists dedicated to monitoring compliance. Alongside national regulators across the EU, the new enforcement team will oversee implementation of the rules, investigate potential breaches and monitor systemic AI risks ranging from deepfakes and cyber threats to harmful manipulation and attacks on fundamental rights.
The EC has also introduced new whistleblowing and compliance reporting tools, making it easier for employees and users to confidentially report suspected violations.
According to Brussels, enforcement has begun.
Henna Virkkunen, the EC’s Executive Vice-President for Tech Sovereignty, described the latest measures as an important step towards ensuring AI is something “people and businesses can understand and trust.”
Transparency is now a legal obligation
The new requirements are designed to tackle one of the biggest challenges created by generative AI which is knowing what is real.
Businesses must clearly inform users whenever they are interacting with AI rather than a human. AI-generated or AI-manipulated content must also be labelled appropriately, with some content requiring machine-readable markers such as digital watermarks to enable reliable identification.
The rules are particularly focused on deepfakes and other synthetic content that could mislead the public. The EC has repeatedly warned that generative AI allows misinformation to be produced faster, at greater scale and with increasing sophistication, making transparency essential for maintaining public trust.
There are limited exemptions for artistic, satirical and fictional works, as well as certain personal uses, but content produced in professional settings generally falls within the scope of the new obligations.
Many organisations are further behind than they realise
Perhaps the most concerning aspect is how unprepared many organisations appear to be.
Recent compliance research suggested that nearly four out of five organisations covered by the AI Act had taken little or no meaningful action towards compliance. Many mistakenly believed they had until 2027 because of the delayed implementation timetable for some provisions.
That misunderstanding could prove costly.
The transparency rules are already enforceable, and national regulators across all 27 EU member states now have the authority to investigate organisations and impose penalties. While legal experts expect regulators to focus initially on organisations demonstrating genuine efforts towards compliance, businesses that have ignored the requirements altogether may find themselves exposed much sooner than anticipated.
What should businesses do now?
The first step is understanding where AI is already operating inside your organisation. Many businesses have introduced AI incrementally through customer support tools, marketing platforms, document generation systems, productivity software and internally developed applications without fully considering the regulatory implications.
Organisations should identify every AI system that interacts with customers, employees or the public and determine whether users are being clearly informed they are engaging with AI. They should also review whether any AI-generated content, including marketing copy, reports, images or videos, requires disclosure or technical labelling.
Businesses should also examine contracts with AI vendors. While technology providers can support compliance, they cannot assume responsibility for obligations that belong to the deploying organisation. Governance processes, documentation and clear accountability will become increasingly important as regulators begin scrutinising AI deployments.
Organisations should also stop viewing the AI Act as tomorrow’s problem. AI governance is rapidly becoming an operational requirement rather than simply another compliance project.
The bottom line is businesses that have already mapped where AI touches EU users, documented their deployments and built transparency into their customer journeys will likely enter this next phase with confidence.
Those that assumed the law only applied to Silicon Valley AI labs or that compliance could wait until 2027 may now face a far more urgent reality.







