EU Begins Enforcing New AI Act Rules as Commission Expands Staffing

Header Image

Chatbots and AI-generated content face new transparency duties as the Commission strengthens its AI Office.

 

The European Commission will begin actively enforcing key provisions of the EU Artificial Intelligence Act from 2 August, introducing new transparency requirements for chatbots and artificially generated or manipulated content. At the same time, Brussels is recruiting additional staff as the responsibilities of its AI Office continue to expand.

New transparency requirements

Under the new rules, chatbots and other interactive AI systems must inform users that they are communicating with a machine rather than a person.

Deepfakes, including images, videos and audio created or altered using artificial intelligence, must be clearly labelled. Other AI-generated or manipulated content must also carry machine-readable markings to make it easier to identify.

According to the Commission, the measures aim to limit deception and manipulation while strengthening public and business confidence in the technology. The obligations apply to public authorities operating across the EU, as well as private companies using AI tools in their interactions with the public.

Providers of systems placed on the market before 2 August have until 2 December 2026 to comply with the labelling requirements.

Powers over general-purpose AI providers

The Commission’s AI Office will now exercise enforcement powers over providers of general-purpose AI models, known as GPAI models.

Providers whose models may pose systemic risks face additional obligations to address large-scale dangers, including chemical, biological, radiological and nuclear threats, loss of control, cyberattacks and risks to fundamental rights.

All GPAI providers must also maintain a copyright policy and publish a sufficiently detailed summary of the material used to train their models.

How oversight will work

Responsibility for enforcing the AI Act will be divided among three authorities.

The AI Office will oversee AI systems supplied by the same provider as the underlying GPAI model. It will also supervise systems integrated into very large online platforms or search engines covered by the Digital Services Act.

National competent authorities will be responsible for other AI systems, while the European Data Protection Supervisor will oversee systems used by EU institutions, bodies and agencies.

Penalties for prohibited AI practices can reach €35 million or 7% of a company’s worldwide annual turnover. Other breaches can result in fines of up to €15 million or 3% of global annual turnover.

AI Act implementation timetable

A Commission official told journalists on Thursday that prohibited AI practices have applied since February 2025, while the rules covering GPAI models have been in force since August 2025. The transparency provisions take effect this year.

Through the AI Omnibus package, the application of rules for standalone high-risk AI systems has been postponed until 2 December 2027. The deadline for high-risk systems incorporated into regulated products has been moved to 2 August 2028.

The same legislative package introduces new prohibitions on AI systems that generate non-consensual sexually explicit content or child sexual abuse material. These restrictions will apply from 2 December 2026.

Code of conduct and complaint channels

The Commission has published a list of more than 180 organisations that have voluntarily signed the code of conduct on transparency for AI-generated content. The code was prepared by independent experts with input from more than 180 stakeholders.

A scientific panel of 60 independent AI experts will support the Commission’s supervisory work. The panel recently held its first meeting, while University of Oxford professor Alessandro Abate has been appointed chief scientific adviser.

The AI Office has also introduced separate channels for complaints from citizens and businesses, whistleblowers working with AI providers and downstream providers seeking to report concerns about the models on which their systems depend.

Commission plans 40 new positions

As its enforcement responsibilities grow, the Commission has advertised new contract positions for two units within the AI Office, which operates under the Directorate-General for Communications Networks, Content and Technology.

One unit is responsible for AI regulation and compliance. The second focuses on how the most advanced AI models manage risks such as cyberattacks and loss of control.

The two units currently employ a combined 71 people, while the Commission expects approximately 40 additional positions to become available across both units during 2027.

The recruitment process follows concerns raised by policymakers and AI experts about whether the two-year-old AI Office has sufficient staff to carry out its expanding responsibilities.

Source: CNA.