In short
On 2 August 2026 the Commission's AI Office and national authorities began enforcing the AI Act, and the transparency obligations in Article 50 took effect. Competence is split three ways: the AI Office for general-purpose AI models, national competent authorities for other systems in their territory, the European Data Protection Supervisor for the EU institutions themselves.
The split, which is the first thing to know
Nobody supervises everything, which is why "who checks on me" has no single answer. The Commission's AI Office deals directly with general-purpose AI models, with power to request technical documentation, run evaluations, demand corrective steps and issue fines. National competent authorities handle other AI systems operating within their borders. The European Data Protection Supervisor oversees the EU institutions.
- Your client develops or makes available a general-purpose model: they answer to the AI Office
- Your client uses an AI system in their business: they answer to the national authority designated in their state
- Your client is an EU institution or body: they answer to the EDPS
- Your client is a controller processing personal data with that system: they also answer to the data protection authority, which is a parallel track, not an alternative one
What became mandatory on 2 August
The Article 50 transparency obligations are the part that touches the largest number of companies, because they concern not those who build models but those who use them to talk to the public. Systems must tell users they are interacting with a machine, and when content has been generated or altered by AI.
- Chatbots must identify themselves as automated systems
- Deepfakes must be labelled
- Machine-generated or edited content must carry machine-readable marks so it can be detected
- Fines for these breaches reach EUR 15 million or 3% of worldwide annual turnover, whichever is higher
For general-purpose model providers the obligation is different: document certain information and make it available to competent authorities and downstream providers, put in place a copyright policy, and publish a sufficiently detailed summary of the content used for training. Providers of the most advanced models must also address risks of large-scale harm: chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, harmful manipulation, threats to fundamental rights.
The "first AI Act fines" going around appear in no official source
Precise figures have been circulating for weeks: eighteen million against an HR technology company, fifteen against a retail chain for emotion recognition, fourteen against a credit scoring provider, all issued by the AI Office days after 2 August. Those figures appear only on promotional content sites and never in a Commission release. They also contain a structural error that gives them away: the AI Office does not fine those who use an AI system, it handles general-purpose models; deployers are dealt with by national authorities. What happened on 2 August is that enforcement powers became exercisable, not that they were exercised.
The transparency Code of Practice
Alongside the start of enforcement, the Commission published a first list of more than one hundred and eighty organisations that signed the Code of Practice on transparency of AI-generated content. The Code is voluntary, but the obligations underneath it are law either way: signing documents how you meet them, it does not replace them. That is a distinction worth explaining to a client who asks whether "joining is enough".
What has not arrived yet
- Requirements for high-risk systems were moved to 2 December 2027
- Those for high-risk systems embedded in already regulated products go to 2 August 2028
- From 2 December 2026 systems generating non-consensual sexually explicit content or child sexual abuse material will be banned
The concrete thing to do now
For every client with a chatbot, a site assistant or a content generator, check one thing: does the user understand they are talking to a machine before they start, and does the produced content carry a mark. You do not need an impact assessment to answer, you need to open the site and look. It is the simplest obligation in the whole AI Act and the one most often missing.
Worth remembering that the Commission had already used other instruments before this date: in January 2026 it opened a formal investigation into X over its Grok tool under the Digital Services Act. The lesson for the DPO is that the AI Act does not land on empty ground: it adds to regimes the same authorities are already enforcing.
Official source:Commissione europea - Commission starts enforcing AI Act rules and new transparency requirements on 2 AugustOfficial source:Commissione europea - Il quadro di applicazione dell'AI ActOfficial source:AI Act, art. 50 - Obblighi di trasparenzaLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free