
On August 2, 2026, the EU AI Act entered into force. The law's transparency provisions now apply; the European Commission has begun enforcing the obligations for general-purpose AI model providers, and national authorities can pursue failures involving many other AI systems. The ceiling is real: fines can reach 15 million euros or 3% of worldwide turnover, enforced mainly by national market surveillance authorities, with the AI Office holding only a limited role.
Axios captured the shift on August 28 with a useful account of what "enforcement" means outside a legal memo.
A customer may meet a chatbot that identifies itself as AI. A campaign asset may carry a machine-readable signal. A provider may have to produce documentation or grant the AI Office access to a model for evaluation. Within a company, the change can be less visible yet more consequential: contracts, publishing controls, and approval records have to match the system actually used.
Some major high-risk provisions still arrive later. Article 50 is already here.
The most obvious change appears at the beginning of a conversation. Providers of AI systems designed for direct interaction must ensure that people are told they are dealing with AI from the start, unless that fact would be obvious to a reasonably informed and observant person. A branded service bot that looks and sounds human cannot safely rely on the audience figuring it out halfway through the exchange.
Generated content creates a second layer. Providers of systems that produce synthetic text, audio, images, or video must make covered outputs detectable through machine-readable marks. Those marks may sit in metadata or in patterns that a person cannot see. They serve a different purpose from the clear label a deployer must provide when publishing a deepfake. The Commission's guidance says that a deployer cannot use an invisible provider mark as a substitute for a visible or audible deepfake disclosure.
Text has its own boundary. AI-generated or manipulated text published to inform the public on matters of public interest must be labeled if it has not received substantive human review or editorial control. A superficial check for spelling or format does not qualify.
Where a knowledgeable person examines the substance, an editor has power to change or reject it, and a person or company accepts legal responsibility for publication, the Article 50 label can be unnecessary.
That boundary is narrower and more useful than the claim that every AI-assisted campaign needs an on-page warning. Standard editing can fall outside the provider's marking obligation, and deployer labeling does not attach to every synthetic image or every piece of commercial copy. The actual questions are what the system changed, whether the result appears to be authentic in error, what the publication is intended to do, and who controlled the final version.
Anthropic now watermarks text produced by Claude models launched on or after August 2, 2026, with a transition period bringing older models into line over the coming months. The method is a version of Google DeepMind's SynthID-Text, published in 2024 and descended from a 2022 proposal by Scott Aaronson: it changes how the model selects among equally plausible words, leaving a pattern that is invisible to a reader but detectable with the corresponding key. Files carry a different signal — a signed C2PA content credential written into the metadata of supported types such as .png, .jpg, and .svg. Anthropic applies the watermark globally at launch because it does not yet have a durable way to confine the feature to Europe, and it is offering a detection API in private preview to eligible organizations and enterprises with compliance needs.
The detection has limits worth stating plainly. It is probabilistic.
Short passages, factual language, code, and lightly edited material may provide too little room for a strong signal. A positive result indicates a likelihood that Claude helped write the text; it does not identify a person, reveal a chat, or prove exclusive authorship.
OpenAI's published response spans two different parts of the Act. At model level, it now provides summaries of the content used to train specified general-purpose AI models under Article 53. At output level, it describes a layered provenance approach using Content Credentials and C2PA, together with SynthID watermarking for images and audio and tools that check for supported signals. OpenAI also warns that provenance can disappear through editing or platform changes — a caveat that the vendors' own tooling cannot engineer away, and one that belongs in every agency workflow built around metadata.
Microsoft's response is both organizational and technical. The company says it has dedicated groups across governance, engineering, legal, and public policy, has updated contracts, is revising restricted-use policies, and is reviewing products for needed mitigations. It also says it is implementing Article 50 disclosures and clarifying what provenance support is available for third-party models sold through Azure.
Anthropic, OpenAI, and Microsoft all signed the provider section of the EU's voluntary Code of Practice on Transparency of AI-Generated Content. Signing offers a recognized route for demonstrating compliance. The underlying Article 50 duties remain mandatory.
The signals these vendors produce are only useful if they survive to the point of publication — which makes them the agency's problem, not the vendor's. An agency using a third-party model will often be a deployer. That label is not permanent. An agency that develops an AI system, has one developed, and places it on the European market or puts it into service under its own name can become a provider. A client can also be a deployer, depending on who controls the use and publication. Employees and freelancers working under a company's authority do not each become separate deployers.
The practical response should follow the asset. For a synthetic campaign, the file should identify the tool and model version, when generation occurred, the extent of later editing, whether provenance survived export, and why a visible disclosure was or was not required. The same record should name the person who reviewed the substance and the legal entity that approved publication. Article 50 does not impose this exact universal form. It is the evidence an agency will wish it had if a client, platform, regulator, or litigant asks how the decision was made.
Production systems can easily break the chain. A designer may download an image with Content Credentials, resize it in another application, send it through a project-management preview, and upload a compressed version to a social platform. The final asset may no longer carry the original signal. Checking at creation is therefore insufficient. Provenance has to be checked again on the file that will actually be delivered or published.
Many agencies already have a final approval email. That may prove the client said yes. It does not necessarily prove human review of the substance, editorial authority, or legal responsibility under the Commission's interpretation of Article 50.
A defensible approval should state what the reviewer examined and whether that person could require changes. For public-interest text, the record should also identify who accepts editorial responsibility. For a synthetic image, audio clip, or video involving a real person, place, object, or event, the review needs to address whether the result could falsely appear authentic and therefore meet the Act's deepfake definition. If the answer is yes, the audience-facing disclosure should be approved with the asset, including its wording, placement, and timing.
Contracts need the same precision. The agency and client should know who controls the AI system, who preserves provenance, who decides that content is a deepfake, and who owns the final publication decision. A broad promise to "comply with applicable law" leaves the operational questions unanswered.
Axios is right to treat the EU as a possible global benchmark, although the benchmark may spread through product design rather than legislative imitation. Anthropic's decision to watermark Claude text worldwide is an early example. Multinational agencies may also prefer one production standard over a separate European process, especially when campaigns move across markets after launch.
Technical standards will not settle every case. Watermarks can weaken, metadata can disappear, and a label that satisfies Article 50 may not resolve consumer-protection, privacy, copyright, or election-law duties elsewhere. Nor does the Code of Practice replace the Act; it supplies a recognized compliance route for signatories.
The next test will be mundane. A campaign file will reach legal or procurement with an AI-generated asset inside it, and someone will ask which model made it, whether its provenance survived, why the audience saw a label or did not, and who had authority to approve the answer. Agencies should be able to open the record and show them.