
Tech • AI • Robotics
The EU AI Act entered a major enforcement phase on 2 August 2026, making companies newly exposed to checks and penalties on staff training, disclosure of AI use, and labeling of synthetic content, while several high-risk rules were delayed.
The AI Act did not start from zero this summer: some obligations already existed, others became applicable on 2 August 2026, and several expected provisions were postponed. The result is a layered regime in which companies may already be non-compliant even if they only now became aware of practical enforcement risks.
One part of the framework, drafted before the generative AI boom in 2021, focused on uses of algorithmic systems, especially harmful forms of surveillance or automated social scoring. A second layer was added in 2023 after the rise of ChatGPT, shifting pressure toward model makers and general-purpose AI providers, with compliance demands seen as harder for European players to bear than for large American or Chinese groups.
The best-known obligation concerns AI literacy in companies. Employers must ensure that employees using AI systems receive adequate training, and workers are entitled to that training. Despite widespread reporting around August 2026, this duty has applied since 2 February 2025; what changed is that enforcement is now supposed to be possible.
If an employee misuses AI and causes damage, a company may have to prove that the person was trained. That issue matters not only for regulators but also for insurers and liability disputes. The concern is amplified by the possibility that sanctions could be assessed over time, taking into account how long a company remained non-compliant after the February 2025 deadline.
In France, implementation remains fragmented. Around 14 public bodies have reportedly been involved in dividing oversight by sector, such as finance, data, education, or business activities. That creates uncertainty over who would actually inspect a company, even though the legal obligations are already in place.
Another key rule now in force is transparency toward users. A chatbot on a commercial site must be identifiable as AI, rather than presented ambiguously as customer service staffed by humans. The same logic can extend to AI-drafted business communications: if recipients are not clearly informed that an email or response was generated with AI assistance, the company may face compliance issues.
Liability does not disappear because a third-party vendor built the tool or because the underlying model comes from OpenAI, Anthropic, Google, or another provider. The entity deploying the AI toward customers or the public is responsible for ensuring users are not misled about the nature of the interaction.
The Act also requires that AI-generated content be marked in ways detectable by machines, not just by humans. That applies to images, audio, video, and increasingly text. This requirement has drawn attention after Anthropic said it had introduced marking for much of its model-generated text, while Gemini had already used similar practices earlier.
Synthetic content that convincingly resembles a real person or real-world situation can trigger extra disclosure duties. The legal definition remains blurry, but the practical test is whether the output appears real enough to be believable and tied to something that exists. That could cover translated avatar videos or realistic synthetic speakers even when the use is not malicious.
The framework includes the possibility of heavy fines, with references to sanctions reaching 3% of turnover in some cases. Even if many businesses expect weak enforcement in the short term, the combination of penalties, private disputes, competitor complaints, and insurance consequences creates a real incentive to comply.
Some of the most sensitive questions, including AI used in recruitment, credit scoring, insurance pricing, education, policing, justice, and health, were expected to advance but have been delayed and, in some cases, softened. That means the strictest societal safeguards are not arriving as quickly as the more operational obligations imposed on businesses.
The current phase of the EU AI Act puts immediate compliance pressure on companies using AI in everyday operations, especially around training and transparency. At the same time, several of the most consequential rules for high-risk social uses of AI remain deferred, leaving a gap between business obligations and broader public protections.
Explain this