Skip to content
erika.taranto
ITENDE中文RU
Blog News

The EU AI Act Now Applies. Yes, Even If You're Not European

Since 2 August 2026 the EU AI Act applies almost in full: transparency, labelling, fines. What changes for creators, sellers and buyers.

Erika Taranto Erika Taranto
Official selection · AI for Good 2026 8 min read
The EU AI Act Now Applies. Yes, Even If You're Not European
In short

Since 2 August 2026 the AI Act, the first comprehensive law in the world on artificial intelligence, applies almost in full across the whole European Union. The most dangerous practices have been banned for a while already, and now it is the turn of the transparency obligations: saying when you are talking to an AI, making generated content recognizable, labelling deepfakes. It applies to 27 countries, and it reaches companies from outside too, those that sell or operate in the European market.

On 2 August, while most of Europe was on holiday, the most important deadline in the short history of artificial intelligence kicked in: from that day the AI Act, the European regulation on artificial intelligence, applies almost in full. It is not a new law: it had entered into force two years earlier, on 1 August 2024, but the rules arrived in waves. The August one is the wave that completes almost the whole picture.

If you have not followed the story, I will tell it to you without lawyer language. And if you are not European, you should read it anyway: this law, most likely, concerns you too.

One law, twenty-seven countries

It is the first comprehensive law in the world on artificial intelligence. Europe did what no other big bloc has done yet: take AI of every kind, from chatbots to the systems that screen CVs, and give it a single frame of rules. The United States is trying state by state, China regulates individual services, but an organic design like this exists only there, for now.

Its strength is also the most important practical point: being an EU regulation, it applies directly in the 27 countries of the Union, Italy, Germany, France, Spain and so on, with no national steps in between. One law for a market of about 450 million people. For those who work with technology it is a rarity: usually every country does its own thing, here it does not.

Anyone can grasp the underlying idea in one sentence: AI is not regulated in itself, but based on the risk of what it does.

The rules follow the risk

Instead of asking “is it AI or is it not AI?”, the law asks “how much damage can it do?”. The answer divides everything into four tiers:

TierWhat it requires
1 · BannedUnacceptable practices have been illegal since February 2025. Harmful manipulation, social scoring of citizens, indiscriminate collection of faces from the web and from cameras, emotion recognition in the workplace and at school. Banned full stop, not “regulated”: whoever uses them commits an offence.
2 · High riskSystems that touch rights and safety: work, education, biometrics, critical infrastructure, justice. They must be documented, tested, supervised by human beings, and they must pass conformity checks before being sold. It is the heaviest part of the law, and the one whose deadline was moved (I talk about it below).
3 · TransparencyAI that meets the public: chatbots, generated images, voices and videos. They must declare themselves. Whoever talks to an assistant must know it is an assistant, deepfakes must be labelled, generated content must be recognizable as such. This is the tier that since August concerns millions of creators and companies.
4 · FreeEverything else: spam filters, AI in video games, everyday tools with no particular risk. No specific obligations. Most of the AI you touch every day sits here, and it asks nothing new of you.

This structure is the reason the law is not “Europe against AI”. A spam filter and a system that decides whether you get a mortgage cannot carry the same weight of rules: that is exactly what the risk pyramid is for.

Four dates that explain everything

The rollout came in steps, and the order of the steps explains what is already in force:

  • February 2025: banned practices become illegal, and the AI literacy obligation arrives for companies.
  • August 2025: the rules for general-purpose models, the engines like GPT, Gemini and the like, plus the European surveillance structure.
  • August 2026: the rest of the picture. Transparency, oversight by national authorities, the penalties system.
  • December 2027: the full obligations for standalone high-risk systems (the original date was August 2026, then moved).
AI Act timeline: February 2025, banned practices become illegal. August 2025, rules for general-purpose models. August 2026, transparency and fines. December 2027, full obligations for high-risk systems

In practice, the August novelty for anyone using AI in front of the public is the transparency rules. If your site has a chatbot, the visitor must know they are talking to an AI. If you publish a video with a voice or a face that does not exist, it must be labelled as artificial content. If an AI-generated text is used to inform the public, the AI must be declared too. No bans: just clarity on what is real and what is not.

Then there are those who got more time: general-purpose models already on the market before August 2025 are allowed until August 2027 to fully align.

Postponed does not mean cancelled

If you read somewhere that “Europe is giving up on AI rules”, this is where the confusion comes from. In November 2025 the Commission proposed, and the Parliament then approved, the so-called Digital Omnibus: the package that moves the obligations for standalone high-risk systems from 2 August 2026 to 2 December 2027.

There are two reasons. The first is technical: the harmonised standards, that is, the operational instructions to prove conformity, were not ready, and asking for compliance with incomplete rules would have generated nothing but litigation. The second is political: strong pressure from the big tech companies, which had been asking for time for months. The debate on this is heated: some see a realistic choice, others a gift to big tech.

What is useful to understand is that the rules have not been cancelled, only moved. High risk, the AI that touches work, school, biometrics, arrives in December 2027. Later than planned, but it arrives.

The question is not where you are

And then there is the part almost everyone underestimates. The AI Act, like the GDPR for privacy, has a reach that goes beyond European borders: it applies to anyone who puts an AI system on the European market or uses it in Europe. American, Chinese, Japanese, Brazilian company: if your product enters the EU, the law reaches you where you are.

It is not legal colonialism, it is market geometry. Europe cannot control what happens inside other countries, but it can decide the conditions to access its 450 million consumers. And since for many companies Europe is too big to give up, the European rule becomes the de facto global standard: it is easier to apply it everywhere than to run two parallel systems. It already happened with privacy: the GDPR changed how the whole world handles data, regardless of where the server sits. With AI, an encore is on its way.

The question is not “am I European?”. It is: “does the AI I use, sell or buy pass through the European market?”. If yes, the law is your business.

Who sells, who buys, who gets fined

For those who do business for a living, from anywhere on the planet, the question is one: what does it mean, concretely, to operate inside the European market now?

If you sell AI, or services that use AI, in Europe: the first thing to understand is which risk tier your tools fall into. Most creative and marketing services sit in the transparency tier: the compliance cost is low, it is a matter of declaring the AI where the public meets it. If instead you sell systems that touch hiring, education or biometrics, you are in high risk: you have time until December 2027 for documentation, human supervision and assessments, but you had better start early, because that is not paperwork you prepare in a week. And since August, with the penalties system active, the risk of ignoring the matter is concrete.

The fines, to understand their weight: up to 35 million euros or 7% of annual worldwide turnover (the higher of the two) for banned practices. Up to 15 million or 3% for high risk and transparency. Up to 7.5 million or 1% for those who give wrong information to the authorities. Numbers designed to be taken seriously, even by the giants.

If you buy AI for your business in Europe: the law gives you more than it asks of you. You have the right to know when you are interacting with an AI instead of a person, and to receive artificial content labelled as such. If you buy tools for sensitive areas, you will start seeing guarantees and documentation in contracts that nobody asked for before: suppliers from outside Europe will receive those requests from European clients, and this extends the rule well beyond the EU borders, in practice.

If you see an opportunity in it: it is real. Those who comply first, with real transparency and not a facade, build the rarest thing of this moment: trust. In a market where everyone suspects everything synthetic, being able to say “my work with AI is declared, checkable and compliant” is a competitive advantage, not a cost. And the high-risk delay to 2027 gives B2B suppliers a window to prepare calmly instead of running.

I already declare the AI I use

I work with these tools every day: images, videos, voices. And my reaction to these rules is the unpopular kind: I am fine with them. Not because I love bureaucracy, but because the real problem with generative AI is not that it exists, it is that nobody knows what is real anymore. When everything can be fake, the only thing worth declaring is what is not.

For a creator, the practical version is simple: declare the AI when the public meets it, do not hide it like a bad habit. If you generate images for your work, the tools to do it do not change: the only thing that changes is that saying it becomes a rule, not a courtesy. Those who are already in the habit of being transparent, as I try to be, have nothing new to do.

Hands tying a paper tag to a print: declare the AI when the audience meets it

And this is where the point becomes useful outside Europe too: the public of any country is developing the same allergy to artificial content passed off as real. The European rules anticipate what users will demand everywhere, sooner or later, law or no law.

The list is shorter than you think

If you want to be ready without reading 400 pages of regulation, this is enough:

  • Know where your AI sits. Take an inventory of the tools you use and which risk tier they fall into. In most cases you will discover you are in the free or transparency tier, and the weight is minimal.
  • Declare it where the public meets it. A chatbot that introduces itself as AI, recognizable generated content, labelled deepfakes. That is the obligation in force since August.
  • If you sell in Europe, put it in writing. Contracts and pages that say clearly where there is AI in your service. European clients will start asking for it, if they do not already.
  • If you are in high risk, use the 16 months. Documentation, human supervision, assessments: December 2027 looks far away until you start working on it.
  • If you buy tools for sensitive areas, demand the documentation. It is your right in the European market, and it also works as an excellent filter for serious suppliers.

You can argue about the details, the timing, the pressure applied. But the direction is this one: AI is leaving the wild west, and Europe walked in first, as it already did with privacy. Those of us who use it for work, me included, need one thing more than all the rest: for people to trust what they see.

If you use AI in your work and want to do it well, without fear and without finding yourself exposed when the rules come knocking, that is exactly my job: see how I work.

Sources

Did you like it? Share it.
Comments

Leave a comment

Comments are reviewed and approved before they appear.

Your email will not be published.

FAQ

Frequently asked questions

What is the European Union's AI Act? +
It is the first comprehensive law in the world on artificial intelligence. A European Union regulation that entered into force on 1 August 2024 and is applied in phases: banned practices from February 2025, rules on general-purpose models from August 2025, and almost everything else from 2 August 2026. It applies in all 27 member states, so it is a single law for about 450 million people.
When does the EU AI Act take effect? +
It entered into force on 1 August 2024 and applies in steps: banned practices became illegal in February 2025; rules for general-purpose models arrived in August 2025; from August 2026 the rest of the framework (transparency, oversight, fines). The full obligations for standalone high-risk systems arrive in December 2027 after the Digital Omnibus shift.
Which AI practices does the AI Act ban? +
Banned since February 2025: unacceptable practices, meaning harmful manipulation, social scoring of citizens, indiscriminate face scraping from the web and cameras, emotion recognition at work and school. These are not regulated, they are illegal. High-risk AI (work, education, biometrics) is not banned, but requires documentation, controls and human oversight.
Does the AI Act also apply to companies or creators outside Europe? +
Yes, if the AI reaches the European market. The law applies to anyone who puts an artificial intelligence system on the EU market or uses it in Europe, even if the company is American, Chinese or from any other country. It is the same principle as the GDPR for privacy: the point is not where you are, but whether you operate in the European market.
What do you have to do if you create content with AI? +
The transparency rules in force since August 2026 require you to say clearly when you are interacting with an AI (for example a chatbot), to make AI-generated content identifiable where it is relevant, and to clearly label deepfakes and synthetic texts used to inform the public. For most creators it is mainly this: transparency towards those who read and those who watch.
What are the AI Act fines? +
The penalties go up to 35 million euros or 7% of annual worldwide turnover, whichever is higher, for banned practices. Up to 15 million or 3% for violations concerning high-risk systems and transparency obligations. Up to 7.5 million or 1% for those who give incorrect information to the authorities.
Why were the rules on high-risk AI postponed? +
With the Digital Omnibus the Union moved the obligations for high-risk systems used in sensitive areas such as work, education and biometrics from 2 August 2026 to 2 December 2027. The reasons: the harmonised technical standards were not ready, and there was strong pressure from the big tech companies. The rules stay; what changes is the date they become binding.
Keep reading
Gene Wilder's AI Voice: Who Decides When You're Gone? News
August 2026

Gene Wilder's AI Voice: Who Decides When You're Gone?

Read
Claude Fable 5 is back (after the shutdown) News
July 2026

Claude Fable 5 is back (after the shutdown)

Read
Create images with ChatGPT: 2026 guide Guides
July 2026

Create images with ChatGPT: 2026 guide

Read