EU AI Act Enforced: Over 30 AI Firms Ordered to Disclose Cybersecurity and Copyright Compliance

August 26, 2026
EU AI Act Enforced: Over 30 AI Firms Ordered to Disclose Cybersecurity and Copyright Compliance
  • The EU AI Act’s Article 50, now in effect since early August 2026, mandates transparency by providers of generative AI and requires detectable labeling for synthetic content, with deployers also tasked to disclose deepfakes and label AI-generated public-interest content.

  • Transparency obligations began on 2 August 2026, and agencies should document AI inputs, changes, and editorial responsibility chains to demonstrate governance and compliance to clients.

  • Europe’s AI Act has moved from concept to enforcement, marking a new era of transparency for chatbots and AI-generated content starting in August.

  • Officials stress the goals of these measures are to strengthen cybersecurity and infrastructure protections, prevent model theft, and monitor access by external evaluators while implementing safety recommendations.

  • Practical guidance suggests building adaptable governance rather than chasing evolving rulebooks, since enforcement will shape expectations more than the text alone.

  • The enforcement toolkit includes model evaluations and remedial measures, with penalties potentially reaching up to 3% of annual turnover for non-compliance.

  • Startup guidance calls for: (a) integrating disclosure into product discovery, (b) developing native labeling tools to aid compliance, and (c) proving transparency to accelerate vendor approval.

  • Regulatory trends point to stricter board-level accountability for cybersecurity oversight, with possible personal liability for supervisory directors in some regimes.

  • Regulators are targeting labs developing the most advanced AI models; some providers have been contacted as dialogues continue with others not yet included.

  • The AI Act complements DORA, NIS2, and the Cyber Resilience Act to bolster digital resilience and third‑party management, with many institutions still at lower resilience maturity.

  • For organizations, the delay in rule enforcement creates runway to achieve compliance, but obligations remain in force and should be treated as opportunities to close gaps rather than delays.

  • GPAI discussions include publishing information on web crawlers and robots.txt usage to help rightsholders identify crawlers under Measure 1.3(4).

Summary based on 13 sources


Get a daily email with more EU News stories

More Stories