Enforcement has a phone number
The transparency duties are live, they apply to everything already shipped, and one of the three is an unsolved research problem being required by law.
The clause doing the work
The obligations apply regardless of when a system was placed on the market. No grandfathering. A product shipped in 2024 and running unchanged is in scope today.
Which means the burden lands hardest on whoever has the most deployed product.
Most technology regulation applies prospectively because retrofitting is expensive. This one deliberately did not, and that is a policy choice about who should bear the cost.
Two easy duties and one impossible one
Self-identification is a string in a system prompt. Labelling a deepfake is a UI decision. Embedding a durable machine-readable provenance mark that survives re-encoding, cropping and screenshotting is an open research problem now written into law as an obligation.
The first enforcement actions will decide what machine-readable means in practice. A metadata field satisfies the letter and is stripped by any upload pipeline. A robust watermark satisfies the intent and does not reliably exist.
Four dates, four programmes
Staggering was meant as relief. In practice each date needs a different capability, and they do not build on each other. The December content ban is the underestimated one — prohibiting a category of output is a guarantee about behaviour under adversarial input, which is the thing nobody can currently promise.
What this asks of you
Treat these as four programmes with four owners, not one project with milestones. And start with the installed base, because the first date has already passed and it does not care when you shipped.
European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August → · Cooley — EU AI Act: Transparency Obligations Take Effect 2 August 2026 →