EU AI Act Core Rules Enforced: 38-Person Team to Monitor Global AI Companies, Transparency Mandates Effective
Summary
Key Takeaways
The European Commission announced that core rules of the AI Act took effect on August 2, marking the most important enforcement milestone since the Act entered into force in August 2024.
New requirements mandate that interactive AI systems (e.g., chatbots) must inform users they are interacting with AI; AI-generated or manipulated deepfakes must be labeled; and AI-generated content must carry machine-readable markings for identification.
The European AI Office has added 38 staff members to monitor global AI companies, with powers to request documentation, conduct model evaluations, enforce risk mitigation measures, and impose fines. A whistleblower tool was also launched for anonymous reporting.
Providers of advanced general-purpose AI models that pose systemic risks must fulfill additional obligations to guard against cyberattacks, model loss of control, and harmful manipulation. Over 180 organizations have signed the AI-generated content transparency code of practice. High-risk AI system rules for employment, education, and law enforcement are postponed until December 2027. Violations may result in fines or market access bans.
Why It Matters
Beneath the veneer of user protection, the EU AI Act imposes substantial operational compliance costs and may lock in a regulatory-driven supply chain for machine-readable markings (e.g., C2PA), creating new ecosystem lock-in. Model evaluations and risk mitigation demands require significant compute and expertise, potentially increasing deployment latency for large models and introducing evaluation blind spots. The 38-person team's capacity to monitor global AI companies is questionable, but the threat of fines and market access bans forces heavy investment. High-risk AI rules delayed to 2027 but enterprises must start building compliance frameworks now to avoid iteration bottlenecks. Control shifts from AI providers to regulators, yet detection technologies for deepfakes remain immature, with false positives and evasion risks. Enterprises should be wary of compliance tool vendors exploiting regulatory panic.
PRO Decision
【Vendors】Competitors (e.g., Anthropic, Mistral AI) should leverage the EU AI Act's transparency requirements by publishing detailed model cards and compliance reports, publicly attacking OpenAI and Google for lacking sufficient transparency and risk management details. Lobby for stricter evaluation standards to capture enterprise customers.
【Enterprises】CIOs and architects should immediately conduct AI vendor compliance audits, incorporating compliance costs into TCO. Prioritize vendors offering complete model evaluation reports and machine-readable markings, and consider on-premise or open-source models to avoid cross-border data compliance risks. Build internal AI governance frameworks to prepare for future high-risk rules and avoid lock-in to a single compliance technology vendor.
【Investors】Look beyond regulatory panic: compliance technology vendors (content marking, model auditing, risk management) will see growth but may be overvalued. Large AI companies (e.g., OpenAI, Meta) face margin compression from compliance costs, while small compliant AI startups may exit due to burden. Monitor whether EU standards become global benchmarks and which C2PA ecosystem winners emerge.
Get 3-5 key AI infrastructure signals weekly →
💬 Comments (0)