European Commission begins enforcing EU AI Act transparency and deepfake-labelling provisions from 2 August 2026, with its AI Office empowered to inspect models, demand technical records, and order changes
The European Commission's AI Office in Brussels and national regulators across the EU began enforcing key provisions of the EU Artificial Intelligence Act (AI Act) on 2 August 2026, marking the entry into force of the August 2026 phase of the legislation. This phase introduces broader transparency requirements and stronger oversight of general-purpose AI models (large AI systems capable of performing a wide range of tasks). Specifically, companies are now required to identify deepfakes (AI-generated video or audio content made to appear genuine), label AI-generated material, and control serious cyber risks associated with powerful AI systems. The EU AI Office now has the power to inspect advanced AI models, demand technical records, examine how models work, question company staff, and order changes where systems fail to meet legal requirements. The expanded enforcement team will investigate whether companies operating in the EU are in strict compliance with the Act. This follows earlier phases: the AI Act entered into force in August 2024, bans on certain unacceptable uses began applying in February 2025, and August 2026 represents the next significant implementation milestone. The high-risk AI rules, which impose the most stringent obligations on AI systems used in critical sectors such as healthcare, law enforcement, and employment, are expected to apply from 2027. For law firms and their corporate clients, the practical effect is that any organisation deploying general-purpose AI tools in the EU, whether for client-facing services or internal operations, now faces active regulatory scrutiny over their content-labelling and cyber-risk management practices.
Why this matters
The August 2026 enforcement phase of the AI Act is the most operationally significant milestone since the prohibition on unacceptable-risk AI in February 2025, because it directly affects the widest range of commercial AI deployments: any business using a general-purpose AI model to generate content, summarise documents, or interact with customers in the EU must now demonstrate compliance with transparency and labelling obligations or face investigation. For law firms advising technology clients and deploying AI tools internally, the enforcement powers granted to the AI Office, including the ability to demand technical records and question staff, mean that non-compliance is no longer an abstract compliance risk but a live enforcement exposure. The one-year gap before high-risk rules apply in 2027 creates a compressed window for clients to build compliant AI governance frameworks.
On the Ground
This story activates technology and AI regulation (EU AI Act compliance programme design, general-purpose AI model obligations), data protection and privacy (intersection with GDPR obligations on AI-generated content), and commercial technology (AI vendor contract review and due diligence). A trainee in an AI and data practice would assist with drafting AI governance policy documents, preparing regulatory impact assessment memos mapping client AI deployments against the Act's transparency requirements, reviewing technology licence agreements to identify Shariah-equivalent AI compliance representations, and preparing vendor due diligence questionnaires asking providers to confirm their AI Act compliance status. No specific law firms are named as advisers in the sources.
Interview prep
Question you might get
“What obligations does the August 2026 phase of the EU AI Act impose on a UK law firm that uses a general-purpose AI model to assist with document review for EU-based clients?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeSources
My notes
saved