← Journal
5 September 20264 min read

The AI Act clock started, and it reaches further than Europe

From 2 August the EU began enforcing its AI rules. The transparency duties apply to where your output lands, not where your company is registered.

On 2 August 2026 the European Union's AI Act moved from a law that existed to a law that is enforced. According to the Commission's own implementation timeline, that date turned on the Article 50 transparency rules and started enforcement, at both national and EU level, for general-purpose AI models, the prohibited practices, the transparency obligations, and the AI literacy provisions.

Plenty of coverage read this as a European problem. For anyone outside Europe who sells software, that reading is expensive.

Where the rules attach

The Act is not scoped by where your company is registered. It attaches to where the output is used. If you build a chatbot for a client whose customers are in the EU, or a content tool whose output is published there, the obligations reach you through that relationship — usually as a clause in the contract, arriving from a client who has their own compliance officer to satisfy.

For a studio in Kathmandu, Lagos, or São Paulo, this is the practical mechanism. Nobody from Brussels is going to knock. Your European client's legal team is going to send you a questionnaire, and the speed with which you can answer it becomes a commercial advantage or a lost contract.

What Article 50 actually asks for

The transparency duties are the ones most likely to touch ordinary product work, and they are not onerous. In substance:

Systems that interact with people must make clear that the person is dealing with an AI, unless it is obvious from context. Synthetic audio, image, video and text must be marked as artificially generated in a machine-readable way. Deepfakes and AI-generated text published to inform the public on matters of public interest must be disclosed. Emotion recognition and biometric categorisation systems must tell the people subjected to them.

Read that list as an engineering checklist rather than a legal one and most of it is a week of work: a disclosure line in the chat header, provenance metadata written at generation time, a label in the publishing flow. The cost of doing it late — retrofitting provenance into content already shipped — is what turns it into a project.

The dates that follow

The August milestone is not the whole schedule, and the rest of it has moved.

2 December 2026 brings the new prohibitions on deepfakes and child sexual abuse material, along with a transitional compliance deadline for providers of synthetic content systems already on the market. That transitional deadline is the one to diarise if you have something live today.

2 December 2027 is when the high-risk rules in Annex III come into force, and 2 August 2028 covers high-risk AI embedded in regulated products under Annex I. Both were pushed back from earlier dates by the Digital Omnibus amendments.

That deferral is worth reading precisely. The high-risk regime slipped. The transparency duties and the enforcement powers did not. A good deal of commentary in the spring reported "the AI Act is delayed" and left it there, which is the kind of summary that gets a team to stop paying attention eighteen months before it should.

For the model providers

Providers of general-purpose AI models are now inside an active enforcement regime rather than a stated one — the Commission can request information, require model access, and compel withdrawal. The penalties attached to GPAI obligations run to €15 million or 3% of global annual turnover, whichever is higher.

Most of us are not shipping foundation models, so this reads as somebody else's problem. It is not entirely. When your upstream provider's obligations tighten, that propagates: through terms of service, through changes in what a model will do in a given jurisdiction, and through the documentation you are handed to pass on to your own clients. If you build on an API, the compliance posture of that API is now part of your supply chain.

What is worth doing now

If you build AI features for anyone who might sell into Europe, three things are worth an afternoon.

First, work out whether your output lands in the EU. Not your company — your output. If a client's users are there, you are in scope through them.

Second, look at your generation paths and ask where a disclosure or a provenance marker would have to go. Write down what it would take. If the answer is "we would have to change the schema", find that out now rather than in a procurement questionnaire.

Third, put 2 December 2026 in the calendar, because the transitional deadline for systems already on the market is the one that catches people who assumed they had until 2027.

None of this is a reason to be alarmed, and it is certainly not a reason to buy a compliance platform. The Act's transparency provisions largely codify things a careful team would do anyway: say when a machine is talking, mark what a machine made. The risk is not the requirements. It is finding out about them from a client rather than from a calendar.

regulationEU AI ActcomplianceAI

Building something like this?

We are a product studio in Kathmandu. Tell us what you are building and an engineer will reply.