What happened

New transparency obligations under the European Union's AI Act took effect on August 2, requiring companies that offer certain AI systems in the EU to disclose specific information to users -- including telling people when they are interacting with an AI system rather than a human, and labeling AI-generated content in a machine-readable way.

What we know

The obligations, confirmed by the European Commission and detailed by multiple international law firms tracking the regulation, apply broadly to companies offering AI products and services within the EU -- regardless of where the company is headquartered. That means U.S. technology companies operating in European markets must comply if their systems are used by people in the EU, even if the company has no physical presence there.

The specific requirements include disclosure obligations for chatbots and other systems designed to interact with people, labeling requirements for AI-generated or AI-manipulated audio, image, video, or text content, and disclosure requirements for certain uses of biometric categorization and emotion-recognition systems.

Why it matters

The EU AI Act is one of the first comprehensive AI-specific regulatory frameworks from a major global market, and companies elsewhere have often used EU rules as a template given the size of the European market. For American companies with EU users, non-compliance carries financial risk, since the Act includes penalty provisions for violations. Beyond direct compliance costs, the rules could influence how AI products are designed globally, since building separate versions of a product for different regulatory regimes is often more expensive than building a single compliant version.

The transparency-specific obligations that took effect in August are only one part of the broader AI Act, which is being phased in over several years, with different categories of obligations -- including stricter rules for "high-risk" AI systems -- taking effect on a separate, later timeline.

Background

The EU AI Act was formally adopted after years of negotiation and is designed to regulate AI systems according to their level of risk, with the strictest rules reserved for applications considered to pose the greatest risk to safety or fundamental rights. Its phased implementation schedule means different provisions take effect at different times, which has required companies to track a rolling set of compliance deadlines rather than a single effective date.

The law applies based on where an AI system is used or has its output experienced, not where the company developing it is headquartered -- meaning US companies offering AI products to EU users are subject to the same obligations as European firms. That extraterritorial reach has made the Act a significant compliance consideration for American technology companies regardless of whether they have a physical presence in Europe.

The bigger picture

The EU has taken a more prescriptive, risk-tiered approach to AI regulation than the United States, which has so far relied more heavily on a mix of voluntary industry commitments, executive actions, and sector-specific rules rather than a single comprehensive federal law. Because major AI companies operate globally, compliance requirements set in Brussels often end up shaping product design and disclosure practices well beyond the EU's borders -- a dynamic sometimes called the "Brussels effect" that has previously played out with EU privacy law.

What happens next

Additional provisions of the AI Act, including obligations specific to high-risk AI systems, are scheduled to phase in over the following months and years. Companies operating in the EU will need to continue adjusting their products and disclosures as each new set of requirements takes effect.

Sources

This article is based on official guidance from the European Commission and compliance analysis published by international law firms including Cooley, Latham & Watkins, and Stibbe.