What just happened

On August 2, 2026, the European Union stopped talking about the AI Act and started enforcing it. The European Commission's AI Office and national authorities now have live enforcement powers, and a new set of transparency obligations took effect the same day (European Commission). This is the moment AI governance shifted from a policy conversation to a compliance reality, and it is the first time any jurisdiction has put comprehensive, binding rules on artificial intelligence behind real penalties.

If you work anywhere near AI, whether you build it, buy it, audit it, or advise on it, the ground moved this month. Here is what actually changed, and why it matters well beyond Europe.

The new transparency rules, in plain terms

The obligations that took effect on August 2 are about honesty with users. In practice:

  • Chatbots must identify themselves. If a person is interacting with an AI system, they have to be told, unless it is obvious.
  • Deepfakes must be labeled. AI-generated or manipulated images, audio, and video need to be disclosed as artificial.
  • AI content must be machine-detectable. Synthetic or altered content has to carry machine-readable markers so it can be identified automatically downstream.

None of this is exotic. It is the kind of basic disclosure that any mature governance program should already encourage. The difference now is that it is law, with consequences.

Who the regulators can go after, and for how much

The AI Office also gained real teeth over general-purpose AI (GPAI) models, the large foundation models that sit under most modern AI products. It can request technical documentation, evaluate models, require corrective measures, and issue fines. For the transparency and GPAI obligations now in force, non-compliance can reach up to 15 million euros or 3% of worldwide annual turnover, whichever is higher (Help Net Security). For a large enterprise, 3% of global revenue is not a rounding error. It is a board-level number.

What is still coming

The Act rolls out in phases, and a package of amendments known as the AI Omnibus adjusted some timelines. The heavier obligations for high-risk AI systems were pushed to December 2, 2027, and high-risk systems embedded in regulated products to August 2, 2028 (Cooley). So the transparency rules are the opening move, not the whole game. Organizations that treat August 2 as the finish line are going to be caught flat-footed in 2027.

Why this matters far beyond Europe

Two reasons. First, the AI Act reaches any organization whose AI outputs are used in the EU, not just companies headquartered there, so a lot of non-European businesses are now in scope. Second, Europe is not alone. South Korea's AI law took force in early 2026, Texas enacted its Responsible AI Governance Act, and Colorado, California, and New York are all advancing their own rules. The result is a fragmented, jurisdiction-by-jurisdiction landscape that companies have to navigate deliberately rather than hope to ignore.

The through-line is simple: binding AI regulation is no longer a forecast. It is operational, and it is multiplying.

The real takeaway: AI governance is now a job, not a memo

Here is what I keep seeing as someone who has spent nearly two decades in IT audit and governance. Regulations do not comply with themselves. They create demand for people who can translate a legal text into controls, evidence, and decisions that hold up under scrutiny.

And the supply of those people is thin. The gap is widest with autonomous systems: research suggests a large majority of organizations expect meaningful use of AI agents within a couple of years, while only a small minority have a mature governance model in place (Superblocks). Someone has to close that gap, and the organizations that just came into scope on August 2 are looking for those people right now.

That is the opportunity. If you understand privacy, risk, audit, or compliance, AI governance is the natural next step, and it is early enough that credentials still set you apart. The IAPP AIGP (Artificial Intelligence Governance Professional) has become the first widely recognized certification for exactly this role. It is honestly why I built AIGov Prep: I wanted a way to help practitioners get certified and step into these roles with confidence, using exam-realistic practice grounded in the actual laws and frameworks, including the EU AI Act.

You do not need to be an AI engineer to lead here. You need to understand governance, and you need to prove it. If you want to see what that knowledge looks like in practice, try 25 free AIGP practice questions and check yourself against the frameworks that just became enforceable. When you are ready to go deeper, the full question bank, timed exam simulation, and analytics are on the AIGov Prep plans.

The EU AI Act just proved that AI governance is now a hard requirement, not a nice-to-have. The people who build that skill now will be the ones companies turn to next. Start with 25 free questions and take the first step toward becoming one of them.