The AI Compliance Brief · Issue 03

The AI Compliance Brief — Issue 03

Independent editorial briefing on AI regulation, enforcement, and verification. Published weekly.

Issue 03 | August 2026 | Clause5afe Systems, Inc.

Independent editorial briefing on AI regulation, enforcement, and verification. Published weekly.

In this issue

•The EU AI Act entered a major new enforcement phase on August 2. The AI Office now holds direct supervisory powers over general-purpose AI models.

•Transparency obligations under Article 50 apply now. High-risk obligations do not, and the reason for the delay is worth understanding.

•The Commission is building an EU evaluation capacity for independent third-party assessment of AI models, expected operational in 2027.

•Related developments from US state chatbot disclosure laws and the AI Office’s own capacity constraints.

THE LEAD

The European Commission’s AI Office and national authorities began enforcing the EU AI Act on August 2, 2026, alongside the application of new transparency obligations.

The AI Office holds enforcement powers over general-purpose AI models. It can request technical documentation, evaluate models directly, require corrective measures, and issue fines for non-compliance. Supporting the enforcement function, the AI Board, the Scientific Panel, and the Advisory Forum steer and advise the Act’s governance.

The scope of that authority extends beyond substantive breaches. Under Article 91, the AI Office can require any general-purpose AI model provider to produce technical documentation, training data summaries, and model reports, and providers that fail to respond or supply misleading information face fines under Article 101. Under Article 92, where information gathered is insufficient or the Scientific Panel issues a qualified alert about systemic risks, the AI Office can evaluate a model directly.

KEY FACTS

Regulation : EU Artificial Intelligence Act, Regulation (EU) 2024/1689

Enforcement start : August 2, 2026, by the AI Office and national market surveillance authorities

Transparency obligations : Article 50, applying from August 2, 2026 to all in-scope systems regardless of when placed on the market

What Article 50 requires : Chatbots and interactive systems must disclose they are AI; deepfakes must be labelled; AI-generated or altered content must carry machine-readable marks; emotion recognition and biometric categorisation systems must inform individuals

Transitional period : A grace period runs to December 2, 2026 for the marking and detection obligation covering generative AI systems already on the market before August 2, 2026

Penalties under Article 50 : Up to €15 million or 3% of worldwide annual turnover for companies, up to €750,000 for EU institutions, with proportionality applied to SMEs and small mid-caps

Enforcement bodies : National market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are providers or deployers

Extraterritorial reach : The Act applies to providers, deployers, importers, and distributors placing AI on the EU market or whose AI outputs are used within the EU. Non-EU providers must appoint an EU-based authorised representative

WHY IT MATTERS

The Commission adopted guidelines interpreting Article 50 on July 20, 2026, and the AI Office published a voluntary Code of Practice on Transparency of AI-Generated Content offering providers a recognised path to demonstrate compliance with the marking and detection obligations. Legal analysis of the mechanism, including from Cooley, describes signatories as benefiting from a degree of presumption of conformity and a more favourable enforcement posture, with non-signatories facing closer scrutiny and needing to demonstrate compliance through other means. Several major providers have signed.

That structure is worth noting. The EU has created a two-tier compliance environment in which demonstrating conformity through a recognised mechanism produces materially different regulatory treatment than asserting it independently.

The Commission is also building verification infrastructure. Under the July 2026 Action Plan on Cybersecurity and Artificial Intelligence, the Commission will launch a dedicated call to establish an EU evaluation capacity, expected to be operational in 2027. The stated purpose is to strengthen third-party assessment of AI capabilities and risks globally and to contribute to the regulatory function of the AI Office. The Commission also plans to propose criteria for third-party evaluators under the General-Purpose AI Code of Practice.

COMPLIANCE IMPLICATIONS

For providers of general - purpose AI models : Documentation obligations are now directly enforceable, and the failure to produce documentation is itself a fineable event independent of any underlying compliance failure.

For any organisation deploying AI systems in the EU : Article 50 reaches deployers, not only providers. Organisations using generative AI in customer-facing contexts should confirm whether chatbot disclosure and deepfake labelling obligations apply to their deployments.

For non - EU organisations : A US address does not remove an organisation from the regulator’s reach where AI outputs are used within the EU. The EU-based authorised representative requirement applies to non-EU providers.

For organisations awaiting the high - risk regime : The deferral is not a reduction in eventual obligation. Conformity assessment, technical documentation, CE marking, and database registration requirements remain, on a later timeline.

RELATED DEVELOPMENTS

High - risk obligations did not take effect . The Digital Omnibus on AI deferred Annex III standalone high-risk systems, including recruitment, credit scoring, education, law enforcement, and border control applications, from August 2, 2026 to December 2, 2027. AI embedded in products already covered by EU product safety law under Annex I moved to August 2, 2028. The stated reason is procedural: member states were slow to designate national competent authorities, and the harmonised standards and conformity assessment tools that high-risk compliance depends on were not finished. The obligation for member states to establish national regulatory sandboxes was postponed from August 2, 2026 to August 2, 2027.

New prohibitions arrive in December . The Omnibus adds prohibitions effective December 2, 2026 on AI systems generating non-consensual intimate imagery and child sexual abuse material.

AI Office capacity is a live question . Analysis published in May found the unit responsible for overseeing general-purpose AI models with systemic risk to be small relative to its mandate, with one report recommending scaling supervisory capacity to at least 160 staff by 2030. The AI Office has since opened a hiring round for 40 posts dedicated to AI Act enforcement, with expressions of interest due September 8.

US state chatbot disclosure laws expand . Nearly 100 chatbot bills appeared across 34 states in 2026, and thirteen states enacted laws requiring AI disclosure and protections for minors. Some prohibit chatbots from claiming to be licensed mental health professionals. Many exempt routine customer service tools.

WATCH LIST

First enforcement actions : Which national market surveillance authorities move first under Article 50, and what documentation those actions treat as sufficient evidence of compliance.

The December 2 marking deadline : Whether generative AI systems placed on the market before August 2, 2026 meet the machine-readable marking obligation when the grace period closes.

EU evaluation capacity : The terms of the Commission’s call, and the criteria it proposes for third-party evaluators under the General-Purpose AI Code of Practice.

Standards readiness : Whether CEN-CENELEC JTC 21 delivers the harmonised standards underpinning high-risk conformity assessment in time for the December 2027 date, given that their absence drove the original deferral.

THE CLAUSE5AFE PERSPECTIVE

Three jurisdictions, three approaches, one direction.

Illinois mandated annual independent audits. Massachusetts convened a commission to study whether to. The European Union is going further in a different way: rather than only requiring verification, it is building the capacity to perform it, and proposing criteria for who qualifies as a third-party evaluator.

That last piece is the one to watch. A verification requirement is only as meaningful as the standard applied to the verifier. The questions the Commission will have to answer, what independence requires, what access an evaluator is entitled to, what qualifies someone to assess a frontier model, are the same questions the Massachusetts commission will face and the same ones the Illinois statute leaves to generally accepted auditing standards.

Whoever answers them first will shape what independent verification means for the next decade.

SOURCES

•European Commission, Commission starts enforcing AI Act rules and new transparency requirements on 2 August, July 31, 2026

•European Commission, Safer and more transparent AI, August 2, 2026

•European Commission, Governance and enforcement of the AI Act

•European Commission, EU Action Plan on Cybersecurity and Artificial Intelligence, July 7, 2026

•European Commission, guidelines on transparency obligations, July 20, 2026

•Cooley, EU AI Act: Transparency Obligations Take Effect 2 August 2026, August 3, 2026

• Technology.org , EU AI Act: What Actually Applies on 2 August 2026, July 17, 2026

•Covington, EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions, May 2026

•Lawfare, How Much Power Does the EU AI Office Actually Have, May 18, 2026

•CNBC, EU AI Act enforcement powers coverage, August 3, 2026

•Al Jazeera, What came into force with the EU’s AI Act this week, August 6, 2026

Clause5afe Systems, Inc.

Independent third-party AI certification. One standard. All frameworks.

clause5afe.com

The AI Compliance Brief is published weekly. Editorial responsibility rests with Clause5afe Systems, Inc. This brief is informational and does not constitute legal advice.

Continue exploring

Return to the controlled Clause5afe record.

Each canonical publication retains its author, date, source basis, and approved revision.

All Newsletter Issues