The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems.
From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails.
The AI Act moved from theory to practice for three big areas:
- General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
- Transparency obligations: Transparency rules kick in for interactive systems and AI‑generated content: chatbots must say they are bots, and synthetic audio, images, video and text need to be marked as AI‑generated or manipulated.
- Banned AI uses: A set of “unacceptable risk” AI uses is now formally prohibited, with enforcement shared between the AI Office, national authorities and the European Data Protection Supervisor for EU institutions.
Note that content that was generated and published before August 2, doesn’t need to be retro‑labelled, but anything published on or after that date falls under the rules, even if it was generated earlier.
From a security perspective, the AI Act’s transparency push is less about banning AI and more about taking away its best camouflage: pretending to be human.
Non‑compliance with transparency obligations can attract fines up to 15 million Euros (17.3 million USD) or 3% of worldwide annual turnover, whichever is higher, which should be significant enough to get large providers’ attention.
To make enforcement more than a paper tiger, the AI Office has launched tools aimed at people who see problems from the inside or as users:
- Complaint tool: Individuals and organizations can report alleged infringements of the AI Act by providers or deployers of AI systems supervised by the AI Office.
- Whistleblower tool: People professionally connected to AI providers or deployers get an anonymous channel to flag potential violations that could endanger fundamental rights, health or public trust.
- Downstream complaints channel: Firms building on top of GPAI models can report suspected breaches by the underlying model providers.
This creates a formal path for reporting systemic issues: think unsafe model behavior, ignored red‑team findings, or deployments that quietly cross legal lines around manipulation or discrimination.
Bans on “nudifiers” and abusive content
The AI Office has introduced explicit prohibitions on AI systems that generate non‑consensual sexually explicit or intimate content (including “nudifier” apps) and child sexual abuse material.
For victims of these abuses, that’s more than a symbolic move. It gives regulators and law enforcement a clear legal basis to go after both providers and deployers of such systems in the EU, rather than trying to squeeze them into older, less specific laws.
These rules will apply from December 2, 2026, with companies given time to bring their systems into compliance or pull them from the EU market.
Regrettably, this will not stop abuse completely. Attackers will still use unlabeled tools and infrastructure outside the EU. But it raises the bar for legitimate services and makes it harder for mainstream platforms to ignore the risks of deceptive AI‑driven features.
The AI Act won’t make AI safe overnight, but it shifts the default from “anything goes” to “you must play by some basic rules if you operate in the EU.” For users, that’s a step toward AI systems you can at least recognize and question, instead of having invisible technology quietly shape our online experience.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.




