NeuralOS
Industria

Countdown: on August 2, the EU AI Act's fines for general-purpose models kick in

While everyone was watching the 2027 extension, a legal analysis from Latham & Watkins confirms what actually takes effect in weeks: mandatory transparency, labeling of AI-generated content, and enforcement powers over GPAI providers. Fines of up to €35M or 7% of worldwide revenue.

EN
Equipo NeuralOS
Radar de IA
Jul 13, 20266 min read
In short

On August 2, 2026, the EU AI Act's transparency and content-labeling obligations for general-purpose models take effect, with fines of up to €35M or 7% of worldwide revenue: what applies now, not in 2027.

Everyone celebrated the extension. Almost nobody read the fine print. When Brussels announced that the EU AI Act's "high-risk" rules were being pushed back, much of the ecosystem breathed a sigh of relief and filed the whole thing away as "next year's problem." That's a misreading. A recent analysis from Latham & Watkins — one of the firms tracking European AI regulation most closely — pins down the hard dates and makes it clear there's a block of obligations that was NOT postponed: it takes effect on August 2, 2026. In a matter of weeks, not years.

## What actually takes effect: transparency and the lock on GPAI

Two gears start turning on that August 2. The first is the transparency obligations under Article 50: any AI system that interacts with people must disclose that it is AI, and any content generated or manipulated by AI —images, audio, video, synthetic text— must be labeled in a machine-readable way, which in practice means watermarking or verifiable metadata. There's one nuance worth not glossing over: for generative AI systems that were already on the market before that date, the specific labeling requirement is deferred to December 2, 2026. The second gear is that the European Commission gains direct enforcement powers over providers of general-purpose models (GPAI): those large foundation models like Claude, GPT, or Gemini that almost everything else is built on top of. Transparency stopped being a best-practice recommendation and became an obligation with a fine attached.

## The numbers that wipe the smile off a CFO's face

The fines aren't symbolic. Failing to meet the transparency obligations can cost up to €15 million or 3% of total annual worldwide revenue, whichever is higher. For the most serious violations —the prohibited practices, such as non-consensual intimate content or AI-generated child sexual abuse material— the ceiling rises to €35 million or 7% of global revenue. To gauge the scale: that 7% is a multiple of what GDPR itself allows, the rule that already re-educated half the planet about privacy. The EU is saying it in the language boards understand: the traceability of synthetic content is not optional. As a capstone, "nudifier" apps —the ones that strip people using AI— are outright banned as of December 2, 2026.

## Why "I'll deal with it in 2027" is a trap

Here's the nuance that got lost in the headlines. Yes, high-risk —AI systems in hiring, credit, healthcare, or justice— was postponed, and that's real: standalone high-risk systems have until December 2, 2027, and those operating as safety components of already-regulated products have until August 2, 2028. But transparency and GPAI oversight travel on a separate track that starts now. The confusion is dangerous because it manufactures a false sense of calm: a startup deploying a chatbot, or an app that generates images for European users, might believe it has two years of runway, when in reality it has weeks to make sure its content ships labeled and that its users know they're talking to a machine. And the rule has extraterritorial reach: it doesn't matter where your company is, it matters where your users are. If there are Europeans using your product, the rule applies to you.

## The context: an Omnibus that simplifies, not that forgives

It's worth understanding why the dates moved. These changes are part of the EU's "Digital Omnibus" package, an effort to simplify digital regulation and resolve the overlap between the AI Act and the sector-specific safety legislation that already existed. That's the origin of the high-risk extension: decongest, give the industry room to breathe, avoid duplication. But the legislator was surgical: what it postponed was the technically heavy compliance, not transparency. The correct read isn't "the EU eased up," but "the EU chose what to tighten first." And what it chose, precisely, was the traceability of what a machine produces.

## What it means for anyone building with AI

The lesson is uncomfortable but clean: in the era of generative AI, knowing where a piece of content came from stopped being a technical detail and became a legal obligation with eight- and nine-figure numbers behind it. Labeling what a machine generates, disclosing that someone is talking to an agent, and being able to prove traceability is no longer a "nice to have": it's the line that separates operating from paying. This lands squarely on anyone shipping an AI-built app to a European audience. At NeuralOS we look at this with total honesty and no smoke: when you build and deploy an app with agents that generates content for the public, transparency and labeling stop being a roadmap ornament and become part of the "production-ready" checklist. We're not saying it to scare you, but because we'd rather you think about it today —when labeling your content costs a design decision— and not on August 2, when it already costs a percentage of your revenue.

Share
Ready to build?

Start building in
under 3 minutes

Join 4,200+ builders. No credit card. Build your first app with AI in minutes.