28 August 2026
The EU AI Act started enforcing this month.
On August 2, the transparency rules went live. Chatbots must disclose they're AI. Deepfakes must be labelled. The high-risk deadline got pushed to 2027, so most companies relaxed. That might be exactly the wrong response.
I’ve been reviewing the EU AI Act enforcement notices for several months now - the ones that went live on August 2 - partly because a few clients have been asking whether it affects them, and partly because I run commercial operations and governance at an AI company and wanted to see how our own house looks against it.
The short version is that transparency obligations are now enforceable across the EU. Chatbots must identify themselves as AI. Deepfakes must be labelled. AI-generated content needs disclosure. These aren’t the high-risk classification rules everyone’s been watching… those got pushed to December 2027. These are the quieter ones that landed while most people were still exhaling about the deadline extension.
I wonder how many SLTs have actually checked which of their tools are affected. Not in the “we’ll get legal to review it” sense, but in the practical sense of listing every customer-facing AI system and asking whether it currently tells the user it’s not human. In most large companies, that list is surprisingly hard to assemble, because the tools were deployed by different teams at different times and there’s no central register.
Running commercial operations and governance at an AI company gives you a useful vantage point on this. You see the gap between what the technology can do and what the regulation assumes it does. You also see how quickly that gap changes shape. The OECD now tracks over 900 AI policy initiatives across more than 80 jurisdictions. That’s not a single compliance exercise, it’s an atmosphere.
I’d suggest the transparency rules are actually the interesting ones, more so than the high-risk framework. High-risk compliance is expensive and complicated but it’s legible - there’s a classification, a process, a deadline. Transparency is harder because it requires you to know what you have. You can’t disclose what you haven’t inventoried.
If you’re part of an SLT, could you list every AI system that interacts with your customers, and confirm each one identifies itself? If assembling that list takes more than a day, that’s the finding.
The regulation just formalised what was already a gap in most operating models. Worth running that audit before December 2027 turns the conversation from transparency to risk classification. The easy rules are always the ones that catch you out, precisely because they looked easy.
More from the Friday Frame archive.
- 21 August 2026
Gen Z hasn't stopped using AI. They've just stopped enjoying it.
A friend's design house lost its production work and its first-year jobs over several years, without a single month where anything visibly h...
- 15 August 2026
The last mile.
AI can be at the table. It can't be in the dock. Three answers I gave a panel about what I wouldn't use AI for, and a fourth I nearly missed...
- 7 August 2026
Human-in-the-loop is doing less than you think.
If reviewers miss a third of dangerous agent requests, what you've written into policy as a control is really a story you're telling the boa...
Get a heads up when there is new writing here.
I publish irregularly. The Friday Frame ships most weeks. The longer essays land when they are ready. Drop your email and you will get a note when something new goes up, or when an existing post gets a meaningful rewrite. Nothing else.