The AI Act's high-risk rules moved to 2027. Its model, copyright and transparency duties did not.
The regulator arrives before the rulebook is complete
The European Commission has added 38 people to the AI Office in Brussels as the office moves from preparation to enforcement. According to the Associated Press, the expanded team will monitor providers ranging from startups to the largest American and Chinese AI companies. It can seek documents, question company personnel and investigate reports submitted through new whistleblower and compliance channels.
That is the visible event. The harder story sits behind it. Europe has reached a major application date for the AI Act, and much of the coverage describes the moment as though a single switch has been thrown across the continent.
The law is now "in force," the headlines say, often followed by a quick reference to labels on AI content, high-risk systems and enormous fines. That account compresses several legal clocks into one.
The AI Act entered into force on August 1, 2024. Its prohibitions, definitions and AI-literacy provisions began applying in February 2025. Obligations for providers of general-purpose AI (GPAI) models began applying in August 2025. On August 2, 2026, the Commission acquired the power to enforce the model-provider rules, while Article 50 transparency duties began applying to a broad range of AI systems and professional users. Most requirements for high-risk systems, however, have moved further into the future.
Enforcement has begun, but it has begun selectively. The difference is more than calendar trivia. It determines which company is answerable, which authority can ask the questions, and which records should already exist.
August 2 is a junction, not a finish line
The AI Omnibus, which entered into force on July 27, postponed major high-risk requirements after the standards and institutional machinery needed to support them fell behind schedule. Rules for the Annex III systems used in areas such as employment, education, access to essential services and certain law-enforcement functions will apply from December 2, 2027. Requirements for high-risk AI embedded in regulated products covered by Annex I, including medical devices and machinery, will apply from August 2, 2028.
The same regulation added obligations even as it postponed others. Two new prohibitions enter Article 5 on December 2, 2026: AI systems that generate non-consensual intimate imagery, and AI-generated child sexual abuse material. The Omnibus companies cite for relief is also the instrument that set a nearer deadline on the conduct the new Brussels team was assembled to police.
Those postponements are substantial. They also have a narrow legal meaning.
They do not suspend the AI Act as a whole, excuse general-purpose model providers from duties that already apply or defer Article 50 transparency across every system. Nor do they displace copyright, consumer protection, data protection or platform rules that may already govern the same activity. Even GPAI enforcement contains a cohort distinction: models placed on the market before August 2, 2025 generally have until August 2, 2027 to comply, while models placed on or after that date are within the current compliance population.
The enforcement structure is split as well. The Commission has exclusive power to supervise and enforce the AI Act's chapter on general-purpose AI models, acting through the AI Office. National market-surveillance authorities retain the central role for most AI systems. The European Data Protection Supervisor covers AI used by EU institutions and bodies. The AI Office's role under Article 50 is more specific, and was recently extended by the Omnibus to certain systems built on general-purpose models and systems integrated into very large online platforms or search engines.
A company therefore cannot answer "Are we in scope?" by looking only at whether it operates a high-risk system. It must first identify its legal role, the type of model or system involved, when that model entered the EU market, and what the company does with the output. One product can place several organizations on different clocks.
Training inputs are now part of the compliance record
For providers of general-purpose AI models, the most consequential current obligations concern the material from which the model was built and the information available to those who rely on it.
Subject to limited open-source exemptions, providers must maintain technical documentation for authorities and provide downstream system developers with enough information to understand the model's capabilities and limits. Every covered provider must adopt a policy designed to comply with EU copyright and related-rights law and publish a sufficiently detailed summary of the content used for training with the Commission's mandatory template. Providers outside the EU generally need an authorized representative before placing a covered model on the Union market.
The copyright policy is not a ceremonial statement.
Article 53 requires providers to identify and respect rights reservations expressed under the EU text-and-data-mining framework, using state-of-the-art technologies. The voluntary General-Purpose AI Code of Practice shows how the Commission expects a credible policy to operate. Its copyright chapter addresses lawful access, paywalls, crawler behavior, machine-readable reservations and complaints from rights holders. Signatories commit to making their crawlers follow the Robot Exclusion Protocol and to recognizing other appropriate machine-readable protocols as they become standardized or widely adopted.
That code deserves careful wording. Signing it offers an accepted route for demonstrating compliance with the AI Act; the code is not itself a judicial ruling that a training use was lawful. Copyright disputes remain governed by EU and national copyright law, with courts retaining the final word. A policy can be well designed and still fail in practice. A crawler can honor one protocol while the provider lacks a defensible account of material obtained elsewhere.
The operational burden therefore falls on evidence. A provider should be able to reconstruct which crawler was used, what instructions it recognized at the time of collection, how access controls were treated, and what happened when a rights holder complained. The policy document is the top layer. The collection and decision records underneath it are what an investigator can test.
A public summary is neither a confession nor a clean bill of health
The training-content summary has been pulled into the copyright debate as though it were a catalog of every work ingested by a model. The Commission's template asks for something different: a structured public account of the types and scale of training content, the sources from which it came and processing choices relevant to people with legitimate interests under EU law.
Providers must describe categories such as public datasets, private datasets, material scraped from online sources, user data and synthetic data. The summary must appear on the provider's website and alongside the model across public distribution channels. Further training may require an update at six-month intervals or sooner when the new material changes the account significantly.
This disclosure can help a publisher, artist or database owner decide whether to investigate. It does not establish that every included work was licensed, that an exception applied or that no protected expression was reproduced. It also does not require public release of the complete training corpus. The summary is a visibility mechanism attached to a separate copyright duty.
That separation is easy to lose in corporate governance.
Communications teams may want the summary to sound reassuring. Legal teams may want to say as little as possible. Engineers may possess the only accurate account of collection and filtering. If those groups meet only when publication is due, the summary will expose the weakness of the underlying records. The same problem reaches downstream providers when model documentation is too vague to support their own compliance.
The obligation applies to open-source model providers too, even where they qualify for exemptions from some technical-documentation duties. Openness of weights and code does not erase the copyright policy or public-summary requirements.
Synthetic output carries a different burden
Article 50 governs the other side of the model. Providers of systems that generate or materially manipulate synthetic text, audio, images or video must make the output machine-readable and detectable as artificially generated or altered. A watermark may contribute, as may metadata, cryptographic provenance, logging or fingerprinting. The provider needs both a mark and a means of detecting it. The Commission's guidance expects the combined solution to be effective, interoperable, robust and reliable to the extent technically feasible.
This technical duty belongs primarily to the system provider. Professional users have their own disclosure duties. A deployer that publishes a deepfake must make its artificial origin clear to people without requiring a special detection tool. The same general rule applies to AI-generated or materially manipulated text published to inform the public about matters of public interest, unless the text has undergone substantive human review or editorial control and a person or organization accepts editorial responsibility.
The exception requires more than a glance at the copy.
The Commission describes fact-checking as a minimum part of human review. A grammatical check, an automated review, or a nominal approval does not qualify. A substantive AI edit made after human sign-off can remove the benefit of the exception.
The output rules do not decide who owns the content. Machine-readable marking records artificial origin; it does not determine authorship, copyright protection, permission or infringement. A visibly labeled deepfake can still violate copyright, privacy, trademark, advertising or criminal law. Conversely, the presence of an AI marker does not answer whether a human contribution is protected. Origin disclosure and copyright status are separate legal questions.
The Omnibus created a limited transition for systems already on the market before August 2, 2026. Their providers have until December 2, 2026 to comply with the machine-readable marking and detection duty. That grace period does not generally postpone the other Article 50 requirements. An older chatbot still needs to disclose the interaction now. A deployer publishing a new deepfake cannot assume the provider's four-month extension excuses its own visible label.
Marketing has entered the evidence chain
Article 50 will often be experienced first through advertising, corporate communications and social media rather than a regulator's letter.
The Commission's guidance gives a blunt example: a realistic synthetic video of a chief executive congratulating employees can qualify as a deepfake. So can a fabricated celebrity influencer in a promotion or an altered product image that changes how the product's appearance or qualities are perceived. An obviously fantastical scene may fall outside the deepfake definition, and minor technical edits may escape the machine-marking rule. The classification turns on what was changed, how the content appears in context, and whether the intended audience could mistake it for an authentic representation.
Marketing teams cannot manage that analysis with a blanket footer stating that "AI may have been used."
They need to know which system generated the asset, whether its embedded mark survived editing and export, whether a real person or product was synthetically represented, and where a visible disclosure will appear. If a campaign makes claims about health, safety or sustainability, text that looks like ordinary promotion may also concern a matter of public interest. Human review then needs substance, a named owner and an approval point after the final AI-assisted revision.
The practical tension is familiar. Production workflows strip metadata. Agencies use several tools without recording model versions. A designer may composite a marked image into an unmarked final asset. A local market rewrites approved copy through another model after legal review. None of these steps is inherently unlawful. Each can break the evidence needed to show why the published output was handled correctly.
The postponement can produce its own compliance failure
Moving the high-risk deadlines was rational. Companies cannot build dependable conformity programs around standards that have not arrived, and national authorities need time to develop consistent supervisory capacity. The danger lies in how organizations translate the delay internally.
"The AI Act was postponed" is a convenient sentence for a budget meeting.
It can freeze inventories, vendor reviews and documentation projects precisely when other obligations have become enforceable. It also encourages businesses to organize around labels such as "high risk" rather than the acts they perform. Model placement, training-data collection, public communications and professional deployment each create different obligations before the postponed dates arrive.
Delay can also weaken future readiness. A company that waits until late 2027 to determine whether an employment or credit system falls within Annex III may discover that it cannot recreate the data lineage, testing decisions or human-oversight design from several years earlier. Conformity work depends on the history of a system, not merely its condition on the deadline.
The staggered timetable rewards organizations that preserve options. A serious inventory can distinguish a GPAI model from a system built on it, record whether the organization is provider or deployer in each context, and connect every use to its applicable date. That work is less glamorous than a policy launch. It is also far more useful when an authority asks a narrow question about a specific model version.
What the record should show now
A general-purpose model provider should already have a dated scope analysis for each model placed on the EU market on or after August 2, 2025. Its technical file should match the version actually offered. Downstream documentation should reach integrators rather than sit behind an inaccessible request process. The copyright policy needs named responsibility and operating proof, including the rights-reservation signals recognized by the crawler, the treatment of restricted sources and the path for substantiated complaints. The public training-content summary should reconcile with the underlying data account and use the Commission's template.
Providers of generative systems should preserve the design and test evidence for their marking and detection methods. If they rely on the transition for a preexisting system, they should record why the system qualifies and how compliance will be reached by December 2, 2026. A voluntary code can simplify the demonstration, but non-signatories still need an adequate method and should expect more questions about it.
Deployers need a use-level record. It should identify where people interact with AI, where emotion recognition or biometric categorization occurs, and where synthetic material reaches an audience. The record should show who assessed each exception and which human accepted editorial responsibility. Contracts with providers and agencies should address access to model documentation, preservation of machine-readable marks and notification when a system or marking method changes.
For marketing and communications departments, the asset history now belongs beside the approval history. The final file, the tools used to create or alter it, the label decision and the last substantive human review should be recoverable. A campaign that passes through an agency, localization vendor and social platform should not lose its provenance at each handoff.
The Brussels team will attract attention because it represents visible enforcement. Its deeper significance is the kind of organization the AI Act is beginning to reward. The first serious investigations are unlikely to turn on a company's broad promise to use AI responsibly. They will turn on whether the company can produce a coherent record of what it built, what entered the model, what left the system, and who made the final decision.