The EU AI Act Newsletter #107: Enforcement Powers Arrive
The Commission publishes new transparency guidelines and confirms the Code of Practice on AI-generated content, as attention turns to the EU's enforcement powers taking effect on 2 August.
Welcome to the EU AI Act Newsletter, a brief biweekly newsletter by the Future of Life Institute providing you with up-to-date developments and analyses of the EU artificial intelligence law.
Legislative Process
Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems: The European Commission announces guidelines to help providers and deployers of AI systems meet the AI Act’s transparency obligations, which begin to apply on 2 August 2026. According to the Commission, these obligations are intended to help people recognise when they are interacting with AI or when content has been generated or altered by AI, thereby reducing the risk of deception and manipulation. In practical terms, providers must design systems that inform users of direct interaction with an AI and add machine-readable marks to enable detection of AI-generated or manipulated content. Deployers must disclose deep fakes, unreviewed AI-generated content on matters of public interest, and emotion recognition or biometric categorisation systems. The guidelines clarify key concepts, exemptions and examples, and explain how compliance may be demonstrated, including through a code of practice. Systems placed on the market before August must comply with marking obligations from 2 December 2026.
Commission opinion on the assessment of the Code of Practice on Transparency of AI-generated content: The European Commission concluded that the Code of Practice on Transparency of AI-generated content adequately covers the obligations set out in Articles 50(2), (4) and (5) of the AI Act and facilitates their effective implementation. The AI Board adopted its own Adequacy Assessment of the code. According to the Commission, all providers and deployers of generative AI systems are invited to sign this code, since it is the EU-wide adequate instrument for ensuring compliance regardless of their place of establishment or competent market surveillance authority, although adherence does not constitute conclusive evidence of compliance. The code sets out commitments and measures covering generative and general-purpose AI systems and deepfakes. Finally, the AI Office will consider facilitating formal updates to the code at least every two years.
Analyses
Europe’s AI enforcers pick up their tools at critical time: Maximilian Henning of Euractiv reports that the AI Act’s enforcement powers take effect on 2 August, though he questions whether the bloc will dare to use them. Having signed off on the law two years ago, the EU imposes its strictest requirements on the largest general-purpose models from the likes of OpenAI and Anthropic. When the law was drafted, systemic risks such as AI-enabled cyberattacks seemed distant; Henning notes that models like Anthropic’s Mythos have made them tangible. The key enforcer, the Commission’s AI Office, has 145 staff, yet fewer than a quarter work directly on regulation and compliance. From August, enforcers may request information from the developers, seek technical changes and ultimately impose fines of up to 3% of annual revenue. However, Henning raises concerns that political pressure, particularly from a Trump White House opposed to sanctions on US firms, could temper enforcement. Nonetheless, the AI Act’s co-author, Brando Benifei, and civil society groups urge the EU to defend its rulebook confidently.
OpenAI flagged Hugging Face hack to EU authorities: Pieter Haeck of POLITICO reports that OpenAI informed the European Commission of a security incident in which one of its agents escaped a laboratory test and hacked another tech firm. According to Commission spokesperson Thomas Regnier, the EU received a notification from OpenAI and held exchanges on the matter. OpenAI recently confirmed that an AI agent breached the infrastructure of Hugging Face using two of its models, the recently released GPT 5.6 Sol and another, yet-to-be-released model. As a developer of general-purpose AI models, OpenAI faces specific obligations under the AI Act, including assessing and mitigating cybersecurity and loss-of-control risks. Although these rules have applied since last August, enforcement by the Commission’s AI Office only begins this August. OpenAI is also a signatory of the code of practice for general-purpose AI models.
ChatGPT didn’t break the AI Act, but showed why adaptive regulation matters: Writing in Tech Policy Press, I argue that the familiar story of ChatGPT blindsiding the AI Act’s negotiators is incomplete. When the Commission proposed the Act in April 2021, it deliberately regulated AI according to the risks of its use rather than the technology itself, which left a gap around general-purpose models that could underpin thousands of downstream applications. As Future of Life Institute and other stakeholders warned in the August 2021 consultation, that hole was spotted early; ChatGPT simply made it politically impossible to ignore. Rather than freezing the original proposal, the process adapted, moving from the Slovenian and French presidencies through the Parliament's tiered foundation-model regime to the December 2023 trilogue, which produced layered GPAI obligations alongside a voluntary Code of Practice. Consequently, while these duties have applied since August 2025, the real test arrives on 2 August 2026, when enforcement powers begin.
Parliament considers single digital regulator to oversee EU tech rules: Pieter Haeck from POLITICO describes how the European Parliament will prepare a report on whether the EU should establish a single digital regulator to centralise enforcement of the bloc’s technology rules. According to a document dated 15 July, lawmakers in the Parliament’s legal affairs committee have decided to write an own-initiative report on “the case for a European Digital Enforcement agency”. While such reports carry no legal force, they often allow lawmakers to advance a policy or influence the Commission’s thinking. At present, enforcement of rules such as the Digital Services Act, the Digital Markets Act and the AI Act is spread across several Commission services and member-state authorities. Because these rules have faced criticism from both the US government and industry, there have been calls to centralise enforcement outside the Commission to shield it from political pushback. Finally, German Greens lawmaker Sergey Lagodinsky made the pitch, with other groups supporting it pending a change to the report’s title.



Interestingly, the Hugging Face hack was at least partly enabled by OpenAI’s evaluation setup. OpenAI states that the models were run with "reduced cyber refusals for evaluation purposes" and that the deployment safeguards were intentionally disabled for the evaluation. This does not mean that they intended the breach, but it does mean that the incident was not purely accidental and was made possible by the conditions of the test. See: https://openai.com/index/hugging-face-model-evaluation-security-incident/
Thanks for this. The OpenAI/Hugging Face item is the one worth sitting with: a live agent breach testing the loss-of-control obligations before the enforcement powers meant to check them come online. A community-maintained catalog of AI-agent security incidents already lists what looks like the same breach at roughly 17,000 agent actions before it was caught - well past what a human-oversight process is built to interrupt in real time. August 2 gives the Commission the power to ask whether OpenAI's cybersecurity and loss-of-control mitigations were adequate on paper. It doesn't yet give anyone the power to ask whether those mitigations could have stopped the agent mid-breach, which is the harder question the incident raises.