Welcome to the EU AI Act Newsletter, a brief biweekly newsletter by the Future of Life Institute providing you with up-to-date developments and analyses of the EU artificial intelligence law.
Legislative Process
Fourth GPAI Signatory Taskforce meeting: The European Commission’s AI Office reports on the Taskforce’s 17 July 2026 session, which covered the Safety and Security and Copyright chapters of the GPAI Code of Practice. On the former, the Office explained how analysing model usage can form part of post-market monitoring under Measure 3.5, since information about how a model is used, and its behaviour during usage, complements pre-deployment evaluations and informs several stages of systemic risk assessment. Participants also discussed ‘marginal-risk’ clauses, which indicate that, should competitors begin pushing the frontiers of capabilities by deploying unsafe models, a provider could consider doing likewise. The Office highlighted that such clauses could be invoked only in exceptional circumstances and under appropriate evidentiary and procedural safeguards. Turning to copyright, Measure 1.3(4) commits signatories to publishing information that enables affected rightsholders to learn which web crawlers are used and their robots.txt features, and to notifying them automatically of updates.
How are AI agents addressed within the AI Act? The Commission’s AI Act Service Desk sets out, in an FAQ, how the Act applies to AI agents. It acknowledges that the term is often used inconsistently in public debate and is not clearly defined, while noting broad agreement that an agent must be able to receive and process input from its environment and execute actions based on this processing. On that basis, the Service Desk explains that agents are not a separate category under the Act, but that the definitions of an AI system in Article 3(1) and of a general-purpose AI model in Article 3(63) are sufficient to cover them. Consequently, the prohibitions on harmful manipulation and exploitation of vulnerabilities may require safeguards at the design and development stage. The transparency rules apply from 2 August 2026 where an agent is intended to interact with natural persons or generate content. Furthermore, the high-risk requirements follow in December 2027 or August 2028 where it is classified as high-risk. Autonomy and tool use may also be decisive in the designation of the model as a model with systemic risk.
Analyses
Hiding your use of AI is about to get much harder thanks to Brussels: Pieter Haeck from POLITICO examines how the EU’s new watermarking requirements, which came into effect this month, could upend how internet users engage with AI-generated images, videos and text. Although leading AI companies said they wanted to address the risk to so-called photographic truth by identifying the provenance of content their models generate, their efforts have been largely voluntary. Since 2 August, however, providers of the most cutting-edge generative AI models, such as Anthropic and OpenAI, have had to ensure their users know they are interacting with AI and that the output is marked as AI-generated. Ashley Casovan of the IAPP’s AI governance centre doubts that people grasp the scale of the change, describing a move from making an educated decision about whether something is AI-generated to seeing a verified symbol or overlay. Walter Pasquarelli of the University of Cambridge adds that providers will need to work with platforms to visualise such marks, and points to evidence that engagement with media drops significantly once people know it is AI-generated.
How Claude’s text watermark works: Anthropic announces that future Claude models will generate watermarked text, a means of determining the likelihood that Claude was involved in writing it, a change made alongside several other major AI providers to comply with the EU AI Act. The chosen method, the company states, has no practical impact on the quality or content of Claude’s outputs, and readers will not be able to distinguish watermarked from un-watermarked text. Nothing is added to the text and there are no hidden characters. Because no extra tokens are required, watermarking will not be more expensive, while the watermark itself carries no identifying information and cannot be traced to a person, organisation or chat. Nor will the practice be specific to Claude, since other developers that signed the same Code of Practice will implement watermarks of their own.
EU’s push for watermarking won’t worsen AI writing, experts say: Maximilian Henning from Euractiv reports how experts are defending watermarking of AI-generated text against concerns that it degrades outputs, after Anthropic faced criticism for a transparency step preferred under EU rules. The AI Act obliges in-scope developers to mark audio, image, video and text invisibly, to help users spot synthetic content and reduce risks such as disinformation. Since watermarking slightly influences a model’s word choices, some critics maintain that it must by definition make text worse. Kalina Bontcheva, a professor of text analytics at the University of Sheffield who co-chaired the drafting of the transparency code, replies that quality suffers only in very short texts, a threshold discussed with major providers and set at 200 tokens, or roughly 150 words. Dino Pedreschi, professor of computer science at the University of Pisa and another co-chair, concurs, while a Commission spokesperson likewise rejects the suggestion that the rules worsen outputs.
What the EU AI Act means for you and your business: Romain Digneaux, Public Policy Manager at Proton, explains how the AI Act affects those who use AI-powered products or services in the EU, whether for personal or business purposes. One effect is already visible in the labels or disclosures on platforms such as Instagram and TikTok indicating that content was generated or manipulated using AI, which became applicable in August 2026 under the transparency rules. Since these form part of a much broader law being introduced in stages, Digneaux works through how the Act treats risk, from unacceptable-risk and high-risk systems to transparency-risk and low-risk ones, before turning to the obligations attached to GPAI models, whether the Act restricts the use of people’s data for training, how far it protects intellectual property, and when each provision applies. For businesses, compliance begins with establishing the company’s role and the kind of AI it uses.
We’ve built the most comprehensive website on the EU AI Act to help answer all your questions. Here are a few of our most popular resources used by 60,000+ professionals every week:
AI Act Explorer: Explore the official AI Act text on any device, in any EU language, with helpful cross-links, added context, and more.
Compliance Checker: In just 10 minutes, figure out exactly what your business or organisation must do to comply with the AI Act.
High-level Summary: A short overview of the AI Act, with a breakdown on risk categorisation, obligations, prohibited systems, and timelines.
Small Businesses’ Guide: Everything you need to know, for small and medium-sized enterprises (SMEs) in the EU and beyond.



I like living in EU. I am starting to see AI content labeled and its really such a relief every time.
A bit frightening sometimes too. There was this audio ad playing on radio for months now. Just recnty they added one sentence disclaimer: "Read by an AI lector." I listened to it every other day and had no idea!
Very interesting stuff. I've also written about this. Your stack should be a good resource for me in the future.