Welcome to the EU AI Act Newsletter, a brief biweekly newsletter by the Future of Life Institute providing you with up-to-date developments and analyses of the EU artificial intelligence law.
Commission starts enforcing AI Act rules and new transparency requirements: The European Commission reports that, from 2 August 2026, its AI Office, alongside national authorities, has begun enforcing the AI Act. Additionally, the new transparency rules have also taken effect. Under those rules, chatbots and other interactive systems must tell users they are dealing with AI rather than a human, deepfakes must be labelled, and AI-generated or altered content must carry machine-readable marks so it can be detected more easily. Alongside this, the Commission published a first list of more than 180 organisations that have signed the Code of Practice operationalising those transparency rules. Enforcement now also covers prohibited practices and providers of general-purpose AI models, including their documentation, copyright policy and training-data summaries, with extra obligations for models posing systemic risks. Responsibility for enforcing the transparency rules and prohibited practices is shared between the AI Office, national competent authorities and the European Data Protection Supervisor. The AI Omnibus, meanwhile, postpones the high-risk rules to 2 December 2027 and the rules for high-risk AI systems integrated into regulated products to 2 August 2028.
New AI Act enforcement tools: The European Commission's AI Office outlines the channels it has launched to support enforcement of the AI Act. Chief among them is the Complaint Tool, through which natural and legal persons can report alleged infringements by providers or deployers of AI systems falling under the AI Office’s exclusive competence, on the basis of Article 85. Because complaints must stay within that scope, the tool does not cover infringements of other EU or national laws. Alleged breaches of Articles 53 to 55 go instead to a dedicated channel for downstream providerswho may complain under Article 89(2) where they believe the provider of a general-purpose AI model has failed on technical documentation, copyright policy, training-data summaries, incident reporting and cybersecurity or, for models with systemic risks, risk assessment and mitigation. Separately, a Whistleblower Tool lets those working with providers report possible violations securely.
Europe’s AI safety rules take on US rogue agents and Chinese ambitions: Pieter Haeck from POLITICO reports that the AI Act's second anniversary on 2 August triggered new Commission powers over how companies handle systemic risks from their most advanced models. The AI Office can now request documentation, conduct evaluations and even request access to the models, and can fine companies up to 3 per cent of global turnover. The powers follow the first known case of an autonomous AI agent going rogue, when an agent driven by two OpenAI models hacked into the platform Hugging Face, a breach OpenAI called “unprecedented”. US lawmakers responded with a bipartisan House bill, the “AI Kill Switch Act”. Meanwhile, Xi Jinping has declared Beijing ready to lead global AI governance, with 29 countries signing a pact in Shanghai that is light on specifics. Earlier this month, think tanks, parliamentarians and experts urged the AI Office in an open letter to use its powers fully.
Commission’s digital kingpin extended for twelfth year: Théophane Hartmann from Euractiv reports that Roberto Viola, who has led the Commission’s Connectivity directorate (DG CNECT) since 2015, will stay in post until 30 September 2027, according to a Commission spokesperson, rather than leaving when his contract was due to expire in September 2026. This marks the second such one-year extension, granted in accordance with the EU staff regulations, under which officials reaching the age of 66 must retire unless they request and are granted annual extensions, up to the age of 70; Viola turns 67 in September. Over his time at the helm of DG Connect, he has overseen the drafting and execution of several landmark tech rules, among them the GDPR, the Digital Services Act and Digital Markets Act governing platforms, and the AI Act.
Advancing responsible AI across Europe: OpenAI sets out in a blog post how it has strengthened its approach to safety, security, transparency and provenance in line with the EU framework as the AI Act enters its next phase. The company argues that such rules must be pragmatic, proportionate and risk-based to advance governance while supporting innovation. OpenAI also notes that it contributed to and endorsed both the General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Its support for the former rests on internal governance alongside collaboration with external experts, governments and peers, including pre-release testing, system cards, its Red Teaming Network and the public Model Spec. For provenance, OpenAI uses two reinforcing systems, Content Credentials (C2PA) and SynthID watermarks, and is now extending them to audio outputs. It says it will widen provenance measures across other modalities, text included, as standards and tooling mature.
Large hiring round at the EU AI Office: The European Commission has opened a call of interest for around 40 contract agent posts dedicated to enforcing the AI Act, recruiting Technology Specialists, Legal Officers, Operations Specialists and Paralegals, primarily into the units responsible for AI regulation and compliance (CNECT A.2) and AI safety (CNECT A.3). On the technical side, the call seeks expertise in model evaluations and red-teaming, interpretability and alignment, model weight security and confidential computing, AI-enabled cyber threats, agentic AI, and compute and hardware supply chains. It also looks for risk-area specialists on loss of control, CBRN, cyber and harmful manipulation, as well as strategic foresight and quantitative analysis, including capability forecasting and game-theoretic modelling of regulatory and competitive dynamics. Contracts run initially for one year and may be extended up to six. Applicants must be EU citizens, will be based in Brussels, and should apply by midday on 8 September 2026.
We’ve built the most comprehensive website on the EU AI Act to help answer all your questions. Here are a few of our most popular resources used by 60,000+ professionals every week:
AI Act Explorer: Explore the official AI Act text on any device, in any EU language, with helpful cross-links, added context, and more.
Compliance Checker: In just 10 minutes, figure out exactly what your business or organisation must do to comply with the AI Act.
High-level Summary: A short overview of the AI Act, with a breakdown on risk categorisation, obligations, prohibited systems, and timelines.
Small Businesses’ Guide: Everything you need to know, for small and medium-sized enterprises (SMEs) in the EU and beyond.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.