Enforcement now reaches inside the model provider
On August 2, 2026, the EU AI Act entered a consequential enforcement phase: the European Commission’s AI Office and national authorities gained enforcement powers, while new transparency requirements began applying to certain AI systems. This is not the simultaneous activation of every provision. The Commission’s updated timetable places major high-risk-system requirements in December 2027 and August 2028. (digital-strategy.ec.europa.eu)
The AI Office oversees general-purpose AI models and specified systems, including those developed within the model provider’s business group. National authorities supervise other systems; the European Data Protection Supervisor covers EU institutions. The Office can request information, require model access for evaluations and seek restrictions on a model’s public availability. A dedicated complaints channel lets downstream developers report alleged model-provider violations. (digital-strategy.ec.europa.eu)
The commercial significance is therefore not just potential fines. The enforcement design gives customers a route to challenge suppliers’ compliance. That could strengthen a software developer’s bargaining position when it needs information from a model vendor. However, an available complaints mechanism is not evidence that complaints are being resolved quickly or producing remedies. (digital-strategy.ec.europa.eu)
Model documentation becomes a supplier deliverable
General-purpose-model obligations began applying on August 2, 2025, with special transitional treatment for older models. The 2026 change adds enforcement to that earlier layer rather than creating it from scratch. Providers must prepare technical documentation, supply information to downstream developers, maintain a copyright-compliance policy and publish a training-content summary. Systemic-risk models face additional evaluation, incident-reporting, risk-mitigation and cybersecurity obligations. Providers outside Europe are covered when placing models on the EU market. (digital-strategy.ec.europa.eu)
These duties suggest concrete cost centres: documentation staff, testing, incident handling and coordination with customers. They also suggest a benefit for buyers: less dependence on voluntarily supplied information. Neither proposition establishes the net cost. The Commission’s explanation does not provide measured, provider-level compliance spending. (digital-strategy.ec.europa.eu)
The voluntary GPAI Code of Practice offers a compliance route, not automatic legal clearance. Adherence does not create a presumption of conformity; providers choosing alternatives must justify their adequacy. The likely incentive is to reuse a recognised framework rather than design and defend a separate one. That is an inference about administrative effort—not proof that signing eliminates liability or makes a model safe. (digital-strategy.ec.europa.eu)
A visible label and a machine-readable mark do different jobs
The transparency regime separates responsibilities. Providers must inform people about direct AI interactions and add machine-readable marks to generated or manipulated content. Deployers face disclosure duties for deepfakes, emotion-recognition and biometric-categorisation tools, and certain public-interest text publications lacking human review or editorial control. The Commission’s guidelines also address exceptions, including standard editing. This is not a blanket requirement to put the same warning on every AI-assisted publication. (digital-strategy.ec.europa.eu)
The distinction matters operationally: a provider’s output-marking process and a publisher’s audience-facing disclosure are separate tasks. As a practical implication, procurement and publishing reviews should ask who supplies each function, rather than treating a vendor’s general assertion of compliance as sufficient. (digital-strategy.ec.europa.eu)
The transparency code supplies an implementation route; organisations declining it must demonstrate equivalently adequate alternatives for marking and labelling. This flexibility complicates the assumption that compliance necessarily means purchasing one prescribed technology. It also leaves an evidentiary question: demonstrating that a marking method meets obligations is different from demonstrating that audiences understand disclosures. The guidelines describe how compliance can be shown, not measured reductions in deception. (digital-strategy.ec.europa.eu)
Google’s adoption shows adaptation, not settled economics
Google announced on July 24, 2026, that it was signing the transparency code, following its 2025 GPAI-code signing. It connected the decision to existing work on the C2PA provenance standard and its SynthID watermarking technology. That is evidence of a global provider adapting through tools it was already developing—not evidence that the Act created those tools. (blog.google)
The same announcement challenged the implementation’s complexity. Google warned that overlapping labels and disclosures could confuse users and that evolving technical solutions made additional regulation burdensome. Those concerns deserve consideration because disclosure design is part of the policy’s effectiveness. But the announcement supplies neither a quantified cost estimate nor a user study establishing that the EU requirements cause confusion. (blog.google)
Google’s position also complicates a simple compliance-versus-innovation narrative: a company can participate while disputing the design. Its existing investment suggests a possible uneven burden—providers with mature transparency infrastructure may need less additional work than newcomers. The announcement cannot establish the size of that advantage or whether costs will reach customers. (blog.google)
The next useful evidence would be specific: engineering hours attributable to compliance, the adequacy of documents delivered to customers, disclosure-comprehension tests and the handling of substantiated complaints. Those observations would distinguish a functioning accountability regime from a growing collection of compliance statements.
Sources
- https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act
- https://digital-strategy.ec.europa.eu/en/faqs/general-purpose-ai-models-ai-act-questions-answers
- https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations
- https://blog.google/company-news/outreach-and-initiatives/public-policy/eu-ai-act-transparency-code-of-practice/




By
By
By
By







