Summary of Key Points
The EU's AI regulatory framework has officially entered a phase of "strict enforcement": The AI Office has been granted the authority to impose direct fines (up to 15 million euros or 3% of global turnover) and can request the removal of non-compliant models. AI-generated content must be labeled; responsibilities are clearly divided between "providers" (companies that develop AI) and "deployers" (businesses that use AI). The deadline for compliance is tight, with some companies receiving a short grace period, but non-EU firms are also subject to these regulations. The industry has begun to respond (for example, OpenAI has signed the EU's Transparency Code of Conduct), although implementation varies among member states.
1. The AI Office's New Powers: Fining and Removing Non-Compliant Models
Although the EU AI Office existed before, it did not have direct enforcement powers over general-purpose AI models like ChatGPT. Now, that period has ended, and the office finally has concrete measures:
- Powerful Authorities: It can request access to companies' technical documentation, evaluate models, order corrections, and impose substantial fines; it can also require the removal of non-compliant models.
- Reporting Channels: Ordinary citizens can report issues, downstream companies using AI models can file complaints, and internal employees can act as whistleblowers through confidential channels.
- Challenges: Not all EU member states have established corresponding regulatory mechanisms; currently, only 8 countries have set up contact points. Therefore, enforcement for high-risk AI applications (such as medical AI) depends on the individual capabilities of each country.
2. Labeling of AI Content: Failure to Comply Leads to Heavy Fines
Starting this month, all AI-generated or modified content must be clearly labeled:
- Specific Requirements:
- Chatbots must explicitly inform users that they are AI-powered.
- Deeply manipulated images/videos (e.g., face-altered ones) must be clearly marked.
- All AI content must include invisible watermarks that can be detected by machines, though not necessarily visible to humans.
- Fines: Fines range up to 15 million euros (approximately 120 million RMB) or 3% of global turnover, whichever is higher.
- No Exemptions: Even US-based companies (like OpenAI) that sell AI products or services to the EU must comply.
3. Clear Division of Responsibilities
The EU has differentiated the roles within the AI ecosystem, assigning different responsibilities:
- Providers (AI Developers): Are responsible for ensuring their products meet regulatory standards. For example, when developing chatbots, they must include a "I am AI" prompt; when creating image/video-generating AI, they must embed invisible watermarks in the content.
- Deployers (Businesses Using AI): Are responsible for informing users about the use of AI. For instance, stores using AI cameras to analyze customer emotions must display prominent notices; companies generating news or using deepfake content must clearly indicate that it is AI-generated.
4. Tight Compliance Deadlines with Grace Periods
Companies need to act quickly:
- Providers' Grace Period: There is a 4-month grace period for implementing invisible watermark requirements. If an AI system was sold in the EU before August 2, companies have until December 2 to make necessary changes; new systems must comply immediately.
- Deployers Without a Grace Period: All businesses using AI must comply with the labeling and notification requirements starting from August 2.
- Future Adjustments: Regulations for high-risk AI (e.g., medical, autonomous driving) will be postponed until 2027-2028. Additionally, a new ban on AI-generated pornographic content and child abuse materials without consent will take effect in December 2026.
5. Industry Response
Companies are already taking action to comply:
- OpenAI Leads the Way: OpenAI has signed the EU's Transparency Code of Conduct for AI-generated Content and uses two watermark systems (C2PA and SynthID), which currently apply to audio and will soon be extended to text.
- Legal Advice:
- Providers: Check their products for prompts and watermarks; if a grace period applies, keep written records.
- Deployers: Review their operations (e.g., whether they use AI for sentiment analysis or news generation) and determine who is responsible for labeling content. Consider using third-party providers for watermarking to avoid violations.
In summary, the EU is serious about these regulations, and both AI companies and businesses that utilize AI must take compliance seriously, or they risk facing significant fines. Non-EU firms doing business in the EU also need to comply with these rules.