Join WhatsApp
EU AI Act: New Rules for AI
Vinit
23 August 2026

EU AI Act: New AI Rules, Generative AI, Copyright &

EU AI Act 2026: New Rules for Generative AI, Copyright, Deepfakes and Consumer ProtectionEU AI Act 2026: New Rules for Training Data and Copyright

The European Union’s AI Act has entered a major enforcement phase in 2026, bringing some of the world's most significant legally binding rules for artificial intelligence into practical effect. The legislation takes a risk-based approach, placing different obligations on AI systems depending on the potential harm they can cause.

For ordinary users, one of the most visible changes is arriving from 2 August 2026, when new transparency obligations apply to certain AI systems. These rules cover areas such as informing people when they are interacting with AI, identifying certain AI-generated or manipulated content, and labelling deepfakes. (Digital Strategy)

The law is particularly important for companies developing Generative AI and General-Purpose AI (GPAI) models because it introduces obligations around transparency, copyright, documentation, safety and systemic risks.


What Is the EU AI Act?

The EU AI Act is the European Union's comprehensive legal framework for regulating artificial intelligence.

Instead of treating every AI system in exactly the same way, the legislation follows a risk-based model.

In simple terms:

The greater the potential risk from an AI system, the stronger the legal requirements.

The framework covers everything from prohibited AI practices to high-risk systems and transparency requirements for certain generative and interactive AI applications. (Digital Strategy)

The European Commission describes the AI Act as the first comprehensive legal framework of its kind addressing AI risks while attempting to support innovation and protect fundamental rights.


Why Is the EU AI Act Important in 2026?

The important point is that the AI Act is not coming into force as one single set of rules on one day.

Different provisions apply at different times.

As of August 2026, several major provisions are already applicable, including rules concerning:

  • Prohibited AI practices

  • General-Purpose AI models

  • AI governance and enforcement

  • Transparency requirements for certain AI systems

The Commission and national authorities began enforcing relevant AI Act provisions from 2 August 2026. (Digital Strategy)

Other requirements, particularly many high-risk AI rules, have later application dates.


The Four Broad Risk Levels

The EU AI Act broadly divides AI applications according to the level of risk they pose.

1. Unacceptable Risk — AI Practices That Are Prohibited

Certain AI practices are considered incompatible with European fundamental rights and values and are therefore prohibited.

Examples include certain forms of:

  • Manipulative AI

  • Exploitation of people's vulnerabilities

  • Unacceptable social scoring

  • Certain biometric practices

  • Certain predictive-policing applications

The exact legal scope depends on the provisions and exceptions established by the regulation. (Digital Strategy)

The idea is simple:

Some uses of AI are considered too dangerous to be allowed in the EU market.


The European Parliament has adopted a resolution on copyright and generative AI. The resolution states that the development of AI must not undermine EU copyright law or the rights of creators. It2. High-Risk AI Systems

The next category covers AI applications that can significantly affect people's safety, rights or access to important opportunities.

Examples can include AI used in areas such as:

  • Employment and recruitment

  • Education

  • Critical infrastructure

  • Certain medical applications

  • Essential services

These systems face considerably stronger compliance requirements than ordinary low-risk AI applications.

Depending on the system and its classification, obligations can include:

  • Risk management

  • Data governance

  • Technical documentation

  • Record keeping

  • Human oversight

  • Accuracy and robustness requirements

  • Cybersecurity safeguards

Many high-risk AI rules have later application dates, with the Commission currently stating that rules for high-risk systems listed in Annex III apply from 2 December 2027, while high-risk AI embedded in regulated products follows a later date of 2 August 2028. (Digital Strategy)


3. Generative AI and Transparency Rules

This is probably the part ordinary internet users will notice most.

From 2 August 2026, Article 50 transparency obligations apply to certain AI systems. (Digital Strategy)

The objective is to make it easier for people to understand when they are interacting with AI or seeing content generated or manipulated by AI.

AI systems must provide information in relevant situations

Providers of certain interactive AI systems must design them so that people are informed when they are directly interacting with AI.

That means an AI chatbot should not misleadingly present itself as a human.

The rules are designed to help users make better decisions about how much trust they place in AI-generated information. (Digital Strategy)


AI-Generated Images, Videos and Audio

One of the most important changes concerns synthetic content.

Under the transparency framework, providers must apply machine-readable markings to AI-generated or manipulated content in relevant cases so that such content can be detected.

The rules cover forms of:

  • AI-generated images

  • AI-generated video

  • AI-generated audio

  • Other synthetic or manipulated content

There are exceptions, including certain standard editing and assistive applications where the input is not substantially altered. (Digital Strategy)

This does not simply mean that every image created using an AI tool will necessarily display a huge visible "AI GENERATED" label across the picture.

The legal requirements distinguish between machine-readable marking and visible labelling, depending on the type of content and how it is used.


What About Deepfakes?

Deepfakes are a major focus of the new transparency rules.

A deepfake can involve an AI-generated or manipulated image, video or audio that resembles a real person, place, object or event and could misleadingly appear authentic.

Under the applicable transparency rules, deployers must clearly disclose relevant deepfakes. (Digital Strategy)

This could become particularly important for:

  • Fake celebrity videos

  • Fake political speeches

  • AI-generated news footage

  • Fake interviews

  • Manipulated social-media videos

  • Impersonation content

The objective is to reduce deception and make it easier for people to distinguish synthetic material from authentic content.


EU AI Act: What Changes on 2 August 2026? | NetNordicAI-Generated Public-Interest Text

There is another interesting rule that could affect digital media.

Certain AI-generated or manipulated text publications about matters of public interest must be appropriately disclosed when they have not undergone human review and editorial responsibility.

This is particularly relevant in an era when websites can automatically generate thousands of articles using AI.

However, the rule contains conditions and exceptions, including situations where human review and editorial responsibility are involved. (Digital Strategy)

For publishers and news websites, this makes human editorial oversight increasingly important.


Copyright and General-Purpose AI Models

Copyright is another major part of the AI Act.

General-Purpose AI models can be trained using enormous datasets containing text, images, code and other material.

The EU AI Act requires providers of GPAI models to establish policies for complying with EU copyright law and to respect applicable rights reservations.

They must also make a sufficiently detailed public summary of the content used to train their models. (Digital Strategy)

This is significant because it pushes AI developers toward greater transparency regarding the data used to train powerful models.


What Are General-Purpose AI Models?

A General-Purpose AI model, or GPAI model, is an AI model capable of performing a broad range of tasks rather than being designed for only one narrow application.

Large language models are an obvious example.

They can potentially be integrated into:

  • Chatbots

  • Search tools

  • Productivity software

  • Coding assistants

  • Education platforms

  • Image-generation systems

  • Business applications

Because one model can power thousands of downstream applications, the EU has created specific obligations for GPAI providers. (Digital Strategy)


Rules for the Most Powerful AI Models

The EU AI Act also contains additional requirements for GPAI models with systemic risk.

These are the most powerful models that could potentially create large-scale risks.

Their providers face additional obligations relating to:

  • Model evaluation

  • Safety and security

  • Risk assessment

  • Cybersecurity

  • Systemic-risk management

  • Cooperation with the AI Office

The European AI Office can also conduct model evaluations and request access to models in appropriate circumstances. (Digital Strategy)


What Is the EU AI Office?

The European AI Office plays a central role in implementing and enforcing parts of the AI Act, particularly those relating to General-Purpose AI.

Its responsibilities include supporting implementation, supervising relevant GPAI providers and coordinating with national authorities.

The enforcement structure therefore involves both:

European-level authorities + national market-surveillance authorities. (Digital Strategy)


Can Consumers Complain About AI?

Yes.

The AI Act's enforcement framework includes mechanisms through which individuals and organisations can submit complaints regarding suspected violations within the relevant supervisory structure.

The European Commission has also launched an AI Act Complaint Tool and a whistleblower mechanism for reporting potential violations. (Digital Strategy)

This gives consumers and other affected parties a more formal route for raising concerns.


How Much Can Companies Be Fined?

The EU AI Act comes with significant financial penalties.

For violations involving prohibited AI practices, penalties can reach:

€35 million or 7% of worldwide annual turnover

For other breaches, including certain GPAI obligations, fines can reach:

€15 million or 3% of worldwide annual turnover

For AI systems, certain failures involving information requests can result in penalties of up to:

€7.5 million or 1% of worldwide annual turnover

The actual amount depends on factors such as the nature, gravity and duration of the infringement. (Digital Strategy)


What Does the EU AI Act Mean for Indian AI Companies?

This is where the law becomes particularly interesting for India.

An Indian AI company may think:

"The EU is far away, so why should I care?"

But if that company provides AI products or services in the European market, EU regulations can become highly relevant.

For example, an Indian company developing:

  • AI software

  • Chatbots

  • Generative AI tools

  • Enterprise AI platforms

  • AI APIs

  • AI-powered applications

may need to assess whether its activities fall within the AI Act's scope when operating in or supplying the EU market.

This could increase compliance costs but could also encourage Indian companies to build stronger systems for:

  • Data governance

  • Copyright compliance

  • AI transparency

  • Model documentation

  • Risk management

  • Cybersecurity


What Does It Mean for Indian Users?

For an ordinary Indian user, the EU AI Act does not automatically mean that every AI tool used in India is now governed by EU law.

However, the regulation can have indirect global effects.

Major AI companies often operate internationally. If their products need to comply with EU requirements, companies may choose to introduce similar safety and transparency features across multiple markets.

This could eventually mean users around the world see more:

  • AI labels

  • Content provenance signals

  • Deepfake warnings

  • Copyright disclosures

  • AI interaction notices

But whether a particular feature appears in India will depend on the company, product and applicable laws.


Could This Change AI Content on Social Media?

Potentially, yes.

Imagine opening social media and seeing a realistic video of a famous person saying something they never actually said.

Under stronger transparency requirements, identifying relevant AI-generated or manipulated content becomes much more important.

This could help users ask:

"Is this real, or was it created by AI?"

That is especially important as generative AI becomes capable of producing increasingly realistic:

  • Faces

  • Voices

  • Videos

  • Images

  • Articles

  • Advertisements

The EU's transparency framework is explicitly designed to reduce deception and manipulation. (Digital Strategy)


AI Act vs Innovation: Will Regulation Slow AI Down?

This is one of the biggest debates surrounding AI regulation.

Critics of strict regulation can argue that excessive compliance requirements may increase costs for startups and slow experimentation.

Supporters argue that clear rules can actually increase trust.

For example, consumers may be more willing to use AI if they know:

  • When they are interacting with a machine

  • Whether an image is synthetic

  • Whether a video has been manipulated

  • What safeguards powerful AI models have

  • How copyright responsibilities are handled

The EU's approach attempts to combine innovation with safety and fundamental-rights protection. (Digital Strategy)


The "Brussels Effect": Could Europe Influence the Rest of the World?

The EU has previously demonstrated that its regulations can influence global technology companies.

The GDPR is the best-known example.

The AI Act could produce a similar effect if international companies decide that maintaining one strong compliance architecture is easier than developing completely separate systems for Europe and other markets.

This is often described as the "Brussels Effect."

However, it is too early to say that the EU AI Act will automatically become a worldwide standard.

Its global influence will depend on how companies, governments and other regulators respond.


EU AI Act Implementation Timeline

Date Major Development
1 August 2024 AI Act entered into force
2 February 2025 Prohibited AI practices and AI literacy provisions began applying
2 August 2025 GPAI obligations began applying
2 August 2026 Major enforcement phase and Article 50 transparency obligations apply
2 December 2026 Certain additional prohibitions relating to non-consensual intimate material and CSAM apply
2 December 2027 Certain Annex III high-risk AI rules apply
2 August 2028 High-risk AI systems embedded in regulated products follow later application

The EU has designed the AI Act as a progressive implementation, rather than switching every requirement on simultaneously. (Digital Strategy)


What Should AI Users Remember?

The biggest change is not that AI is being banned.

Instead, the EU is trying to establish clearer rules about where AI can be used, how risky systems must be controlled, and when people should be told that AI is involved.

For everyday users, the most relevant developments are:

AI interaction → transparency

Deepfake → disclosure

Synthetic content → machine-readable marking in relevant cases

Powerful AI models → additional safety obligations

Copyrighted training data → greater transparency and compliance requirements

Prohibited harmful AI practices → bans


Final Takeaway

The EU AI Act marks a major shift in how governments regulate artificial intelligence.

The legislation does not treat AI as a single technology. Instead, it distinguishes between low-risk applications, high-risk systems, prohibited practices and powerful General-Purpose AI models.

The most visible changes in 2026 concern AI transparency, including requirements around AI interactions, synthetic content and deepfakes. At the same time, GPAI providers face obligations involving copyright, documentation and systemic risks. (Digital Strategy)

For India, the biggest impact may come indirectly.

Indian AI companies selling into Europe will need to pay attention to EU compliance, while global technology companies may increasingly build transparency and safety features into products used worldwide.

The bigger question is no longer whether AI will be regulated.

It is:

How much regulation will other countries adopt after Europe?

The answer could shape the next phase of the global AI industry.

Note: The EU AI Act is being implemented progressively, so individual obligations depend on the type of AI system, provider/deployer role, market activity and applicable date. The article above reflects the EU Commission's official information available in August 2026. (Digital Strategy)

Related Articles

Back to Blog