As of August 2, 2026, the European Regulation on Artificial Intelligence comes into general application. The most visible change for citizens affects transparency: users must know when they are interacting with an AI, and certain content, such as deepfakes or artificially generated texts on matters of public interest, must be identified. However, Brussels has postponed a good part of the most demanding obligations for systems considered high risk.
The European Union has reached one of the fundamental dates in the implementation calendar of its Artificial Intelligence Law. Since August 2, 2026, Regulation (EU) 2024/1689 will be applied generally after a two-year transitional period since its entry into force.
This does not mean that all its rules have now begun. Some prohibitions have been in effect since February 2025, and the obligations for large general-use artificial intelligence models began to apply in August of that same year. Additionally, a European reform approved this summer has postponed until 2027 and 2028 a good part of the obligations corresponding to high-risk AI systems.
What does the EU Artificial Intelligence Law consist of?
Although it is commonly referred to as the "Artificial Intelligence Law" or AI Act, legally it is a European regulation and, therefore, is directly applicable in all Member States, including Spain, without the need for each country to previously transform it into national law.
The regulation uses a risk-based system: the greater the potential harm of an artificial intelligence application to security or fundamental rights, the greater the obligations it must fulfill.
It generally distinguishes between prohibited practices, high-risk systems, systems subject to specific transparency obligations, and applications of minimal risk.
As of August, it will be necessary to notify when we talk to an AI
One of the changes that citizens will notice most directly comes from Article 50, applicable from August 2.
Providers must design certain systems so that a person is informed that they are interacting with an artificial intelligence, unless it is evident from the circumstances.
This especially affects tools such as chatbots, virtual assistants, or automated customer service systems. The goal is to prevent a person from believing they are having a conversation with another human being when they are actually dealing with a machine.
The images, videos, and audios generated by AI must be detectable
Providers of systems capable of producing audio, images, videos, or synthetic texts must also incorporate mechanisms that allow for the technical identification that this content has been generated or manipulated by AI.
The Regulation requires that this information be detectable in a machine-readable format and that the solutions used be effective, interoperable, robust, and reliable to the extent that it is technically possible.
There is, however, an important transitional exception. Systems that were already marketed before August 2, 2026, have until December 2, 2026 to adapt this marking function.
Deepfakes will have to be identified
The regulation also introduces a specific obligation for deepfakes.
When an AI tool generates or manipulates an image, audio, or video in such a way that it appears authentic, whoever publishes or uses that content must clearly inform that it has been artificially created or modified.
The legislation introduces nuances for artistic, satirical, creative, or fictional works: it must be warned of the use of artificial intelligence, but in a way that does not hinder the normal enjoyment of the work.
There are also exceptions related to certain legally authorized uses for investigating, preventing, or prosecuting crimes.
What changes for the media?
This is one of the particularly relevant aspects for newspapers, television, websites, and social networks.
Since August, when an AI system generates or manipulates a text intended to inform the public about matters of public interest, it must be indicated that the content has been artificially created.
However, the Regulation itself incorporates a fundamental exception: it will not be mandatory to label the text as AI-generated when it has gone through a process of human review or editorial control and there is a natural or legal person who assumes editorial responsibility for its publication.
Therefore, the regulation differentiates between the automated publication of information and the use of AI tools within a journalistic process supervised by professionals.
It must also be notified of the recognition of emotions
People must be informed when they are exposed to certain systems of emotion recognition or biometric categorization.
For example, if a company uses a system that attempts to identify certain emotional states through the face, voice, or other biometric signals, the individuals subjected to the system must know how it works.
These tools are also subject to other restrictions. Some uses of artificial intelligence to infer emotions in educational centers and workplaces have already been prohibited since February 2025, except for exceptions primarily related to medical or security reasons.
What rights do citizens gain?
Since the general application of the Regulation, several protection mechanisms are also fully operational.
Any natural or legal person who believes that the AI Law has been violated can file a complaint with the competent market surveillance authority.
The Regulation also provides a right to receive explanations when certain decisions that produce legal effects or significantly affect a person are made based on artificial intelligence systems considered high risk.
The practical application of this last guarantee will be linked to the specific timetable of high-risk systems, whose main obligations have been postponed.
Fines can reach 15 million for violating transparency rules or 3% of a company's annual global turnover, applying the proportionality criteria established for small and medium-sized enterprises.
Surveillance will mainly fall on the competent national authorities. The European Artificial Intelligence Office will have specific competencies over certain systems and general-purpose models, while the European Data Protection Supervisor will act regarding the institutions of the Union.
What is postponed until 2027 and 2028?
The major exception affects high-risk artificial intelligence.
In July 2026, the EU modified the timetable through Regulation 2026/1744 due, among other reasons, to the delay in the development of technical standards and tools that would allow companies to meet the requirements correctly.
The complete obligations for the systems used in sensitive areas of the annex III, such as employment, education, access to certain essential services, biometrics, migration, asylum, border control, or administration of justice, will begin to apply on December 2, 2027.
The high-risk systems incorporated into regulated products, such as certain medical devices, machinery, or products subject to European safety legislation, will have until August 2, 2028.
Therefore, August 2, 2026 represents an important leap in the application of the European Artificial Intelligence Act, but does not yet represent the end of its regulatory calendar.