World Report Network
  • Home
  • Blog
  • About Us
  • Contact
Font ResizerAa
World Report NetworkWorld Report Network
  • Home
  • Blog
  • About Us
  • Contact
Search
  • Home
  • Blog
  • About Us
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Politics

The EU now polices deepfakes. The rules on hiring and asylum algorithms just slipped to 2027.

Hailey King
Last updated: 2 September 2026 23:28
Hailey King
Share
The Berlaymont building in Brussels, headquarters of the European Commission
The Berlaymont in Brussels, headquarters of the European Commission. Credit: almathias (CC0).
SHARE

On 2 August 2026 the European Union began enforcing the part of its Artificial Intelligence Act that most people will actually notice: chatbots must say they are chatbots, and synthetic images, audio and video must carry machine-readable labels marking them as generated.

Contents
What is now enforceableWhat was postponed, and why it matters moreThe pressure from outsideHow the Act has been phased inWhat happens nextWhat “high-risk” covers, in concrete termsHow you actually label a deepfakeThe enforcement questionWhat organisations have to do nowWhether the Brussels effect still applies

In the same week, the Commission confirmed that the part of the Act civil-society groups considered its core — the rules on “high-risk” AI systems — would not take effect as planned. Those have been pushed to 2 December 2027.

What is now enforceable

Article 50 of the AI Act imposes transparency duties that came into force on 2 August:

  • Interactive AI systems must disclose to users that they are dealing with a machine rather than a person.
  • AI-generated or manipulated media — deepfakes included — must be marked in a machine-readable format.
  • Emotion-recognition and biometric categorisation systems must notify the people being scanned.

Penalties run to €15 million or 3 per cent of global annual turnover, whichever is higher. By early August, more than 180 organisations, OpenAI among them, had signed the Commission’s voluntary Code of Practice on transparency of AI-generated content. Euronews reported Meta as a notable holdout among the major Western labs.

What was postponed, and why it matters more

The high-risk category covers AI used in biometrics, employment, education, access to essential services, and migration, asylum and border management. These are the applications where an automated error is not an inconvenience but a life outcome: a job application filtered out, a benefit refused, an asylum claim assessed by a model.

Until December 2027, systems in these areas remain governed only by the GDPR and existing sector rules.

Commission Executive Vice-President Henna Virkkunen defended the delay as intended to “make it easier to innovate without lowering the bar on safety.”

Civil-society organisations read it differently. Stefi Richani of the Equinox Initiative for Racial Justice warned the postponement “will increase surveillance and discrimination, and even result in asylum claims being unlawfully rejected.” Laura Lazaro Cabrera of the Centre for Democracy & Technology put the criticism in terms of priorities: “Enforcement should not be headline-driven, but should address the full spectrum of risks.”

It is an uncomfortable pairing. The rules that arrived on schedule are the visible, consumer-facing ones. The rules that slipped are the ones that would have governed decisions made about people, often about people with the least capacity to contest them.

The pressure from outside

The delay did not happen in a vacuum. The Trump administration has been openly critical of European technology regulation as a device aimed at American companies. MEP Michael McNamara (Ireland, Renew) warned that enforcement risks being read in Washington as an attack on US commercial interests.

Industry criticism runs the other way, arguing that even the surviving provisions push companies to hire lawyers rather than engineers. MEP Axel Voss (Germany, EPP) has argued for better alignment across the EU’s digital rulebook rather than piecemeal postponement.

How the Act has been phased in

  • February 2025 — prohibited AI practices banned outright.
  • August 2025 — obligations on general-purpose AI models.
  • 2 August 2026 — transparency and deepfake-labelling rules (now in force).
  • 2 December 2027 — high-risk system obligations (postponed from August 2026).

What happens next

The European AI Office is continuing to build enforcement capacity, including a complaints tool and a whistleblower channel. The practical question for the next eighteen months is whether the transparency rules are enforced with enough visible consequence to establish that the Act has teeth — because that, rather than the text on the page, is what determines whether a 2027 deadline holds.

What “high-risk” covers, in concrete terms

The phrase does a lot of work and is rarely unpacked. The Act’s high-risk category is defined by use, not by how sophisticated a system is. The same underlying model can be unregulated in one application and high-risk in another.

The postponed obligations cover systems used to:

  • Screen job applicants, rank CVs, or evaluate candidates in recruitment.
  • Assess students for admission, or score examinations.
  • Determine eligibility for essential public services and benefits.
  • Assess creditworthiness in ways that decide access to finance.
  • Process migration, asylum and border claims, including risk assessments applied to applicants.
  • Perform biometric identification and categorisation.

What the postponed rules would have required is not exotic: risk management systems, documented data governance, technical documentation, human oversight arrangements, accuracy and robustness standards, and registration in an EU database. In effect, the ability to explain how a system reaches decisions about people, and to demonstrate that someone competent reviewed it.

Those obligations now arrive on 2 December 2027. In the interim these systems remain subject to the GDPR and to existing sector rules — which is real protection, but general-purpose protection, not designed for automated decision-making at this scale.

How you actually label a deepfake

The transparency rules require AI-generated or manipulated media to carry machine-readable markings. That requirement is easier to write than to implement, and the practical difficulties are worth understanding.

Two broad approaches exist. Metadata provenance attaches a cryptographically signed record to a file describing how it was made and by what — the approach behind content-credential standards. Watermarking embeds a signal into the pixels or audio itself, intended to survive re-encoding.

Each has a known weakness. Metadata is stripped by most social platforms as a matter of course during upload processing, often for legitimate reasons including privacy. Watermarks degrade under compression, cropping and re-recording, and a determined actor can usually remove them.

This matters for what the rule can realistically achieve. It will work reasonably well against the ordinary case — commercial content, corporate use, casual generation — where nobody is trying to evade it. It will work poorly against the case that motivated the rule: someone deliberately producing a deceptive political deepfake, who will simply strip the marking.

That is not an argument against the requirement. Establishing a norm that generated content is labelled has value even when the norm is evadable, because it makes unlabelled content anomalous. But it is an argument against expecting the rule to solve disinformation.

The enforcement question

A regulation is worth what its enforcement is worth, and this is where the Act’s near-term credibility will be decided.

The European AI Office is building capacity, including a complaints tool and a whistleblower channel. Both are meaningful: they mean enforcement does not depend solely on regulators noticing violations themselves.

The obstacles are the familiar ones. The regulator must be technically capable of assessing systems built by companies with far greater resources; must coordinate with national authorities of varying capability; and must survive the political pressure that follows the first significant fine against a large American firm.

The maximum penalty for transparency violations is €15 million or 3 per cent of global annual turnover. For the largest AI companies the percentage figure is the binding one, and it is large enough to matter — if it is ever applied.

What organisations have to do now

For anyone deploying AI systems reachable by users in the EU, the obligations that took effect on 2 August are practical rather than abstract:

  • Disclose the machine. A chatbot or voice agent must make clear it is not a person. This applies to customer service, sales and support tools, not only consumer products.
  • Mark generated media. Images, audio and video produced or materially altered by AI need machine-readable markings.
  • Notify people being analysed. Emotion-recognition and biometric categorisation systems must tell the people they scan.

Note the reach. The Act applies to systems whose output is used in the EU, regardless of where the provider is established. A company with no European office can be within scope.

Whether the Brussels effect still applies

The EU’s regulatory influence has historically travelled beyond its borders through a simple mechanism: multinational companies find it cheaper to build one compliant product than to maintain separate versions per market. The GDPR is the standard example, having reshaped privacy practice well outside Europe.

Whether the AI Act repeats that is genuinely uncertain, and this delay is part of the reason.

The argument for is that compliance costs are largely fixed, transparency features are cheap to ship globally, and 450 million consumers are not a market to configure around.

The argument against is that AI systems are far easier to regionalise than a privacy architecture — a model can be served differently by jurisdiction — and that the political environment has changed. A postponement of the Act’s central provisions, arriving amid open American criticism of European tech regulation, weakens the signal that the EU will hold a line under pressure. The Brussels effect depends on other jurisdictions believing that the rules will actually bind. The next eighteen months are where that belief is either confirmed or eroded.


Sources

  • European Commission, “Commission starts enforcing AI Act rules and new transparency requirements on 2 August,” 2 August 2026 — digital-strategy.ec.europa.eu
  • Al Jazeera, “What came into force with the EU’s AI Act this week – and what didn’t,” 6 August 2026 — aljazeera.com
  • Euronews, “EU rules on AI models become enforceable. What’s going to change?,” 2 August 2026 — euronews.com
  • Cooley LLP, “EU AI Act: Transparency Obligations Take Effect 2 August 2026,” 3 August 2026 — cooley.com
TAGGED:AI ActArtificial IntelligenceDeepfakesEuropean UnionRegulation
Share This Article
Email Copy Link Print
Previous Article The Peace Arch monument on the Canada–United States border between Surrey, British Columbia and Blaine, Washington A 1930 law, a fight over French streaming quotas, and a trade war that starts on Tuesday
Next Article A camp for internally displaced people in Darfur, Sudan The UN found “markers of genocide” in one Sudanese city. It is now racing to reach the next one first.
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad image

You Might Also Like

An open-plan office workspace
Technology

140,000 tech jobs are gone this year. The AI explanation keeps outrunning the evidence.

By Hailey King
Passengers queuing at airport passport control
Travel

Europe’s €20 travel authorisation just lost its launch date. Do not pay anyone for it.

By Hailey King
High-voltage electricity transmission lines
Technology

America’s biggest grid operator will start switching off data centres in 2027

By Hailey King
The Peace Arch monument on the Canada–United States border between Surrey, British Columbia and Blaine, Washington
Politics

A 1930 law, a fight over French streaming quotas, and a trade war that starts on Tuesday

By Hailey King
World Report Network
Navigation
  • Home
  • Blog
  • About Us
  • Contact
Usefull Links
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • DMCA Policy

© World Report Network. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?