The EU AI Act Is Now Enforceable — Here's What Changed July 10

The European Union's AI Act entered enforcement July 10, 2026. Not "went into effect." Not "became law." Entered enforcement — which means real legal penalties for non-compliance are now on the table.

After years of legislative development and phased implementation, the rules governing AI deployment in Europe are binding. If your business deploys an AI chatbot, virtual assistant, or any automated conversational system in contact with EU users, you are legally required to disclose that the user is interacting with AI. Fail to do that and you face fines, service bans, or both.

This is the most significant moment in AI regulation history. The EU has moved from drafting policy to enforcing it.

What Changed July 10

Chatbot disclosure requirements are now live and enforceable. That is the headline. The rest of the AI Act's provisions roll out over the next two years, but this one is active now.

If a user in the EU interacts with your AI system and you do not disclose that it is AI, you are in violation. The enforcement mechanism is not theoretical — the Digital Omnibus on AI was provisionally agreed May 7, 2026, formally adopted by the European Parliament June 16, 2026, adopted by the Council June 29, 2026, and signed July 8, 2026. The legal framework is complete and binding.

What "Enforceable" Means

It means the EU can levy fines. It means regulatory bodies can ban your service. It means if you operate in Europe or serve EU users, you either comply or you accept that risk.

The AI Act defines compliance obligations by risk tier. Chatbot disclosure is a baseline transparency requirement — low-friction, high-impact. It does not require technical changes to how the AI works. It requires you to tell users what they are talking to.

That is the wedge. The requirements for high-risk AI systems (hiring algorithms, credit scoring, law enforcement tools) are more complex and will take longer to enforce. But chatbot disclosure is simple, verifiable, and effective immediately. It sets the precedent that AI regulation in the EU has teeth.

EDPB Guidelines on AI Training Data — The Other Shoe

July 8, 2026, the European Data Protection Board adopted Guidelines 03/2026 on Web Scraping in the Context of Generative AI. This is the first pan-EU framework to address AI training data collection under GDPR.

The guidelines make three things clear:

1. GDPR applies to AI training data collection. Transparency, data minimisation, and accuracy requirements all apply. If you scrape data to train a model, you must comply with GDPR principles at the collection stage, not just at deployment.

2. Consent is not viable as a legal basis for large-scale scraping. You cannot rely on consent to justify mass data collection from people who never interacted with your service. The EDPB has closed that loophole.

3. Per-deployment assessments are required. Each model deployment needs a separate GDPR compliance review. You cannot assess once and deploy indefinitely. Every new model, every new dataset, every new deployment requires a fresh analysis of whether the processing is lawful under GDPR.

The guidelines are open for public consultation until October 30, 2026, but the framework is set. AI labs can comment, but the EDPB has drawn the line: training data is not exempt from GDPR just because it is used for AI.

What This Does to "Move Fast and Break Things"

The EU just told AI labs that the era of scraping the web without legal review is over. If you want to train a model on EU data or deploy a model to EU users, you must demonstrate GDPR compliance at every stage — collection, processing, deployment.

That includes:

• Documenting your legal basis for processing (and "legitimate interest" requires actual documentation, as OpenAI discovered when the Italian Garante penalized them for inadequate justification).

• Respecting robots.txt and other technical opt-out signals. The EDPB has given those signals regulatory weight.

• Conducting per-deployment assessments, which means you cannot train once and iterate indefinitely without revisiting compliance.

Italian, Irish, Dutch, and French data protection authorities have already taken enforcement actions against AI companies. Italy penalized OpenAI over inadequate legitimate-interest documentation and ordered a public awareness campaign explaining how user data is handled. That is what enforcement looks like under GDPR — financial penalties plus reputational damage.

The AI Act and GDPR now converge. You must comply with both. Chatbot disclosure is AI Act compliance. Training data collection is GDPR compliance. Deploy a model trained on unlawfully scraped data and you have violated both.

Why July 10 Matters

This is not a warning. It is not a grace period. It is the enforcement start date.

Companies that have been operating on the assumption that AI regulation is distant or theoretical now face binding legal obligations with real penalties. The EU is not waiting for consensus or for global frameworks to align. It is enforcing its own rules, and those rules apply to any company that serves EU users — regardless of where the company is headquartered.

The extraterritorial reach is the point. GDPR established that. The AI Act extends it. If your service is accessible in the EU, EU law applies.

What Comes Next

Chatbot disclosure is the easy part. The AI Act's provisions on high-risk AI systems — tools used for hiring, credit decisions, law enforcement, critical infrastructure — are more complex and will roll out over the next two years. Those requirements include risk assessments, transparency obligations, human oversight, and conformity assessments before deployment.

The EDPB's guidelines on training data will finalize after the October 30 consultation period. Expect clarifications, but not retreat. The framework is set: GDPR applies, consent is not viable for mass scraping, per-deployment assessments are required.

And enforcement will accelerate. The Italian Garante has already acted. Other data protection authorities will follow. The precedent is live.

If you deploy AI in Europe or scrape EU data to train models, the compliance clock started July 10. The question is whether you noticed.