In the space of a few weeks, AI regulation has shifted from drafts and guidance into hard obligations with real penalties across multiple major jurisdictions. The European Commission has now activated the enforcement machinery for the AI Act, California has put its AI Transparency Act into operation, China is treating agentic and anthropomorphic AI as distinct regulatory categories, and Illinois has joined the small club of US states targeting frontier-scale systems. Taken together, the last stretch before August has turned what was once a patchwork of proposals into a concrete compliance landscape that large developers and platforms will have to navigate in parallel.
In Brussels, the European Commission’s new AI Office has formally taken over enforcement of the AI Act, ending the grace period that applied to general-purpose model providers. The obligations attached to these models have technically been in force since mid-2025, but August 2 marked the moment those rules acquired an enforcer with jurisdiction and a penalty schedule instead of polite warnings. For providers of powerful foundation and generative models, that means the EU’s ability to levy significant fines is now backed by an institution whose sole job is to monitor and act on noncompliance, in coordination with national regulators.
On the same date, the AI Act’s transparency obligations under Article 50 moved from abstract principle to law in application across the bloc. Any chatbot aimed at EU users must now clearly disclose that it is a machine, and deepfakes or AI-written text touching on matters of public interest must be labeled as such. Deployments of emotion-recognition and biometric-categorization systems must be disclosed to the people exposed to them, and while generative systems already on the market get a brief reprieve on machine-readable content marking until December 2, systems launched from August 2 onwards have to comply immediately, with violations exposing firms to multimillion-euro fines or a percentage of global turnover.
The Commission spent July tightening the screws on how those transparency rules will work in practice. It adopted a detailed, 51-page set of transparency guidelines and assessed a Code of Practice on AI-generated content labeling as adequate, while explicitly deciding not to grant open-source models any blanket exemption. One notable softening from earlier drafts is that image, audio and video deepfakes generated before the August 2 deadline never need retroactive marking, with the date of generation acting as a cut-off, whereas AI-written text is judged by its publication date, meaning older text released publicly after the deadline must still be labeled. Separately, a Digital Omnibus package confirmed that some stand-alone high-risk obligations under the AI Act will kick in later, and narrowed the test for what counts as a safety component.
China, meanwhile, has become the first country to treat agentic AI as a category of its own, rather than folding it into generic automation. Implementation Opinions on Intelligent Agents issued by the country’s internet, planning and industry regulators require that every agent’s decisions be tiered in advance into human-only, approval-required and fully autonomous levels before deployment, with filing and testing duties in sensitive sectors. A separate set of Interim Measures aimed at anthropomorphic interactive services took binding effect on July 15, governing companion-like AI by imposing security assessments, banning engineered dependency and prohibiting virtual intimacy features for minors; major consumer products reportedly pulled features that same day to stay on the right side of the new rules.
In the United States, California has quietly turned itself into a de facto AI transparency hub by aligning its timeline with the EU. The first wave of the state’s AI Transparency Act now applies to covered generative systems with large user bases that are publicly accessible in California, requiring them to offer a free AI detection tool, apply visible disclosures and embed latent, machine-readable disclosures in AI-generated image, video and audio content. A late amendment was designed to sync the operative date with the EU’s Article 50 obligations, and the law is structured to expand in phases through 2027 and 2028 to cover large online platforms, hosting providers and capture devices, steadily extending disclosure duties along the AI content supply chain.
Illinois has taken a different tack by stepping directly into frontier AI safety, joining California and New York around a common legislative template targeted at the most computationally intensive models and their developers. Its Artificial Intelligence Safety Measures Act adds a new layer of obligations for organizations training systems beyond a very high threshold of compute and above a substantial revenue line, and notably stands out as the first frontier law anywhere to mandate independent audits of such models. While details on implementation and enforcement have yet to be fully tested in practice, the move signals that states are no longer waiting for federal action before placing specific safety expectations on the developers at the bleeding edge of AI.
Why this matters
The turning-on of these rules across the EU, China and key US states marks a structural shift in the AI industry’s operating environment, with transparency, safety and human oversight becoming regulated design constraints rather than optional ethics add-ons. Developers of general-purpose and generative models now have to think about disclosure and labeling requirements at the architecture and product level, from machine-readable watermarking to user-facing notices, if they plan to operate at scale across these markets. At the same time, those pushing agentic or companion AI have to grapple with the fact that some jurisdictions now treat these systems as distinct, high-touch categories that demand pre-deployment tiering of autonomy, safeguards around human reliance and explicit protections for minors.
The near-term practical impact will be felt in product roadmaps, compliance budgets and cross-border rollout plans, as companies weigh whether to harmonize toward the strictest common denominator or maintain region-specific variants that reflect local law. The EU’s move to defer certain high-risk obligations while hardening transparency rules gives developers some breathing room on safety components, but also raises expectations that labeling and disclosure will be handled competently from day one. China’s agent and companion frameworks could serve as early models for other governments wrestling with how to regulate AI that acts on behalf of users or interacts with them in human-like ways, while US states experimenting with frontier thresholds and audits may shape future national or international norms. With enforcement bodies now in place and penalties concrete, the next phase of AI regulation will be measured less by how many laws pass than by how many systems change in response.