On 2 August, new EU rules came into force requiring chatbots to disclose that they are AI systems and AI-generated content to carry machine-readable labels, with non-compliance subject to fines of up to €15 million or 3% of global turnover. The Commission described the measures as making AI “safer and more transparent”, while an industry federation representing marketers countered that transparency is “not the same as trust”. Both are, in their own terms, describing the same rules accurately. The significance lies in the gap between those two interpretations, between transparency as a regulatory requirement and trust as something that regulation alone cannot guarantee.
The key point for any company with EU exposure is that the enforcement mechanism is considerably softer than the headline penalty suggests.
The labelling icon set is voluntary. Independent research has already shown the underlying watermarking can be defeated for under $50 a try. Compliance is largely self-attested unless a regulator specifically investigates. That gap, real fines, soft verification, is not unique to this rule, but it is unusually well-documented here, making it a useful reference case for how "compliant on paper" and "compliant in practice" diverge.
There is a real design tension underneath, not just a soft-enforcement story. The rule triggers on the presence of AI, not on harm. An industry counter-argument, echoing the familiar GDPR cookie-banner problem, is that presence-based disclosure generates label fatigue on low-risk content, an AI-touched-up product photo gets the same treatment as a fabricated deepfake, while doing little to catch sophisticated, deliberately deceptive uses, exactly the cases the rule is designed to stop. That's not simply industry deflection. A harm-based standard would require exactly the case-by-case judgment that's expensive to enforce at scale, which is presumably why regulators chose the cheaper, broader trigger instead.
Three institutions, three different framings of the same rule.
- The Commission explains the measure’s existence and intent. Enforcement-side critics identify its technical weak points and potential loopholes. Industry explains the design logic and who ultimately bears the compliance costs. None of these perspectives is necessarily dishonest or simply wrong. That is precisely the problem: a reader exposed to only one framing could come away with a confident, defensible, and incomplete understanding of the measure.
What this means in practice
- Treat the Code of Practice and icon set as a base, not a compliance ceiling. Self-attestation without an internal verification process is the exact gap this rule's own critics have already identified in public.
- For companies using AI in client-facing content, marketing, or investor communications, document the actual disclosure logic now, on presence or on risk, since that design choice is the substance of the coming regulatory debate, not a formality.
- Expect this fight, presence-based versus harm-based triggers, to recur across other jurisdictions' AI transparency rules. It's a template disagreement, not a one-off, and it will resurface every time a regulator has to choose between a rule that's cheap to audit and one that's actually precise.
For asset managers and companies tracking regulatory risk in AI-exposed holdings, the useful signal isn't whether a rule like this exists. It's whether the enforcement mechanism underneath it can actually be tested, and this one, on the evidence so far, mostly can't yet.