Claude Sonnet 4.6 achieves new benchmarks /// OpenClaw hits 50K stars /// Vibe Coding surges 340% /// Claude Sonnet 4.6 achieves new benchmarks /// OpenClaw hits 50K stars /// Vibe Coding surges 340% ///
AI Strategy

The EU’s New AI Disclosure Rule Is Not a 7% Fine

The EU’s New AI Disclosure Rule Is Not a 7% Fine
Everyone reported a 7% fine. The real ceiling for the EU AI Act's new disclosure obligations is 3% of global turnover, and the expensive half of the law just slid to December 2027.

Between July 16 and July 31, Google shipped Gemini Spark to Google AI Pro subscribers in more than 160 countries. Spark is its always-on agent, the one that reaches across Gmail, Docs, Calendar, and now Chrome. The EEA didn’t get it. Neither did Switzerland, the UK, or Nigeria. Google published no reason and no timeline for lifting the exclusion.

Then Article 50 of the EU AI Act became binding law. That was August 2, a Sunday, two days after the last of those rollouts.

Google has never said the two facts are connected. Commentators have. Inference, not confirmation, and I won’t pretend otherwise. But the shape of it is hard to ignore, especially since Personal Intelligence, the feature that wires Gemini into Gmail, Photos, and Search, carves out the same three markets. A company pushes autonomous agents into 160 countries and routes around the one jurisdiction that just made agent disclosure a legal obligation.

Every summary I read this week carried the same penalty figure: fines up to 7% of global turnover. I went and read the Act’s penalty provisions twice, because that number didn’t sit right. It’s misfiled. The 7% ceiling, with its €35 million floor, belongs to the Act’s prohibited practices, things like social scoring and certain biometric surveillance. Article 50 transparency breaches sit a tier down, at up to €15 million or 3% of global annual turnover, whichever is higher.

Nobody should feel comforted by that correction. Take a company doing €40 billion a year, mettons a large European grocer. 3% is €1.2 billion. That’s not a small number, that. But a legal team planning against a ceiling more than double the real one will spend in the wrong places, and the wrong places are expensive.

What the rule actually asks for

Three obligations, and they are nowhere near equally hard.

When an AI system interacts directly with a person, the person has to be told, in the moment, that they are dealing with a machine. Chatbots, voice assistants, AI companions, social-media bots, and autonomous agents reaching out on someone else’s behalf are all in scope. This part is a banner and a line of text. Cheap.

Generative output is where it gets real. Synthetic audio, image, video, and text need machine-readable marks so that AI-generated or altered material can be detected downstream. Machine-readable means a program can verify it without a human squinting at the pixels. In practice that means a watermark or provenance metadata durable enough to survive a re-encode, a crop, or a screenshot. Watermarks tend not to survive light paraphrase. Provenance metadata tends not to survive any tool that doesn’t bother preserving it. I don’t know of a method that holds up across all three of those conditions, and I would genuinely like to be corrected on that.

That leaves the third piece. Deepfakes and AI-written text on matters of public interest have to be disclosed to the reader, plainly.

Enforcement sits with the EU AI Office, which holds investigation, complaint-handling, and whistleblower-reporting powers over this obligation. Reach is extraterritorial in the GDPR sense: it binds any provider or deployer serving EU users, wherever the company is headquartered. More than 180 organizations have signed the related Code of Practice on transparency, which is voluntary and does not substitute for the obligation itself.

The timing is awkward for a specific reason. Deloitte surveyed 3,235 senior leaders across 24 countries between August and September 2025. Roughly one in five had a mature governance model for autonomous systems, against 74% who expected to deploy agentic AI inside two years. Take that at face value and roughly four in five companies now owe a legal disclosure duty on systems they cannot yet govern. Self-reported maturity, note, and self-reported maturity flatters. The true figure is probably worse than one in five.

The expensive half got pushed to 2027

Here’s the part that should change how you read this week’s coverage. The Annex III high-risk regime was originally due on August 2, 2026 as well. It covers recruitment, credit scoring, law enforcement, education, and border control. The Council’s Digital Omnibus agreement, adopted June 29, 2026, moved it to December 2, 2027, and Annex I regulated-product systems now have until August 2, 2028.

So the documentation, risk-management, and human-oversight requirements that enterprise compliance teams spent a year bracing for are more than sixteen months out. What went live on Sunday is the narrow, consumer-facing slice of the law.

Practical DevSecOps, in its AI security statistics report for 2026, has the Annex III conformity requirements taking full effect on August 2, which would make red-teaming and adversarial robustness testing legally mandatory that day. They didn’t take effect. Those obligations live inside the high-risk conformity regime that just moved. Red-teaming your agents is still worth doing, for reasons that have nothing to do with Brussels. But anyone selling it to you as an August 2 legal requirement is selling a deadline that has already slipped once.

Even the live obligation has slack in it. Article 50(2) watermarking carries a grace period to December 2, 2026 for systems already on the market. Incumbents have four more months.

One sharp edge did survive the deferral, though. Customizing, retraining, or rebranding a general-purpose model can reclassify a deployer as a provider, which pulls the full obligation set down on your head. Few organizations have mapped that risk internally. If you have put your own logo on someone else’s model and told customers it’s yours, go read that clause today.

Where I might be wrong

The strongest case against all of this is that a label changes nothing. GDPR’s most visible legacy is a consent banner people dismiss without reading, and there’s no obvious reason “you are chatting with an AI” won’t land in the same reflex bucket by next spring. Disclosure is a cheap obligation precisely because it doesn’t require the system underneath to be any better than it was on Saturday.

There’s also a fair argument that users don’t need telling. Prophet’s 2026 AI Consumer Insights Report, published in April, puts US generative AI adoption at 73%, up from 45% in 2024. Stanford HAI’s 2026 AI Index puts US adoption at 28.3% of the population, 24th in the world, behind Singapore at 61% and the UAE at 64%. Same label on both numbers, a factor of 2.6 between them. Some of the gap is definitional: the AI Index counts share of population, Prophet counts share of surveyed consumers, and a survey panel is not a country. I don’t know which one to believe. Before I let either figure carry an argument about what the public already understands, I’d want the question wording from both, and I’d want to know who was excluded from the panel.

And enforcement is entirely theoretical today. Zero fines have been issued under Article 50, for the excellent reason that it has been binding for two days. A penalty ceiling is a number in a PDF until an AI Office decision makes it real. Should December 2027 slip the way August 2026 slipped, the argument that regulatory deadlines drive engineering behaviour gets thin fast.

Bon. Two dates then, not one. December 2, 2026 is when the watermarking grace period closes for systems already shipped, and that’s the test worth watching, because it’s the only obligation here that can’t be discharged with a banner and a lawyer. Either the large generative providers ship provenance marking that survives a screenshot, or they ship a metadata field set to true and hope nobody checks.

The second date has no number on it. It’s whenever Gemini Spark quietly shows up in Brussels.

Dominic Plouffe

Staff writer at Neural Pulse.