This website uses cookies

Read our Privacy policy and Terms of use for more information.

Sponsored by

A quick note: this is the first of four summer editions prepared in advance — one essay, one thesis each, back to the regular multi-story format in late August. The next three are a Build Lab series on the governed AI stack: agent patterns, MCP infrastructure, and the governance hub.

On Sunday, August 2, the EU AI Act stops being a preparation exercise and becomes an administered regime. Two things switch on: the Commission's enforcement powers over general-purpose AI models, and the Article 50 transparency obligations that reach every AI system that talks to people or generates content. Most commentary will frame Sunday as a cliff. It is better understood as a change of tense — from "will apply" to "applies" — whose practical consequences arrive not as a wave of dawn raids but as a slow, permanent shift in who can ask you questions and what happens when you cannot answer them.

This essay is the one-page version of everything this newsletter has covered since May, arranged for the day itself: what becomes true on Sunday, what pointedly does not, what the first weeks will actually look like, and the five questions your organisation should be able to answer from a single folder.

Save 10+ Hours a Week With 37 Claude Prompts

Every manager faces the same situations before lunch: a message to land, a meeting to run, a hiring call, a report due. The AI Report built 37 Claude prompts for exactly those moments, organised by the situations every manager faces. 

Copy the prompt, fill the brackets, run it in Claude, and get back 10+ hours a week. Oh, and it's free. 

All you have to do is subscribe to The AI Report, a 5-minute daily AI brief read by 400,000+ business leaders at IBM, AWS and Microsoft, and the full prompt pack lands in your welcome email. The newsletter and the prompts, both free. Subscribe and grab both

What Becomes True on Sunday

The Commission can now enforce against GPAI providers. The obligations for general-purpose AI models have applied since August 2025; what arrives Sunday is the machinery — the AI Office can request documentation, conduct evaluations, require mitigation measures, order market restrictions, and impose fines up to 3% of global annual turnover or €15 million under Article 101. The one-year grace between obligation and enforcement is over.

Article 50 transparency applies — to almost everyone. Systems that interact with people must disclose it (50(1)). Generative systems must mark outputs machine-readably (50(2)). Deployers of emotion recognition and biometric categorisation must inform the people exposed (50(3)). Deepfakes and AI-generated public-interest text must be disclosed (50(4)). These are horizontal duties: they do not care whether your system is "high-risk," and non-compliance sits in the middle penalty band — up to €15 million or 3% of turnover. Unlike a documentation gap, an Article 50 failure is visible to any user, journalist, or competitor.

The transparency Code of Practice is the recognised route. The marking Code published in June — two layers: signed provenance metadata plus imperceptible watermarking, including free-form text above roughly 200 tokens — is the acknowledged way to demonstrate 50(2) compliance. The signatory window for the initial list closed Monday evening (July 27, 18:00 CEST); the Commission publishes that first list before Sunday, and it becomes a public procurement signal the moment it appears — check it for your vendors, and expect to be checked against it yourself.

And the final guidelines are here. The missing piece landed on July 20: the Commission adopted its final Guidelines on Article 50 transparency obligations — 51 pages clarifying scope, the provider/deployer split, and how the disclosure duties operate in practice. Non-binding, but this is the interpretive document authorities and complainants will both read. If your disclosure decisions were built to the draft, the task this week is a same-week re-read against the final text — it is precisely the kind of dated, minuted review that belongs in the folder below.

Downstream diligence rights are now enforceable-adjacent. Article 53(1)(b) and Annex XII entitle every enterprise integrating a GPAI model to a defined information package — and for Code-signatory providers, a 14-calendar-day response expectation on reasoned requests. From Sunday, the regime behind those rights has teeth. If you sent your diligence requests in July, your paper trail predates enforcement — the strongest position available.

What Does Not Happen on Sunday

Precision about what is not arriving matters as much, because over-reaction wastes the budget under-reaction squanders.

High-risk obligations do not apply. The Omnibus moved them: December 2027 for stand-alone Annex III systems, August 2028 for AI embedded in regulated products. Your classification work should be underway; your conformity assessment is not due Sunday.

Pre-existing generative systems keep the marking grace. Systems on the market before August 2 have until December 2 for machine-readable marking specifically — everything else applies now. Systems launched from Sunday onward get no grace at all.

No dawn raids. Day-one enforcement it is the beginning of complaint-driven, evidence-request-driven administration. Which is the real point.

What Day One Actually Looks Like

The first weeks of any new EU regime follow a pattern: complaints arrive from users, competitors, and civil-society groups; authorities send information requests to the most visible or most complained-about actors; and the earliest cases become the worked examples everyone else studies for years. You do not want to be a worked example.

The question a first letter asks is never "are you perfect?" It is: who is accountable for this system, what obligations did you determine apply, and what have you done about them? That question is answered from a folder, not a programme. If the last month's sprint happened — owners named, systems mapped, requests sent, disclosures decided, decisions minuted and dated — the letter is an administrative task. If it did not, the letter is a crisis, because assembling six weeks of evidence under a deadline, in August, is how bad worked examples get made.

The same folder now has a second audience. Enterprise buyers were asking for governance evidence before the deadline; from Sunday, "are you Article 50 compliant?" becomes a one-line question in every serious procurement. The folder answers both.

The Five Questions — Answer Them From One Folder

  1. Who is accountable for each AI system we run? → the owner list.

  2. Which of our systems carry Article 50 duties, and which bucket — pre- or post-August 2? → the system map.

  3. How do our generative systems mark their outputs, and by when? → the marking plan (Code method, December 2 dates for legacy systems).

  4. What do we know about the models we build on? → the Annex XII requests and responses, dated.

  5. What happens if a model we depend on disappears? → the continuity scenario and tested fallback.

If all five have answers, Sunday is a date. If two or more are blank, the gap itself is your finding — and the returning-from-summer priority list writes itself.

The Playbook (Condensed)

  1. This week: assemble the folder — one index, every artifact dated. Completeness is not the standard; organised, attributable effort is.

  2. Legal: pre-draft the response skeleton for an information request now, calm and in advance, not in the 48 hours after one arrives.

  3. Comms: prepare the two-sentence answer to "are you AI Act compliant?" for sales and press. Vague confidence reads worse than specific candour.

  4. Everyone: put December 2 in the calendar now — the legacy-system marking deadline is the next cliff, and it is closer than it feels from a beach.

Next Steps

What to Watch (While I'm Away)

  • The first information requests and complaints — who receives them and on what grounds sets the enforcement tone for the year.

  • The initial Transparency Code signatory list — the window closed Monday; the Commission publishes the first list before Sunday. Read it for your vendors' names, then expect it in RFPs by autumn.

  • Your Article 50 re-read — the final guidelines landed July 20; if the disclosure re-read against the final text hasn't happened yet, it is the one task that should not wait for September.

  • The OpenAI–Hugging Face post-mortems — last week's containment breach (covered in the July 23 edition) is now generating the first formal analyses, including CISO guidance from the Cloud Security Alliance. The joint technical post-mortem, when it lands, defines the reference threat model for agentic containment. Read it from the beach if you must.

  • December 2 — the marking grace expires for pre-existing systems.

That’s it for this week.

The next three Thursdays are the Summer Build Lab: the governed AI stack from the ground up — how multi-agent patterns distribute accountability, whether your MCP layer should be shared or dedicated, and the reference architecture for an AI governance hub. Written in advance, built to be used. See you in the replies in late August.

Until next Thursday, João

OnAbout.AI delivers strategic AI analysis to enterprise technology leaders. European governance lens. Vendor-agnostic. Actionable.

If this landed in your inbox from a forward — subscribe here to get the full picture every week.

Keep Reading