# EU AI Act, August 2, 2026: GPAI Enforcement and Article 50 Transparency Go Live

> Source: https://sukruyusufkaya.com/en/blog/eu-ai-act-gpai-yaptirim-madde-50-seffaflik-2026
> Updated: 2026-08-05T01:47:02.437Z
> Type: blog
> Category: yapay-zeka
**TLDR:** As of August 2, 2026 the EU AI Act GPAI enforcement powers and Article 50 transparency rules are live. What changed for Turkish firms, who is in scope, and a 90-day action list.

**TL;DR —** August 2, 2026 is the day AI regulation shifted from "rules on paper" to "supervision and fines." The EU AI Act's enforcement powers for general-purpose AI (GPAI) models went live: the AI Office inside the European Commission can now demand documentation, run technical evaluations, restrict or withdraw a model from the market, and issue fines of up to 3% of global annual turnover or €15 million, whichever is higher. The same day, Article 50 transparency obligations took effect: chatbots must identify themselves as AI at the start of an interaction, and generated content must carry machine-readable labels. For companies based in Turkey but serving Europe, this is not a "doesn't concern me" topic. This piece explains what changed, who is in scope, the concrete obligations of GPAI providers, and a step-by-step 90-day action list.

## What exactly happened on August 2, 2026?

A sentence I hear constantly in the field: "Didn't the AI Act pass back in 2024 — what's new?" It did pass; but there is a serious difference between a law's text being published and that law actually binding you. The EU AI Act enters into force on a staggered timeline. The substantive obligations for GPAI models had in fact applied since August 2, 2025 — technical documentation, training-data summaries, extra evaluation for systemic-risk models had all been written for a year. But the AI Office's powers to enforce these obligations were deliberately suspended for a year, to give both providers and the regulator operational breathing room.

That one-year grace period ended on August 2, 2026. The AI Office can now formally open investigations, run technical evaluations, demand compliance and risk-mitigation measures, and if needed restrict or withdraw a model from the European market. In other words: the rule did not change, the power behind the rule did. To borrow a field analogy — the traffic rules had been posted for a year but the radar was off; on August 2 the radar switched on. And once the radar is on, "we didn't know about this" is no longer a legal defense.

There is also a psychological dimension to the timing. While a regulation lacks enforcement, most companies push the work to "next quarter." When the enforcement date arrives, everyone suddenly tries to move in the same week, consultants fill up, legal teams drown. That is why the smartest move is to be ahead of the wave, not behind it.

## Fines: why the numbers matter so much

The ceiling for breaching GPAI obligations is 3% of global annual turnover or €15 million, whichever is higher. Let that sink in for a moment. For prohibited practices (e.g. social scoring, subliminal manipulation, emotion recognition in the workplace) the ceiling is even higher: up to 7% of turnover or €35 million. High-risk system breaches sit in the 3% / €15 million band. Even providing incorrect or misleading information to the authority is a separate penalty item.

Why do I dwell on this? Because we know from the GDPR experience that turnover-based penalties move compliance off the legal department's desk and onto the board agenda. A 3% fine can wipe out an entire year's net profit for most companies. Once the CFO and CEO see that picture, the budget for AI governance is suddenly taken seriously. In other words, enforcement power is not merely a legal matter; it is a lever that changes resource allocation and prioritization.

> The cost of compliance is always cheaper than the cost of a breach; the problem is that the compliance cost is visible today, while the breach cost sits in an uncertain future. Activating enforcement powers turns that "uncertain future" into "the next audit cycle."

## The concrete obligations of GPAI providers

So if you place a GPAI model on the European market, what concretely must you do? There are four main headings. First, technical documentation: documents on the model's architecture, training process, capabilities and limitations, prepared both for the authority and for downstream developers who integrate the model. Second, a copyright policy: a written policy that complies with EU copyright law, particularly the text-and-data-mining exceptions. Third, a training-data summary: a sufficiently detailed public summary of the content used to train the model, following the template published by the AI Office. Fourth, downstream transparency: sharing the information developers need to ensure their own compliance.

The practical way to operationalize these obligations is to join the General-Purpose AI Code of Practice coordinated by the AI Office. These voluntary rules provide a concrete path to compliance and give signatory providers a more predictable footing in supervision. Not signing is not an offense, but then proving compliance another way is up to you — which is usually more laborious.

## Systemic-risk models: an added burden

Not all GPAI models are in the same basket. Models that exceed a certain compute threshold (measured by total training compute) or are classified as such by the AI Office fall into the "systemic risk" category. These carry additional obligations: state-of-the-art model evaluation and adversarial testing (red-teaming), documenting and mitigating systemic risks, reporting serious incidents to the AI Office, and adequate cybersecurity protection.

Most companies in Turkey may not be building a "systemic-risk foundation model"; you are most likely on the side using these models. But knowing this distinction matters, because which category your supplier falls into determines the documentation and guarantees you can demand from them. When integrating a model, asking the provider for a "compliance with AI Act GPAI obligations" commitment should now be a standard clause in contract negotiations.

## Article 50: transparency is no longer optional

The second big headline of August 2 is the Article 50 transparency obligations. Because this article touches products in direct contact with end users, it is where technical teams must act fastest. There are three core requirements.

First, AI systems that interact directly with people — chatbots, voice assistants — must clearly tell the user they are talking to an AI. Cases where it is "obviously apparent" are exempt, but in practice adding an opening disclosure is the safest path for most products. Second, AI-generated or manipulated image, audio, and video content — including deepfakes — must be marked in a machine-readable format. This explains why watermarking and content-credential (C2PA-like) standards gained so much weight this year. Third, similar disclosure obligations extend to AI-generated text published on matters of public interest.

Picture this: if your customer-service chatbot does not identify itself before the user asks "are you human?", that is now a compliance gap. The good news is that meeting this article is technically the easiest job; the bad news is that it is also the most visible in an audit. Before an inspector examines your complex model documentation, they open your chatbot and look at whether the first screen shows a notice.

### What Article 50 means in practice

| Product component | Old state | After August 2, 2026 |
|---|---|---|
| Customer chatbot | Disclosure optional | "AI assistant" notice required at start |
| Generated image/video | Labeling discretionary | Machine-readable label required |
| Voice assistant | No audio warning | Must disclose it is AI |
| Automated content generation | No disclosure | Disclosure for public-facing content |
| Deepfake content | Unrestricted | Marking and disclosure required |

## Who is in scope? "I'm based in Turkey" is no excuse

This is the most misunderstood point. The scope of the EU AI Act is determined not by where you are established, but by whether your output is used in the European Union — just like the GDPR. So if you are a SaaS company in Istanbul and your product is used by a German customer's employees, you are in scope. If you place a GPAI model on the European market you are a provider; if you use someone else's model inside your product you are a deployer, and each role carries separate obligations.

For Turkish exporters — especially tech firms selling software and services into Europe — the practical consequence is this: "AI Act compliance" is becoming a supplier-evaluation criterion in customer contracts. To protect its own compliance chain, the European buyer will ask you for documentation, transparency commitments, and a risk classification. So even if the penalty risk does not land directly on you, commercial pressure arrives through the supply chain. Picture a Turkish fintech selling software to a European bank: the buyer's procurement team cannot get the contract past legal approval without your compliance documentation. That is exactly the moment regulation turns into commercial reality.

## Five common mistakes

I hear the same misunderstandings repeatedly in the field, so let's correct them briefly. First mistake: "We only use a ready-made model, the obligation is on the provider." Partly true; but as a deployer you also have transparency and intended-use obligations. Second mistake: "We're a small company, we're exempt." There are some reliefs for SMEs but no full exemption. Third mistake: "Our model is open source, we're out of scope." There are some exceptions for open-source models, but they do not apply to systemic-risk models or to Article 50.

Fourth mistake: "Writing one line 'this is an AI' on the chatbot finishes the job." The transparency article is a start; the real burden is documentation and governance in high-risk uses. Fifth mistake: "Enforcement targets big American companies, not us." The AI Office's first targets may be large providers, but supply-chain audits and European customers' contract demands quickly spread the pressure to small suppliers too.

## An e-commerce scenario, end to end

Let's make it concrete. Say you are a Turkish e-commerce company that also sells into Europe, and your site has three AI components: a product-recommendation chatbot, AI-generated product images, and automatically written product descriptions. After August 2, what must you do for each?

For the chatbot: a clear "you are talking to an AI assistant" disclosure at the start and a handoff-to-human option. For the generated images: a machine-readable content-credential label and, if a real person's likeness is processed, disclosure under both the AI Act and the Turkish advertising rules that took effect on August 1. For the automatic descriptions: avoiding misleading claims and, where relevant, indicating they are AI-generated. And all of this must be recorded in an inventory, with a named owner and a review cycle. As you can see, it is not a single "compliance project"; it is a way of working baked into the product's DNA.

## Measurement: how do you track compliance?

The cliché "you can't manage what you can't measure" applies here too. You should treat compliance not as a one-off project but as a continuously monitored state. I recommend tracking: what percentage of AI systems in the inventory are risk-classified, what percentage have current technical documentation, what percentage of surfaces requiring Article 50 have the disclosure implemented, what percentage of suppliers have provided a compliance commitment, and whether a serious-incident reporting process is defined. These few metrics show your compliance maturity to the board on a single slide.

## This picture is actually an opportunity

The most consistent pattern I have seen across years of working with organizations: the gap between companies that see regulation as a cost center and those that see it as a trust advantage turns, within a few years, into a measurable difference in market share. When a European buyer chooses between two suppliers and one says "I can document AI Act compliance, my transparency commitment is ready, my audit trail is complete," while the other says "we haven't looked yet" — it is clear who wins the contract.

August 2, 2026 is not merely an enforcement date; it is the name of the threshold that turns trust in AI into a commercial differentiator. If you start building your inventory this week, implementing the Article 50 quick wins this month, and demanding supplier commitments in your next contract cycle, you will enter the next audit cycle prepared — and may even turn it into a sales argument. The regulatory wave is coming; the difference between getting on the surfboard and being caught under the wave is hidden in the steps you take today.