On August 2 it became illegal across the European Union to build a machine that talks to people without telling them it is a machine. Twelve days later, Google shipped a setting that lets you turn the visible watermark off the images, video and music Gemini makes for you.

Europe's AI transparency rules arrived on schedule, and almost nothing a normal person would notice arrived with them. The marking duty that would leave evidence was deferred to December. The one visible mark a large provider had been applying became a preference. And the Commission's own list of who enforces any of this has not been updated since September 2025.

I did not test a single product, because I cannot audit code I do not run. Everything below comes from the law, the Commission's own guidance and pages, the companies' and a national regulator's own documentation and announcements, a few published reports, and one table I counted myself.

Start with the schedule, because the loudest version of this story was that August 2 had been gutted. That comes from the Digital Omnibus on AI, Regulation (EU) 2026/1744, an EU law passed to amend an earlier EU law, in force since July 27. It did push the heavy machinery back, moving the high-risk rules to December 2027 for stand-alone systems and August 2028 for AI built into regulated products. What it did not do was postpone the date Article 50, the transparency chapter, starts applying. The duty to tell you that you are talking to a machine started on time, and for a large company it carries fines of up to 15 million euros or 3 percent of worldwide revenue, whichever is larger.

That was never the advice, only the impression it left. The client alert that put me onto this, filed on May 27, six weeks before the text was adopted, says in its own Key Takeaways that August 2 "remains an active compliance date."

The law is stricter than the little gray disclaimer

Thirteen days before the deadline the Commission published a 51-page set of guidelines on how Article 50 is meant to work, and they are tougher than I expected. Several standard industry habits, they say, do not on their own satisfy the duty to tell you what you are dealing with: a disclosure living "only in terms and conditions, URLs, or documentation"; "generic references to 'assistant'"; and a site-wide line like "Services on this website use AI," which the guidelines name and call insufficient. Separately, and as a recommendation rather than a requirement, they suggest a phone line tell you out loud at the start that you are talking to an AI, with reminders through a long call.

The same document warns against disclosures that produce "habituation effects (so-called 'banner blindness')," so the Commission knows what it is building. Europe has done this before, with cookies. A machine-readable watermark is on that list of insufficient measures too, because it is not "perceivable by users at the point of interaction." But the guidelines add in the very next breath that this "does not affect the appropriateness of such marks to comply with Article 50(2)."

The visible mark was never the tool's job to carry

Here is the distinction that explains the whole thing. Article 50(2) binds the provider, the company that builds the tool and puts it on the market under its own name, and asks for machine-readable marking so output can be detected as artificial. Article 50(4) binds the deployer, whoever publishes a deepfake, and says only that they must "disclose" it. The tool has to leave a fingerprint. The person posting has to put up the sign. That the sign be "clear and distinguishable" comes from Article 50(5).

So when Google added its Media Watermark setting on August 14, announced by Josh Woodward, VP of Google Labs, the Gemini app, and AI Studio, according to Search Engine Journal, it was not skirting the regulation. On the face of the text, the visible mark was never Google's duty to carry. Google's own help page, which I pulled on August 20, is careful about the rest: the setting "only controls the visible watermark," and "All AI-generated media created or edited with Gemini Apps includes an invisible SynthID watermark," alongside C2PA metadata, an open standard that records where a file came from. The fingerprint stays. Only the sign became a preference.

What caught my eye is where the preference is withheld. Google's page says that in India, South Korea and Vietnam you only see the setting at all if you hold an AI Ultra subscription, and that anyone on a work or school account does not get it either. No EU member state appears on that list. So a European can switch the visible AI mark off, and someone in India without an Ultra subscription cannot. Woodward said the toggle would not appear in countries that legally mandate a visible watermark, which is Google's account of its own reasoning rather than a citation to anyone's statute. Three weeks earlier, signing the voluntary code, Google's EU public policy head Karen Massin had warned that "if online content is flooded with overlapping AI labels and legal disclosures, it becomes harder for people to get the clear context they need." There is now one fewer label.

One company committed to marking, and the part you would use is forthcoming

The clearest thing that changed came from Anthropic, reported on August 11, and what changed is a commitment and a page describing it. The support page says Claude models launched in the EU on or after August 2 "will support machine-readable marking at launch," with watermarks woven into generated text and provenance data on files, and that those marks apply "wherever Claude is offered, worldwide." Write a rule for the European market and the rest of the world tends to get it thrown in.

The page is candid that this is a plan in motion rather than a finished job: "Existing models are in progress." On the half that would let anyone verify a file, detection will be supported "as the Code requires, and we'll share details in forthcoming documentation."

That retrofitting is permitted, and it is the deferral that matters. The Omnibus gave providers of generative systems "placed on the market before 2 August 2026" until December 2, 2026 to comply with the marking duty. So every generative product a European was already using got four extra months on the one obligation that produces evidence. Even after that date there is no way to check across providers. Per-provider checking exists, and Google's help page links a tool for verifying Gemini media; what the guidelines concede is that there is no common one, letting each provider run its own detector, "so long as those solutions ensure interoperability with the detection solutions used by other providers," until "a standardised provider-agnostic interoperable detection solution" turns up. The voluntary Code of Practice asks signatories to build one "by 2 February 2027," a promise inside a voluntary code.

The EU also designed a set of icons for AI-generated content, and its own page says deployers "may use" them. The labeling duty is compulsory. The mark is not. There is no one symbol for a European to learn to look for.

The Commission's list of who enforces this has not been updated since September 2025

Enforcement of Article 50 sits mostly with national market surveillance authorities. Member states had to designate them and notify the Commission by August 2, 2025, a full year before the obligations bit, and the Commission publishes the resulting list of single points of contact.

On August 20 I pulled that page and counted the rows. There are 27, one per member state. A dash sits against 19 of them. Only 8 carry the name of an authority, and the page flags 3 of those as still pending final adoption, which leaves 5 settled: Cyprus, Ireland, Italy, Latvia and Lithuania. Then I looked at the footer, which reads "Last update" above the date "26 September 2025." The directory a European is pointed to for who polices this law was last touched ten months before the law started applying.

That staleness cuts both ways, and I want to be fair about it. Germany shows as a dash, and Germany has an authority: the Bundesnetzagentur announced on July 29, in a German-language press release, that a new national law had made it a market surveillance authority, the single point of contact and the central complaints office. Germany split the rest by sector, leaving finance with its financial regulator and media with the state media authorities. None of that is on the Commission's page. So the honest reading is not that 19 countries have nobody. It is that the map is nearly a year out of date, and the map is what a citizen is handed.

About 190 organizations have signed the voluntary code, OpenAI, Google, Meta, Microsoft, Anthropic and Mistral among them. More telling is who took part and then did not sign. The Commission's participant list for the code's two working groups, dated 8 December 2025, includes Adobe, Amazon, Apple, Midjourney, Stability AI and TikTok among others, and none of those six appears on the signatory list I pulled on August 20. The code is voluntary and Article 50 binds them either way, so what that really means is that their methods get judged one at a time, by the authorities the Commission's own page cannot name.

So here is the useful part, and it turned out better than I went in expecting. Article 85 gives any person who has grounds to think the regulation has been broken the right to complain, and you do not have to find your national regulator to use it. The AI Office runs an AI Act complaints tool taking submissions from individuals in any official EU language. It is not anonymous. It is scoped to the systems the AI Office supervises itself, which under Article 75(1) means those where one company built both the underlying general-purpose model and the product sitting on top of it. In practice, the big consumer chatbots.

Know the limit before you use it. Article 50(1) does not apply where being an AI is "obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect," so a help widget labeled as a chatbot is not what this is for. Something that lets you get several turns in while behaving like a person is. The Commission has already written down, in its own guidelines, that a line buried in the terms and a vague "assistant" are not enough. If you meet one of those, the regulator is in Brussels, and it has a form.