The EU Artificial Intelligence Act moves forward: new obligations for companies and providers
The European Union’s Artificial Intelligence Regulation (AI Act) continues its gradual implementation, with new obligations coming into force for companies and organizations that develop, market, or use AI systems. This new phase strengthens transparency, establishes requirements for general-purpose artificial intelligence models, and bans certain practices considered particularly harmful. Understanding these developments is essential for organizations to anticipate changes, comply with the regulation, and take advantage of the opportunities offered by safer and more trustworthy artificial intelligence.
The application of the European Artificial Intelligence Regulation, known as the AI Act, continues to move forward. As of 2 August 2026, new obligations relating to the transparency of AI systems and the supervision of general-purpose artificial intelligence models will begin to apply.
European legislation establishes a common framework to ensure that artificial intelligence is developed and used safely, transparently and in accordance with fundamental rights. Its application will be progressive and will affect providers, developers, companies using AI and public bodies.
Greater transparency in the use of artificial intelligence
One of the main new developments in this phase is the application of the transparency obligations set out in the Regulation. From now on, certain systems will be required to:
- Inform people when they are interacting with an artificial intelligence system.
- Identify content generated or modified using AI.
- Incorporate mechanisms that make it possible to detect synthetic content, such as images, videos or audio.
- Properly label manipulated or artificially generated content, including what are known as deepfakes.
These measures seek to reduce the risks of deception, manipulation and disinformation, and make it easier for citizens to make more informed decisions about the origin of content and the nature of digital interactions.
The specific obligations must be applied taking into account the type of system, its purpose and the associated level of risk. In addition, the technical solutions used to identify AI-generated content will need to evolve to ensure effective and reliable detection.
Supervision of general-purpose AI models
This new period of application also strengthens the supervision of general-purpose artificial intelligence models, such as those that serve as the basis for tools capable of performing multiple tasks and that are integrated into different products and services. Some of the best-known examples include GPT, developed by OpenAI; Gemini, by Google; Claude, by Anthropic; and Llama, by Meta. These models are used as underlying technology in conversational assistants, content-generation tools and numerous business solutions.
The obligations for providers of these models include:
- Prepare and maintain technical documentation on the models.
- Provide information to the competent authorities and to other providers that integrate these models.
- Have policies in place to comply with copyright legislation.
- Publish sufficiently detailed summaries of the content used to train the models.
- Adopt additional measures when dealing with models that pose systemic risk.
Models considered to pose systemic risk are those that, due to their capabilities and scope, could cause large-scale harm. The risks covered include those related to cybersecurity, the manipulation of people, the loss of control over systems and potential violations of fundamental rights.
Certain AI practices are prohibited
The Regulation also prohibits certain practices considered particularly harmful, such as systems intended to manipulate people’s behaviour, exploit the vulnerabilities of certain groups or carry out unjustified assessments that could affect citizens’ rights.
Compliance supervision will be distributed among different authorities. The European AI Office will assume responsibility for certain categories of systems and general-purpose models, while national authorities will supervise a large part of the applications deployed in each Member State.
In Spain, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) plays a central role as the competent national authority, in coordination with other bodies depending on the scope of application of each system. Authorities such as the Spanish Data Protection Agency, the General Council of the Judiciary or the Central Electoral Board may also become involved.
A progressive implementation
The application of the AI Act will continue to develop progressively over the coming years. Although most of its provisions will already be in force from August 2026, certain specific obligations will be introduced in stages. In December 2026, new prohibitions relating to certain unlawful synthetic content will begin to apply, such as non-consensual sexual deepfakes or child sexual abuse material. Subsequently, the obligations for certain high-risk AI systems will begin to apply from December 2027, while those relating to high-risk systems integrated into regulated products will be extended until August 2028.
For companies, especially SMEs, this means the need to understand which obligations apply to them, review how they use artificial intelligence and establish control, documentation and supervision procedures.
Regulatory compliance should not be understood solely as an obligation, but also as an opportunity to strengthen the trust of customers and users, improve risk management and differentiate themselves in the market by developing more responsible and secure AI solutions.
If you would like to learn more about the scope of this regulation and understand how it may affect your organisation, we recommend consulting the content available on ONE. In Key aspects of the Artificial Intelligence Regulation, you will find a guide to the principles, obligations and scope of application of the AI Act. You can also consult Do you know about the new Artificial Intelligence Act?, which explains the key features of the new European regulatory framework and its main implications.
You can also access the webinar AI Act: how to turn regulation into a competitive advantage, in which several experts analyse the main challenges and opportunities that this legislation presents for companies and entrepreneurs.
AI regulation is no longer a matter for the future. With these new measures coming into application, understanding the AI Act becomes a fundamental step towards harnessing the potential of artificial intelligence in a safe, responsible and competitive way.