The AI Act's Transparency Duty Just Went Live — Here's What Actually Changed
Plus: Nvidia and 30+ tech firms launch a security alliance after the OpenAI-Hugging Face breach — pointedly without OpenAI, Google or Anthropic — and Elon Musk's xAI sues Minnesota over the first state law banning AI "nudification" apps.
Here's what mattered most to me this week — after three issues tracking the countdown, 2 August arrived. The EU AI Act's Article 50 transparency duties and the Commission's enforcement powers over general-purpose AI models with systemic risk are now live: national market surveillance authorities can investigate and sanction breaches, and the AI Office can fine GPAI providers up to €15m or 3% of global turnover. The high-risk regime is still deferred to December 2027 — that's the only part of the timeline that moved. If your organisation hasn't yet worked out which of its systems need to disclose they're AI, this is the week to do it, not the week to relax because you heard "AI Act delay" somewhere. Also in this issue: the security-alliance fallout from last week's OpenAI/Hugging Face story, and a brand-new state AI law already in court before its ink is dry.
Or jump to: this week's workshop · the Article 50 & GPAI applicability interview
This Week's Reading
This is no longer a compliance calendar entry — it's live law. If you haven't already inventoried which of your organisation's chatbots, content tools and copilots need a disclosure, that's now overdue rather than upcoming. For every GPAI vendor sitting under those tools, ask directly whether they've been classified as systemic risk and how they'd respond to an Article 55 information request.
If your incident response plan assumes you can point any AI tool at a live security investigation, this incident says otherwise. Closed-model guardrails can block the very forensic work you need most during a breach. Ask your security team whether your incident response tooling has been tested against exactly this failure mode, not just against the attack itself.
Whatever happens in court, the exposure math is the real lesson. Per-violation state penalties can compound into existential numbers far faster than a typical liability cap anticipates. If your organisation offers or embeds any content-generation feature, check now whether your terms of use, technical safeguards and indemnities would actually hold up against a per-image, per-state penalty regime like this one — not just a generic IP or defamation claim.
This Week's Workshop
Does the AI Act Actually Apply to You?
Now that Article 50's transparency duties and the Commission's GPAI enforcement powers are live, the real question for most in-house teams isn't "is the AI Act delayed?" — it's "which of these four duties actually bite on what we're doing, and does anything need to change?" This week's workshop walks through the interactive prompt below live: interrogating a real (anonymised) set of AI tools against each Article 50 trigger and the Article 53/55 GPAI thresholds, to show what an honest applicability answer looks like — including the cases where the honest answer is "this sits with your vendor, not you."
Agent Builder Course — Five Days, One Hour a Day
Learn to build, deploy and continuously improve AI agents for your legal team's hardest recurring work — contract triage, due diligence, document assembly, compliance monitoring. No coding required. Works with any LLM, including Microsoft Copilot. Spaces are limited.
More details and booking here →
Book a CallCopy-Paste Ready: The Article 50 & GPAI Applicability Interview
Use this to work out, in plain terms, whether the AI Act's Article 50 transparency duties and the Article 53/55 general-purpose AI (GPAI) obligations actually apply to what your organisation is doing — and if so, what needs to change. It interviews you across your interactive AI systems, synthetic content, emotion recognition/biometric tools, deepfakes and public-interest text, and your GPAI model status, with the legal basis for each question built in. Paste the whole thing into Claude, ChatGPT, or any LLM and answer one question at a time. It's a long, structured prompt, so it's saved as a document rather than run inline here:
The prompt ends with a reminder that this is an indicative, first-pass check based on your own answers — not legal advice. Speak to a lawyer about how the AI Act applies to your organisation's specific circumstances.
Want More Prompts & Workflows?
For prompts and more detailed workflows like this one, take a look at our book on AI for legal professionals. Explore step-by-step guides, ready-to-use prompts, and best practices for integrating AI safely into your legal work.
Explore the Book →Until next Monday,
— Richard Nicholas
Got a story I should cover, or a question about something here? Just hit reply — I read every one. (Received this one secondhand? Reach me directly at [email protected].)
Get This Newsletter Every Week
Curated AI and legal governance news, a copy-paste prompt, and a practical workshop — delivered free to in-house counsel every Monday.
Get Next Monday's Issue →