Published on · 7 min read
Europe regulates the AI it doesn't build
On Sunday, the machines that talk to us have to admit they are machines. That is roughly all the AI Act delivers, because the hard part slipped to 2027.
August 2, 2026 was supposed to be the day Europe's AI regulation stopped promising things and started requiring them. It lands on Sunday, and it lands light, because Parliament and then the Council voted in June to push the heavy obligations back sixteen months. What actually takes effect fits inside a single article, number 50, and its ambition amounts to basic manners, knowing who you are talking to.

On Sunday, machines have to introduce themselves
Article 50 covers transparency and applies to every system, whatever its risk level. A chatbot has to tell you it isn't human, unless that much is obvious. Audio, images, video and text produced or altered by a machine have to carry a machine-readable mark, where technically feasible. Deepfakes have to say so. Anyone put through emotion recognition or biometric categorization has to be told. And AI-generated text published to inform the public on a matter of public interest has to disclose where it came from, unless a human reviewed it and took editorial responsibility for it[1].
Missing any of that runs to 15 million euros or 3 percent of worldwide annual turnover, whichever hurts more[2]. It isn't the revolution the calendar promised, but it isn't nothing either, because "I am a machine" heads off a startling number of misunderstandings before they start.
The hard part waits until December 2027
The rest of the text, and by far the heavier half, just slid. The package known as the Digital Omnibus, sold as simplification, was agreed between Council and Parliament overnight on May 6, cleared Parliament on June 16, and got the Council's final sign-off on June 29[3]. So the Annex III high-risk systems, the ones that screen job applications, grant credit, grade students or watch critical infrastructure, won't be covered until December 2, 2027. The ones buried inside already-regulated products, medical devices, machinery and toys, wait until August 2, 2028.
I should be outraged and I can't manage it, because the reason holds up. The harmonized standards from CEN-CENELEC, the documents meant to spell out how you actually prove compliance on risk management, data quality and human oversight, won't be ready. First drafts went out for public consultation in November 2025 and final adoption isn't expected before the second half of 2027[4]. It's hard to hold a company to a rule when nobody has finished writing the instructions. Europe simply admitted it had scheduled the exam before writing the syllabus.
Nobody has ever mentioned it to me
Here is the detail that struck me hardest while I put this together. I advise on and run digital projects, I spend my days inside tools stuffed with AI, enough to build my own, and nobody has ever said the name of this regulation in front of me. Not in a kickoff, not in a memo, not from a lawyer worried about the assistant we were about to install. The most discussed piece of European law since the GDPR has never made it through the door of a project I run.
The French state didn't do much better. Every country was supposed to name its market surveillance authorities by August 2, 2025. France let the date pass and was still, five months later, among the countries that had officially named nobody[5]. It took until February 17, 2026 for the Senate to approve the text making the CNIL the lead authority, flanked by roughly fifteen sector regulators carved up by domain, consumer protection, broadcasting, banking, drugs and health technology[6]. That same August 2, 2026 also requires every member state to open a regulatory sandbox, the supervised space where you test an AI under the regulator's eye before turning it loose[7].
The CNIL has since put AI on its 2026 inspection program[8], so the subject will reach people's desks eventually, mine included. Until then, Sunday's compliance work comes down to two moves for most organizations, inventory the AI that talks to people or makes content, then write an honest sentence at the top of the chatbot. I have watched website redesigns burn more energy picking a shade of blue.
Meanwhile, Microsoft is renting French GPUs
On July 21, Mistral AI and Microsoft announced a multibillion-dollar deal. The easy story was the American buying the French company. What happened is the reverse, because Microsoft is renting compute from Mistral's European data centers, with no new equity stake, to serve customers on the continent who insist their data stays home[9]. Mistral is standing up thousands of NVIDIA Vera Rubin GPUs for it and placing its models in Azure, Foundry and Copilot Studio, while a funding round in the works reportedly targets a valuation near 20 billion euros[10].
Sovereignty is now a service, billed by the compute-hour, bought by Microsoft from a Paris company and resold to Europeans. You can call that a French win and you wouldn't be wrong. You can also read it the way I do, that the value sits in the machines and the models, never in the articles of a regulation.
The contrast with the Brussels calendar is a little cruel. In June, an imaginary Mistral model set the networks on fire for a whole weekend, purely because we want a European AI that can compete. Days earlier, Washington had cut off access to Anthropic's two best models for every foreign national, a useful reminder of who holds the handle. In between, Europe writes rules, and at that scale rules are about all it ships.
I still prefer this Europe to the one that would have written nothing at all. A continent that starts from the principle that you are entitled to know whether you are talking to a machine defends something Washington and Beijing will never defend on its behalf. It just has to start building what it governs, or its rules will mostly apply to products made somewhere else.
So on Sunday the machines will say their names. Most of them already did, which tells you the law arrived after the habit rather than before it. See you on December 2, 2027 for the serious half, three model generations later, with a regulation that has hopefully learned to run as fast as the thing it regulates.
The obligations are set out in Article 50 of the regulation, also available on the European Commission's AI Act Service Desk. ↩︎
Article 99 sets three ceilings, 35 million euros or 7 percent of turnover for prohibited practices, 15 million or 3 percent for breaches of provider and deployer obligations including Article 50, and 7.5 million or 1 percent for misleading information given to authorities. ↩︎
Gibson Dunn, "EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes". The European Parliament tracks the file on its Legislative Train Schedule. ↩︎
CEN-CENELEC joint technical committee JTC 21 owns the harmonized standards that make the regulation workable. August Debouzy covers the timeline in its analysis of the Digital Omnibus (in French). ↩︎
Amélie Favreau, MIAI, "EU AI Act Implementation: France Still Without Designated National Competent Authorities", January 20, 2026. ↩︎
Leto breaks down the split between the CNIL and the sector regulators, and Banque des Territoires covers the Senate vote in "Le Sénat valide une régulation de l'IA en mode puzzle" (both in French). ↩︎
Article 57 requires every member state to have at least one operational regulatory sandbox by August 2, 2026. ↩︎
IT Social, "Conformité IA, les chantiers que la CNIL inscrit au programme de ses contrôles 2026" (in French). ↩︎
Microsoft, "Microsoft and Mistral AI deepen strategic partnership", July 21, 2026. ↩︎
Maddyness, "Mistral AI signe un accord de plusieurs milliards de dollars avec Microsoft", July 21, 2026, and L'Usine digitale, "Pourquoi Microsoft fait aujourd'hui appel aux data centers de Mistral AI" (both in French). ↩︎