112 days until AI Act — Article 50 marking, systems already on the market (EU)
From August 2, the EU AI Act's transparency rules became enforceable. Chatbots must disclose AI interaction, deepfakes need labels, and AI-generated content needs machine-readable marks. The Commission's AI Office opened complaint and whistleblower channels for reporting violations.
Article 50 covers disclosure only. It says nothing about retention or training once a conversation leaves your product for a vendor's model, meaning that vendor's data practices become part of your compliance exposure whether you accounted for them or not.
Fines for missing an AI disclosure run up to €15 million or 3% of global turnover, whichever is higher.
In brief
AI Office Opens Complaint and Whistleblower Channels (EU)
The AI Office's Complaint Tool lets anyone report alleged violations by providers or deployers under Article 85, but only within its exclusive competence — other EU or national law claims go elsewhere. Downstream providers report GPAI documentation or copyright failures through a separate Article 89(2) channel. A Whistleblower Tool covers internal reports. The EU AI Act Newsletter
Youth AI Privacy Act Clears Committee, Weaker (US)
The Senate Commerce Committee advanced the Youth AI Privacy Act, which would limit manipulative chatbot design, ban advertising to minors through AI chatbots, and restrict using minors' data for model training. Markup removed the bill's private right of action, so enforcement would run through regulators, not individual lawsuits. EPIC
Court Says Addictive Feeds Aren't Free Speech (US-CA)
A district court ruled that TikTok, Meta, and Google's engagement-maximizing feed features are not First Amendment speech, rejecting their challenge to California's SB 976. The court called the feeds 'a mirror' reflecting users' own interests, not expression — weakening a defense tech companies use against algorithmic design rules. EPIC
The Arsenal
AI Act Implementation Timeline Infographic
FPF's updated infographic maps every AI Act milestone against the Omnibus's revised dates — high-risk obligations now due December 2027 (Annex III) and August 2028 (Annex I). Useful when you need to verify a deadline claim against the current text. Future of Privacy Forum
Mini-Playbook: The Vendor Data Audit
For your team: Privacy lead or whoever signs AI vendor contracts.
Forward this to whoever signs your AI vendor contracts.
Article 50 requires disclosure, not retention limits. If your product routes conversations through a third-party model, that vendor's training and retention defaults become your exposure — check them now.
Step 1: Find the default
Pull the privacy policy for every third-party model your product calls. Stanford HAI's review of six major US AI developers found every one used customer chat data for training by default, with some retaining it indefinitely. Confirm whether your vendor is one of them, and what its default actually is.
Step 2: Test the opt-out
An opt-out toggle doesn't always stop retention. Google keeps Gemini conversations reviewed by human annotators for up to three years even after a user turns off Gemini Apps Activity — once flagged for review, the conversation sits on a separate track. Ask your vendor the same question in writing.
Step 3: Check the opt-out's reach
Some opt-outs only cover certain users. Character.AI trained on conversations by default and offered an opt-out only to users in the EEA and UK. If your user base spans regions, confirm the opt-out actually applies to all of them, not just the jurisdiction that demanded it.
The outcome: You'll end with a one-page record of what each vendor does with conversation data and where the opt-out breaks down. Use it to decide whether to renegotiate terms or disclose the gap to users.
Deadline Radar
Date | Where | What you must do |
|---|---|---|
2026-08-02 | EU | AI Act — Article 50, penalties, GPAI enforcement — In force. Transparency duties apply (label AI interaction, mark synthetic content, disclose deepfakes), the penalty regime applies, and the AI Office can demand information, evaluate models, order mitigations, and fine GPAI providers. |
2026-08-02 | US-CA | California AI Transparency Act (SB 942) — Operative now. Covered generative AI providers must offer a free AI-detection tool and apply latent and manifest disclosures to AI-generated content. |
2026-12-02 | EU | AI Act — Article 50 marking, systems already on the market — AI systems placed on the market before 2 August 2026 must comply with the machine-readable marking obligations from this date. This is the grace period for existing products, and it is the next hard EU deadline. |
2027-01-01 | US-CA | California AI Transparency Act (SB 942) — platform duties — Large online platforms must detect provenance data on uploaded content and label it as AI-generated where the data is present. |
Next steps
Confirm your chatbot displays an AI disclosure before December's marking deadline hits legacy systems.
Request each AI vendor's written training and retention policy this week.
Check whether your vendor's opt-out applies to every region you operate in.
Operator note
My read: the labeling rule got the headlines because it's visible, but it's the shallower risk. Getting Article 50 disclosure wrong is a fixable bug. Not knowing that your chatbot vendor trains on every conversation by default is a standing liability you inherit silently. If I owned this, I'd audit vendor contracts before I touched another label.
If your team just finished a labeling sprint and hasn't looked at what your model vendor does with the conversations underneath it, you're not alone. Reply and tell us which vendor's terms you're stuck untangling.
Next issue: Next: does the Youth AI Privacy Act's training-data ban survive full Senate markup intact?
P.S. A disclosure banner and a data retention policy are two different compliance problems; treat them separately.
Not legal advice — this brief summarizes public sources so you can act on them; verify against the primary text before you rely on it. Researched and drafted with AI, human-reviewed before publishing.
