The next major European Union AI Act milestone arrives on August 2, 2026. For U.S. companies, this is not simply a European legal-development story. It is a product, vendor, communications, and governance deadline that may affect organizations offering AI-enabled services to people in the EU or placing AI-generated content into European markets.

The European Commission added practical detail on June 10, 2026, when it published the final voluntary Code of Practice on marking and labelling AI-generated content. The Commission presents the Code as a way for providers and deployers of generative AI systems to prepare for transparency obligations applying from August 2.

The Commission specifically highlights disclosures for interactive AI systems such as chatbots, clear labelling for deepfakes, and labelling of certain AI-generated or AI-manipulated text published to inform the public on matters of public interest.

Every company should obtain legal advice about its specific obligations, territorial exposure, and role under the regulation. But businesses do not need to wait for a final legal memo before completing the operational work that supports readiness. They can identify where AI appears, determine who is affected, document vendor responsibilities, test disclosures, and preserve evidence showing that controls operate as intended.

Why the August 2 Deadline Matters to U.S. Companies

The AI Act is a European Union regulation, but digital products and services rarely remain within one jurisdiction. A U.S. software company may serve customers in Europe, make an application available to EU users, embed a third-party AI model in a global product, or publish AI-generated material that reaches European audiences.

The first step is not to assume that every U.S. organization is covered. The first step is to determine whether the company’s activities, users, distribution, and contractual relationships create relevant EU exposure.

That analysis should include more than the headquarters address. Product teams should identify where users are located, how AI-enabled features are offered, whether European customers receive the same functionality as U.S. customers, and whether channel partners or enterprise clients deploy the company’s technology in Europe.

A business may also occupy different roles across different use cases. It could be a deployer of a purchased AI assistant for internal work while functioning as a provider of an AI-enabled feature offered to customers. Those distinctions can affect responsibility.

Legal counsel should validate the final role and applicability analysis. Product, engineering, procurement, marketing, compliance, and security teams should supply the underlying facts.

Build a Complete Inventory of AI Use Cases

Many leadership teams can name the company’s flagship AI feature but cannot produce a complete inventory of where AI influences products, operations, or communications.

AI may appear in customer support, search, content generation, fraud detection, meeting summaries, automated recommendations, sales workflows, marketing tools, development assistants, security platforms, hiring systems, document analysis, and third-party components embedded in a larger service.

Some functions are visible to customers. Others operate behind the scenes while still influencing an output, recommendation, or decision.

Create one inventory record for each use case. Record the business purpose, product owner, technical owner, model or service provider, people affected, geographic availability, data processed, output type, level of automation, human-review process, and whether users are informed that AI is involved.

The inventory should also identify whether the system generates or modifies text, images, audio, or video. Record whether the output can be exported, republished, or displayed through another platform that may remove a notice or technical marker.

Do not limit the inventory to products marketed as AI. Vendors routinely add AI-assisted functionality through ordinary product updates. Employees may connect general-purpose models to company data through APIs or automation platforms without launching a formal AI project.

If the organization cannot identify where AI is operating, it cannot make reliable transparency decisions.

Determine the Company’s Role for Each Use Case

The AI Act uses defined roles, including providers and deployers. A company’s role can vary across its portfolio.

A business that develops an AI-enabled system and places it on the market may have different responsibilities from one that uses another vendor’s chatbot internally. A company may rely on a general-purpose model provider while still controlling the customer interface, deployment context, disclosure language, or downstream use of model output.

This is why a statement such as “our model vendor handles compliance” is not a complete governance strategy.

The upstream vendor may supply technical documentation, machine-readable markings, or configurable controls. The U.S. company may still decide where the feature appears, which users encounter it, whether a visible notice is displayed, how output is published, and whether employees can remove a label.

For every use case, document a working role classification, the facts supporting it, the person who approved it, and the date it was reviewed. Where the classification affects legal obligations, have qualified counsel validate the conclusion.

Role analysis should be repeatable. A feature that begins as an internal productivity tool may later become customer-facing. A vendor update may convert a passive recommendation feature into an interactive assistant. Those changes can require reassessment.

Review Every AI Interaction Presented to a Person

The European Commission’s June announcement emphasizes that people must be informed when they are interacting with an AI system such as a chatbot.

A transparency notice is useful only if the person can see and understand it.

Review chatbots, virtual assistants, automated intake flows, support agents, voice interfaces, embedded widgets, and other interactive experiences. Determine whether the AI nature of the interaction is clear before or at the beginning of the experience.

Do not assume a sentence buried in a privacy policy provides the same user experience as a direct notice in the interface. “You are chatting with an AI assistant” is easier to understand than a paragraph describing automated technologies in abstract legal language.

Test whether the disclosure remains visible on mobile devices, embedded interfaces, integrations, and localized versions of the product. Confirm that it is available in relevant languages. If the business context requires human escalation, verify that the route to a person is understandable and functional.

The company should also preserve evidence of which notice appeared, when it appeared, and which product version displayed it. A screenshot taken once during implementation is not enough if later releases can modify the interface.

Identify Content That May Require Labelling

The Commission’s final Code of Practice addresses marking and labelling AI-generated content. The Commission calls attention to deepfakes and certain AI-generated or AI-manipulated text published to inform the public on matters of public interest.

That should trigger a broader review of content workflows.

Marketing, communications, education, healthcare, public-sector, and media-facing teams may generate or modify text, images, audio, and video with AI. Employees may substantially edit model output before publication. Vendors may apply technical markers that disappear when content is exported, recompressed, edited, or passed through another platform.

Create a decision process that helps content owners determine whether material was generated or manipulated by AI, whether a transparency requirement may apply, what visible notice is appropriate, whether a machine-readable marker is available, and how content provenance will be retained.

The procedure should identify who can approve an exception and how disputed cases are escalated. A policy that says “label AI content where required” is not operational until employees know who decides when labelling is required and how that decision is documented.

Companies should also evaluate whether labels are understandable to ordinary users. A technically accurate marker that no one can recognize may not accomplish the transparency objective.

Evaluate Whether Vendors Support Your Obligations

Vendor due diligence should move beyond asking whether a provider is “EU AI Act compliant.” That phrase may conceal important limitations and does not establish how responsibility is divided in a specific deployment.

Ask vendors whether their systems support visible disclosure, output provenance, machine-readable marking, configuration by geography or use case, audit logging, model-version history, and documentation of material system changes.

Determine whether those capabilities are enabled by default, require a premium subscription, depend on a particular API, or disappear when content is exported. Ask whether downstream editing removes technical markers and whether the vendor provides guidance for preserving them.

Contracts should clarify which party handles user notices, technical markings, documentation, incident communication, and notification of material model changes. The contract should also address access to evidence if the company must investigate or demonstrate how a feature operated.

Record vendor answers in the AI inventory. Customer-facing statements should reflect what is actually configured, not only what a vendor says its platform can support.

If a vendor cannot provide sufficient information, record the gap and decide whether additional controls, restricted deployment, or an alternative service is necessary.

Keep Evidence, Not Just Policies

Regulatory readiness depends on the ability to demonstrate how decisions were made and how controls operate.

Useful evidence may include AI inventory records, product requirements, role-classification decisions, screenshots of disclosures, interface test results, vendor documentation, contract terms, content-labelling procedures, technical-marker validation, staff training records, model-version logs, approved exceptions, and governance meeting decisions.

Evidence should have an owner and retention period. It should be stored where legal, compliance, product, and security teams can retrieve it without reconstructing the entire history of a feature.

This work can support more than regulatory readiness. Enterprise customers increasingly ask how AI is governed, what data is used, whether outputs are labelled, whether humans can intervene, and how model changes are reviewed.

A well-organized evidence package can reduce friction during customer security reviews, vendor assessments, audits, and procurement discussions.

Test Transparency Controls in the Real Product

Do not treat transparency as a documentation-only exercise. Test it like any other product requirement.

Ask someone unfamiliar with the feature to use it and explain whether they understood that AI was involved. Verify that notices appear in every supported interface and language. Check what happens when a third-party integration displays the same interaction or output.

For generated content, confirm that the expected visible label and technical marker remain present after export, editing, resizing, recompression, or publication. If a marker does not survive a common workflow, document the limitation and add a compensating control.

Include failure scenarios. What happens if a labelling service is unavailable? Can an application update accidentally suppress a disclosure? Can an employee disable the notice without review? Does a geographic configuration fail when a user travels or accesses the service through a corporate network?

Testing should produce evidence, assigned findings, and remediation deadlines. A successful design review does not prove that the production implementation works.

Assign Accountable Owners

AI transparency obligations cross traditional organizational boundaries. Legal may interpret the regulation, but legal cannot inventory every integration or test every interface. Engineering can implement notices, but engineering should not make every role-classification decision alone.

Assign accountable owners for the overall AI inventory, each product use case, vendor due diligence, legal interpretation, disclosure design, testing, evidence retention, employee training, and incident escalation.

Define who has authority to approve a new AI feature and who can stop deployment when required evidence is missing. Identify who reviews vendor changes and who determines whether a product must be reassessed.

Ownership should be visible to leadership. If everyone participates but no one is accountable, deadlines will produce fragmented last-minute work.

A Practical Readiness Plan for U.S. Companies

Organizations can organize the work into four parallel tracks.

Scope: Inventory AI use cases, geographic exposure, affected users, company roles, data flows, and output types. Obtain legal advice where territorial scope or role classification remains uncertain.

Product: Implement and test user notices, content labels, technical markings, human-escalation paths, and failure behavior. Verify the actual production experience rather than relying on documentation.

Vendor: Confirm provider capabilities, contractual responsibilities, evidence availability, change notifications, marker persistence, and incident communication.

Governance: Assign owners, document decisions, train relevant teams, preserve evidence, manage exceptions, and establish recurring review.

Leadership should receive a concise readiness report showing which use cases were reviewed, which controls are implemented, what evidence exists, where legal analysis is pending, which vendor gaps remain, and which risks have been accepted.

The August milestone should not result in one generic disclaimer being placed on every AI feature. Different systems, roles, users, and outputs create different transparency questions.

The better approach is to know where AI operates, make deliberate decisions for each use case, test the controls in production, and retain evidence that the process is working.

Start With What Can Be Proven

The EU AI Act’s August 2026 milestone is not only a legal deadline. It is a test of whether an organization can explain where AI is used, who is responsible, what users are told, how generated content is identified, and what evidence supports those claims.

U.S. companies should not make sweeping conclusions about applicability based on a blog post. They should work with qualified counsel and use current European Commission guidance and the regulation itself.

At the same time, they should not postpone basic governance while waiting for every interpretive question to be resolved.

An accurate AI inventory, clear ownership, tested notices, documented vendor responsibilities, and organized evidence are useful regardless of the final legal conclusion for a particular system.

Readiness begins by replacing general assurances with facts the organization can verify.

How WCS Can Help

Walden Cybersecurity Solutions helps growing organizations translate AI governance requirements into practical inventories, vendor reviews, control roadmaps, evidence structures, and leadership-ready plans.

The objective is not to slow responsible AI adoption. It is to make AI use easier to explain, oversee, test, and sustain.

Explore WCS AI Security and Governance services or review Compliance Readiness Consulting.

References

  1. European Commission, “Commission publishes Code of Practice on marking and labelling AI-generated content,” June 10, 2026.
  2. European Commission, “AI Act,” regulatory framework, risk-based approach, compliance information, and implementation resources.
  3. Regulation (EU) 2024/1689, Artificial Intelligence Act, Official Journal of the European Union.
  4. European Commission, Code of Practice on marking and labelling of AI-generated content.

This article provides general readiness guidance and is not legal advice. Organizations should consult qualified counsel regarding the AI Act’s application to their products, services, users, contracts, and geographic activities.