欧盟《人工智能法》扩大实施,透明度与通用模型义务开始执法

聊天机器人须告知用户、深度伪造须带机器可读标识,高风险条款推迟

欧盟《人工智能法》于 2026 年 8 月 2 日进入新的执法阶段:面向公众的系统必须披露 AI 身份,深度伪造必须带机器可读标识,通用 AI 模型提供商开始受欧洲 AI 办公室监管;高风险条款经"综合简化"一揽子计划推迟至 2027 年 12 月起分批适用。

时间2026 年 8 月 2 日 级别A · 行业级 组织 状态已核验 · 2 个来源
编辑插图:深色背景上一排等距的发光立柱,顶部各带一点微光
AI Chronicle 原创插图:等距立柱阵列,对应分阶段生效的规则框架。 AI Chronicle

2026 年 8 月 2 日,欧盟《人工智能法》进入新的执法阶段。这一天起,面向欧盟公众的聊天机器人必须告知用户"正在与 AI 互动";AI 生成或修改的图像、视频、音频必须标识,且带机器可读标记。同一天,欧洲 AI 办公室开始对通用 AI 模型提供商执法,可能造成系统性风险的先进模型须防范网络攻击、模型失控、有害操纵与对基本权利的侵犯。

这些条款对普通人的意义最先落在界面层:与客服对话时看到一行"这是 AI 助手",刷到合成视频时认出水印。标识不能替代理解,但它把"这段内容是 AI 做的"从厂商的自觉变成法律义务,也让监管从"事后追责"走向"事前提振"——创作者必须在一开始就标注来源。对深度伪造最直接的遏制,不在于事后找到谁,而在于让每一次生成都留下可识别的记号。

对开发者与出海团队,影响是工程清单上的新增项:部署面向欧盟用户的生成与对话产品,需要加入披露文案、机器可读水印、模型卡的合规说明。通用模型义务更把监管对象从应用上移到模型本身——提供方要说明训练数据、评估与风险缓解措施,而不再只是"模型由客户负责"。开源社区的处境尤其微妙:权重发布者与部署者之间的责任如何划分,条款文本与实务之间仍有大量待解释空间。

同期的"综合简化一揽子计划"给出了另一种信号:招聘、教育、执法等领域的高风险义务推迟到 2027 年 12 月 2 日,医疗器械、机械等受监管产品内嵌的高风险系统推迟到 2028 年 8 月 2 日。禁令与通用模型义务不在推迟之列。企业在同一天收到严与松两套信息:触碰消费者的条款先行落地,成本更高的组织义务留给缓冲期。

《人工智能法》从 2024 年 8 月生效至今,完成了从立法到执法的交接。这并不意味着 AI 治理有了标准答案——条款的执行细节、开源社区的合规路径、成员国执法口径的差异,都会在接下来的真实案例里被逐条检验。可以确定的是,对任何面向欧盟市场的产品,标识与披露不再是可选项。规则的时代,从这一周开始有了具体的模样。

On August 2, 2026, the EU AI Act moved into a new enforcement phase. From that day, chatbots facing EU users must tell users they are interacting with AI; AI-generated or AI-modified images, video, and audio must be labeled, with machine-readable marks. On the same day, the European AI Office begins enforcing against general-purpose AI providers, and advanced models that could pose systemic risk must guard against cyberattacks, loss of control, harmful manipulation, and harm to fundamental rights.

For ordinary people, these provisions land first on the interface: a line saying "this is an AI assistant" in a support chat, a watermark on a synthetic video. Labels do not replace understanding, but they turn "this content is AI-made" from a vendor's choice into a legal duty, and push enforcement from after-the-fact attribution toward marking at creation. The most direct constraint on deepfakes is not finding the author later; it is making every generation leave a recognizable trace.

For developers and teams shipping to the EU, the effect is new items on the engineering checklist: disclosure copy, machine-readable watermarks, and compliance notes for generative and conversational products. The GPAI duties move the object of regulation from applications up to the models themselves—providers must document training data, evaluation, and risk-mitigation measures, and "the customer is responsible" no longer ends the conversation. The open-source community sits in the most delicate position: how responsibility divides between weight publishers and deployers leaves wide room for interpretation.

The companion Digital Omnibus package sent a different signal. High-risk obligations for hiring, education, and law enforcement are deferred to December 2, 2027; embedded high-risk systems in regulated products such as medical devices and machinery to August 2, 2028. Prohibitions and GPAI duties are not deferred. Companies received strict and lenient news in the same week: rules touching consumers land first; the more expensive organizational duties get a runway.

Since entering into force in August 2024, the AI Act has completed the handover from legislation to enforcement. That does not mean governance now has a standard answer—enforcement details, the open-source compliance path, and diverging national approaches will all be tested case by case. What is certain: for any product facing EU users, labeling and disclosure are no longer optional. The era of rules now has a concrete shape.

展开完整事件档案人物、主题、模型与产品
人物
模型
产品
来源

原始资料

  1. 01新华社布鲁塞尔:欧盟《人工智能法》扩大实施新华社 · report
  2. 02央视新闻:欧盟 AI 法案新规 8 月 2 日起适用央视新闻 · report

试试搜索