
The grace period is over. The European AI Office now holds live investigative powers, three complaint channels are open, and the transparency obligations have applied since 2 August 2026. This is no longer a draft regime. It is an operational reality carrying fines of up to 7% of global turnover.
Global AI regulation has crossed a threshold. The EU Artificial Intelligence Act, formally Regulation (EU) 2024/1689, entered into force in August 2024, and its obligations have since unfolded along a staged timeline. Two years on, the initial preparation period has ended. The European Commission, acting through the EU AI Office and the national competent authorities of the Member States, has begun enforcing the Act in practice.
For technology companies, founders, software developers and organisations in Israel that offer AI-based products, services or systems into the European market, the message is unambiguous. AI regulation is no longer a theory, a position paper or a draft awaiting adoption. It is a binding legal and operational reality, backed by supervisory powers, reporting mechanisms and substantial financial penalties.
On 24 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal of the European Union, and it entered into force on 27 July 2026. The Regulation postponed the application dates for the high-risk obligations, but not the bulk of the transparency obligations. Those apply from 2 August 2026, subject to a four-month extension until 2 December 2026 for content-marking in systems already placed on the market before that date.
The EU AI Act rests on a risk-based approach, sorting AI systems into tiers that run from unacceptable risk, which is prohibited outright, down to minimal risk, which carries no dedicated obligations. Those duties are phased in along a staged timeline, most recently revised by the Omnibus Regulation that took effect in July 2026.
Correct classification is the first and most consequential step. The same underlying model may fall into an entirely different tier depending on the use made of it:
Article 50 imposes direct and detailed transparency duties, whose enforcement began in the present wave, on both providers and deployers of AI systems:
Any AI system that interacts directly with people, including chatbots, voice assistants and automated response systems, must make clear to the user, in a clear and distinguishable manner and no later than the first interaction, that they are dealing with an AI system rather than a human being. The exemption applies where this is obvious to a reasonably observant user, and, subject to safeguards, to systems authorised by law to detect, prevent, investigate or prosecute criminal offences.
Providers must embed machine-readable markings in any text, audio, image or video generated or manipulated by AI, and offer detection mechanisms. Accepted technologies include Content Credentials (C2PA), digital watermarking such as SynthID, and cryptographic metadata.
A clear legal duty to disclose, visibly and audibly, any visual or audio content constituting a deepfake, meaning content that realistically depicts people, places or events. A parallel duty applies to text published on matters of public interest, unless the material has undergone substantive human editorial review.
Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to the system that it is operating, and process the personal data in accordance with the GDPR. This is particularly relevant to recruitment, customer service and security systems.
On 10 June 2026 the European Commission published the Code of Practice on Transparency of AI-Generated Content, a non-binding instrument translating Article 50 into measurable technical practice. By the end of July 2026 roughly 190 companies and organisations had signed it. Signing is voluntary, but it confers a practical safe harbour: the Commission has confirmed that signatory providers and deployers may rely on its measures to demonstrate compliance with the Act. The Commission has also published a standard icon set for labelling content.
The Act devotes an extensive chapter to providers of general-purpose AI models, models capable of performing a wide range of tasks and serving as infrastructure for many downstream applications:
Models of exceptionally high computational capability, or with broad market impact, are subject to an additional layer of obligations:
To make enforcement effective, the EU AI Office has formally launched a set of digital tools enabling close supervision. In practice, this creates three distinct exposure routes for every provider:
A mechanism allowing any individual or organisation to file a formal complaint concerning infringements of the Act by providers or deployers of AI systems falling within the AI Office's exclusive competence. The complaint requires the complainant to identify themselves.
A dedicated mechanism for companies developing applications on third-party general-purpose models. It allows them to complain where the GPAI model provider has failed to supply the technical documentation, training data summaries or safety information required under Articles 53 to 55.
A secure and anonymous channel for employees and others with a professional connection to AI providers, enabling confidential reporting of internal breaches of safety and regulatory procedures that endanger fundamental rights, health or public trust.
The sanctions regime is graded across four levels. At each level the applicable figure is the higher of the two: a percentage of global turnover, or a fixed amount in euro.
| Type of infringement | Examples | Maximum fine |
|---|---|---|
| Prohibited practicesArticle 5 | Social scoring, cognitive manipulation, real-time biometric identification in public spaces, untargeted mass scraping of facial images | 7%or EUR 35 million |
| Breach of substantive obligationsArticles 16, 26, 50 and others | Failure to disclose interaction with a chatbot, absence of marking on generated content, unlabelled deepfakes, breach of high-risk system obligations | 3%or EUR 15 million |
| GPAI provider obligationsArticle 101 | Failure to supply technical documentation, failure to publish a training data summary, failure to cooperate with the AI Office | 3%or EUR 15 million |
| Supply of incorrect informationArticle 99(5) | Supplying incorrect, incomplete or misleading information to competent authorities or to notified bodies | 1%or EUR 7.5 million |
For small and medium-sized enterprises and start-ups, a softened mechanism applies: the fine is capped at the lower of the two components. That is a meaningful concession, and one relevant to a substantial share of the Israeli ecosystem.
The EU AI Act has broad extraterritorial reach, following the model established by the GDPR. An Israeli company physically located in Israel, but developing, selling or operating an AI system accessible to users or businesses in the European Union, or whose output is used within the Union, is subject to the obligations of the Act that attach to its role and to the risk classification of the system. The test is not where you are established. It is where the effect lands.
Alongside the European arena, Israeli organisations are in the middle of a parallel domestic shift. Amendment 13 to the Protection of Privacy Law, in force since August 2025, substantially expanded the enforcement powers of the Privacy Protection Authority and imposed an obligation to appoint a Data Protection Officer on a wide range of entities.
The Privacy Protection Authority has also published a position stating that the Protection of Privacy Law applies to artificial intelligence systems. Its main elements include: a heightened informed consent duty covering how the system operates and the risks it carries; a duty to notify users when they are interacting with an automated bot; a determination that scraping data from the internet to train models, without consent, may constitute an unlawful invasion of privacy; and an emphasis on access and rectification rights, including correcting algorithms that have produced inaccurate information.
Eight steps every organisation exposed to the European regime should take. Tick off what is already done:
אתר מונגש
אנו רואים חשיבות עליונה בהנגשת אתר האינטרנט שלנו לאנשים עם מוגבלויות, וכך לאפשר לכלל האוכלוסיה להשתמש באתרנו בקלות ובנוחות. באתר זה בוצעו מגוון פעולות להנגשת האתר, הכוללות בין השאר התקנת רכיב נגישות ייעודי.
סייגי נגישות
למרות מאמצנו להנגיש את כלל הדפים באתר באופן מלא, יתכן ויתגלו חלקים באתר שאינם נגישים. במידה ואינם מסוגלים לגלוש באתר באופן אופטימלי, אנה צרו איתנו קשר
רכיב נגישות
באתר זה הותקן רכיב נגישות מתקדם, מבית all internet - בניית אתרים.רכיב זה מסייע בהנגשת האתר עבור אנשים בעלי מוגבלויות.