Leadership1 distinct publisher3 min readPublished
The EU AI Act's transparency duties have been enforceable since August 2, and because the text does not settle which systems count, the answer a deployer can defend comes from its own capability inventory rather than from the statute.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The trigger in Article 50 is a capability rather than a technology. Providers have to disclose whether their systems can generate or manipulate content, including text, audio and video [5]. That phrasing moves the compliance question inside the product: the answer turns on what each system does to material a person will eventually see, and on whether anyone has written that down in a form a third party could check. When a law names an effect and declines to name the class of systems that produce it, the defensible position is an inventory of your own making, with dates on it.
The tradeoff is between two failure modes with different payment schedules. Garraghan's illustration is a software provider drawing on 1,000 different libraries, and his question is whether each one needs its own disclosure [8]. Disclose everything and the duty is discharged, at the price of a document that has to be regenerated whenever a dependency changes. Disclose on a capability test you wrote yourself and the maintenance is tractable, but you are holding an interpretation rather than a rule. The first cost recurs at every release; the second arrives once, in a conversation where you have to show your reasoning.
The age of the term is part of why it makes such a poor scope key. Artificial intelligence dates from a workshop held at Dartmouth in 1956, and the artificial neural network from which modern models derive was conceived in the 1940s [4][10]. Enforcement therefore began 70 years after the field acquired its name [1]. A category that has absorbed seven decades of unrelated engineering will not sort a product catalogue, which is why the workable internal question is what a system can do rather than which decade's vocabulary it belongs to.
Garraghan's sharpest claim is that agents may already sit outside the text, because they are not designed to generate content but to perform and facilitate actions, and he believes there is a strong argument that this exempts them [6]. A skeptic would point out that the reading comes from the founder and chief science officer of Mindgard, writing in a vendor council column [12], and that authorities tend to read transparency duties for purpose rather than for grammar. That is fair, and it leaves the deployer roughly where it started, because nothing in the material tells us how any authority will read the provision. We do not know yet, and a firm that never recorded which reading it adopted has nothing to defend later.
This is where the quarter's decision sets up the next one. A scope call made once, when a product is first classified, is inherited by every release that follows, and agent features are exactly the kind of change that alters what a system does without altering how it was described. If the internal test is whether a system produces or alters content a user sees, action-taking features fall out of scope quietly unless someone re-runs the test at release. The choice worth making this quarter is who owns that re-test and where its output is filed, because that record is what a later inquiry can actually read.
Ranked by verification strength, evidence, and original report placement.
Article 50 of the EU AI Act mandates strict disclosure and transparency measures for both AI providers (those who provide the AI models) and deployers (those who use models to build AI solutions).
The term Artificial Intelligence dates back to a workshop held at Dartmouth in 1956.
The EU AI Act mandates that providers must disclose if their AI solutions can generate or manipulate content, including text, audio and video.
The Artificial Neural Network, the model from which modern LLMs and agents are derived, was conceived in the 1940s.
Peter Garraghan is founder and chief science officer of Mindgard, and published the argument through the Forbes Technology Council.
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Europe labelled the deepfakes that want to be seen. Bank identity checks sit on the other side1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
build
Invoked in three runs, executed in none: the cost rule that never got asked1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Thin: one contributed opinion piece
The cluster rests on a single Forbes Technology Council post. Its checkable elements — the existence of Article 50 duties on providers and deployers and the August 2, 2026 enforcement date — are stated plainly and are internally consistent, but the load-bearing arguments (undefined scope, agent exemption, disclosure overbreadth) are asserted without statutory citation, regulator guidance, legal analysis, or any second publisher.
No compliance or usage data
The only dated event available is the statutory enforcement milestone itself, which measures a legal deadline rather than uptake. The cluster contains no disclosure filings, compliance surveys, vendor implementations, enforcement actions, or usage figures showing how providers or deployers have responded since August 2, 2026, so adoption cannot be scored.
Assertive conclusions run ahead of the evidence
The framing is critical rather than promotional, so this is not product hype — but the headline verdict ('insufficient, incomplete and unenforceable') and the claim that there is a 'strong argument' agentic AI is exempt are stated with more confidence than the single-source, uncited argument can carry. The verifiable statutory facts are modest; the conclusions drawn from them are sweeping.
Vendor byline arguing for vendor-led governance
The piece is contributed content published under Forbes' paid-membership council program by the founder and chief science officer of Mindgard, an AI security firm. Its prescription — do not wait for regulators, instrument your own capability-level safeguards and meet customer expectations now — aligns directly with demand for third-party AI assurance and testing, and the commercial alignment is not disclosed in the text.
Low: single opinion source, unmeasured adoption
One publisher, one contributed opinion piece, no adoption or enforcement data, and a disclosed-by-inference vendor incentive. Confidence is limited to the statutory facts and to an accurate reading of what the author argues; it does not extend to whether the scoping and exemption arguments hold.