To those who have passed the AIGP since the last mail, congratulations 🎉, well earned. It is a hard exam, and passing it says something about how you think, not only what you memorised.
If you have recently passed, or you are using the Playbook to prepare, I would love to hear from you. Hit reply.
The revision facts are now an audiobook. All 100 essential facts, read aloud, four episodes, one per domain. Built for the commute, the night before, the morning of. Free, no login.
Have you explored the EU AI Act Brain? It maps the whole Act as a knowledge graph, structured the way an AI agent reads it rather than the way a PDF is laid out. If you would like something similar built for your own material, a framework, a policy set, or internal training, that is work I take on. Mention it in your reply.
I won the Google Cloud hackathon recently, building a runtime AI governance platform.
I mention it because it connects to the story below. Disclosure and content labelling cannot be discharged by a policy document. They have to hold at the moment the system acts. That gap, between governance on paper and governance at runtime, is where the interesting work is heading.
The EU AI Act's transparency obligations are now enforceable.
As of August 2, 2026, Article 50 applies. It covers four situations, and most summaries only list three. Direct interaction with a person, so chatbots must disclose they are AI. AI-generated content, which must be marked. Emotion recognition and biometric categorisation, which must inform the people subject to them. And deep fakes plus AI-generated text on matters of public interest, which must be labelled. That fourth one is the one people forget.
The penalties are real: up to €15 million or 3% of global turnover, whichever is higher, enforced mainly by national market surveillance authorities.
One nuance worth knowing, because it is easy to get backwards. There is no general grandfather clause, so a system you shipped in 2024 is in scope. But there is one narrow transitional carve-out: the provider-side marking obligation under Article 50(2), for systems already placed on the market before August 2, does not bite until December 2, 2026, and content published before then does not need labelling retroactively. That relief covers the marking obligation only. The other Article 50 obligations that apply to your system have applied since August 2.
The Commission adopted guidelines on July 20 clarifying what compliance looks like, and the AI Office has published a voluntary Code of Practice on Transparency of AI-Generated Content. Signing up is a recognised way to demonstrate compliance with the marking obligations, though providers can also demonstrate it through other appropriate means.
For those preparing for the exam: Article 50 carries the Act's transparency obligations, commonly associated with the limited-risk category, and the exam likes testing exactly that distinction. These obligations do not, by themselves, make a system high risk.
Missed an earlier issue? Every one of these is now on the site, in full and free to read: https://aigpplaybook.com/newsletter/
If you know someone preparing for the AIGP or building in this space, forward this to them. They can subscribe at aigpplaybook.com.
One thing before you go. If you are actually working in AI governance, what is the biggest challenge you are seeing right now? Reply and tell me. I read every one, and the answers shape what I write next.
What is actually moving in AI governance, plus what it means if you are sitting the AIGP. No fixed schedule, only when something matters.