EU AI Act Enforcement Begins

Table of Contents

There are some key aspects of the EU AI Act. that are now being enforced. The European Union’s Artificial Intelligence Act has entered a new and significantly more consequential phase.

Beginning 2 August 2026, the European Commission’s AI Office and national authorities can enforce major provisions of the EU AI Act. New transparency requirements also apply to chatbots, generative AI systems, deepfakes, emotion-recognition technologies and certain AI-generated content.

This is not simply another future compliance deadline. Organizations offering or using covered AI systems in the European Union must now be able to demonstrate that required disclosures, labels, technical markings and governance controls actually work.

The European Commission has also launched complaint, whistleblower and downstream-provider reporting channels that give individuals, employees and businesses direct ways to report suspected violations.

For companies, the practical message is clear: AI governance can no longer exist only in policies, committee notes or vendor contracts. Organizations need an accurate record of where AI is being used, what role they play under the Act, which obligations apply and what evidence exists to prove compliance.

What Changed on 2 August 2026?

The EU AI Act entered into force on 1 August 2024, but its requirements have been introduced in stages.

Prohibited AI practices and AI-literacy obligations began applying in February 2025. Obligations for providers of general-purpose AI models began applying in August 2025. The important development on 2 August 2026 is that regulators now have enforcement authority over these provisions, while the transparency requirements in Article 50 have also become applicable.

According to the European Commission’s enforcement announcement, covered organizations must now address requirements including:

  • Telling people when they are interacting directly with an AI system, unless that fact is obvious.
  • Marking AI-generated or manipulated audio, images, video and text in a machine-readable format.
  • Clearly labelling deepfakes.
  • Informing people when they are exposed to emotion-recognition or biometric-categorization systems.
  • Labelling certain AI-generated text published to inform the public about matters of public interest when it has not received meaningful human review or editorial control.
  • Maintaining required documentation and copyright policies for general-purpose AI models.
  • Publishing sufficiently detailed summaries of the content used to train general-purpose AI models.
  • Managing systemic risks associated with the most advanced general-purpose AI models.

These requirements affect different participants differently. A company that develops a model, a software provider that builds a product on that model and a business that deploys the finished system may each have separate responsibilities.

Transparency Has Become a Technical Requirement

One of the most important developments is that the AI Act does not treat transparency as a privacy-policy exercise.

For interactive AI systems, users may need to be told that they are communicating with AI rather than a person. For synthetic content, the requirement may include machine-readable markings that allow AI-generated or altered material to be detected. For deepfakes and certain public-interest content, clear human-facing labels may also be required.

The European Commission’s Article 50 guidance separates these obligations between providers and deployers.

Providers may be responsible for designing systems that:

  • Disclose AI interaction appropriately.
  • Produce machine-readable marks for synthetic or manipulated content.
  • Preserve the effectiveness, interoperability and reliability of those markings.

Deployers may be responsible for:

  • Informing people about emotion-recognition or biometric-categorization systems.
  • Labelling deepfake content.
  • Disclosing covered AI-generated public-interest material.
  • Ensuring that disclosures are clear and provided no later than the first interaction or exposure.

A generic statement buried in terms and conditions may not be enough. Organizations should examine the actual user experience, including where the disclosure appears, when it appears, whether it remains visible and whether the technical marking survives publication or distribution.

The Difference Between AI Providers and Deployers

Many companies assume the AI Act is mainly directed at model developers. That is incorrect.

The Act distributes responsibility across the AI supply chain.

A general-purpose AI model provider develops or places a broadly capable model on the European market. An AI system provider may build an application or service using that model. A deployer uses an AI system under its own authority in a business process.

A company could therefore be a deployer when it uses AI for recruiting, employee monitoring, customer support, fraud detection or content creation. It could become a provider if it substantially modifies a system, changes its intended purpose or offers an AI-powered product under its own name.

This classification matters because the applicable documentation, disclosure and risk-management requirements depend on the organization’s role.

Vendor contracts do not automatically transfer every regulatory responsibility to the underlying model provider.

General-Purpose AI Enforcement Begins

The European AI Office can now enforce obligations applicable to providers of general-purpose AI models.

Those providers must maintain technical documentation, make certain information available to downstream providers, adopt a policy for complying with EU copyright law and publish an adequate summary of the content used to train the model.

Providers of the most advanced GPAI models that present systemic risks face additional duties involving model evaluations, adversarial testing, incident reporting, cybersecurity and systemic-risk assessment and mitigation.

The European Commission has endorsed a voluntary General-Purpose AI Code of Practice to help providers demonstrate compliance. Following the Code is not mandatory, but providers that choose another approach must be able to show that their alternative controls adequately satisfy the Act.

Models placed on the market before 2 August 2025 generally receive additional time to comply with the GPAI obligations, until 2 August 2027. That transition should not be confused with a general delay in enforcement for newer models.

The Commission Has Opened New Reporting Channels

Enforcement will not depend entirely on conventional regulatory investigations.

The Commission has introduced:

  • An AI Act Complaint Tool for individuals and legal entities reporting alleged violations by providers supervised by the AI Office.
  • A secure Whistleblower Tool for people professionally connected to AI-system or GPAI-model providers.
  • A dedicated complaint channel for downstream providers that believe a general-purpose model provider has violated its obligations.

These channels could bring internal documentation, product behavior, vendor representations and gaps between written policies and actual system operation directly to regulators.

Organizations should expect complaints to come from multiple directions, including consumers, employees, competitors, civil-society organizations and companies further down the AI supply chain.

Who Enforces the EU AI Act?

Enforcement responsibility is divided among several authorities.

The European AI Office supervises general-purpose AI models and certain systems connected to those models. Its jurisdiction also covers certain AI systems integrated into very large online platforms and very large online search engines regulated under the Digital Services Act.

National competent authorities enforce the Act for other AI systems within their jurisdictions. The European Data Protection Supervisor handles covered AI systems used by EU institutions, bodies and agencies.

A 60-member independent Scientific Panel supports the AI Office and national authorities on technical questions, including model capabilities and systemic risks.

This structure means organizations may need to manage overlapping regulatory relationships, particularly when an AI system also processes personal data or operates in a separately regulated industry.

What Are the Potential Penalties?

The AI Act allows significant financial penalties.

According to the Commission’s AI Act enforcement framework, violations involving prohibited AI practices can result in penalties of up to €35 million or 7% of total worldwide annual turnover, subject to the Act’s rules for calculating penalties.

Other violations, including breaches of certain GPAI obligations, may result in penalties of up to €15 million or 3% of worldwide annual turnover. Supplying incorrect, incomplete or misleading information to authorities can also produce separate penalties.

The amount imposed will depend on factors including the nature, gravity and duration of the violation, whether it was intentional or negligent, the organization’s cooperation and the corrective measures taken.

The financial exposure is important, but enforcement can also require corrective action, changes to a system, restrictions on its availability or evidence that previously ineffective controls have been repaired.

EU AI Act Resource: Key Requirements and Deadlines

EU AI Act Compliance Timeline

Date Requirement
1 August 2024 The EU AI Act entered into force.
2 February 2025 Prohibited AI practices and AI-literacy obligations began applying.
2 August 2025 GPAI model-provider obligations began applying.
2 August 2026 Article 50 transparency duties apply, while AI Office and national enforcement powers become operational.
2 December 2026 New prohibitions involving AI-generated non-consensual sexually explicit content and child sexual abuse material apply.
2 August 2027 Compliance deadline for certain GPAI models placed on the market before 2 August 2025.
2 December 2027 Requirements for designated high-risk AI systems in areas such as employment, education, biometrics and essential services apply.
2 August 2028 Requirements for high-risk AI integrated into regulated products apply.

The revised high-risk deadlines reflect changes introduced through the AI Omnibus. The Commission’s current EU AI Act overview should be monitored for additional implementation guidance.

EU AI Act Risk Categories

Category Examples General Treatment
Prohibited AI Harmful manipulation, exploitation of vulnerabilities, certain social scoring and certain biometric practices Generally banned
High-risk AI Certain systems used in employment, education, biometrics, essential services, law enforcement and regulated products Extensive risk, documentation, oversight and monitoring requirements
Transparency-risk AI Chatbots, deepfakes, synthetic content, emotion recognition and biometric categorization Disclosure, marking or labelling requirements
General-purpose AI Models capable of performing a broad range of tasks Documentation, copyright and training-content transparency obligations
GPAI with systemic risk Highly capable GPAI models capable of creating large-scale harm Additional evaluation, cybersecurity, incident-reporting and systemic-risk duties
Minimal-risk AI Many ordinary productivity, recommendation and automation tools Generally permitted, although other laws may still apply

Immediate EU AI Act Compliance Checklist

  1. Create an AI inventory. Identify sanctioned and unsanctioned AI systems used across marketing, human resources, sales, customer support, security, product development and operations.
  2. Determine the organization’s role. Document whether the business is acting as a provider, deployer, importer, distributor or downstream provider for each system.
  3. Classify each use case. Evaluate whether a system is prohibited, potentially high-risk, subject to Article 50 transparency requirements or outside the higher-risk categories.
  4. Test user-facing disclosures. Confirm that chatbot notices, deepfake labels and other disclosures appear at the required time and remain understandable and accessible.
  5. Verify machine-readable markings. Determine whether synthetic content contains required technical markings and whether those markings survive ordinary export, editing and publication workflows.
  6. Review AI-generated public content. Establish when human review and editorial responsibility are required, particularly for material addressing matters of public interest.
  7. Strengthen vendor governance. Obtain documentation concerning model origins, intended uses, limitations, training-data summaries, copyright controls, security and downstream compliance support.
  8. Document AI literacy. Maintain evidence that employees and contractors using or supervising AI systems have received training appropriate to their responsibilities.
  9. Establish incident and complaint procedures. Decide who receives AI-related complaints, how they are investigated and when legal, privacy, security and executive teams must be notified.
  10. Preserve compliance evidence. Retain assessments, approval records, system versions, testing results, disclosures, vendor documentation, training records and remediation decisions.

AI Compliance Must Be Operational

The EU AI Act’s enforcement phase exposes a familiar weakness in corporate compliance: the difference between having a policy and being able to prove that the policy controls what the technology actually does.

An organization may state that AI-generated content is labelled, but can it prove that the label appears consistently? It may require human review, but is that review recorded? It may prohibit certain AI uses, but does it know which AI tools employees have connected to company data?

An effective AI governance program should connect legal requirements to system inventories, risk assessments, vendor oversight, technical testing, employee training and evidence retention.

As EU AI Act enforcement begins, organizations should assume that regulators will examine the operation of the system, not merely the language of the policy describing it.

Captain Compliance helps businesses turn privacy and AI governance requirements into practical compliance workflows, documented assessments and defensible records. Organizations operating in or affecting the European market should review their AI systems now rather than waiting for a complaint or regulatory inquiry to reveal gaps in their controls.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.