Skip to main content
WireRead
Back to all news

AI policy

The AI Act stops being a timetable: Brussels starts enforcing

Transparency obligations, general-purpose AI powers and the penalty regime all became live on 2 August. The compliance question moves from 'when' to 'who checks'.

By , Editor-in-Chief · WireReadVerified September 2026

The answer

The EU began enforcing the AI Act on 2 August 2026, with fines to 3% of global turnover.

For two years the AI Act has been discussed in the future tense — a timetable, an implementation plan, a compliance project with a date attached. On 2 August 2026 the tense changed. The European Commission's AI Office, working with national authorities, began enforcing the regulation, and the transparency obligations that most directly touch consumer-facing AI products became live law rather than forthcoming law.

What became enforceable

The headline change is disclosure. Three obligations started applying at once, and all three are behavioural rather than documentary — they change what a product does in front of a user, not just what sits in a compliance folder.

Users must be clearly informed when they are not interacting with a real person, but an AI system, for example a chatbot, AI agent, and avatar.

Source: European Commission · 2 August 2026

Alongside that: deepfakes — images, video or audio generated or edited with AI — must be labelled, and AI-generated or altered content must carry machine-readable marks so it can be detected automatically. The Commission has produced a set of icons for the purpose. The machine-readable requirement is the technically consequential one, because it pushes provenance signalling down into the file rather than leaving it to a visible badge a screenshot removes.

Certain AI-generated or manipulated content must be clearly and visibly labelled and include machine-readable marks.

Source: European Commission · 2 August 2026

Enforcement powers over general-purpose AI took effect at the same time, along with the penalty regime — up to €15 million or 3% of global annual turnover for companies, with proportionality provisions for SMEs and a separate ceiling of up to €750,000 for EU institutions. Those numbers sit below the GDPR's headline maximums, which is a deliberate calibration rather than an oversight: the Act's designers wanted deterrence without making European deployment commercially irrational.

Who actually enforces it

This is where implementation gets harder than drafting. Enforcement is split three ways: national market surveillance authorities in each member state, the European AI Office centrally for general-purpose AI, and the European Data Protection Supervisor for EU institutions. Distributed enforcement is how the single market normally works, and it is also how the single market normally produces divergence — twenty-seven authorities with different resourcing, appetite and interpretation.

The AI Office has been staffing up accordingly, running a hiring round for around 40 posts dedicated to enforcing the Act. In September the Office and national data protection authorities began initiating technical audits on Article 11 technical files, and by 15 September providers of general-purpose AI above the 10^25 FLOPs training threshold were due to submit their first formal systemic risk evaluations — covering red-teaming methodology, energy disclosures and copyright training summaries.

What is still coming

August 2026 is a milestone, not the finish line. The remaining schedule matters for anyone planning product roadmaps against it.

Date What applies
2 August 2026 Transparency rules, GPAI enforcement powers, penalties
2 December 2026 New prohibited practices
2 December 2027 Annex III high-risk systems
2 August 2028 Annex I product systems

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — is already in force alongside this. Among the newer prohibitions, the 'nudifier' ban is drawn unusually broadly: it captures not only systems designed to produce non-consensual intimate imagery but also systems marketed without reasonable safeguards against that use, which shifts liability towards how a general-purpose tool is distributed rather than only what it was built for.

The wider context is divergence. The United States has moved in the opposite direction at federal level, with a June 2026 executive order establishing a voluntary framework for pre-release model access and a separate push to preempt state AI laws — while individual states legislate anyway. Europe is now the jurisdiction with binding, enforceable, generally applicable AI rules, which makes it the de facto compliance baseline for any product shipped globally. That is the Brussels effect working exactly as intended, and the thing to watch over the next year is whether the first enforcement actions are proportionate enough to make it stick.

Frequently asked questions

What changed on 2 August 2026 under the EU AI Act?
Transparency rules became enforceable: chatbots must disclose they are AI, deepfakes must be labelled, and AI-generated content must carry machine-readable marks. Enforcement powers over general-purpose AI and the penalty regime also took effect.
What are the fines under the AI Act?
Up to €15 million or 3% of global annual turnover for companies, with proportionality for SMEs, and up to €750,000 for EU institutions.
Who enforces the AI Act?
National market surveillance authorities in each member state, the European AI Office for general-purpose AI, and the European Data Protection Supervisor for EU institutions.
Does the AI Act apply to companies outside the EU?
Yes, where AI systems are placed on the EU market or their output is used in the EU — which is why it functions as a global compliance baseline in practice.
What are the next AI Act deadlines?
New prohibited practices on 2 December 2026, Annex III high-risk systems on 2 December 2027, and Annex I product systems on 2 August 2028.

Sources

← All news