AI policy
The AI Act stops being a timetable: Brussels starts enforcing
Transparency obligations, general-purpose AI powers and the penalty regime all became live on 2 August. The compliance question moves from 'when' to 'who checks'.
The answer
The EU began enforcing the AI Act on 2 August 2026, with fines to 3% of global turnover.
For two years the AI Act has been discussed in the future tense — a timetable, an implementation plan, a compliance project with a date attached. On 2 August 2026 the tense changed. The European Commission's AI Office, working with national authorities, began enforcing the regulation, and the transparency obligations that most directly touch consumer-facing AI products became live law rather than forthcoming law.
What became enforceable
The headline change is disclosure. Three obligations started applying at once, and all three are behavioural rather than documentary — they change what a product does in front of a user, not just what sits in a compliance folder.
Users must be clearly informed when they are not interacting with a real person, but an AI system, for example a chatbot, AI agent, and avatar.
Alongside that: deepfakes — images, video or audio generated or edited with AI — must be labelled, and AI-generated or altered content must carry machine-readable marks so it can be detected automatically. The Commission has produced a set of icons for the purpose. The machine-readable requirement is the technically consequential one, because it pushes provenance signalling down into the file rather than leaving it to a visible badge a screenshot removes.
Certain AI-generated or manipulated content must be clearly and visibly labelled and include machine-readable marks.
Enforcement powers over general-purpose AI took effect at the same time, along with the penalty regime — up to €15 million or 3% of global annual turnover for companies, with proportionality provisions for SMEs and a separate ceiling of up to €750,000 for EU institutions. Those numbers sit below the GDPR's headline maximums, which is a deliberate calibration rather than an oversight: the Act's designers wanted deterrence without making European deployment commercially irrational.
Who actually enforces it
This is where implementation gets harder than drafting. Enforcement is split three ways: national market surveillance authorities in each member state, the European AI Office centrally for general-purpose AI, and the European Data Protection Supervisor for EU institutions. Distributed enforcement is how the single market normally works, and it is also how the single market normally produces divergence — twenty-seven authorities with different resourcing, appetite and interpretation.
The AI Office has been staffing up accordingly, running a hiring round for around 40 posts dedicated to enforcing the Act. In September the Office and national data protection authorities began initiating technical audits on Article 11 technical files, and by 15 September providers of general-purpose AI above the 10^25 FLOPs training threshold were due to submit their first formal systemic risk evaluations — covering red-teaming methodology, energy disclosures and copyright training summaries.
What is still coming
August 2026 is a milestone, not the finish line. The remaining schedule matters for anyone planning product roadmaps against it.
| Date | What applies |
|---|---|
| 2 August 2026 | Transparency rules, GPAI enforcement powers, penalties |
| 2 December 2026 | New prohibited practices |
| 2 December 2027 | Annex III high-risk systems |
| 2 August 2028 | Annex I product systems |
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — is already in force alongside this. Among the newer prohibitions, the 'nudifier' ban is drawn unusually broadly: it captures not only systems designed to produce non-consensual intimate imagery but also systems marketed without reasonable safeguards against that use, which shifts liability towards how a general-purpose tool is distributed rather than only what it was built for.
The wider context is divergence. The United States has moved in the opposite direction at federal level, with a June 2026 executive order establishing a voluntary framework for pre-release model access and a separate push to preempt state AI laws — while individual states legislate anyway. Europe is now the jurisdiction with binding, enforceable, generally applicable AI rules, which makes it the de facto compliance baseline for any product shipped globally. That is the Brussels effect working exactly as intended, and the thing to watch over the next year is whether the first enforcement actions are proportionate enough to make it stick.
Frequently asked questions
What changed on 2 August 2026 under the EU AI Act?
What are the fines under the AI Act?
Who enforces the AI Act?
Does the AI Act apply to companies outside the EU?
What are the next AI Act deadlines?
Sources
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission, 2 August 2026
- Safer and more transparent AI — European Commission, 2 August 2026
- EU begins enforcing AI Act, putting AI models under the microscope — Help Net Security, 4 August 2026
- Implementation Timeline — EU Artificial Intelligence Act — EU Artificial Intelligence Act, 2 August 2026