# The AI Act stops being a timetable: Brussels starts enforcing

> The EU began enforcing the AI Act on 2 August 2026, with fines to 3% of global turnover.

*Transparency obligations, general-purpose AI powers and the penalty regime all became live on 2 August. The compliance question moves from 'when' to 'who checks'.*

By Behzad Hosseini · WireRead
Canonical: https://wireread.com/news/eu-ai-act-enforcement-august-2026-analysis

For two years the AI Act has been discussed in the future tense — a timetable, an implementation plan, a compliance project with a date attached. On 2 August 2026 the tense changed. The European Commission's AI Office, working with national authorities, began enforcing the regulation, and the transparency obligations that most directly touch consumer-facing AI products became live law rather than forthcoming law.

## What became enforceable

The headline change is disclosure. Three obligations started applying at once, and all three are behavioural rather than documentary — they change what a product does in front of a user, not just what sits in a compliance folder.

> Users must be clearly informed when they are not interacting with a real person, but an AI system, for example a chatbot, AI agent, and avatar.
> — [European Commission](https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en), 2026-08-02

Alongside that: deepfakes — images, video or audio generated or edited with AI — must be labelled, and AI-generated or altered content must carry machine-readable marks so it can be detected automatically. The Commission has produced a set of icons for the purpose. The machine-readable requirement is the technically consequential one, because it pushes provenance signalling down into the file rather than leaving it to a visible badge a screenshot removes.

> Certain AI-generated or manipulated content must be clearly and visibly labelled and include machine-readable marks.
> — [European Commission](https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en), 2026-08-02

Enforcement powers over general-purpose AI took effect at the same time, along with the penalty regime — up to €15 million or 3% of global annual turnover for companies, with proportionality provisions for SMEs and a separate ceiling of up to €750,000 for EU institutions. Those numbers sit below the GDPR's headline maximums, which is a deliberate calibration rather than an oversight: the Act's designers wanted deterrence without making European deployment commercially irrational.

## Who actually enforces it

This is where implementation gets harder than drafting. Enforcement is split three ways: national market surveillance authorities in each member state, the European AI Office centrally for general-purpose AI, and the European Data Protection Supervisor for EU institutions. Distributed enforcement is how the single market normally works, and it is also how the single market normally produces divergence — twenty-seven authorities with different resourcing, appetite and interpretation.

> **Key:** The practical question for any company shipping AI in Europe is no longer 'does the Act apply to us' but 'which authority will ask first, and what will it consider adequate'. Those are different questions with different answers in Dublin, Paris and Warsaw.

The AI Office has been staffing up accordingly, running a hiring round for around 40 posts dedicated to enforcing the Act. In September the Office and national data protection authorities began initiating technical audits on Article 11 technical files, and by 15 September providers of general-purpose AI above the 10^25 FLOPs training threshold were due to submit their first formal systemic risk evaluations — covering red-teaming methodology, energy disclosures and copyright training summaries.

## What is still coming

August 2026 is a milestone, not the finish line. The remaining schedule matters for anyone planning product roadmaps against it.

| Date | What applies |
| --- | --- |
| 2 August 2026 | Transparency rules, GPAI enforcement powers, penalties |
| 2 December 2026 | New prohibited practices |
| 2 December 2027 | Annex III high-risk systems |
| 2 August 2028 | Annex I product systems |

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — is already in force alongside this. Among the newer prohibitions, the 'nudifier' ban is drawn unusually broadly: it captures not only systems designed to produce non-consensual intimate imagery but also systems marketed without reasonable safeguards against that use, which shifts liability towards how a general-purpose tool is distributed rather than only what it was built for.

The wider context is divergence. The United States has moved in the opposite direction at federal level, with a June 2026 executive order establishing a voluntary framework for pre-release model access and a separate push to preempt state AI laws — while individual states legislate anyway. Europe is now the jurisdiction with binding, enforceable, generally applicable AI rules, which makes it the de facto compliance baseline for any product shipped globally. That is the Brussels effect working exactly as intended, and the thing to watch over the next year is whether the first enforcement actions are proportionate enough to make it stick.

## Key takeaways

- Enforcement of the AI Act began on 2 August 2026, run by the Commission's AI Office alongside national authorities.
- Chatbots must identify themselves as AI, deepfakes must be labelled, and generated or altered content must carry machine-readable marks.
- The penalty regime is live: up to €15 million or 3% of global annual turnover, with proportionality for SMEs.
- Enforcement is distributed across national market surveillance authorities, the European AI Office and the European Data Protection Supervisor.
- The next hard dates are 2 December 2026 for new prohibited practices, then December 2027 and August 2028 for high-risk systems.

## FAQ

### What changed on 2 August 2026 under the EU AI Act?
Transparency rules became enforceable: chatbots must disclose they are AI, deepfakes must be labelled, and AI-generated content must carry machine-readable marks. Enforcement powers over general-purpose AI and the penalty regime also took effect.

### What are the fines under the AI Act?
Up to €15 million or 3% of global annual turnover for companies, with proportionality for SMEs, and up to €750,000 for EU institutions.

### Who enforces the AI Act?
National market surveillance authorities in each member state, the European AI Office for general-purpose AI, and the European Data Protection Supervisor for EU institutions.

### Does the AI Act apply to companies outside the EU?
Yes, where AI systems are placed on the EU market or their output is used in the EU — which is why it functions as a global compliance baseline in practice.

### What are the next AI Act deadlines?
New prohibited practices on 2 December 2026, Annex III high-risk systems on 2 December 2027, and Annex I product systems on 2 August 2028.

## Sources

- [Commission starts enforcing AI Act rules and new transparency requirements on 2 August](https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august) — European Commission, 2026-08-02
- [Safer and more transparent AI](https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en) — European Commission, 2026-08-02
- [EU begins enforcing AI Act, putting AI models under the microscope](https://www.helpnetsecurity.com/2026/08/04/eu-ai-act-enforcement-ai-models/) — Help Net Security, 2026-08-04
- [Implementation Timeline — EU Artificial Intelligence Act](https://artificialintelligenceact.eu/implementation-timeline/) — EU Artificial Intelligence Act, 2026-08-02
