EU AI Act enforcement goes live — what companies must do now
On August 2, 2026 the European Commission’s AI Office and national authorities turned EU AI Act obligations from paper into enforceable powers. Providers of general‑purpose AI models face information requests, technical evaluations, and fines; deployers must also obey new transparency rules for synthetic content.
What changed — enforcement arrived on August 2, 2026
The EU moved from rule‑making to regulation: on August 2, 2026 the Commission’s AI Office, working with national market‑surveillance authorities, activated the AI Act’s enforcement machinery for transparency duties and the obligations that apply to general‑purpose AI (GPAI) model providers. The announcement set a clear dividing line: many duties for GPAI providers have existed since August 2025, but only now can authorities compel documents, demand model evaluations, order restrictions and impose administrative penalties. (malaniru.com)
How enforcement works in practice
The AI Office’s toolkit is procedural and technical. It can issue information requests and formal Commission decisions under Articles 90–92; require model access and run technical evaluations; request corrective measures including interim restrictions or recalls; and refer matters to national authorities for further action. Those signals matter because they are not symbolic — the Commission has already begun information‑gathering targeted at major providers. (dlapiper.com)
The first enforcement wave
In late August the AI Office issued formal requests for information to more than 30 GPAI providers, covering model security, independent red‑teaming and the documentation of training content and copyright policies. These are evidence‑gathering steps, not findings of wrongdoing, but they mark the point where documentation gaps become regulatory risk. (artificiallyconfident.com)
Enforcement has shifted from paper to teeth: Europe’s AI Office can now demand model internals, force evaluations and — if necessary — order restrictions that ripple through global vendor contracts.
Why this matters globally
The EU’s supervision of GPAI providers is the first large‑scale, cross‑border enforcement regime aimed at foundation models. The practical effects are immediate: vendors that sell models or APIs to EU customers must be able to produce technical documentation, training‑content summaries and evidence of red‑teaming and post‑deployment monitoring on short notice. Downstream deployers (platforms, enterprises, public bodies) must ensure the providers they rely on can deliver that evidence or face operational and contractual disruption. (eur-lex.europa.eu)
What the law can penalise — and how much it can cost
The AI Act sets tiered ceilings for administrative fines and enforcement outcomes. Member states must apply effective and dissuasive sanctions within those ceilings; for example, the Act contemplates high ceilings for prohibited practices and differentiated caps for GPAI obligations and information‑request failures. The overall design means non‑compliance can be financially material and reputationally public. (eur-lex.europa.eu)
Constraints and breathing room — the Digital Omnibus and grandfathering
The Commission and co‑legislators preserved transitional relief for specific high‑risk categories. The Digital Omnibus (Regulation (EU) 2026/1744) deferred some Annex III high‑risk timelines and gave a short compliance window for generative systems already on the market, but it did not spare Article 50 transparency duties or the AI Office’s GPAI supervisory powers that started on August 2, 2026. That means product teams have to reconcile staggered deadlines: some obligations are enforceable today, others have more time. (malaniru.com)
Winners, losers and market effects
- Compliance and audit firms, red‑teaming vendors and model‑ops tooling providers will see immediate demand as companies rush to create audit trails. (dlapiper.com)
- Cloud and API providers that can present standardized, machine‑readable documentation and attestations gain an edge in enterprise sales. (malaniru.com)
- Smaller open‑source projects and startups face a two‑edged problem: reputational benefit from transparency, but disproportionate compliance burden and legal uncertainty. (eur-lex.europa.eu)
Operational checklist — three immediate steps for CTOs and GC teams
- Inventory and evidence: assemble Article 53 technical documentation, training‑content summaries and red‑team reports in a governed evidence store. (eur-lex.europa.eu)
- Legal and contract hygiene: update provider‑to‑customer terms so model‑access and audit obligations are contractually supported across jurisdictions. (dlapiper.com)
- Response rehearsals: run a mock Article 91 information‑request exercise with counsel to practice accurate, time‑boxed replies and preserve privilege where appropriate. (gamingtechlaw.com)
Risks and open questions regulators still face
Enforcement exposes gaps in how EU law treats trade secrets, cross‑border data access (including Cloud Act exposure), and the technical durability of machine‑readable marks for synthetic content. There is also a practical enforcement tradeoff: aggressive supervision can produce quick compliance wins but risks chilling research or forcing model retirements if providers can’t produce retrospective artefacts. The Commission’s approach so far balances targeted information‑gathering with phased deadlines, but companies should assume the AI Office will escalate where documentation and governance are weak. (malaniru.com)
Bottom line — what to prioritize this quarter
Treat the AI Act as operational risk, not a distant policy. Start by certifying the factual basis of your documentation, hardening monitoring and incident‑reporting channels, and aligning commercial contracts so providers can satisfy EU information requests. Expect the AI Office to continue using information requests and targeted evaluations as its principal supervisory tools; prepare accordingly. (artificiallyconfident.com)
Further reading (primary sources and practical guides)
For legal text and Commission materials see the EU’s official regulation and the Commission press materials; for practical enforcement guidance consult legal‑firm briefings and specialist compliance trackers mentioned above. (eur-lex.europa.eu)
Sources
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August (IP/26/1714)
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex
- AI Act investigations: How to handle the first information requests — DLA Piper
- European Commission sends its first AI Act enforcement requests to more than 30 companies — Artificially Confident