AI policy
EU begins enforcing the AI Act
Transparency rules, GPAI powers and penalties applied from 2 August.
The answer
The EU began enforcing the AI Act on 2 August 2026, including transparency rules and penalties.
The European Commission's AI Office, together with national authorities, began enforcing the AI Act on 2 August 2026. New transparency rules applied from the same date.
Chatbots and other interactive AI systems will have to tell users they are dealing with AI, not a human.
Deepfakes must be labelled. AI-generated or altered content must carry machine-readable marks so it can be detected automatically. The Commission has issued a standard icon set for the purpose.
Penalties and enforcement
Fines run to €15 million or 3% of global annual turnover for companies, with proportionality for SMEs and up to €750,000 for EU institutions. Enforcement is divided between national market surveillance authorities, the European AI Office and the European Data Protection Supervisor.
The AI Office ran a hiring round for around 40 enforcement posts. In September it began technical audits on Article 11 technical files with national data protection authorities.
General-purpose AI providers above the 10^25 FLOPs threshold were due to submit first systemic risk evaluations by 15 September 2026, covering red-teaming methods, energy disclosures and copyright training summaries.
Timeline
| Date | Applies |
|---|---|
| 2 Aug 2026 | Transparency, GPAI enforcement, penalties |
| 2 Dec 2026 | New prohibited practices |
| 2 Dec 2027 | Annex III high-risk systems |
| 2 Aug 2028 | Annex I product systems |
Regulation (EU) 2026/1744, the Digital Omnibus on AI, is already in force. The forthcoming nudifier ban covers systems designed to create non-consensual intimate imagery and those marketed without reasonable safeguards against such use.
The Act applies to systems placed on the EU market or whose output is used in the EU, regardless of where the provider is established. That extraterritorial scope is why compliance work has been undertaken by US and Chinese providers as well as European ones.
The United States has moved differently. A June 2026 executive order established a voluntary framework for pre-release model access for cybersecurity and national security assessment, and a separate order seeks to preempt state AI laws. Individual states continue to legislate, producing regulatory divergence.
Brazil is voting on Bill 2338 and India is presenting an AI liability framework, leaving the EU as the only jurisdiction currently operating a comprehensive, enforceable AI regime.
Frequently asked questions
When did EU AI Act enforcement start?
What are the maximum fines?
What is the next deadline?
Sources
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission, 2 August 2026
- Safer and more transparent AI — European Commission, 2 August 2026
- EU begins enforcing AI Act, putting AI models under the microscope — Help Net Security, 4 August 2026
- Implementation Timeline — EU Artificial Intelligence Act — EU Artificial Intelligence Act, 2 August 2026