The EU AI Act: Enforcement Is No Longer Theoretical (Part I of II)

For years, compliance officers could talk about the EU AI Act as a looming, mostly future obligation, something to plan for rather than something actively enforced. That era is over. As of August 2, 2026, the European Commission, acting through its European AI Office, holds formal investigative and enforcement authority over general-purpose AI model providers and over the Act’s prohibited AI practices, and the agency has already used it. This is Part 1 of a two-part series on where EU AI Act enforcement actually stands today. Part 2 will get into what the Digital Omnibus changed, the current compliance timeline, and what companies operating in or selling into the EU need to be doing right now.
Prohibited Practices Have Been Live Since Early 2025
It’s worth remembering that not all of the AI Act’s obligations arrived at once. The Act’s outright bans on certain AI practices, manipulation of individuals, exploitation of vulnerabilities, unfair biometric or social scoring in ways that threaten fundamental rights, and predictive policing based solely on individual profiling, have already been in force since February 2025. That means the prohibition regime has had well over a year to mature before the Commission gained its full enforcement toolkit, and any company still operating an AI system that arguably falls into one of these prohibited categories has been out of compliance for a meaningful stretch of time already, not just since August.
GPAI Obligations Have Also Been Running Since Last Summer

General-purpose AI model providers, the companies building the large foundation models that power a huge share of downstream AI applications, have been subject to their own set of obligations since August 2025: transparency requirements toward downstream providers, respect for copyright in training data, and, for the most advanced models, additional security and safety obligations. Notably, eight foundation models that exceed the regulatory compute threshold of 10^25 FLOPs are already required to submit monthly systemic risk evaluations to regulators, an ongoing reporting obligation rather than a one-time certification. If your organization builds on top of, fine-tunes, or heavily customizes one of these frontier models, you need to understand which obligations flow down to you as a downstream provider, because the Act’s transparency requirements are specifically designed to pass certain disclosures through the supply chain.
The Commission Has Already Opened Investigations
This is the detail that should change how every compliance officer thinks about this regulation: enforcement isn’t hypothetical anymore. The EU AI Office opened its first round of formal investigations back in June 2026, targeting AI systems deployed across European markets in three specific categories: hiring tools, credit scoring systems, and student monitoring applications. That’s a deliberately chosen starting point, all three categories involve AI systems making or materially influencing decisions about individuals in ways that directly implicate fundamental rights, exactly the kind of use case the Act was built to scrutinize most closely.
Since the Commission’s formal enforcement powers activated in August, the AI Office now has the authority to request information and technical documentation, obtain direct access to models for evaluation, require corrective or risk-mitigation measures, and impose fines. For general-purpose AI model violations, those fines can reach the higher of 15 million euros or 3 percent of the provider’s global annual turnover. For violations of the prohibited practices provisions, the exposure is significantly higher: up to 35 million euros or 7 percent of worldwide turnover. For a large multinational technology or AI company, 7 percent of global revenue is not a rounding-error penalty; it’s a figure capable of reshaping a company’s entire risk calculus around AI deployment in the EU market.

Transparency Obligations Now Apply Broadly, Regardless of Where You’re Based
One of the most operationally significant obligations now in force involves AI transparency toward end users. Any AI-powered chatbot, voice agent, or interactive system deployed to EU users must clearly disclose, at the start of the interaction, that the user is dealing with an AI system rather than a human being. AI-generated or manipulated content, including deepfakes, must carry machine-readable labels identifying it as synthetic. Critically, this obligation applies based on where the end users are located, not where the deploying company is headquartered. A U.S. company with no EU physical presence but with EU residents using its AI-powered customer service chatbot or content-generation tool is squarely within scope of this requirement.
Why This Matters Even If High-Risk Systems Got a Deadline Extension
Part 2 of this series will cover the Digital Omnibus in detail, but it’s worth flagging now that the compliance deadline for high-risk AI systems under Annex III has been pushed back significantly, to December 2027. Some compliance teams have understandably read that extension as a reason to deprioritize EU AI Act work generally. That reading is a mistake. The deadline extension applies specifically to the high-risk use-case category. It does nothing to change the fact that prohibited practices have been enforceable for well over a year, that GPAI obligations have been running since last August, that transparency requirements for AI chatbots and synthetic content are live now, and that the Commission has already opened investigations and holds real fining authority today. Treating the entire AI Act as deferred because one specific compliance track got more runway is exactly the kind of mistake that turns into an enforcement action.











