The European Union's AI Act reached full general-purpose AI enforcement on August 2, 2026, banning manipulative and deceptive AI systems, imposing strict high-risk obligations, and exposing non-compliant providers to fines of up to 7% of global annual turnover. The milestone completes the Act's two-year phase-in, which began with prohibited-use rules in February 2025 and continues through 2027 for the highest-risk categories.
What Went Live on August 2
The August 2 enforcement milestone covers general-purpose AI (GPAI) providers, including OpenAI, Anthropic, Google DeepMind, and Meta AI. GPAI providers must publish a summary of training data, comply with EU copyright law (including the Copyright Directive's opt-out for text-and-data mining), and implement a copyright-compliance policy. Providers of GPAI models classified as posing "systemic risk" must additionally conduct model evaluations, adversarial testing, and serious-incident reporting.
High-risk AI systems, including those used in employment screening, credit scoring, biometric identification, critical infrastructure, and law enforcement, must comply with risk-management, data-governance, transparency, human-oversight, and accuracy requirements. August 2 was the deadline for bringing existing high-risk systems into compliance, with new high-risk systems requiring conformity assessment before deployment.
Enforcement and Penalties
National market-surveillance authorities in each EU member state are responsible for enforcement, coordinated through the new European AI Office in Brussels. Penalties for non-compliance scale with severity: prohibited-use violations carry fines of up to 35 million euros or 7% of global annual turnover, whichever is higher; other violations carry fines of up to 15 million euros or 3% of global turnover.
The European Commission published its first enforcement guidance on July 25, clarifying how the AI Office will prioritize cases in its first year. The guidance emphasizes "systemic risks to fundamental rights" and lists biometric categorization, emotion recognition in workplaces and schools, and social-scoring AI as priority enforcement targets. Several member-state authorities, including France's CNIL and Italy's Garante, have signaled that they will open investigations in Q4 2026.
Brussels Effect in Action
The AI Act is accelerating the Brussels Effect across global tech supply chains. Major U.S. AI providers have already begun publishing the training-data summaries required by the Act, even for products sold exclusively outside the EU. Cloud providers including Microsoft Azure and AWS have introduced "EU-compliant AI deployment" configurations that bundle model-evaluation and audit-log services for enterprise customers globally. Japan's August 26 AI training-data principles, while voluntary, are explicitly modeled on the EU framework.
The compliance burden is not uniform. Open-source AI providers, defined as providers releasing model weights under a free-and-open-source license, are exempted from most GPAI obligations. The exemption has prompted several foundation-model labs, including Mistral and Alibaba's Qwen team, to lean into open-source positioning. Critics argue that the exemption creates a two-tiered compliance regime that may concentrate systemic-risk obligations on a smaller set of providers.
What to Watch Through Year-End
Three checkpoints follow. The first formal enforcement action by a national market-surveillance authority, expected in Q4 2026, will be the first concrete signal of how aggressively the AI Office will use its penalty power. The European AI Office's first annual report on GPAI compliance, due in February 2027, will indicate how broadly the systemic-risk threshold has been applied. And the EU-US Joint AI Forum, expected to meet for the first time in October, will be the first test of whether the Brussels Effect can be reconciled with competing U.S. policy approaches.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.