BusinessIndustry Guide12 min readPublished August 3, 2026

GPAI enforcement live · high-risk tier deferred to Dec 2027 · roughly a third to half of member states staffed

EU AI Act Enforcement Begins: Penalties and Powers

On August 2, 2026, the EU AI Office gained the power to investigate and fine general-purpose AI providers, prohibited-practice penalties became exercisable, and Article 50 transparency duties took effect. But the Digital Omnibus quietly deferred the headline high-risk tier to December 2027 — which makes day-one enforcement quieter, narrower, and easier to misread than most coverage suggests.

DA
Digital Applied Team
Senior strategists · Published August 3, 2026
PublishedAugust 3, 2026
Read time12 min
SourcesAct text · law-firm alerts
Prohibited-practices cap
€35M
or 7% of global turnover
Art. 99
GPAI-provider cap
€15M
or 3% of global turnover
Art. 101
Annex III high-risk duties
Dec 2027
deferred by Digital Omnibus
was Aug 2026
Authorities designated
9–13/27
member states, trackers differ

EU AI Act enforcement formally began on August 2, 2026 — but not the enforcement most headlines describe. What activated is the European Commission’s power, exercised through the EU AI Office, to investigate and fine general-purpose AI model providers, plus exercisable penalties for prohibited AI practices and new Article 50 transparency duties for chatbots, synthetic media, and deepfakes.

What did not activate is the tier that dominated two years of compliance planning: the high-risk system obligations covering hiring tools, credit scoring, and education. The Digital Omnibus — Regulation (EU) 2026/1744, in force since July 27, 2026, roughly a week before enforcement day — deferred those duties to December 2, 2027. Misreading which track your systems sit on leads to over-reacting in one direction or sleepwalking in the other.

This guide maps the enforcement machinery itself: the penalty tiers and the two distinct fining articles, who actually enforces what, the complaint paths, and what day-one enforcement realistically looks like given that only a fraction of member states have staffed their side. It is deliberately not another compliance checklist — for that, see the risk-tier compliance checklist and the broader EU compliance guide.

Key takeaways
  1. 01
    August 2 activated enforcement, not new duties.The EU AI Office can now investigate and fine GPAI providers for obligations that have applied since August 2025, prohibited-practice penalties are exercisable, and Article 50 transparency applies. The underlying rulebook did not change on the day.
  2. 02
    The high-risk tier is deferred — that is the story.The Digital Omnibus (Regulation (EU) 2026/1744, in force July 27, 2026) pushed Annex III stand-alone high-risk obligations to December 2, 2027 and Annex I embedded systems to August 2, 2028. High-risk duties are not enforceable today.
  3. 03
    Two penalty tracks are routinely conflated.Article 99 sets the general tiers — €35M/7% for prohibited practices, €15M/3% for most operator duties, €7.5M/1% for misleading authorities. GPAI providers face a separate, lower Article 101 cap of €15M or 3% — not the €35M figure often reported.
  4. 04
    Enforcement is split three ways, and thinly staffed.The AI Office covers GPAI models and very-large-platform AI; national market surveillance authorities cover everything else; the EDPS covers EU institutions. Roughly a third to half of member states had designated authorities as of mid-2026 — two trackers disagree on the exact count.
  5. 05
    Process offences are freestanding exposure.Refusing an information request, answering misleadingly, or blocking a model evaluation is independently fineable — no underlying substantive breach required. And the reach is extraterritorial: non-EU providers need an EU-based authorised representative.

01Day OneWhat actually switched on August 2.

Strip away the “AI Act enforcement day” framing and three specific things went live. First, per Wilson Sonsini’s client alert, the Commission — acting through the EU AI Office — became formally entitled to exercise investigative and enforcement powers over general-purpose AI model providers and the prohibited-practices rules. The GPAI obligations themselves have applied since August 2, 2025; what is new is the teeth. Second, penalties for Article 5 prohibited practices — social scoring, manipulative systems — became exercisable. Third, Article 50 transparency duties took effect for chatbots, synthetic content, deepfakes, and emotion-recognition systems.

Track 1
Prohibited practices
Article 5 · penalised via Article 99

The bans on practices like social scoring and manipulative systems were already on the books. What day one changes is that the penalty machinery for breaching them is now exercisable — at the Act's highest fine tier.

Cap: €35M or 7% of turnover
Track 2
GPAI enforcement
Articles 91–93 powers · Article 101 fines

Obligations for general-purpose AI providers have applied since August 2025. The one-year grace period was on enforcement, not on the duties — and it just expired. The AI Office can now request information, run model evaluations, order mitigations, and fine.

Cap: €15M or 3% of turnover
Track 3
Article 50 transparency
Chatbots · synthetic media · deepfakes · emotion AI

Disclosure and marking duties apply from August 2, 2026 to in-scope systems regardless of when they shipped, with one narrow transition for machine-readable marking on pre-existing systems (December 2, 2026).

Cap: €15M or 3% of turnover

The named-company framing matters here. CNBC’s enforcement-day coverage put Anthropic, OpenAI, and Google at the front of the new scrutiny — frontier labs whose models fall squarely into the GPAI category the AI Office now polices. The backdrop is already tense: EU regulators fined Google $1 billion in July 2026 in a separate Digital Markets Act case — not an AI Act action — which drew a tariff threat from President Trump. AI Act enforcement now unfolds inside that wider EU–US friction.

"Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale."— Henna Virkkunen, Executive Vice-President, European Commission, via CNBC

02The Digital OmnibusThe high-risk tier got a 16-month reprieve.

The Digital Omnibus on AI is now law: Regulation (EU) 2026/1744. Council and Parliament reached political agreement on May 7, 2026; the text was published in the Official Journal on July 24 and entered into force on July 27 — three days after publication, and roughly a week before AI Act enforcement day arrived. Its timing is the whole point: the postponement took legal effect before the deadline it postponed.

The substance, per Gibson Dunn’s analysis: stand-alone high-risk AI systems under Annex III — employment and HR screening, education, credit scoring, law-enforcement-adjacent uses — moved from August 2, 2026 to December 2, 2027. High-risk systems embedded in regulated products under Annex I, such as medical devices and machinery, moved from August 2, 2027 to August 2, 2028. Wilson Sonsini’s alert makes the complementary point explicit: the Omnibus postponed the Act’s principal high-risk requirements but does not affect any of the August 2, 2026 developments covered in this guide.

The correction that is the story
Much of the enforcement-day coverage frames August 2 as the moment “the AI Act became enforceable.” It did not — not for the high-risk tier. High-risk obligations are not enforceable today: Annex III duties land December 2, 2027 and Annex I duties August 2, 2028. What is enforceable now is what was already in force — prohibited practices, GPAI obligations, and Article 50 transparency. Plan against the track your systems are actually on.

03Penalty TiersArticle 99, Article 101, and the conflation trap.

The Act runs two distinct penalty tracks, and press coverage routinely merges them. Article 99 sets the general framework in three tiers: up to €35 million or 7% of global annual turnover — whichever is higher — for prohibited AI practices; up to €15 million or 3% for breaches of most other operator obligations, including Article 50 transparency; and up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities or notified bodies.

EU AI Act maximum fines · by penalty article and conduct

Source: Articles 99 and 101, Regulation (EU) 2024/1689
Prohibited practices — Art. 99Article 5 violations · whichever is higher
€35M / 7%
Most operator obligations — Art. 99Includes Article 50 transparency · whichever is higher
€15M / 3%
GPAI model providers — Art. 101Separate Commission-enforced cap · whichever is higher
€15M / 3%
Misleading information — Art. 99Incorrect or incomplete answers to authorities
€7.5M / 1%

The track that matters for frontier labs is Article 101: a GPAI-provider-specific cap of 3% of global annual turnover or €15 million, whichever is higher. Triggering conduct includes infringing the GPAI obligations, failing to respond accurately to an Article 91 information request, ignoring Article 93 risk-mitigation measures, or blocking Commission access for model evaluations. Beam.ai’s enforcement analysis explicitly flags the €35M/7% figure as commonly mis-attributed to GPAI providers — the higher tier belongs to prohibited practices, not to model-provider obligations.

Two structural softeners are worth knowing. For SMEs and startups, each Article 99 fine is capped at the lower of the percentage or the fixed euro amount — the inverse of the rule for larger undertakings. And Article 101 fines come with procedural safeguards: the Commission must communicate preliminary findings and give the provider a chance to respond before finalizing a decision, the EU Court of Justice holds unlimited jurisdiction to cancel, reduce, or increase a fine, and imposed fines are reported to the European Artificial Intelligence Board. National fining powers carry their own gate — each member state had to lay down proportionate, dissuasive penalty rules by August 2, 2025 and must report annually to the Commission on fines imposed.

04Enforcement MapWho enforces what — and at what cap.

Enforcement authority splits three ways by system and actor type, per the Commission’s enforcement-framework page. The EU AI Office, inside the Commission, enforces GPAI model rules, AI systems built by GPAI providers on their own models, and AI integrated into very large online platforms and search engines. National market surveillance authorities enforce everything else — including most high-risk systems once their compliance dates arrive, and Article 50 transparency for non-GPAI deployers. The European Data Protection Supervisor covers AI systems used by EU institutions themselves. The table below maps obligation to enforcer, penalty basis, cap, and — critically — whether it is actually live.

EU AI Act enforcement map as of August 2, 2026: obligation area, enforcing authority, governing penalty article, maximum fine, and live-or-postponed status. Compiled from Articles 99 and 101 of Regulation (EU) 2024/1689, the European Commission enforcement-framework page, and Wilson Sonsini and Gibson Dunn client alerts on the Digital Omnibus (Regulation (EU) 2026/1744).
ObligationWho enforcesPenalty basisMaximum fineStatus on Aug 2, 2026
Live — enforcement powers exercisable
Prohibited AI practices (Art. 5) — social scoring, manipulative systemsNational market surveillance authorities; AI Office powers where GPAI providers are involvedArt. 99€35M or 7% of global turnoverPenalties exercisable from Aug 2, 2026
General-purpose AI model obligationsEU AI Office (Commission)Art. 101€15M or 3% of global turnoverDuties since Aug 2025; investigation and fining powers live Aug 2, 2026. Pre-Aug-2025 models: runway to Aug 2, 2027
Article 50 transparency — chatbot disclosure, synthetic-content marking, deepfake labels, emotion-recognition noticeNational authorities; AI Office for GPAI providers’ own systemsArt. 99€15M or 3% of global turnoverLive Aug 2, 2026; machine-readable marking for pre-existing systems has until Dec 2, 2026
Incorrect, incomplete, or misleading information to authorities or notified bodiesThe requesting authorityArt. 99 (Art. 101 for GPAI providers)€7.5M or 1% of global turnoverLive — an independent offence, no underlying breach required
Postponed by the Digital Omnibus (Reg. (EU) 2026/1744)
High-risk systems, Annex III (stand-alone) — employment screening, education, credit scoringNational market surveillance authorities (once live)Art. 99€15M or 3% (operator-obligation tier)Postponed: Aug 2, 2026 → Dec 2, 2027
High-risk systems embedded in regulated products, Annex I — medical devices, machineryNational market surveillance authorities (once live)Art. 99€15M or 3% (operator-obligation tier)Postponed: Aug 2, 2027 → Aug 2, 2028

One actor is missing from the table because it polices a different population: the European Data Protection Supervisor, which supervises AI systems used by the EU’s own institutions. For businesses, the operative split is AI Office versus national authority — and which one knocks depends on whether you are a GPAI provider, a platform at very-large scale, or an ordinary deployer.

05GPAI MachineryThe AI Office’s new teeth.

For general-purpose model providers, the AI Office’s toolkit is now fully exercisable, per Wilson Sonsini and the Commission’s framework page:

  • Information requests (Article 91) — demand documentation and answers from providers.
  • Model evaluations (Article 92) — obtain access to the model itself to conduct evaluations.
  • Corrective measures (Article 93) — require risk-mitigation steps, and in serious cases request that a provider restrict, withdraw, or recall a model from the EU market.
  • Fines — up to the Article 101 cap of €15 million or 3% of global turnover.

The subtlety practitioners keep underlining is that the process itself is the exposure. Elisabetta Righini, a partner at Sidley Austin, told CNBC that “A U.S. address does not put a lab outside the EU regulator’s reach” — any company offering a GPAI model in the EU is in scope regardless of where it is based, and non-EU providers must appoint an EU-based authorised representative as the regulator’s point of contact.

"What's rarely appreciated is that GPAI liability isn't limited to substantive breaches: refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own."— Elisabetta Righini, Partner, Sidley Austin, to CNBC

In practice, the AI Office says its preferred opening move is not a fine at all. Its stated initial tool is the technical compliance dialogue — informal engagement to assess compliance and resolve questions — which the Office says will continue and may intensify after August 2, with formal powers reserved for cases dialogue does not resolve. Two more scoping details matter. Models placed on the market before August 2, 2025 have a longer runway — until August 2, 2027 — to reach full compliance, which shapes which models are genuinely exposed today. And the named labs have stayed conciliatory in public: OpenAI’s VP of EMEA policy, Tom Duff Gordon, told CNBC the company has collaborated closely with the Commission on implementing the Act and its Codes of Practice, while a Google spokesperson said the company remains dedicated to meeting all applicable rules as the Act and its codes take effect.

GPAI Code of Practice · signatories as of June 2026
Per Beam.ai’s analysis of the Commission’s signatory list (published June 23, 2026 — status can change), the GPAI Code of Practice’s Transparency, Copyright, and Safety and Security chapters were signed in full by Anthropic, Google, Microsoft, OpenAI, IBM, Mistral AI, Cohere, and Amazon. xAI signed only the Safety and Security chapter; Meta declined entirely, citing legal uncertainty. Signing confers a presumption of conformity for the matching chapters — non-signers must demonstrate compliance by other adequate means. Adherence is not a fine-immunity shield, but the AI Office has said it will weigh it as a mitigating factor when assessing penalties.

06TransparencyArticle 50, briefly.

The transparency tier deserves its own playbook — and has one, in the Article 50 checklist for agencies — so here is only the enforcement-relevant shape. Four duty categories applied from August 2, 2026: AI systems that interact directly with people (chatbots, voice assistants, AI agents) must disclose the interaction is with AI unless obvious from context; systems generating synthetic audio, image, video, or text must mark outputs in a machine-readable, detectable way; deployers of deepfakes and AI-generated text on public-interest matters must disclose the AI origin; and emotion-recognition or biometric-categorization deployers must inform exposed individuals.

The duties apply to in-scope systems regardless of when they were placed on the market — content published before August 2 does not need retroactive labeling, and the only transition is for the machine-readable-marking duty on systems already on the market, which have until December 2, 2026. Breaches sit in Article 99’s €15M/3% tier. On the compliance-support side, the Commission’s enforcement announcement notes that over 180 organizations have signed the voluntary Code of Practice on transparency of AI-generated content — a separate instrument from the GPAI Code above — which the Commission endorses as an adequate way to demonstrate marking and labeling compliance. For the implementation mechanics in an ad pipeline, see our provenance-marking guide for ad creative.

07Readiness GapLegal power is not practical capacity.

Member states were legally required to designate their national competent authorities and single points of contact by August 2, 2025 — a full year before enforcement day. They did not all make it, and the two independent trackers that count disagree on how short the field fell, because they use different completeness criteria. The honest summary: somewhere between a third and half of member states had their enforcement side in place as of mid-2026.

FLI tracker · Jun 17, 2026
Fully designated
9/27

The Future of Life Institute's implementation tracker counts a state only when BOTH the market surveillance authority AND the notifying authority are designated. Twelve states were partial; six had designated neither.

Strictest criteria
regulatoryai.eu · mid-2026
Designated in law
13/27

The same window, looser criteria — counting enactment. Spain, Italy, Denmark, Finland, Sweden, Portugal, and Romania are among the 13; ten states sat at draft-bill stage; four had not started designating.

Looser criteria
Both trackers · mid-2026
No authority named
4–6/27

Austria, Bulgaria, Croatia, and Greece appear in regulatoryai.eu's 'to be designated' bucket; FLI's stricter count puts six states at neither authority designated. Businesses there face a regulator that does not exist yet.

Varies by tracker

Two things stop this from being a free pass. First, the Act applies to providers and deployers regardless of national enforcement readiness — the gap creates no exemption, only uneven near-term enforcement intensity. A company operating from Spain or Italy faces a materially different practical environment than one in Austria or Greece, for now. Second, the Commission’s own channels are already open: an AI Act Complaint Tool for alleged infringements by supervised providers, an AI Act Whistleblower Tool for professionals connected to providers, and a Downstream Provider Complaints Channel for issues with integrated GPAI models. Under Article 85, any natural or legal person — not only those directly harmed — may lodge a complaint with a market surveillance authority. And the same August 2 deadline required every member state to have at least one operational AI regulatory sandbox — a compliance-support mechanism running in parallel with enforcement, not an enforcement power.

08PlaybookWhat to do now, by exposure.

The right response depends entirely on which enforcement track you are on. Four postures cover most businesses:

Frontier + GPAI providers
Answer the mail

The near-term exposure is procedural: information requests, evaluation access, mitigation orders. Refusing or misleading is independently fineable. Appoint the EU authorised representative, engage the compliance dialogues, and treat Code of Practice adherence as documented mitigation.

Engage the AI Office
Agencies + marketing teams
Article 50 is live

Chatbot disclosure, synthetic-content marking, and deepfake labels apply now, at the €15M/3% tier. The marking transition to December 2, 2026 covers only pre-existing systems, and only the machine-readable-marking duty. Instrument the pipeline this quarter.

Comply now
Annex III-adjacent builders
Use the runway

HR screening, credit-adjacent gating, and education systems got until December 2, 2027 — a deferral, not a repeal. Classify your systems now, close documentation gaps on the calm timeline, and avoid rediscovering the deadline in late 2027.

Classify, then pace
Non-EU businesses selling in
Map your exposure

Scope is extraterritorial: offering a GPAI model or in-scope system in the EU puts you in reach regardless of where you are based. Work out which track each product is on and whether you need an EU representative before a regulator asks.

Audit your footprint

Reading the machinery as a whole, the near-term pattern is dialogue-first, process-offence-second: the AI Office says it prefers technical compliance dialogues, which means the earliest real tests are likely to be about how completely and honestly providers answer Article 91 requests — not about headline substantive breaches. Layer on the staffing gap and the picture is an enforcement regime that is legally live everywhere but practically concentrated: strongest at the Commission level over a small set of frontier labs, patchy at national level, and varying sharply by member state.

Looking forward from here, three dates structure the next eighteen months: December 2, 2026, when the marking transition for pre-existing systems closes; August 2, 2027, when pre-Aug-2025 GPAI models must reach full compliance; and December 2, 2027, when the Annex III high-risk tier finally lands. Enforcement day also reframes procurement — “where does my AI run and who is liable” is now a purchasing question, which is exactly the calculus behind the sovereign-AI decision framework. If your systems touch scoring or screening, start with the lead-scoring risk-classification walkthrough; US-based teams should read what US businesses need to do. And if you want the classification and compliance work folded into how your AI systems are actually built, that is what our AI transformation engagements are for.

09ConclusionQuieter, narrower, and still real.

Enforcement day, correctly read

The powers switched on. The headline tier did not.

August 2, 2026 was enforcement day for a narrower slice of the AI Act than most coverage implied: the AI Office’s investigatory and fining powers over general-purpose AI providers, exercisable penalties for prohibited practices, and Article 50 transparency. The high-risk tier that dominated two years of compliance planning was deferred to December 2027 by a regulation that took effect just days earlier — the Digital Omnibus is, in a real sense, the story of day one.

The penalty structure rewards precision. Two articles, two caps — €35M/7% for prohibited practices under Article 99, €15M/3% for GPAI providers under Article 101 — and an enforcement split across the AI Office, national authorities, and the EDPS, with somewhere between a third and half of member states staffed for it. The most underrated exposure is procedural: answering a regulator incompletely is a fineable offence on its own.

The practical move is to place every AI system you provide or deploy on the right track — live now, live December 2026, live December 2027, or live 2028 — and pace the work accordingly. Businesses that over-react to the deferred tier waste a year; businesses that under-react to the live tiers are betting against a regulator that just spent a year building its case-handling muscle before switching it on.

Build compliance-aware AI

Enforcement rewards teams whose compliance is built in, not bolted on.

Our team builds AI systems with EU AI Act classification, transparency instrumentation, and documentation designed in from day one — for marketing, CRM, and operations workloads, delivered in days not quarters.

Free consultationExpert guidanceTailored solutions
What we work on

Regulation-ready AI engagements

  • AI Act track classification across your system inventory
  • Article 50 transparency instrumentation for content pipelines
  • GPAI vendor and Code of Practice exposure reviews
  • Sovereignty-aware model and hosting selection
  • Documentation and audit-trail design for December 2027
FAQ · EU AI Act enforcement

Enforcement questions, answered.

Three things. The European Commission, acting through the EU AI Office, became formally entitled to exercise investigative and enforcement powers over general-purpose AI model providers and the prohibited-practices rules — the GPAI obligations themselves have applied since August 2, 2025, but enforcement capability was held back a year. Penalties for Article 5 prohibited practices, such as social scoring and manipulative systems, became exercisable. And Article 50 transparency obligations — chatbot disclosure, machine-readable marking of synthetic content, deepfake labeling, and emotion-recognition notice — took effect. The same date also required every member state to have at least one operational AI regulatory sandbox. What did not activate is the high-risk system tier, which the Digital Omnibus deferred.
Related dispatches

Continue exploring AI regulation.