Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Breaking Regulation

EU AI Act Enforcement Is Live: Fines Now Real

From August 2, 2026 the EU can fine AI providers up to 3% of global revenue. Chatbots must say they're AI. Deepfakes must be labelled. Grace period is over.

Enterprise DNA | | via European Commission
EU AI Act Enforcement Is Live: Fines Now Real

The European Union’s AI Act entered its enforcement era on August 2, 2026. The theoretical compliance window closed. The fines are now real.

The European Commission’s AI Office, together with national market surveillance authorities across EU member states, activated its full enforcement powers last weekend. For any business using AI to interact with EU users, this is not a future concern. It is current operating reality.

What Changed on August 2

Three things became enforceable simultaneously:

Article 50 transparency obligations. Any AI-powered chatbot, voice agent, or interactive system deployed in the EU must now clearly tell users at the start of an interaction that they are dealing with AI, not a person. AI-generated or manipulated content, including deepfakes, must carry machine-readable labels that allow it to be detected. This applies regardless of where the deploying company is based, so long as EU residents are the end users.

GPAI enforcement powers. The AI Office now holds formal powers over providers of general-purpose AI models, meaning the foundation models that underpin most enterprise AI deployments. This covers documentation requests, technical evaluations of models, access to training data summaries, systemic risk assessments for high-compute models (above 10^25 FLOPs), and the ability to restrict or withdraw a model from the EU market.

Fines. The Commission can now issue penalties of up to the higher of 15 million euros or 3 percent of a company’s worldwide annual turnover for GPAI violations, and up to 35 million euros or 7 percent of global turnover for prohibited AI practices. The Commission confirmed in its press release that violations dating back to August 2025, when the first wave of GPAI obligations took effect, are in scope.

The Diplomatic Phase First

The AI Office’s preferred opening move is what it calls “technical compliance dialogues.” These are structured conversations with model providers and deployers to assess compliance status and clarify grey areas before formal proceedings begin. Think of it as an audit with a conversation before the subpoena.

That said, the dialogues do not pause the clock. Where they do not resolve concerns, the AI Office can escalate to formal enforcement at any point.

The eight foundation models that exceed the 10^25 FLOPs compute threshold are already submitting monthly systemic risk evaluations. Those providers have been under GPAI obligations since August 2025. The difference now is that the Commission could not issue fines during that first year. It can, retroactively, starting this month.

What Did Not Change

High-risk AI systems, which include applications in employment, credit scoring, law enforcement, and healthcare, got a reprieve. The Digital Omnibus, signed into EU law as Regulation 2026/1744 on July 27, extended the conformity assessment deadline for high-risk AI to December 2, 2027. This was a significant concession to industry, particularly smaller AI vendors who argued the original August 2026 deadline was unworkable.

AI models first released before August 2, 2025 have until August 2, 2027 to achieve full compliance, giving legacy deployments a managed runway.

What This Means for Business

If you are deploying AI that interacts with European customers or employees, there are practical steps to take now.

Disclosure on every interaction. Your chatbot, voice agent, or any other AI system that could reasonably be mistaken for a human must open with a clear AI disclosure. This is not optional and is not satisfied by a disclaimer buried in your terms of service.

Content labelling infrastructure. If you generate or modify video, audio, or images with AI, you need machine-readable watermarks or metadata. The standard is defined in the EU’s implementing acts, and national enforcement bodies are already building detection tooling.

Know your model stack. If your enterprise AI applications run on top of a foundation model provider, that provider is responsible for GPAI compliance. But you as the deployer are responsible for Article 50 and for ensuring you are not applying the model in prohibited ways. Supply-chain clarity matters now.

Document everything. The AI Office’s first formal enforcement action will set precedent. Companies that can demonstrate good-faith compliance efforts, documented policies, and active dialogue with regulators are in a substantially better position than those who cannot show the work.

The EU’s approach to AI is not the same as GDPR enforcement, which was slow to start and inconsistent. The AI Office was purpose-built for speed, with a dedicated technical team and direct access to member-state enforcement bodies. The first enforcement actions will likely focus on the most visible violations: chatbots that refuse to disclose they are AI and content providers generating unlabelled synthetic media at scale.

For Enterprise DNA clients building AI-powered products or internal deployments: the EU AI Act compliance question is no longer “when do we need to think about this?” It is “what is our current posture, and where are the gaps?” Getting that clarity now, before an enforcement dialogue lands in your inbox, is the work that matters.

Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

No spam. Unsubscribe any time.