AI Act Enforcement Has Started: What European Businesses Need to Do Now
AI Act Enforcement has entered a new phase in Europe. From 2 August 2026, the European Commission’s AI Office and Member State authorities have enforcement powers under the EU AI Act. At the same time, several obligations have already been in force for months or years, while others will take effect later.
For businesses developing, providing, or deploying AI, the important question is no longer whether the EU AI Act will be enforced. It is which obligations apply to each AI system, who is responsible for them, and whether the business can demonstrate how those obligations are being managed.
The timeline is phased. Prohibited AI practices and AI literacy obligations started applying on 2 February 2025. Governance rules and obligations for general-purpose AI models began applying on 2 August 2025. Enforcement powers for the AI Office and national competent authorities now apply from 2 August 2026, alongside the application of Article 50 transparency requirements. The rules for stand-alone high-risk AI systems covered by Annex III apply from 2 December 2027, while the rules for high-risk AI systems embedded in regulated products under Annex I apply from 2 August 2028.
That makes 2027 a preparation milestone, not a reason to wait. Businesses that start with their AI inventory, role classification, risk assessment, documentation, and evidence now will have more time to resolve gaps before the next major deadline.
What Does AI Act Enforcement Mean for European Businesses?
AI Act enforcement means that designated authorities can oversee compliance with applicable AI Act requirements, investigate potential violations, and take enforcement action within their areas of responsibility.
he enforcement structure is not handled by a single EU regulator. The European Commission’s AI Office has specific responsibilities for providers of general-purpose AI models, certain AI systems linked to those models, and AI systems integrated into designated very large online platforms or search engines. National competent authorities enforce the rules for other AI systems, while the European Data Protection Supervisor has responsibility for AI systems used by EU institutions.
This does not mean every European company will immediately face an inspection. It does mean the AI Act should no longer be treated as a distant compliance project.
The practical question has changed from:
Will the EU regulate AI?
to:
Which AI Act obligations apply to our systems, and can we demonstrate how we manage them?
That question matters not only to AI startups and SaaS companies but also to established businesses using AI in HR, customer service, finance, healthcare, software development, security, and other operational areas.
Why the AI Act Matters Beyond AI Developers
A common misconception is that the AI Act mainly affects companies building AI models.
The regulation applies across the AI value chain, with different responsibilities depending on whether an organization acts as a provider, deployer, or another operator covered by the Act.
For example, a company may use a third-party AI recruitment system internally while also providing an AI-powered SaaS product to its customers. Those activities can create different regulatory responsibilities.
The starting point should therefore be system-level visibility. Businesses need to know what AI systems they use or provide, what each system is intended to do, and the role they play in relation to it.
Which EU AI Act Obligations Apply Now?
Not every AI Act requirement became applicable at the same time. Businesses should separate obligations that are already in application from requirements with future application dates.
1. Prohibited AI Practices
The rules on prohibited AI practices have been in effect since 2 February 2025. The Commission’s current enforcement framework also notes that additional prohibitions concerning the generation or manipulation of non-consensual intimate material and child sexual abuse material apply from 2 December 2026.
The prohibited practices rules cover AI uses considered unacceptable because of their potential impact on fundamental rights and other protected interests.
Businesses should review AI use cases involving areas such as manipulation, exploitation of vulnerabilities, social scoring, or certain forms of predictive policing.
The practical starting point is not a generic policy. It is an inventory of the actual AI systems and use cases operating across the organization.
2. AI Literacy Requirements
Article 4 has been in effect since 2 February 2025. Providers and deployers must take measures to promote AI literacy among staff and others who use or operate AI systems on their behalf. The supervision and enforcement framework for this obligation takes effect in August 2026.
AI literacy should be connected to how people actually use AI.
A developer building an AI feature may need different knowledge from an HR employee using an AI recruitment tool. Training should therefore reflect the system, the person’s responsibilities, and the risks associated with its use.
Businesses should maintain records of:
- Which employees or teams use AI systems.
- What training or guidance they receive.
- Which systems or use cases the training covers.
- When training requirements need to be reviewed.
This makes AI literacy part of governance rather than a one-off training exercise.
3. General-Purpose AI Compliance
The obligations for providers of general-purpose AI models began applying on 2 August 2025. From 2 August 2026, the Commission’s enforcement powers for these obligations apply, including the ability to impose fines. GPAI models placed on the market before 2 August 2025 have a compliance deadline of 2 August 2027.
This distinction matters because not every company using a GPAI model becomes a GPAI model provider.
Businesses should determine whether they are:
- Providing a general-purpose AI model.
- Integrating a GPAI model into another AI system.
- Deploying a third-party AI service.
The applicable obligations depend on the organization’s role and the nature of the system.
4. Article 50 Transparency Requirements
Article 50 is one of the most immediate AI Act issues for businesses in 2026.Article 50 applies from 2 August 2026 and introduces transparency requirements for certain AI systems, including relevant interactive and generative AI systems and certain AI-generated or manipulated content.
Depending on the provision, requirements include:
- Informing people when they are directly interacting with an AI system.
- Applying machine-readable marking to certain AI-generated or manipulated content.
- Labelling applicable deepfakes.
- Providing disclosures for certain AI-generated or manipulated content.
There is a limited transition for certain AI systems placed on the market before 2 August 2026. For systems covered by Article 50(2), the marking and detection requirements for AI-generated content apply from 2 December 2026.
For businesses operating chatbots, generative AI products, synthetic media tools, or public-facing AI services, Article 50 should therefore be reviewed as a current product and operational requirement, not a future item on a compliance roadmap.
What Does the Annex III Deadline Mean?
The Annex III deadline is particularly relevant to businesses developing or deploying AI systems in high-risk use cases.
Under the amended timeline, the rules for high-risk AI systems covered by Annex III apply from 2 December 2027
. High-risk AI systems embedded in regulated products covered by Annex I have an extended date of 2 August 2028.
Annex III covers high-risk use cases across areas including:
- Biometrics
- Critical infrastructure
- Education and vocational training
- Employment and worker management
- Access to essential private and public services
- Law enforcement
- Migration, asylum and border control
- Administration of justice and democratic processes
he additional preparation time is useful, but businesses should not interpret the extension as a reason to postpone classification.
Why Businesses Should Not Wait Until 2027
The difficulty is usually not finding a single AI tool. The harder problem is understanding the full AI estate.
A growing organization may have AI embedded in recruitment software, customer-service platforms, development tools, marketing systems, security products, internal automation, and its own SaaS products.
Before applying the right compliance controls, it needs answers to basic questions:
- Which AI systems are actually in use?
- Who owns each system?
- What is each system intended to do?
- Is the organization a provider, deployer, or both?
- What risk category applies?
- Which obligations are relevant?
- What documentation is required?
- What evidence needs to be retained?
Starting this work shortly before a regulatory deadline creates unnecessary pressure. The better approach is to establish the underlying workflow while there is still time to test and improve it.
What European Businesses Should Do Now
1. Create an AI Inventory
Start with a complete view of the organization’s AI systems.
Include systems used in:
- HR and recruitment
- Customer support
- Marketing
- Finance
- Cybersecurity
- Software development
- Internal automation
- SaaS products
- Third-party business applications
At minimum, the inventory should capture the system, provider, intended purpose, business owner, users, data involved, deployment context, and current assessment status.
Without this information, risk classification and obligation mapping become guesswork.
2. Determine Provider and Deployer Roles
Businesses should establish whether they act as providers, deployers, or both.
A provider generally develops an AI system or has one developed and places it on the market or puts it into service under its name. A deployer uses an AI system under its authority.
The same organization can have different roles for different systems.
That distinction matters because the AI Act assigns different responsibilities to providers and deployers.
3. Classify AI Risk
Risk classification should be based on the AI system’s intended purpose and relevant context.
Businesses should determine whether a system may fall within:
- Prohibited AI practices.
- High-risk AI requirements.
- Article 50 transparency requirements.
- GPAI-related obligations.
- Other applicable AI Act provisions.
Classification should also be revisited when the system’s intended purpose, functionality, deployment context, or other relevant characteristics change.
4. Map Obligations to Each System
A single company-wide checklist is unlikely to reflect the obligations of every AI system.
A customer-service chatbot may require transparency controls, while an AI system used for recruitment may require a substantially broader set of high-risk controls if it falls within Annex III.
Businesses should therefore map obligations per system and per role.
This creates a clearer compliance workflow and makes it easier to assign ownership.
5. Maintain Documentation and Evidence
AI compliance is not demonstrated by having a single policy document.
Organizations should maintain records appropriate to the systems and obligations involved. These may include:
- System descriptions
- Risk assessments
- Technical documentation
- Human oversight procedures
- Training records
- Monitoring records
- Testing and evaluation evidence
- Vendor information
- Compliance decisions and approvals
The objective is to create a traceable record of how the organization assessed and managed its AI systems.
6. Establish Continuous Monitoring
AI systems do not remain static.
A model can be updated. A vendor can change its service. A company can introduce a new use case. An AI feature can move from an internal workflow into a customer-facing product.
Any of these changes can affect the compliance assessment.
Businesses should therefore establish a process for reviewing AI systems, updating classifications, tracking regulatory changes, and maintaining evidence throughout the AI lifecycle.
AI Act Enforcement and Business Compliance Priorities
| Priority | What businesses should do | Why it matters |
| AI inventory | Identify AI systems across the organization | Creates visibility into AI exposure |
| Role classification | Determine provider and deployer responsibilities | Helps assign applicable obligations |
| Risk assessment | Review prohibited, high-risk, transparency, and other relevant categories | Establishes the compliance scope |
| Article 50 review | Assess transparency requirements where applicable | Addresses current 2026 obligations |
| AI literacy | Train relevant employees and retain appropriate records | Supports responsible AI use |
| Documentation | Maintain system and compliance records | Supports traceability |
| Evidence management | Organize supporting evidence | Makes compliance easier to demonstrate |
| Monitoring | Review system and regulatory changes | Keeps assessments current |
| Annex III preparation | Start before December 2027 | Reduces deadline pressure |
Who Enforces the AI Act in Europe?
The AI Act uses a shared enforcement structure.The European Commission’s AI Office has responsibility for specific areas, including GPAI models and certain AI systems. National market surveillance authorities supervise and enforce the rules for other AI systems, including prohibitions and high-risk AI requirements. The European Data Protection Supervisor handles AI systems used by EU institutions.
This means businesses should not assume that AI Act compliance sits entirely with the legal or compliance department.
Product, engineering, IT, security, HR, procurement, compliance, and business owners may all contribute information or controls needed to manage an AI system.
What Are the Penalties for AI Act Violations?
The AI Act provides different maximum penalties depending on the type of infringement.
For prohibited AI practices, fines can reach €35 million or 7% of worldwide annual turnover, whichever is higher, subject to the applicable rules. Other breaches can carry lower maximums. Under the Commission’s current enforcement framework, certain GPAI-related breaches can result in fines of up to €15 million or 3% of worldwide turnover. Certain failures to respond to requests for information about AI systems can result in fines of up to €7.5 million or 1%
Article 50 violations can also result in significant penalties, with fines of up to €15 million or 3% of worldwide turnover. Proportionality may also be considered for SMEs and small mid-cap companies.
The practical risk is broader than the maximum fine. Poor AI governance can also create operational, contractual, reputational, and customer-trust problems.
Why AI Compliance Software Matters
Manual tracking becomes difficult when an organization has AI systems spread across departments, vendors, products, and development environments.
A spreadsheet can provide visibility for a small AI estate. It becomes less effective when teams need to connect individual systems with risk classifications, provider or deployer roles, obligations, documentation, evidence, and ongoing changes.
AI compliance software can support this workflow by bringing together:
- AI system discovery
- Risk classification
- Provider/deployer role assessment
- Obligation mapping
- Compliance documentation
- Evidence management
- Continuous monitoring
The goal is not simply to create another compliance database. It is to make AI governance part of the organization’s operating process.
What Should European Businesses Do in September 2026?
The immediate priority is to separate what applies now from what needs to be prepared for later.
A practical September 2026 action plan is:
- Build or update the AI inventory.
- Identify provider and deployer roles.
- Review prohibited AI practices.
- Assess Article 50 transparency requirements.
- Review AI literacy measures.
- Determine whether GPAI obligations apply.
- Identify potentially high-risk AI systems.
- Map applicable obligations to each system.
- Build documentation and evidence processes.
- Establish a process for ongoing monitoring and change management.
The December 2027 Annex III deadline gives organizations more time to prepare. It does not make preparation optional.
The businesses in the strongest position will be those that know their AI estate, understand their regulatory roles, and can show how decisions and controls are being managed.
How AnnexOps Helps European Businesses Prepare for AI Act Enforcement
AnnexOps is AI compliance software designed to help organizations operationalize their EU AI Act and GDPR requirements. It supports AI system discovery, risk classification, provider and deployer role assessment, obligation mapping, documentation, evidence management, and ongoing monitoring.
For businesses preparing for AI Act enforcement, the platform connects these activities into a structured compliance workflow rather than leaving teams to manage them across disconnected spreadsheets and documents.
Author: Nitin Grover
Nitin Grover is an AI compliance strategist and writer focused on EU AI Act compliance, AI governance, Annex IV documentation, AI risk management, and AI compliance operations for AI startups, SaaS companies, and enterprise AI teams across Europe.Ready to prepare for AI Act enforcement?
AI Act enforcement has started. The next step is knowing exactly which obligations apply to your AI systems. AnnexOps helps you assess AI risk, map obligations, manage documentation, and build audit-ready evidence.
