Who this is for: in-house counsel, external counsel and compliance officers advising businesses that deploy AI systems on the EU market.
Purpose: explain what became applicable on 2 August 2026, what remains deferred, the enforcement and penalty regime, and the practical steps deployers should take now.
Read time: ~12 minutes. Last updated: August 2026.
The eu ai acts main obligations penalty framework moved from theory to enforceable reality when a substantial tranche of Regulation (EU) 2024/1689 became generally applicable on 2 August 2026. From that date, transparency duties, the governance architecture, the supervisory role of the EU AI Office and the headline penalty ceilings all became operative across the Union. For counsel advising deployers, the businesses that use AI systems rather than build them, this milestone shifts compliance from a roadmap exercise to a live legal exposure.
The primary text is Regulation (EU) 2024/1689, the AI Act, the EU’s comprehensive horizontal regulation governing artificial intelligence. The Regulation entered into force on 1 August 2024 and phases in over several years. The 2 August 2026 date marks the point at which the bulk of its operative provisions became generally applicable, giving the eu ai acts main obligations penalty regime real legal teeth for organisations operating in or into the EU.
As of that date, the following categories of provision are active:
Certain earlier-phase provisions were already applicable before this milestone: the prohibitions on certain AI practices and the AI literacy obligations became applicable from 2 February 2025, and the obligations relating to general-purpose AI models applied from 2 August 2025. The August 2026 milestone reinforces the overall enforcement architecture. For most commercial deployers, the practical significance lies in the transparency and governance obligations that now bite on everyday AI use.
Not everything is live. A commercially significant carve-out concerns high-risk AI systems that are embedded in products already regulated under EU harmonisation legislation (listed in Annex I). For those systems, the corresponding obligations apply from 2 August 2028, giving manufacturers and their downstream deployers a longer transitional window. Other high-risk systems listed in Annex III generally fall due from 2 August 2027. Understanding which of your systems benefit from these deferrals, and which do not, is a threshold question for any compliance plan.
The Regulation distinguishes carefully between roles, and the eu ai acts main obligations penalty regime allocates duties accordingly. A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer is a natural or legal person using an AI system under its authority in the course of a professional activity. Many businesses will be deployers even where they never touch a line of model code, for example, an enterprise integrating a third-party generative model into a customer-service chatbot.
The distinction matters because obligations, and therefore liability, follow the role. Providers carry the heaviest documentation and conformity burdens; deployers carry transparency, oversight and use-related duties. In practice, most organisations occupy both roles across different systems, which is why an accurate system-by-system role assessment is the foundation of any credible compliance posture.
The AI Act reaches beyond the borders of the Union. Non-EU companies fall within scope where they place AI systems on the EU market, put them into service in the Union, or where the output produced by their systems is used within the Union. A US software vendor offering an AI-enabled SaaS product to European customers is therefore squarely in scope, as is a non-EU deployer whose AI outputs are used inside the EU. The answer to the common question, does the EU AI Act apply to the US? , is that it can apply to any organisation, regardless of establishment, whose AI activities touch the EU market or produce effects within it.
Cross-border groups should not assume that lack of an EU establishment removes their exposure to the eu ai acts main obligations penalty regime.
The obligations that most immediately affect deployers cluster around transparency and internal governance. These are the duties that generate day-one compliance work and, if neglected, the most predictable enforcement exposure under the eu ai acts main obligations penalty framework.
Article 50 introduces layered disclosure duties. Where an AI system is intended to interact directly with people, those people must be informed that they are dealing with an AI system unless it is obvious from the circumstances. Where a system generates or manipulates image, audio, video or text content, providers must ensure outputs are marked in a machine-readable format as artificially generated or manipulated, subject to certain exceptions. Deployers of systems producing deepfakes must disclose that the content has been artificially generated or manipulated, and deployers publishing AI-generated text on matters of public interest carry specific disclosure duties, again subject to exceptions.
Beyond user-facing transparency, deployers should build the internal scaffolding that demonstrates compliance. That means assigning clear internal ownership for AI governance, maintaining documentation of the systems in use and their classification, and establishing processes to monitor system behaviour and respond to serious incidents. AI literacy is also a live obligation: under Article 4, providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others dealing with AI systems on their behalf. Record-keeping is not merely good practice, it is the evidence that will inform your position if a competent authority opens an inquiry under the eu ai acts main obligations penalty regime.
Deployers depend on upstream providers for much of the information they need to comply. Contractual due diligence is therefore central. When contracting for AI systems, deployers should seek:
The AI Act’s most demanding regime applies to high-risk AI systems. These attract obligations covering risk management, data governance, technical documentation, human oversight, accuracy, robustness and cybersecurity. High-risk systems fall into two broad categories: those listed in Annex III (such as certain systems used in employment, education, essential services and law enforcement), for which obligations generally apply from 2 August 2027; and those that are safety components of, or are themselves, products covered by EU harmonisation legislation listed in Annex I, for which the corresponding obligations apply from 2 August 2028.
Typical examples of the second category include AI components integrated into medical devices, in-vitro diagnostic devices and machinery, and other products whose safety is already regulated under sectoral EU legislation. The rationale is to align the AI conformity pathway with the existing product-safety conformity assessment framework, avoiding duplicative and misaligned deadlines. The deferral is a transitional accommodation, not an exemption: the obligations will apply in full from the applicable date, and the volume of work required, from risk assessment through technical documentation to conformity procedures, is substantial.
Deployers should not treat the 2027 and 2028 deadlines as distant. The lead time to gather documentation, negotiate contractual support from manufacturers and integrate governance controls is long. Sensible steps include:
The penalty structure is tiered by the seriousness of the breach, and the ceilings are calibrated to be capable of affecting even the largest global operators. Under Article 99, the eu ai acts main obligations penalty regime applies the higher of a fixed monetary cap or a percentage of worldwide annual turnover:
For SMEs, including start-ups, each of these fines is capped at whichever of the fixed amount or the percentage is lower, tempering the burden on smaller operators. Separate fine ceilings apply to providers of general-purpose AI models under Article 101.
The turnover-linked design produces very different outcomes depending on the size of the organisation. Consider a group with €4 billion in worldwide annual turnover found to have engaged in a prohibited practice: 7% of turnover equals €280 million, which exceeds the €35 million fixed cap, so the percentage figure governs. By contrast, a mid-sized deployer with €50 million turnover facing a “most other breaches” finding would see 3% equal €1.5 million, well below the €15 million cap, but a genuinely disruptive sum for a business of that size. These illustrations are hypothetical, but they demonstrate why the eu ai acts main obligations penalty regime cannot be dismissed as a large-enterprise concern alone.
When setting fines, authorities weigh aggravating and mitigating factors, the nature, gravity and duration of the infringement, whether it was intentional or negligent, cooperation with authorities, and prior remediation. Robust internal documentation, prompt disclosure and demonstrable good-faith compliance efforts are among the most effective ways to move a case toward the lower end of the available range.
AI Act penalties sit alongside, and do not displace, other EU sanction frameworks. Where the same conduct engages data-protection law, exposure under the General Data Protection Regulation (Regulation (EU) 2016/679) may also arise. Organisations should assess AI compliance and data-protection compliance together, recognising that a single AI deployment can implicate both regimes and generate parallel enforcement risk.
Enforcement of the AI Act is a shared endeavour. The EU AI Office within the European Commission has central coordination and supervisory functions, including exclusive supervisory powers over general-purpose AI models, while day-to-day market surveillance rests with national competent authorities that each Member State must designate. The effectiveness of the eu ai acts main obligations penalty regime therefore depends in part on the operational readiness of national authorities.
That readiness has been uneven across the Union, with Member States at different stages of designating their market surveillance and notifying authorities. The practical consequence is a patchwork enforcement environment in which the intensity and speed of supervision can vary by jurisdiction. Cross-border deployers should not, however, read incomplete designation as a reason to relax, obligations apply uniformly regardless of the state of local institutional build-out, and enforcement capacity is expected to strengthen as designations are completed.
Where a Member State has not completed its designations, deployers may face short-term uncertainty about which body to engage and how quickly enquiries will be handled. The prudent posture is to comply as though full enforcement were already operational, maintain complete records, and monitor official designation updates so that reporting and cooperation channels are known before any incident arises.
The following checklist translates the eu ai acts main obligations penalty framework into concrete deployer actions. It is designed as a starting point for a defensible compliance programme, not a substitute for tailored legal advice.
The AI Act’s ceilings are, at the top tier, higher than those under the GDPR, reflecting the legislator’s intent to deter the most harmful AI practices. The comparison below is a quick comparator only.
| Breach category | AI Act maximum penalty | Indicative GDPR maximum penalty |
|---|---|---|
| Prohibited practices | €35m or 7% of worldwide turnover (higher) | , |
| Most other breaches | €15m or 3% of worldwide turnover (higher) | Up to €20m or 4% for certain GDPR breaches |
| Incorrect information to authority | €7.5m or 1.5% of worldwide turnover (higher) | , |
The AI Act phases in over several years. The compact timeline below shows the key milestones for planning purposes.
| Milestone | Date |
|---|---|
| Entry into force of Regulation (EU) 2024/1689 | 1 August 2024 |
| Prohibited AI practices and AI literacy obligations apply | 2 February 2025 |
| General-purpose AI model obligations and governance provisions apply | 2 August 2025 |
| General applicability, transparency, enforcement, penalty regime | 2 August 2026 |
| High-risk AI systems listed in Annex III, obligations apply | 2 August 2027 |
| High-risk AI systems embedded in products under EU harmonisation legislation, obligations apply | 2 August 2028 |
The eu ai acts main obligations penalty regime is no longer a future concern, significant parts of it are operative law of the Union as of 2 August 2026. Transparency duties, governance requirements and substantial administrative fines now apply to deployers as well as providers, with the most demanding high-risk obligations following in 2027 and 2028. The enforcement landscape is still maturing, but uneven Member State designation is no shield: obligations apply uniformly, and prepared organisations will be those that inventory their systems, implement disclosure and labelling, secure robust provider contracts and maintain the documentation needed to withstand scrutiny.
Treating the eu ai acts main obligations penalty framework as a standing compliance programme rather than a one-off project is the surest route to managing regulatory risk in the years ahead.
This article is provided for general information only and does not constitute legal advice. Organisations should seek tailored advice on their specific circumstances. Need tailored advice? Contact a Global Law Experts counsel specialising in EU AI compliance via the Global Law Experts lawyer directory and the EU Technology & AI practice area.
posted 8 minutes ago
posted 23 minutes ago
posted 39 minutes ago
posted 47 minutes ago
posted 53 minutes ago
posted 53 minutes ago
posted 58 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
No results available
Find the right Legal Expert for your business
Send welcome message