[codicts-css-switcher id=”346″]

Global Law Experts Logo
main obligations and penalties

The EU AI Act: Main Obligations and Penalties Now Applicable (2 August 2026)

By Global Law Experts
– posted 1 hour ago

Who this is for: in-house counsel, external counsel and compliance officers advising businesses that deploy AI systems on the EU market.

Purpose: explain what became applicable on 2 August 2026, what remains deferred, the enforcement and penalty regime, and the practical steps deployers should take now.

Read time: ~12 minutes. Last updated: August 2026.

TL;DR, the EU AI Act’s main obligations and penalty framework changed on 2 August 2026

The eu ai acts main obligations penalty framework moved from theory to enforceable reality when a substantial tranche of Regulation (EU) 2024/1689 became generally applicable on 2 August 2026. From that date, transparency duties, the governance architecture, the supervisory role of the EU AI Office and the headline penalty ceilings all became operative across the Union. For counsel advising deployers, the businesses that use AI systems rather than build them, this milestone shifts compliance from a roadmap exercise to a live legal exposure.

  • Transparency duties are live. Article 50 disclosure and labelling obligations for AI systems that interact with people or generate synthetic content now apply.
  • Governance is operative. The EU AI Office and Member State authorities have supervisory and enforcement functions.
  • Penalty ceilings are in force. Up to €35m or 7% of worldwide annual turnover for prohibited-practice breaches, with lower tiers of €15m/3% and €7.5m/1.5%.
  • Certain high-risk obligations are deferred. Obligations for certain high-risk systems, including those embedded in regulated products, fall due at a later phase (2 August 2027 for certain high-risk categories, and 2 August 2028 for high-risk systems embedded in products covered by EU harmonisation legislation).

Quick action items for deployers

  • Map which of your deployed AI systems fall within Article 50 disclosure duties.
  • Confirm customer-facing labelling and interface disclosures are in place.
  • Review provider contracts for flow-down obligations, warranties and audit rights.

What became applicable on 2 August 2026, legal scope and exclusions

The primary text is Regulation (EU) 2024/1689, the AI Act, the EU’s comprehensive horizontal regulation governing artificial intelligence. The Regulation entered into force on 1 August 2024 and phases in over several years. The 2 August 2026 date marks the point at which the bulk of its operative provisions became generally applicable, giving the eu ai acts main obligations penalty regime real legal teeth for organisations operating in or into the EU.

As of that date, the following categories of provision are active:

  • Transparency obligations under Article 50, covering systems that interact directly with natural persons and systems that generate or manipulate content.
  • Governance provisions, including the functions of the EU AI Office and the requirement for Member States to stand up national supervisory and market surveillance authorities.
  • Enforcement and penalty provisions, giving competent authorities the power to investigate breaches and impose administrative fines.

Certain earlier-phase provisions were already applicable before this milestone: the prohibitions on certain AI practices and the AI literacy obligations became applicable from 2 February 2025, and the obligations relating to general-purpose AI models applied from 2 August 2025. The August 2026 milestone reinforces the overall enforcement architecture. For most commercial deployers, the practical significance lies in the transparency and governance obligations that now bite on everyday AI use.

Exceptions and deferred provisions

Not everything is live. A commercially significant carve-out concerns high-risk AI systems that are embedded in products already regulated under EU harmonisation legislation (listed in Annex I). For those systems, the corresponding obligations apply from 2 August 2028, giving manufacturers and their downstream deployers a longer transitional window. Other high-risk systems listed in Annex III generally fall due from 2 August 2027. Understanding which of your systems benefit from these deferrals, and which do not, is a threshold question for any compliance plan.

Who is in scope, providers, deployers and territorial reach

The Regulation distinguishes carefully between roles, and the eu ai acts main obligations penalty regime allocates duties accordingly. A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer is a natural or legal person using an AI system under its authority in the course of a professional activity. Many businesses will be deployers even where they never touch a line of model code, for example, an enterprise integrating a third-party generative model into a customer-service chatbot.

The distinction matters because obligations, and therefore liability, follow the role. Providers carry the heaviest documentation and conformity burdens; deployers carry transparency, oversight and use-related duties. In practice, most organisations occupy both roles across different systems, which is why an accurate system-by-system role assessment is the foundation of any credible compliance posture.

Territorial scope, when non-EU companies are in scope

The AI Act reaches beyond the borders of the Union. Non-EU companies fall within scope where they place AI systems on the EU market, put them into service in the Union, or where the output produced by their systems is used within the Union. A US software vendor offering an AI-enabled SaaS product to European customers is therefore squarely in scope, as is a non-EU deployer whose AI outputs are used inside the EU. The answer to the common question, does the EU AI Act apply to the US? , is that it can apply to any organisation, regardless of establishment, whose AI activities touch the EU market or produce effects within it.

Cross-border groups should not assume that lack of an EU establishment removes their exposure to the eu ai acts main obligations penalty regime.

Key obligations now applicable, transparency, labelling, content disclosure and governance

The obligations that most immediately affect deployers cluster around transparency and internal governance. These are the duties that generate day-one compliance work and, if neglected, the most predictable enforcement exposure under the eu ai acts main obligations penalty framework.

Transparency obligations (Article 50), compliance checklist

Article 50 introduces layered disclosure duties. Where an AI system is intended to interact directly with people, those people must be informed that they are dealing with an AI system unless it is obvious from the circumstances. Where a system generates or manipulates image, audio, video or text content, providers must ensure outputs are marked in a machine-readable format as artificially generated or manipulated, subject to certain exceptions. Deployers of systems producing deepfakes must disclose that the content has been artificially generated or manipulated, and deployers publishing AI-generated text on matters of public interest carry specific disclosure duties, again subject to exceptions.

  • Confirm that chatbots and conversational agents clearly disclose their artificial nature at the point of interaction.
  • Ensure AI-generated or manipulated media is labelled and, where feasible, carries machine-readable provenance metadata.
  • Review whether any published content triggers the deepfake or public-interest disclosure duties.
  • Check that disclosures are clear, timely and accessible, buried terms-and-conditions language will not suffice.

Governance and record-keeping, internal policies and role designation

Beyond user-facing transparency, deployers should build the internal scaffolding that demonstrates compliance. That means assigning clear internal ownership for AI governance, maintaining documentation of the systems in use and their classification, and establishing processes to monitor system behaviour and respond to serious incidents. AI literacy is also a live obligation: under Article 4, providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others dealing with AI systems on their behalf. Record-keeping is not merely good practice, it is the evidence that will inform your position if a competent authority opens an inquiry under the eu ai acts main obligations penalty regime.

Contracts and upstream supply chain due diligence, what to ask providers

Deployers depend on upstream providers for much of the information they need to comply. Contractual due diligence is therefore central. When contracting for AI systems, deployers should seek:

  • Warranties that the system complies with applicable AI Act obligations, including transparency and, where relevant, high-risk requirements.
  • Flow-down commitments requiring the provider to supply the technical documentation and instructions for use needed to meet deployer duties.
  • Audit and information rights enabling the deployer to verify compliance and respond to authority requests.
  • Clear allocation of liability and indemnities addressing regulatory penalties arising from provider default.

High-risk systems, timelines and implications

The AI Act’s most demanding regime applies to high-risk AI systems. These attract obligations covering risk management, data governance, technical documentation, human oversight, accuracy, robustness and cybersecurity. High-risk systems fall into two broad categories: those listed in Annex III (such as certain systems used in employment, education, essential services and law enforcement), for which obligations generally apply from 2 August 2027; and those that are safety components of, or are themselves, products covered by EU harmonisation legislation listed in Annex I, for which the corresponding obligations apply from 2 August 2028.

Typical examples of the second category include AI components integrated into medical devices, in-vitro diagnostic devices and machinery, and other products whose safety is already regulated under sectoral EU legislation. The rationale is to align the AI conformity pathway with the existing product-safety conformity assessment framework, avoiding duplicative and misaligned deadlines. The deferral is a transitional accommodation, not an exemption: the obligations will apply in full from the applicable date, and the volume of work required, from risk assessment through technical documentation to conformity procedures, is substantial.

Practical steps for deployers of embedded high-risk systems

Deployers should not treat the 2027 and 2028 deadlines as distant. The lead time to gather documentation, negotiate contractual support from manufacturers and integrate governance controls is long. Sensible steps include:

  • Identifying now which deployed systems will fall within a high-risk category and on which date.
  • Requesting a compliance roadmap from providers and manufacturers, including target dates for conformity documentation.
  • Building a phased internal budget and remediation plan that reaches readiness ahead of the applicable deadline.

The eu ai acts main obligations penalty regime, ceilings, categories and enforcement triggers

The penalty structure is tiered by the seriousness of the breach, and the ceilings are calibrated to be capable of affecting even the largest global operators. Under Article 99, the eu ai acts main obligations penalty regime applies the higher of a fixed monetary cap or a percentage of worldwide annual turnover:

  • Prohibited practices: up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher.
  • Non-compliance with most other obligations under the Regulation, including provider and deployer duties: up to €15 million or 3% of worldwide annual turnover, whichever is higher.
  • Supplying incorrect, incomplete or misleading information to notified bodies or competent authorities in reply to a request: up to €7.5 million or 1.5% of worldwide annual turnover, whichever is higher.

For SMEs, including start-ups, each of these fines is capped at whichever of the fixed amount or the percentage is lower, tempering the burden on smaller operators. Separate fine ceilings apply to providers of general-purpose AI models under Article 101.

Penalty examples and hypothetical calculations

The turnover-linked design produces very different outcomes depending on the size of the organisation. Consider a group with €4 billion in worldwide annual turnover found to have engaged in a prohibited practice: 7% of turnover equals €280 million, which exceeds the €35 million fixed cap, so the percentage figure governs. By contrast, a mid-sized deployer with €50 million turnover facing a “most other breaches” finding would see 3% equal €1.5 million, well below the €15 million cap, but a genuinely disruptive sum for a business of that size. These illustrations are hypothetical, but they demonstrate why the eu ai acts main obligations penalty regime cannot be dismissed as a large-enterprise concern alone.

When setting fines, authorities weigh aggravating and mitigating factors, the nature, gravity and duration of the infringement, whether it was intentional or negligent, cooperation with authorities, and prior remediation. Robust internal documentation, prompt disclosure and demonstrable good-faith compliance efforts are among the most effective ways to move a case toward the lower end of the available range.

Interaction with other sanction regimes

AI Act penalties sit alongside, and do not displace, other EU sanction frameworks. Where the same conduct engages data-protection law, exposure under the General Data Protection Regulation (Regulation (EU) 2016/679) may also arise. Organisations should assess AI compliance and data-protection compliance together, recognising that a single AI deployment can implicate both regimes and generate parallel enforcement risk.

Enforcement landscape and Member State designation

Enforcement of the AI Act is a shared endeavour. The EU AI Office within the European Commission has central coordination and supervisory functions, including exclusive supervisory powers over general-purpose AI models, while day-to-day market surveillance rests with national competent authorities that each Member State must designate. The effectiveness of the eu ai acts main obligations penalty regime therefore depends in part on the operational readiness of national authorities.

That readiness has been uneven across the Union, with Member States at different stages of designating their market surveillance and notifying authorities. The practical consequence is a patchwork enforcement environment in which the intensity and speed of supervision can vary by jurisdiction. Cross-border deployers should not, however, read incomplete designation as a reason to relax, obligations apply uniformly regardless of the state of local institutional build-out, and enforcement capacity is expected to strengthen as designations are completed.

What deployers should expect where national authorities are not yet fully designated

Where a Member State has not completed its designations, deployers may face short-term uncertainty about which body to engage and how quickly enquiries will be handled. The prudent posture is to comply as though full enforcement were already operational, maintain complete records, and monitor official designation updates so that reporting and cooperation channels are known before any incident arises.

Practical compliance checklist for deployers

The following checklist translates the eu ai acts main obligations penalty framework into concrete deployer actions. It is designed as a starting point for a defensible compliance programme, not a substitute for tailored legal advice.

  1. Inventory and classify. Identify every deployed AI system and determine whether it falls under Article 50, the high-risk regime, or other obligations.
  2. Labelling and disclosure. Implement user-facing disclosures, API response notices where relevant, and content-provenance metadata for AI-generated media.
  3. Contracts. Secure flow-down obligations, compliance warranties, audit rights and indemnities from providers.
  4. Documentation. Request technical documentation and instructions for use from providers, and retain them.
  5. Risk assessment. Conduct and record assessments proportionate to each system’s classification.
  6. Incident response. Establish processes for detecting, escalating and reporting serious incidents.
  7. AI literacy and training. Ensure staff operating or overseeing AI systems have appropriate understanding.
  8. Record-keeping and retention. Maintain a retention schedule capable of evidencing compliance to an authority.
  9. Budget and roadmap. Plan remediation and build a readiness programme for high-risk systems ahead of the 2027 and 2028 deadlines.

Template contract clauses to request from providers

  • Compliance warranty covering applicable AI Act obligations for the supplied system.
  • Obligation to provide and update technical documentation and instructions for use.
  • Audit and information rights, including cooperation with regulatory enquiries.
  • Indemnity for penalties and losses arising from the provider’s non-compliance.
  • Change-notification duties where the provider modifies the system in ways affecting compliance.

Comparison table, AI Act penalties vs GDPR fines

The AI Act’s ceilings are, at the top tier, higher than those under the GDPR, reflecting the legislator’s intent to deter the most harmful AI practices. The comparison below is a quick comparator only.

Breach category AI Act maximum penalty Indicative GDPR maximum penalty
Prohibited practices €35m or 7% of worldwide turnover (higher) ,
Most other breaches €15m or 3% of worldwide turnover (higher) Up to €20m or 4% for certain GDPR breaches
Incorrect information to authority €7.5m or 1.5% of worldwide turnover (higher) ,

Implementation timeline

The AI Act phases in over several years. The compact timeline below shows the key milestones for planning purposes.

Milestone Date
Entry into force of Regulation (EU) 2024/1689 1 August 2024
Prohibited AI practices and AI literacy obligations apply 2 February 2025
General-purpose AI model obligations and governance provisions apply 2 August 2025
General applicability, transparency, enforcement, penalty regime 2 August 2026
High-risk AI systems listed in Annex III, obligations apply 2 August 2027
High-risk AI systems embedded in products under EU harmonisation legislation, obligations apply 2 August 2028

Conclusion and how to prepare

The eu ai acts main obligations penalty regime is no longer a future concern, significant parts of it are operative law of the Union as of 2 August 2026. Transparency duties, governance requirements and substantial administrative fines now apply to deployers as well as providers, with the most demanding high-risk obligations following in 2027 and 2028. The enforcement landscape is still maturing, but uneven Member State designation is no shield: obligations apply uniformly, and prepared organisations will be those that inventory their systems, implement disclosure and labelling, secure robust provider contracts and maintain the documentation needed to withstand scrutiny.

Treating the eu ai acts main obligations penalty framework as a standing compliance programme rather than a one-off project is the surest route to managing regulatory risk in the years ahead.

This article is provided for general information only and does not constitute legal advice. Organisations should seek tailored advice on their specific circumstances. Need tailored advice? Contact a Global Law Experts counsel specialising in EU AI compliance via the Global Law Experts lawyer directory and the EU Technology & AI practice area.

Illustration: Eu Flag With Ai Circuit Overlay And Legal Scales, Eu Ai Acts Main Obligations Penalty Enforcement (2 Aug 2026)

Sources

  1. European Commission, AI Act policy page (Shaping Europe’s digital future)
  2. EUR-Lex, Regulation (EU) 2024/1689 (AI Act)
  3. European Parliament, Legislative train: European AI Act
  4. European Commission, EU AI Office
  5. EUR-Lex, Regulation (EU) 2016/679 (GDPR)

FAQs

What came into effect on 2 August 2026 under the EU AI Act?
From that date, transparency obligations (including Article 50), enforcement powers and the general penalty regime under Regulation (EU) 2024/1689 became generally applicable, while certain high-risk obligations remain deferred to 2027 and 2028.
They can, where they place AI systems on the EU market, put them into service in the Union, or where the output of their systems is used within the EU. Establishment outside the EU does not by itself remove exposure to the eu ai acts main obligations penalty regime.
Obligations for high-risk AI systems listed in Annex III generally apply from 2 August 2027, and obligations for high-risk AI systems embedded in products regulated under EU harmonisation legislation, such as certain medical devices and machinery, apply from 2 August 2028.
Up to €35m or 7% of worldwide annual turnover for prohibited practices; up to €15m or 3% for most other breaches; and up to €7.5m or 1.5% for supplying incorrect information to authorities, whichever amount is higher (or, for SMEs and start-ups, lower).
Start with disclosure and labelling for systems interacting with people or generating content, then review provider contracts for compliance warranties, documentation flow-down and audit rights.
The EU AI Office coordinates centrally and supervises general-purpose AI models, while national market surveillance and notifying authorities enforce locally. Member States have progressed at different rates in designating these authorities, so deployers should confirm the current position in each relevant jurisdiction.
isda master agreement austria
By Global Law Experts

posted 23 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The EU AI Act: Main Obligations and Penalties Now Applicable (2 August 2026)

Send welcome message

Custom Message