EU AI Act Enforcement: First Compliance Deadlines Hit Enterprises
The EU AI Act transitioned from legislative framework to operational enforcement regime on 2 August 2026, marking the moment when European regulators and national authorities began actively monitoring compliance with the bloc's landmark artificial intelligence legislation. For UK enterprises with EU operations, US and Chinese AI vendors targeting European markets, and the broader global supply chain, this shift represents the first genuine test of whether the Act's risk-based architecture can be implemented at scale.
The past week has seen several enforcement bodies issue formal guidance on phased compliance obligations, confirm investigation protocols, and clarify which AI system categories now fall under immediate scrutiny. Understanding these signals is critical for Chief AI Officers and senior technology leaders operating across EU borders, as misalignment with the Act's requirements now carries material legal and reputational risk.
The Phased Enforcement Timeline: What Triggers Now
The EU AI Act's implementation has unfolded across three distinct phases, with the third wave—covering high-risk AI systems and general-purpose AI model (GPAI) obligations—now in active enforcement mode.
Phase One (August 2024 – August 2026): Prohibition on AI systems deemed unacceptable risk (real-time biometric identification in public spaces, emotional manipulation, social credit systems). Enforcement bodies have already received complaint mechanisms and commenced preliminary investigations.
Phase Two (August 2026 onward): High-risk AI obligations kick in. This category includes systems used in recruitment screening, educational access, critical infrastructure, and law enforcement. Providers must now demonstrate compliance with documentation, testing, human oversight, and transparency requirements. Deployers—the organisations actually using these systems—must maintain records, conduct impact assessments, and notify authorities of incidents.
Phase Three (February 2027 onwards): GPAI model requirements become binding. Large language models, multimodal systems, and other foundational AI models above the Act's computational threshold must provide technical documentation, undergo safety testing, and comply with data transparency and copyright provisions.
For enterprises, Phase Two is the immediate pressure point. If your organisation deploys AI in hiring, loan decisions, benefit eligibility determination, educational placement, employment contracts, or public safety applications within the EU, formal compliance obligations are now live. The Act does not allow a grace period for technical remediation; the enforcement clock began on 2 August 2026.
High-Risk AI Systems: The Compliance Burden Explained
The EU AI Act defines high-risk systems through a two-pronged test: either they appear on the Act's regulatory Annex III (the prohibited and high-risk list), or they pose a risk of harm to fundamental rights and safety, even if not explicitly listed.
For each high-risk system in deployment, providers and deployers must now undertake the following documented activities:
- Risk assessments. Formal evaluation of how the system could cause harm to rights, safety, or lawful interests. This must be conducted before deployment and updated regularly.
- Data governance. High-risk systems must use training and validation datasets that are representative, documented, tested for bias, and retained for audit purposes. Raw training data does not need to be disclosed, but metadata and design decisions must be.
- Technical documentation. Detailed record of system design, training methodology, performance metrics across demographic groups, and known limitations. This is not optional or informal; regulators will inspect it.
- Human oversight protocols. Defined roles, training, and decision-making authority for humans reviewing or overriding system outputs, especially in contexts affecting employment or benefits.
- Testing and monitoring. Ongoing performance tracking, incident logging, and bias monitoring. Significant performance degradation or unexpected outputs must trigger investigation and potential withdrawal.
- Transparency labels. End-users and subjects of high-risk AI must receive notice that a decision or assessment involves automated processing, and be offered meaningful recourse (human review, appeal, or opt-out, depending on context).
The compliance lift is substantial. A recruiter using AI screening, a bank employing AI for loan decisions, or a public authority deploying predictive policing must now maintain audit trails, bias reports, and documented oversight decisions. The UK's Information Commissioner's Office (ICO) and the UK AI Safety Institute have already signalled that they will mirror many of these expectations for AI systems affecting UK citizens, even post-Brexit.
Critically, the Act places liability on both the provider (who builds or trains the model) and the deployer (who uses it in a real business process). A UK software vendor selling an AI hiring tool into the EU is liable for the tool's compliance. The German HR department buying that tool is liable for how they use it. Finger-pointing between vendor and customer no longer suffices.
GPAI Models and Foundation Model Obligations
The most anticipated enforcement shift arrives in February 2027, when obligations for general-purpose AI models (also called foundation models) become binding. This affects all providers of large language models, multimodal systems, and other base models with broad, unpredictable applications.
GPAI obligations include:
- Technical documentation covering training data sources, computational scale, and performance characteristics across common benchmarks.
- Transparency. Disclosure of whether content used in training included copyrighted material, with mechanisms for copyright holders to opt out of future training. This applies retroactively to existing model releases that remain in service.
- Safety testing. Demonstrating that the model does not exhibit severe uncontrolled behaviours, jailbreaks, or prompt injection vulnerabilities. Vendors must document testing protocols and known risks.
- Copyright compliance. Respect for existing copyright protections and fair compensation or licensing arrangements for rights holders whose works were used in training.
- Access restrictions for high-risk deployment. If a GPAI model is used in a high-risk application (e.g., as the backbone of a recruitment or benefit eligibility system), additional governance and testing apply.
Vendors like OpenAI, Anthropic, Meta, and Google have been preparing for this phase, publishing model cards and documentation. However, compliance with retroactive copyright obligations and the demand for deterministic safety testing on models designed to be emergent and adaptable remains contested. The EU Commission has indicated that it will accept good-faith effort and iterative compliance during the first 12 months (February 2027 to February 2028), but enforcement will tighten thereafter.
For UK-based AI labs and startups, the calculus is strategic. Building a GPAI model for EU deployment now triggers regulatory obligations that are currently less stringent under UK law. Some vendors have opted to maintain separate model versions or restrict EU access. Others are embedding compliance into product roadmaps, viewing the Act as a competitive moat (only larger, better-resourced vendors can afford compliance).
National Enforcement Bodies and Cross-Border Investigations
The EU AI Act is enforced through a decentralized network of national data protection authorities (DPAs) and new AI-specific regulatory bodies. In France, the CNIL; in Germany, the BfDI; in Italy, the Garante. Each has begun receiving complaints and initiating investigations.
A key enforcement mechanism is the EU's Market Surveillance and Compliance Mechanism, which coordinates investigations across member states and flags systemic non-compliance. If a GPAI model used by a major public sector deployer in Germany shows discriminatory bias, French regulators will be notified and may initiate parallel investigations targeting the same vendor's operations in France.
For UK enterprises, this matters because the UK's ICO and the proposed AI regulator under the UK AI Bill (currently in development) have indicated they will align enforcement priorities with the EU. British companies cannot rely on geographic separation; regulators share data and co-investigate cross-border harms. The UK's proposed AI regulation focuses on transparency and accountability rather than prescriptive requirements, but enforcement will increasingly coordinate with EU authorities, especially where British-based vendors or deployers affect EU residents.
Enforcement Action: Early Signals and Investigation Patterns
Since the August 2026 deadline, several enforcement bodies have issued formal decisions and investigation notices. The European Commission's Joint Research Centre (JRC) published an enforcement guidance document clarifying that national authorities should prioritize complaints involving:
- Systemic discrimination or rights violations (e.g., facial recognition bias affecting minority communities).
- Non-compliance by market-leading vendors (sending a clear signal to other vendors).
- Deployers in public administration or critical infrastructure (police, courts, benefits agencies).
- Transparency violations (failing to disclose AI use to affected individuals).
The first wave of formal investigations has targeted major AI vendors' practices in high-risk contexts. Companies have begun receiving detailed information requests asking for training data documentation, bias testing results, and human oversight logs. Non-response or incomplete responses trigger escalation to formal enforcement proceedings, with potential fines of up to 6% of global annual revenue for GPAI providers (or 30 million EUR, whichever is higher).
Smaller regional incidents have already surfaced. A municipality in Belgium that deployed an AI system for benefit eligibility without proper transparency notices received a compliance order from the Belgium DPA. A Polish recruitment agency using an untested AI screening tool was formally investigated after complaints of age-based filtering. These are not headline-grabbing cases, but they establish the enforcement pattern: regulators are actively investigating, and consequences range from mandatory system withdrawal to administrative fines.
Practical Compliance Actions for Enterprises Now
For CAIOs and enterprise AI leaders, the enforcement phase demands immediate attention to three areas:
Audit and Documentation. Map all AI systems deployed across EU operations. For each system, determine whether it is high-risk under the Act (affects hiring, benefits, credit, law enforcement, migration, education, or other rights-sensitive domains). Document existing governance, data sources, testing, and oversight. Identify gaps and prioritize remediation for systems with the highest exposure.
Vendor Management. Review contracts with AI vendors and SaaS providers. Clarify liability allocation (who is responsible for compliance documentation, bias testing, incident reporting). Demand that vendors provide compliance certifications or roadmaps aligned with the Act. Establish audit rights to verify vendor claims. Do not assume that vendor disclaimers protect your organization; regulators hold deployers accountable.
Governance and Oversight. Institute documented human review processes for high-risk AI system outputs. Establish incident reporting protocols. Create cross-functional teams (legal, compliance, product, ethics) responsible for ongoing monitoring and bias detection. Brief board members and executive sponsors on AI regulatory risk as part of enterprise risk management.
The Alan Turing Institute and the UK AI Safety Institute have published practical compliance frameworks (adapted from EU guidance) that are applicable to UK-based organizations and their EU operations. These resources emphasize documentation, traceability, and governance as the foundation for demonstrating good-faith compliance effort.
Looking Ahead: The Tightening Regulatory Environment
The EU AI Act is the first comprehensive AI regulation to move from consultation phase to active enforcement. Its success or failure will shape global regulatory responses. The US is monitoring compliance costs and competitive impacts. China is tracking enforcement intensity. The UK's own AI regulation will likely draw on EU lessons, but with lighter-touch requirements in the early phase.
However, the enforcement phase also reveals tensions and ambiguities in the Act itself. Defining GPAI models with sufficient precision to enable consistent enforcement remains challenging. Balancing innovation incentives with safety testing is unresolved. Retroactive copyright compliance is legally complex. Regulators will need to issue additional guidance as edge cases emerge.
For enterprise AI leaders, the next 18 months (now through February 2027) are critical. Phase Two compliance is non-negotiable for any high-risk system. Phase Three preparation—especially for organizations planning to deploy or build GPAI models—must begin now. The enforcement playbook is becoming visible, and early compliance investment reduces regulatory risk, improves AI governance maturity, and positions organizations as trustworthy partners in an increasingly scrutinized sector.
The EU AI Act's enforcement phase is not a burst of regulatory intensity followed by relaxation. It is the beginning of a permanent, coordinated, cross-border oversight of AI systems. Enterprises that treat this as a compliance checkbox will face mounting friction. Those that embed the Act's principles—transparency, documented oversight, bias testing, human review—into AI governance will emerge stronger and better positioned for the global regulatory environment that is now taking shape.