The EU AI Act Just Got Real: Yesterday's Enforcement Date Changes Everything for Global AI
Yesterday — August 2, 2026 — the European Union's AI Act entered its most consequential phase. The bulk of the regulation, held back while companies prepared, is now enforceable. For any organization deploying AI systems that affect people inside the EU, the grace period is over.
What Just Kicked In
The AI Act has rolled out in stages since it came into force in August 2024. Bans on unacceptable-risk AI — including government social scoring and real-time biometric surveillance in public spaces — took effect in February 2025. General-purpose AI rules followed in August 2025. But August 2, 2026 is the date when the full weight of the regulation activates:
- Annex III high-risk AI obligations — covering AI used in employment screening, credit decisions, education admissions, law enforcement, border control, and access to essential services
- Article 50 transparency requirements — rules on disclosing when users interact with AI, and requirements around emotion recognition and biometric categorization
- Full penalty regime — national authorities now have active investigative and sanctioning powers
What High-Risk Compliance Requires
Organizations whose AI systems fall under Annex III's high-risk categories must now maintain technical documentation proving their system's accuracy and robustness, conduct formal conformity assessments, register their systems in an EU database, implement human oversight mechanisms capable of overriding the system, and log activity for post-market monitoring.
This applies to any organization whose AI affects EU residents — regardless of where the company is headquartered. American companies operating in European markets are fully in scope. A deadline extension was discussed earlier this year; the EU held firm.
The Penalty Structure
Fines are tiered and steep. Deploying a prohibited AI practice — the outright bans established in 2025 — carries penalties of up to €35 million or 7% of global annual turnover, whichever is higher. Violations involving general-purpose AI models carry fines of up to 3%. Submitting incorrect or misleading information to regulators carries fines of up to 1.5%.
These are not theoretical. National competent authorities across all 27 EU member states now have the legal powers to investigate, inspect, and sanction non-compliant systems placed on the EU market.
What Happens Next
One major provision remains delayed: Article 6(1), covering certain product-safety categories of high-risk AI, will not apply until August 2027. But for the vast majority of AI applications in enterprise, hiring, credit, and public-sector contexts, yesterday marked the shift from preparation to enforcement.
The coming months will reveal how aggressively national authorities move, and which sectors draw early scrutiny. The employment and financial services sectors — where automated decision-making is most widespread — are widely expected to see the first significant enforcement actions.