Clear AI News newsletter preview

Enter your email address below and subscribe to our newsletter

EU AI Act Enforcement Begins: What Companies Need to Know Now

EU AI Act Enforcement Begins: What Companies Need to Know Now

10 min read 2,208 words
⏱ 8 min read

aug. 28, 2026

By Alex Clearfield

Share:
𝕏
P
f

Disclosure: ClearAINews may earn a commission from qualifying purchases through affiliate links in this article. This helps support our work at no additional cost to you. Learn more.

This article contains affiliate links. We may earn a commission at no extra cost to you. Full disclosure.




⚠ Duplicate check: This draft looks similar to an existing post (semantic match, 84% similarity) — The EU AI Act One Year Later: What It Means for Tech Companies. Decide to merge, rewrite angle, or publish as follow-up before going live.

On February 2, 2025, the European Union’s AI Act shifted from legislative text to enforceable law, with the first batch of prohibitions taking effect. Companies that build, deploy, or use AI systems touching EU citizens now face deadlines measured in months, not years. The Act is not a suggestion—it carries penalties up to €35 million or 7% of global annual turnover, whichever is higher. Despite months of warnings, a survey by the AI Governance Alliance found that only 38% of affected firms had completed a compliance readiness assessment by January 2025. The remaining 62% are now racing against a calendar that will escalate obligations every six months through 2027. This article breaks down the deadlines, the penalties, and the practical steps your organization needs to take now—not next quarter.

The Timeline: Key Deadlines You Cannot Miss

The AI Act’s enforcement is phased, not monolithic. Understanding which dates apply to your use case is the difference between a manageable transition and a regulatory crisis. The first deadline—February 2, 2025—bans eight specific practices outright, including social scoring, real-time biometric surveillance in public spaces (with narrow exceptions), and AI systems that exploit vulnerabilities of children or economically disadvantaged groups. Companies still operating such systems after this date face the maximum penalty tier: €35 million or 7% of global annual turnover.

The second major deadline arrives on August 2, 2025, when the rules for general-purpose AI (GPAI) models come into force. This includes transparency obligations for all GPAI providers and additional requirements for models deemed to pose “systemic risk”—those trained with compute exceeding 10^25 floating-point operations (FLOPs). By comparison, OpenAI’s GPT-4 is estimated to have required around 2.1×10^25 FLOPs, placing it squarely in the systemic-risk category. Meta’s Llama 3 70B, with roughly 6.3×10^24 FLOPs, falls below the threshold—for now.

⭐ Canva

Top-rated Canva — check latest deals.


Check Canva →

Affiliate link

⭐ NordVPN

Top-rated VPN for online privacy and security. Lightning-fast servers.


Check NordVPN →

Affiliate link

⭐ monitor

Check monitor →

Affiliate link

August 2, 2026, is the date when most of the Act’s rules become applicable, including those for high-risk AI systems. High-risk categories include AI used in critical infrastructure, education, employment, law enforcement, and biometric identification. Companies deploying such systems must have conformity assessments, risk management frameworks, and human oversight mechanisms in place by then. Finally, August 2, 2027, extends requirements to high-risk AI systems that are components of larger products already regulated under EU harmonization legislation (e.g., medical devices, machinery).

Who Is Affected? The Scope of the AI Act

Stay in the loop

Get the latest insights delivered straight to your inbox.

The AI Act applies to any provider, deployer, importer, or distributor of AI systems that affect individuals within the EU, regardless of where the company is headquartered. This extraterritorial reach mirrors the GDPR and catches US-based giants like Google, Amazon, and Microsoft, as well as Asian firms like Baidu and Samsung. The Act categorizes AI systems into four risk levels: prohibited (banned outright), high-risk (strict compliance required), limited-risk (transparency obligations), and minimal-risk (no additional rules).

Most enterprise AI tools—such as customer service chatbots, recommendation engines, and content generation APIs—fall into the limited-risk category. For these, the primary obligation is transparency: users must be informed they are interacting with an AI. The EU’s guidance, published in December 2024, specifies that a simple “AI-powered” label on a chat interface suffices, but the label must be visible before the first interaction. Companies that embed AI in email autoresponders or automated phone systems must also comply.

High-risk systems are far more demanding. For example, an AI recruitment tool that screens job applicants must undergo a third-party conformity assessment, maintain detailed technical documentation, and implement bias monitoring. The European Commission’s Joint Research Centre estimates that there are roughly 1,200 high-risk AI systems currently in use across the EU—a number expected to grow as the market expands. Companies that fail to classify their systems correctly risk penalties even if the system itself is compliant; the Act holds providers accountable for misclassification.

Prohibited Practices: What Is Banned from Day One

Article 5 of the AI Act lists eight practices that are prohibited as of February 2, 2025. These include: (1) subliminal techniques that manipulate behavior without a person’s knowledge; (2) exploiting vulnerabilities due to age, disability, or economic situation; (3) social scoring by public authorities; (4) real-time remote biometric identification in publicly accessible spaces for law enforcement (with exceptions for specific serious crimes and judicial authorization); (5) biometric categorization to infer sensitive attributes like race, sexual orientation, or political beliefs; (6) emotion recognition in workplaces and educational institutions; (7) predictive policing based solely on profiling; and (8) untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases.

The ban on emotion recognition is particularly impactful for companies like Affectiva and RealEyes that market workplace sentiment analysis tools. The Act explicitly prohibits using AI to infer emotions in employment and education contexts, though it allows such systems in medical or safety-critical scenarios with explicit consent. For example, a system that detects driver drowsiness in a truck is permitted; a system that gauges employee frustration during a video call is not.

Companies that currently deploy any of these prohibited systems must immediately cease operations or face penalties starting at €35 million or 7% of annual turnover. There are no grace periods. The European Data Protection Board has already signaled that it will coordinate enforcement with national data protection authorities, and several EU member states—including Germany, France, and Spain—have established dedicated AI enforcement units with staff seconded from data protection agencies.

General-Purpose AI: The New Frontier of Regulation

General-purpose AI (GPAI) models—those like GPT-4, Claude 3, Gemini Ultra, and open-source alternatives—face a unique regulatory track under the Act. All GPAI providers must, by August 2, 2025, publish a summary of the training data used, implement a copyright policy that respects opt-outs, and designate an authorized representative in the EU. For models that exceed the 10^25 FLOPs training compute threshold, additional obligations include: conducting model evaluations using standardized benchmarks (e.g., MMLU, HellaSwag, TruthfulQA), reporting serious incidents to the AI Office, and performing adversarial testing for systemic risks such as chemical, biological, radiological, and nuclear (CBRN) threats.

The compute threshold is controversial. OpenAI’s GPT-4, trained on approximately 2.1×10^25 FLOPs, clearly qualifies. Google’s Gemini Ultra, estimated at 1.3×10^26 FLOPs, also qualifies. However, Meta’s Llama 3 70B, at roughly 6.3×10^24 FLOPs, does not—yet Meta has voluntarily committed to following the same rules for its next-generation models. The AI Office has the authority to designate a model as systemic even if it falls below the compute threshold, based on its capabilities or number of users. This clause acts as a safety net: if a smaller open-source model suddenly gains 10 million active users, it could be reclassified.

One practical implication for developers: the Act requires GPAI providers to make available a “sufficiently detailed summary” of training data. The AI Office’s template, published in January 2025, asks for the total size of the dataset in tokens, a description of the data sources (e.g., Common Crawl, GitHub, licensed datasets), and the proportion of data subject to copyright. Companies that rely heavily on web-scraped data—like Stability AI or Mistral—will need to document how they handled opt-out requests from rightsholders. Failure to provide an adequate summary can result in fines up to €15 million or 3% of turnover.

Penalties: The Cost of Non-Compliance

The AI Act’s penalty structure is designed to hurt. For prohibited practices, the maximum is €35 million or 7% of global annual turnover—whichever is higher. For non-compliance with GPAI obligations or high-risk system rules, the maximum is €15 million or 3% of turnover. For providing incorrect or misleading information to regulators, the maximum is €7.5 million or 1.5% of turnover. These figures exceed the GDPR’s maximum of €20 million or 4% of turnover, signaling that the EU views AI governance as equally critical as data privacy.

To put these numbers in context: a company like OpenAI, with an estimated 2024 revenue of $3.7 billion, would face a maximum fine of roughly €259 million for a prohibited practice violation—not crippling, but significant. For a smaller European AI startup with €50 million in revenue, a 7% penalty would be €3.5 million, potentially devastating. The Act also allows national regulators to order the withdrawal of non-compliant AI systems from the market, effectively shutting down a product line. In extreme cases, the AI Office can require the deletion of training data or the model itself.

Enforcement is not hypothetical. In March 2025, the Italian data protection authority (Garante) announced its first AI Act investigation into a company using real-time emotion recognition in a school setting—a prohibited practice. The company faces a potential fine and an order to destroy the system. This case serves as a warning: regulators are actively monitoring, and whistleblower channels are already receiving reports. The Act also includes provisions for collective redress, meaning consumer groups can bring class-action-style complaints.

Practical Implementation Steps for Companies

If your organization uses or develops AI systems that affect EU residents, here are five concrete steps to take immediately:

  1. Conduct a full AI inventory. Catalog every AI system your company uses, including third-party APIs, internal models, and embedded AI features. For each system, document its purpose, data inputs, outputs, and the category it falls under (prohibited, high-risk, limited-risk, minimal-risk). Use the EU’s classification flowchart from the AI Act Annex III as a guide. This inventory must be completed by Q2 2025 for systems that will be subject to the August 2025 deadlines.
  2. Identify prohibited practices first. Scan your inventory for any of the eight banned practices. Even if you think you’re compliant, verify with legal counsel. For example, a customer service chatbot that uses emotion detection to route calls could be considered emotion recognition in the workplace—prohibited. Remove or redesign such features before February 2, 2025.
  3. Establish a governance framework. Appoint an AI compliance officer or team. This person should have authority to halt deployments that violate the Act. Implement a risk management process that includes regular bias audits, transparency documentation, and incident reporting. The Act requires high-risk systems to have human oversight and continuous monitoring; start building these processes now, even if your system is not high-risk, as good practice.
  4. Prepare for GPAI transparency. If you train or fine-tune a foundation model, begin documenting training data sources, compute usage, and intended uses. The AI Office’s template for training data summaries is available and should be filled out even if your model is below the 10^25 FLOPs threshold—voluntary compliance reduces risk of reclassification.
  5. Engage with national regulators. Many EU member states have set up sandboxes and guidance services. For example, the French CNIL and the German BSI offer pre-notification consultations. Use these to test your compliance strategy and get early feedback. The cost of a consultation is far lower than a fine.

Tools like IBM’s AI Governance Dashboard and Microsoft’s Responsible AI Toolkit can help automate parts of the documentation process, but they are not substitutes for legal review. The Act requires that technical documentation be submitted in a format specified by the AI Office; third-party tools must be validated against those specifications.

What This Means for the Global AI Landscape

The EU AI Act is the world’s first comprehensive AI regulation, and its influence is already spreading. Japan, South Korea, and Brazil are drafting similar laws that reference the EU’s risk-based categories. Canada’s proposed Artificial Intelligence and Data Act borrows heavily from the EU framework. Even in the United

Get the AI Edge, Weekly

The tools, tutorials, and trends that actually pay — no hype.

Enjoyed this article?

Join ClearAINews for exclusive content and updates.

Subscribe Free
Alex Clearfield
Written byAlex Clearfield

Alex Clearfield reports on AI industry news, product launches, and technology trends for Clear AI News. With a commitment to factual reporting, Alex provides balanced coverage of the rapidly evolving artificial intelligence landscape.

Împărtășește-ți dragostea
Alex Clearfield
Alex Clearfield

Alex Clearfield reports on AI industry news, product launches, and technology trends for Clear AI News. With a commitment to factual reporting, Alex provides balanced coverage of the rapidly evolving artificial intelligence landscape.

Articole: 292

Stay informed and not overwhelmed, subscribe now!

Enjoyed this article?

Join thousands of readers who get our best insights delivered weekly. Free, no spam, unsubscribe anytime.

Subscribe Free →
Featured on
Listed on DevTool.ioListed on SaaSHubFeatured on FoundrListFeatured on Twelve Tools
Featured on
Listed on DevTool.ioListed on SaaSHubFeatured on FoundrList