The European Union has formally moved the AI Act from legislation into day-to-day enforcement across all 27 member states. With the first milestones now binding, providers and deployers of high-risk AI face real consequences — and fixed deadlines — for transparency, documentation, and human oversight.
Enforcement Begins
The July 2026 enforcement round activates the compliance spine of the regulation: companies placing high-risk AI systems on the EU market must now operate under binding transparency, risk-management, and human-oversight obligations, with national market-surveillance authorities empowered to review, audit, and take corrective action. The AI Office continues to supervise general-purpose and foundation models at the EU level.
What Is Subject to the Rules
The AI Act routes the strictest duties toward high-risk systems — those in employment, education, credit, law enforcement, border management, and essential services, plus safety-relevant components of regulated products. Requirements include:
- Transparency — clear disclosure of AI involvement and capability limits
- Technical documentation — maintainable records of design, data, and testing
- Risk management — documented measures identifying and mitigating foreseeable harms
- Human oversight — meaningful supervision by trained personnel, not rubber stamps
Phased Deadlines
Enforcement arrives in layers. Prohibited practices and general-purpose-AI duties are already live from earlier phases; the current round tightens high-risk obligations, with the remaining high-risk compliance deadlines phased through 2027. Providers launching new high-risk systems are expected to conform before market entry — national authorities can now withdraw or restrict non-compliant systems found in the wild.
Penalties
The regime carries teeth either way:
- Up to 35 million euros or 7 percent of annual worldwide turnover for the most serious violations
- Lower tiers for breaches of documentation, transparency, and conformity duties
- Corrective orders, suspension, and removal for ongoing non-compliance
What Businesses Should Do Now
For companies in scope, the enforcement start is a trigger, not a headline. Priorities are mapping every AI deployment, classifying risk levels, completing gap assessments against the documentation and oversight obligations, and assigning named responsible owners before national authorities begin their first audit cycles. The window to prepare is the phase-in period — and for high-risk systems, that window is closing.