top of page
davydov consulting logo

DAVYDOV CONSULTING BLOG

HOME  >  NEWS  >  POST

EU AI Act Enforcement Has Started: What It Means for Businesses Using AI in 2026

For almost two years the EU AI Act was something companies talked about in the future tense. The rules were adopted, the deadlines were printed on slides, and most business owners filed it under "we will deal with it later". That period is over. On 2 August 2026 the European Commission's AI Office got its enforcement and penalty powers over general-purpose AI models, and on 29 August it used them for the first time, sending formal requests for information to OpenAI, Anthropic, Google and several other frontier model providers.

This matters far beyond the handful of labs that received the letters. If your company runs a chatbot on GPT, an internal assistant on Claude or a document pipeline on Gemini, the compliance status of your vendor is now, in a practical sense, part of your own. And a few obligations that apply directly to ordinary businesses, not only to model makers, also switched on this month.

So let's look at what actually happened, what was pushed back to 2027 and 2028, and what a business that builds digital products on top of AI models should be doing this autumn. Let's sink in!


European Commission headquarters in Brussels with EU flags, where the AI Office now enforces the EU AI Act


What happened on 29 August and why it came so fast

The AI Office is the Commission's dedicated unit for supervising general-purpose AI, the big foundation models that power most commercial AI products today. Its obligations for model providers have been on the books since August 2025, but until this summer the office could not fine anybody or demand documents. That changed on 2 August 2026. Twenty-seven days later, Executive Vice-President Henna Virkkunen confirmed that the office had sent requests for information to "a number of providers of general-purpose AI models based in different regions of the world".

The requests fall into two lines. The first asks for details about model security, independent external evaluations and the monitoring providers do after a model is released. The second targets training-content summaries, the public documentation of what data went into a model, and is aimed at providers that had not published one or had not engaged in the informal compliance talks the office ran over the past year.

Nobody has been fined yet, and a request for information is a normal first step, not a verdict. Still, the speed sends a message. The office did not wait for a complaint or a scandal; it started with its own questions almost immediately. For anyone who assumed European AI regulation would be slow and mostly theoretical, that assumption is now out of date.


The money side: what the fines look like

The penalties for general-purpose AI providers are set out in Article 101 of the Act. The maximum is 15 million euros or 3 percent of global annual turnover, whichever is higher. That tier covers intentional or negligent breaches of the model rules, but it also covers giving false or incomplete information in response to a request and refusing to let the office evaluate a model. In other words, the letters that went out last week are themselves enforceable.

A separate, higher tier of 35 million euros or 7 percent of turnover exists for prohibited AI practices under Article 5, things like social scoring or manipulative systems that exploit vulnerable people. Those bans have applied since February 2025, and from this August they can be enforced with the full penalty. Most businesses are nowhere near that category, but the number is worth knowing because it tends to come up in board discussions.

Beyond fines, the office can order a provider to take corrective measures and, in the worst case, restrict a model's availability in the EU market. That last power is the one that should interest a business owner most, because a model being pulled from Europe would break products built on it overnight.


Business manager and compliance officer reviewing AI vendor contracts and EU AI Act obligations at an office table


What was delayed, and what was not

A lot of the confusion this year comes from the Digital Omnibus package, a set of amendments that EU legislators agreed in May 2026 to simplify the Act. The headline change was a delay for high-risk AI systems. Stand-alone high-risk uses listed in Annex III, such as recruitment screening, credit scoring, education and access to essential services, were originally due in August 2026 and now apply from 2 December 2027. AI embedded in regulated products like medical devices, machinery and vehicles moves to 2 August 2028.

The AI literacy duty in Article 4 was also softened. Instead of guaranteeing a certain level of staff competence, companies must now "support the development of AI literacy" among their people. It is a lighter wording, but the duty itself stays.

What did not move is more important for most readers. The transparency obligations in Article 50 apply from 2 August 2026. That covers telling users when they are talking to an AI system, labelling deepfakes, and marking AI-generated content in a machine-readable way. There is a four-month grace period for the watermarking part for systems already on the market, running to 2 December 2026. And the general-purpose model rules, of course, were never delayed at all, which is exactly why the AI Office could act now.


Why your vendor's compliance is now your problem

Most companies do not build models; they build on them. The Act places the heaviest obligations on the provider of the model, so it is tempting to conclude that a company using an API has nothing to worry about. That is only half true.

Consider the practical chain. A model provider that fails to answer the AI Office, or answers badly, can be ordered to restrict its model in the EU. The company that built its customer-service bot, its search feature or its internal automation on that model then has an outage it did not cause and cannot fix. The regulatory risk sits with the vendor; the operational risk sits with you.

The signatory list of the General-Purpose AI Code of Practice is a useful shortcut here. Full signatories, including OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral and Cohere, are presumed to be following the rules and are therefore lower-risk to build on. Partial signatories such as xAI have to prove some chapters separately, and non-signatories such as Meta must demonstrate compliance by other means. None of this makes one model illegal to use, but it is a reasonable input when you choose a vendor, right next to price and latency.


Software development team building AI-powered digital products with model portability and audit logging in mind


Practical steps for businesses building digital products on AI

Start with a model map. Write down every AI model in your products and internal tools, who provides it, whether it is accessed through an API or self-hosted, and which of your users are in the EU. At many mid-sized companies this list is longer than management expects, because product teams add models faster than anyone documents them. You cannot assess exposure without it.

Second, add compliance status to procurement. When you sign or renew an AI vendor contract, ask whether the provider has signed the Code of Practice, whether it has published a training-content summary and what its process is when a regulator asks questions. A vendor that has answers ready is telling you something about its maturity.

Third, build for portability. Keep prompts, evaluation sets and integration code in a shape that lets you switch models without a rewrite. A thin abstraction layer between your product and the model provider is cheap insurance against a model being restricted or withdrawn.

Fourth, handle the Article 50 items yourself. Make sure your chatbots say clearly that the user is talking to an AI, that AI-generated images and audio in your marketing are labelled, and that machine-readable marking is in place before the December grace period ends. These are small engineering tasks, but they are your obligations as the deployer, not your vendor's.

Finally, keep logs. Record which model version handled what, keep the evaluation results you ran before shipping a feature, and keep records of the AI literacy training you offered staff. If anyone ever asks, the difference between a good afternoon and a bad month is whether the paper trail exists.


What this means for outsourcing and development partners

If you work with an external development team, this is a good time to talk to them about it. A partner that builds AI features for you should be able to show which models they used, how they tested them and where the data flows. Ask for that documentation as a standard deliverable, the same way you would ask for source code and deployment notes.

The reverse is also true. Agencies and freelancers who build AI products for European clients will increasingly be asked these questions in tenders and contract reviews. Being able to answer them cleanly is becoming a competitive advantage rather than an annoying extra.


Final notes

The first requests for information from the AI Office are not the end of the story; they are the start of a supervisory routine that will become normal over the next few years. The delayed high-risk deadlines bought some businesses time, but the rules that affect everyday AI products, the transparency duties and the general-purpose model obligations, are live now.

For a business owner the message is quite simple. Know which models you rely on, choose vendors who can answer a regulator, keep the ability to switch, and label what your AI produces. None of it requires a legal department. It requires a spreadsheet, a few contract questions and a bit of discipline in the engineering team, and that is a much better position to be in than reading about your vendor in the news.

 
 
 

Comments


​Thanks for reaching out. Some one will reach out to you shortly.

CONTACT US

bottom of page