EU AI Act Full Enforcement Is 16 Weeks Away — and Most Companies Are Already Behind
The EU AI Act enters full general enforcement on August 2, 2026 — 16 weeks from now. For most organizations deploying AI in Europe, the preparation window is not closing. It is closed.
The Act has been progressively live since February 2, 2025, when Chapters I and II took effect. Chapter V (general-purpose AI models), Chapter VII (governance), Chapter XII, and Article 78 all applied from August 2, 2025. Companies waiting for this August to begin compliance work are not running late — they are already in breach.
What August 2 Actually Triggers
The August 2, 2026 date activates the final tier: high-risk AI system requirements across nine domains:
- Critical infrastructure (water, energy, transport)
- Education and vocational training
- Employment and worker management
- Access to essential services (credit, insurance)
- Law enforcement and judicial administration
- Border control and migration
- Democratic processes and electoral systems
For deployers in these sectors, documented conformity assessments must be in place by August 2, not filed by then. The EU AI Office’s enforcement machinery is operational and building case precedent.
The Penalty Structure
Fines reach 7% of global annual turnover for serious violations — including use of prohibited AI systems (like real-time biometric surveillance in public spaces). Lesser infringements draw 3% of turnover. Providing incorrect information to regulators: €15M or 1% of turnover.
For a company at OpenAI or Anthropic’s current revenue scale, a 3% fine runs to roughly $900M.
What Operational Compliance Looks Like
The operational test is not “Do we have an AI policy?” It is “Can we show an auditor who owns each AI system, how it was classified, what controls apply, and what evidence proves those controls are working?”
Three compliance pillars have crystallized across enforcement guidance:
Algorithmic Transparency: Deployers of high-risk AI must document the logic behind automated decisions and make that documentation available to affected individuals and supervisory authorities.
Data Sovereignty: Documented controls over how personal data of EU residents is used for model training. This applies to GPAI providers serving European customers — which means every major frontier lab.
Liability Architecture: Clear internal frameworks assigning legal and financial responsibility when AI systems cause measurable harm.
GPAI Providers Are Already Subject to Chapter V
General-purpose AI model providers — a category encompassing GPT, Claude, and Gemini as deployed in Europe — have been subject to Chapter V since August 2025. This includes:
- Systematic capability evaluations before deployment
- Systemic risk assessments for models exceeding 10^25 FLOPs
- Incident reporting to the EU AI Office within defined windows
- Transparency disclosures to downstream deployers
The frontier labs have largely complied with disclosure requirements. Enforcement actions against model providers are more likely to focus on inadequate risk assessments for the highest-capability systems.
The Practical Gap
The August 2026 enforcement cliff is a documentation and governance gap for most enterprises, not a model capability gap. The systems that need conformity assessments are often not cutting-edge; they are existing AI-augmented HR tools, credit-scoring models, and predictive policing software that has been running for years under no formal classification regime.
For US-headquartered AI users: EU AI Act obligations apply based on where AI systems have effects, not where the developer is headquartered. A company with European customers deploying high-risk AI from a US data center is in scope.
The 2026 enforcement window is real. The audit trail that regulators will demand in Q4 2026 is being built — or not built — right now.