Skip to content
← BlogComplianceAnalysis6 min read

The EU AI Act's enforcement phase just went live — here's what actually changed

July 10 activated real enforcement mechanics; August 2 hands the AI Office fining power over general-purpose models. What's binding now, and who it reaches.

By Norbelys Chirinos, Co-founder

Founder-reviewed ·How we research and correct articles

Two dates matter more than any other on the EU AI Act calendar this summer, and they landed nine days apart. On July 10, 2026, the Act’s transparency-and-enforcement machinery for general-purpose AI models moved from “on paper” to “in force,” giving national authorities the legal basis to actually act on complaints. On August 2, 2026 — the Act’s second anniversary of entering into force — a second, bigger set of provisions activates: the European Commission’s AI Office gains direct fining authority over providers of general-purpose AI models, and Article 50’s transparency obligations (the chatbot-disclosure rules) become binding across all 27 member states.

If you run a product with an EU user base and have been treating the AI Act as a 2027 problem, this is the point where that stops being true.

What actually became enforceable, and when

July 10, 2026 — the operational baseline. Market surveillance authorities in member states that had already designated a competent authority (see below — not all had) gained the standing to open investigations and request information under the Act’s general compliance provisions. This is the date most trade coverage flagged as “enforcement begins,” and it’s accurate, but it’s a soft start: without every member state’s authority in place, enforcement in July was uneven by country.

August 2, 2026 — the hard date. Three things change simultaneously:

  • Article 50 transparency obligations become binding. Anyone deploying an AI system that talks to people, or publishing AI-generated content on matters of public interest, has to disclose it — see the companion piece on what Article 50 actually requires for the specifics.
  • The AI Office gets fining power over general-purpose AI (GPAI) models. Before this date, the Office could request documentation and run technical evaluations, but it lacked the statutory authority to impose administrative penalties. After it, the Office can compel action: demand training and evaluation documentation from GPAI providers, run its own technical evaluations, order risk mitigations, and — for the first time — fine noncompliant providers.
  • The two-year grace period on the Act’s core provisions formally ends. August 2, 2026 is exactly two years after the Act entered into force, and several deadlines in the original text were pegged to that anniversary.

The penalty ceilings that come with this are the ones already written into the Act: up to €15 million or 3% of global annual turnover for most infringements (whichever is higher), rising to €35 million or 7% for prohibited practices. Those numbers were always in the regulation — August 2 is when the enforcement machinery capable of actually applying them to GPAI providers switches on.

The part that’s still messy: who’s actually watching

The Act designed enforcement as a two-tier system: national market surveillance authorities handle most day-to-day compliance, and the AI Office steps in specifically for general-purpose models where the same company both builds the model and deploys the downstream system. That only works cleanly if every member state has actually designated its national authority — and as of late July, that rollout is behind schedule. Public trackers put the number of member states with at least one competent authority designated somewhere in the high teens out of 27, with the rest still finalizing legislation or announcements as the August 2 deadline approaches. Germany designated its Bundesnetzagentur (federal network agency) months ago; other member states are visibly still working through their national implementing laws this summer.

Practically, that means enforcement intensity in the second half of 2026 will vary meaningfully by which EU country your users happen to be in — not because the law differs, but because the enforcer does.

Does this reach you if you’re not an EU company

Yes, if you have EU users, regardless of where your company is incorporated. The Act’s territorial scope follows the same logic GDPR made familiar: it applies based on where the AI system’s output is used, not where the provider is headquartered. A US or non-EU SaaS company with a chatbot, an AI-generated content feature, or a general-purpose model integration that EU users interact with is in scope for Article 50 the same way an EU-based company is. The AI Office’s GPAI authority is narrower — it mainly concerns the handful of companies actually training frontier general-purpose models — but the transparency obligations are broad by design and don’t carve out non-EU providers.

What to actually do about it this week

If you ship anything that talks to EU users — a support chatbot, an AI agent, AI-generated marketing copy served to the public — the concrete task is Article 50 disclosure, not GPAI compliance. That’s a narrower, more achievable scope than the headline “EU AI Act enforcement begins” suggests, and it’s covered step by step in the Article 50 guide and, from a builder’s checklist angle, in what to implement this quarter for chatbot disclosure.

For a cold-email or outreach program specifically, the AI Act doesn’t introduce new rules about sending — that’s still governed by CAN-SPAM, GDPR, CASL, and the rest of the regional patchwork — but if your outreach workflow uses an AI agent to draft, personalize, or send on your behalf, and that agent-facing product surfaces to EU recipients as something that looks like it’s talking to them directly, it’s worth checking whether Article 50’s disclosure duty touches that surface too. It’s a narrower question than “is my whole company compliant,” and worth answering precisely rather than broadly.

This is why the shape of the AI layer matters as much as its capability. An agent drafting or personalizing outreach through Norbelys’s API or MCP server doesn’t get to send or reply on its own — a campaign it builds sits in draft state until an explicit launch action, and an inbound reply surfaces for a human to answer rather than getting answered automatically. That structure is worth checking against Article 50 directly: the rule targets systems designed for direct interaction with a person, and an agent that assembles a message for a human to review and approve isn’t conducting that interaction, whatever else about your AI Act posture still needs work. The guardrails worth building around an AI layer that touches a sending domain — rate limits, approval gates, evidence requirements — are covered in full here, and they’re worth having in any outreach stack, Norbelys or otherwise, regardless of which regulation is the one asking.