The European Union’s AI Act has entered its enforcement era, with core obligations now in force as of August 2, 2026. This marks a fundamental shift from the regulatory framework’s formative period to active implementation, with significant implications for AI developers, deployers, and businesses operating within the 27-member bloc.
The transition affects companies across the AI value chain. Providers of high-risk AI systems must now comply with stringent requirements including conformity assessments, technical documentation, transparency obligations, and human oversight mechanisms. Market surveillance authorities in each member state have been empowered to investigate compliance and impose penalties for violations.
Industry response has been mixed. Larger AI providers with substantial legal and compliance resources have been preparing for this moment for months, with OpenAI, Anthropic, and Google each establishing dedicated EU compliance teams. Smaller startups face proportionally higher burden, prompting concerns about competitive disadvantage relative to well-capitalized American counterparts.
The enforcement timeline unfolds progressively. High-risk AI systems in areas like employment, credit scoring, and critical infrastructure face immediate obligations. Prohibited practices—including social scoring systems and certain biometric categorization—are already illegal, with enforcement actions expected to follow swiftly for egregious violations. The full spectrum of obligations, including those for general-purpose AI systems, will phase in through 2027.
Outside the EU, the regulatory landscape remains fragmented. The United States has yet to enact comprehensive federal AI legislation, with state-level initiatives proliferating from California to Texas. This divergence creates compliance complexity for globally deployed AI products, potentially favoring companies with the resources to navigate multiple regulatory regimes simultaneously.
The EU’s enforcement approach will likely set a de facto global standard. Companies designing AI products for international markets may find it more efficient to adopt EU-compliant practices universally rather than maintaining separate compliance tracks. This dynamic could ultimately centralize global AI governance around Brussels’ approach, despite the EU representing a smaller market than the United States or China for many AI applications.
For enterprises deploying AI in Europe, immediate action is warranted. Reviewing existing AI systems against the high-risk categories, updating contractual arrangements with AI providers, and establishing internal governance structures for AI oversight have moved from planning exercises to operational necessities.