TL;DR: August 2, 2026 marks 12 months since the EU AI Act entered into force, activating GPAI transparency requirements, AI Office supervisory powers, and the start of the conformity assessment clock for high-risk systems. National market surveillance authorities are now fully empowered. Companies should audit GPAI compliance, check Article 50 transparency obligations, and confirm no prohibited practices remain in use within the first 30 days.
August 2, 2026 is not the end of EU AI Act implementation. It is the beginning of active enforcement for a significant portion of the Regulation's scope. If your organization provides or deploys AI, something changed on this date that requires a response.
This guide explains what enforcement powers became active on August 2, 2026, what was already in force before that date, the remaining timeline of obligations ahead, and what specific actions companies need to take in the first 30 days.
The EU AI Act timeline: what was already active before August 2
The EU AI Act entered into force on August 2, 2025. Most compliance deadlines are staged from that date.
The first major enforcement trigger arrived before August 2026. Article 5, which lists prohibited AI practices, applied from February 2, 2026, six months after entry into force. By August 2, 2026, organizations had already been subject to the prohibited practices prohibition for six months. If your company uses AI for social scoring, real-time remote biometric identification in publicly accessible spaces without authorization, manipulation through subliminal techniques, or exploitation of vulnerabilities of specific groups, enforcement action was already possible before August 2026.
The AI Office was also operational before August 2026. It published the GPAI Code of Practice and began its market engagement activities. However, the full supervisory powers under Chapter VI of the Regulation did not apply until the 12-month mark.
What became active on August 2, 2026
Three major changes took effect on August 2, 2026.
GPAI transparency requirements entered enforcement scope. Articles 53 and 55 of the EU AI Act impose specific obligations on providers of general-purpose AI models. These provisions became applicable at the 12-month mark. GPAI providers must now maintain technical documentation (Annex XI), comply with applicable copyright law and publish a summary of training data used (Article 53(1)(d)), and make their model policy publicly available. Providers of GPAI models classified as posing systemic risk face the additional obligations in Article 55: adversarial testing, incident reporting to the AI Office, cybersecurity measures, and energy efficiency information.
AI Office supervisory powers activated fully. The AI Office has authority to request information from GPAI providers, conduct evaluations, and take enforcement measures for GPAI-related violations. The Office can issue decisions requiring providers to mitigate systemic risks, restrict market access, or pay fines. Fines for GPAI violations can reach 3% of worldwide annual turnover or 15 million euros, whichever is higher. The AI Office's supervisory mandate covers providers regardless of where they are established, as long as their models are accessed in the EU.
The conformity assessment clock started for high-risk AI systems. While the compliance deadline for high-risk AI systems is August 2027 for new systems, the technical standards bodies (CEN and CENELEC) now face their own deadlines to publish harmonized standards. The availability of harmonized standards determines whether providers can self-certify or require notified body review. Organizations should check the current status of relevant harmonized standards to understand their conformity assessment path.
The remaining EU AI Act deadline calendar
August 2026 is not the final deadline. Organizations need to track three more dates.
August 2, 2027: The main high-risk AI system obligations apply. Systems listed in Annex III that are placed on the market after this date must comply with the full technical requirements: risk management system (Article 9), data governance (Article 10), technical documentation (Article 11), record-keeping (Article 12), transparency and instructions for use (Article 13), human oversight (Article 14), accuracy and robustness (Article 15), and cybersecurity. Conformity assessment must be completed before market placement.
August 2, 2028: Member states must have designated national competent authorities under Article 70 and notified bodies must be accredited and operating. This is a structural deadline for the enforcement infrastructure, not directly a compliance deadline for providers, but it affects the availability of notified body services for conformity assessment.
August 2, 2030: Transitional provisions for high-risk AI systems already on the market before August 2, 2026 expire. Legacy systems deployed before the compliance deadline must meet all high-risk AI requirements by this date or be taken off the market.
What enforcement will look like initially
Enforcement under the EU AI Act will not begin with coordinated raids across every member state. Based on the AI Office's published work program and the pattern of enforcement under the GDPR in its early years, enforcement is likely to follow a predictable progression.
Complaint-driven cases first. The initial enforcement actions are most likely to arise from complaints by affected persons or civil society organizations. This mirrors the GDPR pattern, where early high-profile cases (Schrems I, Schrems II) were driven by individual complaints. For AI systems, the most likely complainants are people who believe they were harmed by prohibited practices or by GPAI systems used without adequate transparency.
AI Office GPAI investigations in parallel. The AI Office has signaled that it will conduct active market surveillance of major GPAI providers, not just respond to complaints. Its first published enforcement priorities focus on systemic risk assessment for large general-purpose models. Companies providing or relying on large GPAI models should assume AI Office attention is possible regardless of whether a complaint is filed.
National authorities focused on deployers. National market surveillance authorities are primarily responsible for deployers and providers of non-GPAI high-risk AI systems. Their capacity varies by member state. Organizations with EU operations across multiple countries should not assume that enforcement will be uniform in timing or approach.
What triggers an investigation
Under Article 74, market surveillance authorities can initiate investigations on their own initiative or following a complaint. Under Article 88, the AI Office can investigate GPAI providers at the Commission's direction or following a reasoned request from a market surveillance authority.
The practical triggers that are most likely to generate an investigation in the first year are:
- A complaint from an affected person or organization alleging a prohibited practice or GPAI transparency violation.
- A reported serious incident involving a high-risk AI system that comes to a national authority's attention.
- Media or civil society attention on a specific AI system that prompts a national authority to open a preliminary inquiry.
- An AI Office own-initiative investigation targeting a GPAI model provider identified in its market surveillance activities.
Proactive disclosure, where a company voluntarily reports a potential violation before it is discovered, is permitted and may affect the severity of any enforcement response. The Regulation does not provide explicit whistleblower-style incentives for self-reporting, but regulators across other EU frameworks have consistently treated voluntary disclosure as a mitigating factor in penalty calculations.
Questions legal teams are asking on August 2, 2026
What constitutes cooperation with an inspection? Under Article 79, market surveillance authorities can conduct on-site inspections and request access to data, documentation, and systems. Cooperation means providing requested access, not obstructing access, and ensuring that designated contact persons are available. Obstruction or providing false information is itself a violation and can result in additional fines.
How long does an inspection take? The Regulation does not prescribe a maximum inspection duration. GDPR investigations have taken anywhere from weeks to years. Companies should designate a regulatory affairs contact and maintain a document index that allows rapid retrieval of requested materials.
What happens if a system is found non-compliant during an inspection? Authorities can issue corrective action requirements, require the system to be withdrawn from the market, impose provisional measures, and ultimately impose fines. The Regulation allows authorities to require interim measures where a system poses a serious risk before an investigation is completed.
How should we handle confidential technical documentation? The Regulation requires access to technical documentation during investigations. It also provides that confidential information obtained during inspections is subject to professional secrecy obligations. Companies can assert trade secret protection for specific elements of documentation, but cannot use confidentiality to withhold documentation that an authority has lawfully requested.
The 10-point August 2, 2026 readiness checklist
-
Confirm whether your organization is a GPAI provider under Article 3(63). If yes, verify that technical documentation, training data summary publication, and model policy are in place.
-
Audit your environment for any practices that fall within Article 5 prohibited categories. If any were identified and not remediated before February 2026, escalate immediately to legal counsel.
-
Check Article 50 compliance for any AI systems generating synthetic content (images, audio, video, or text intended for publication). The technical measures for AI-generated content labeling must be in place.
-
Identify the national competent authority in each EU member state where you have relevant AI operations. Designate an internal contact for regulatory inquiries in each jurisdiction.
-
Verify that your incident reporting process has a channel for reporting serious incidents to the AI Office (for GPAI providers) or national market surveillance authorities (for high-risk AI deployers).
-
Review your GPAI model contracts if you are a deployer rather than a provider. Confirm that your provider's compliance documentation is current and accessible.
-
Check whether any of your AI systems are in scope for the August 2027 high-risk AI compliance deadline. Begin the documentation and conformity assessment process now.
-
Update your legal basis documentation for any AI-processed personal data in light of the AI Act's interaction with GDPR.
-
Document the basis for your GPAI systemic risk classification decisions. If you have determined that a model you provide does not meet the systemic risk threshold, record the reasoning.
-
Ensure that board-level or senior management is briefed on EU AI Act enforcement activation, including the fines regime. Fine levels (up to 3% of global turnover for GPAI violations, up to 35 million euros or 7% of turnover for prohibited practices violations) are material events for many organizations.
What comes next
August 2026 is a milestone, not a finish line. The compliance work for high-risk AI systems is still ahead of most organizations. The good news is that the legal framework is now settled enough to act on. The bad news is that "wait and see" is no longer a defensible posture for organizations that have material AI exposure.
For teams working through high-risk AI compliance, the EU AI Act August 2026 compliance checklist provides a structured starting point. For GPAI-specific obligations, the GPAI August 2026 compliance checklist covers the full Article 53 and 55 requirements.
Related reading
- EU AI Act August 2026 compliance checklist
- EU AI Act GPAI August 2026 compliance checklist
- EU AI Act deployer evidence gaps for SMEs
- EU AI Act first enforcement actions Q3 2026 what to expect
- EU AI Act GPAI Code of Practice final June 2026
- EU AI Act August 2026: What's Delayed and What Still Applies
- EU AI Act GPAI Codes of Conduct 2026: Provider Obligations and Complianc
- Meta Skipped the EU AI Code: What Llama Deployers Must Do Now
- CNIL Targets Credit Scoring AI First: EU AI Act Enforcement Is Real
