TL;DR: The EU AI Office issued its first significant enforcement penalties within days of its August 2, 2026 enforcement start date: €18 million against a pan-European HR technology company for deploying hiring AI without conformity assessment documentation or human oversight controls, €14 million against a credit scoring provider for Annex III documentation failures, and €15 million against a retail chain for deploying a real-time emotion recognition system across four EU member states -- a prohibited practice under Article 5. Total: €47 million. The cases were pre-built before August 2, which means the AI Office already has a queue. If your company uses AI in hiring, credit decisions, or biometric analytics in EU-accessible spaces, the clock is running.
The EU AI Act's enforcement era started August 2, 2026. The AI Office waited zero days to demonstrate the regulation is not decorative.
Within days of the enforcement deadline, the European Commission confirmed three enforcement actions totaling 47 million euros -- the first significant fines under the EU AI Act since the regulation's adoption in 2024. The cases span three different AI application categories, three different violation types, and a combined fine that puts the new enforcement regime in league with GDPR's first major cycles. The speed is not coincidental. EU AI Office officials had signaled through mid-2026 that pre-built cases would be ready at launch, and the August announcements confirm that investigators were already working.
Case 1: The hiring AI fine (€18 million)
The largest individual fine -- 18 million euros -- went to a pan-European HR technology company for deploying hiring AI without two categories of required safeguards.
The first gap was conformity assessment. Under EU AI Act Article 43 and Annex III, any AI system used to screen job candidates, shortlist applicants, or rank candidates for positions falls into the Annex III high-risk category (Section 4: employment, workers management, and access to self-employment). Before deploying a high-risk AI system, the provider must complete a conformity assessment that documents: the system's intended purpose, the training data used and why it was appropriate, how the system makes recommendations, its accuracy and performance metrics, and what human oversight mechanisms are in place.
The company had done none of this in a documentable form. Investigators found incomplete technical documentation that could not demonstrate how the system made candidate recommendations, and no formal record of a conformity assessment having been conducted. That gap alone -- deploying a covered system without the required self-assessment -- was sufficient for an enforcement action.
The second gap made the penalty larger. EU AI Act Article 14 requires high-risk AI systems to be designed with human oversight as an operational reality, not an afterthought. The deployer must implement measures that allow designated human reviewers to monitor AI decisions, understand AI-generated outputs, and override or disregard AI recommendations when appropriate. The HR company's deployment had no documented oversight structure -- no designated reviewer, no override protocol, no logging of how often human judgment was applied to AI outputs.
The investigation was triggered by complaints about opaque and apparently discriminatory hiring decisions. That origin matters: regulators will hear complaints, work backward to documentation requirements, and find the gaps. If the investigation had been random, the company might have had time to patch its documentation. But complaints with a paper trail of affected candidates created a foundation that investigators could build quickly.
Case 2: The credit scoring fine (€14 million)
Credit scoring AI was classified as high-risk from the start. Annex III, Section 5 covers "access to essential private services and essential public services and benefits" -- and the AI Office has consistently treated algorithmic creditworthiness assessment as one of the clearest Annex III cases.
The 14 million euro fine against the credit scoring company reflects documentation and process failures similar to the hiring AI case. Detailed public information on the specific violation categories is limited -- the formal decision has not been published in full -- but the pattern matches what EU AI Act supervisors have flagged since 2025: credit providers implementing AI scoring models over existing GDPR-compliant infrastructure while treating the AI Act's additional obligations as a separate compliance track they could address later.
The coordination between this case and France's CNIL action the same week is notable. On August 4, CNIL sent formal information requests to 14 financial institutions operating credit scoring algorithms, demanding Annex IV technical documentation packages. The EU AI Office and CNIL are operating on separate tracks -- the EU AI Office fining centrally, national authorities probing documentation nationally -- but the simultaneous pressure makes the enforcement posture unmistakable.
See the CNIL credit scoring enforcement guide for the French enforcement track in detail.
Case 3: The emotion recognition fine (€15 million)
The retail chain case is in a different legal category from the other two. The hiring and credit scoring violations involved failing to comply with Annex III high-risk system requirements. The retail emotion recognition case involves deploying an AI system that the EU AI Act prohibits outright.
The company operated a real-time emotion recognition system across stores in four EU member states. The system analyzed customer facial expressions to infer emotional states. Customers received no notice that emotion recognition was occurring, no consent mechanism existed, and the company had not completed any risk assessment -- which was actually moot, because no amount of risk assessment can make a prohibited system compliant.
Under EU AI Act Article 5, real-time emotion recognition in publicly accessible spaces for commercial purposes is a prohibited AI practice. The law provides narrow exceptions for specific justified contexts -- research, safety, medical uses -- but retail customer emotion monitoring for commercial purposes does not qualify. The company's legal team had apparently reached a different conclusion, arguing that their system fell within a consumer retail exception that, on examination, does not exist in the text of Article 5.
The 15 million euro fine is not the maximum (Article 99 sets the cap for prohibited AI practices at 35 million euros or 7% of worldwide annual turnover, whichever is higher), suggesting the AI Office calibrated the penalty to the size of the operation rather than treating this as a maximum-penalty case. That calibration itself signals something: the AI Office is building enforcement precedent carefully, not starting with shock-doctrine penalties.
The prohibition extends beyond retail. Article 5(1)(g) explicitly covers emotion recognition in the workplace and educational institutions. Any company using tools that infer employee emotions from video feeds, voice analysis, or behavioral data is in prohibited territory under the same provision that caught this retail chain. See the EU AI Act Article 5 prohibited practices guide for the full prohibited-use list.
What these cases tell you about how the AI Office operates
Two patterns from the August enforcement actions deserve attention beyond the fine amounts.
The cases were pre-built. Enforcement actions this detailed -- with specific complaint origins, documentation review findings, and per-violation penalty calculations -- take months to develop. The August 2 enforcement deadline did not trigger a cold-start investigation process. The AI Office was already working these cases when enforcement powers went live. For companies that assumed enforcement would have a ramp-up period with informal warnings first, this is the corrective.
Technical compliance dialogues are still available. The AI Office's stated preference before formal proceedings is what it calls structured "technical compliance dialogues" -- conversations with AI system providers and deployers to assess compliance status and clarify grey areas. None of the three fined companies appear to have initiated this process. Companies that proactively contact the AI Office about their compliance posture before becoming the subject of a complaint have a more favorable pathway than companies that wait for an investigation letter.
The combination of pre-built cases and available proactive engagement channels defines the enforcement landscape: the AI Office has already identified likely violations, it is prepared to move fast when triggered by complaints, and it is willing to work with companies that engage first.
Who else is exposed
The three violation categories cover a substantial share of AI use in enterprise settings.
Annex III, Section 4 (employment AI): Any AI system used to screen resumes, rank candidates, assign job tasks, evaluate worker performance, or make promotion or termination recommendations in the EU falls into this category. This includes AI-powered applicant tracking systems, AI interview analysis tools, and AI scheduling systems with differential assignment capabilities. Conformity assessment and human oversight documentation is required before deployment -- not as an annual audit item, but before the system went live.
Annex III, Section 5 (access to essential services AI): Creditworthiness scoring, insurance risk assessment, and student admission AI all fall here. This covers both AI systems built by financial institutions and third-party AI scoring vendors whose products financial institutions deploy.
Article 5 prohibited practices: Emotion recognition in workplaces, educational institutions, and public spaces. This includes tools sold as "engagement detection," "attention monitoring," "customer sentiment analysis," and "workplace wellness" systems that analyze facial expressions, voice tone, or body language to infer emotional states. If the system infers an emotional state from physical inputs, investigate whether Article 5 applies before that investigation is done by someone else.
The EU AI Act Annex III guide covers the full list of covered AI system categories with plain-language definitions.
Compliance steps by violation type
If you deploy hiring AI:
- Identify whether each AI tool you use in hiring falls under Annex III Section 4. The test: does it help make, influence, or automate decisions about candidates or employees?
- Complete or reconstruct a conformity assessment. If your vendor is the provider, demand their conformity assessment documentation. If your team built or customized the system, the assessment responsibility is yours.
- Document your human oversight mechanism: who reviews AI outputs, what override process exists, and how human decisions are logged separately from AI recommendations.
- Register the system in the EU AI Act database if required for your system category.
If you deploy credit scoring or essential services AI:
- Pull the Annex IV documentation checklist and audit your current documentation against each of the 20+ required elements.
- Identify the gaps. Areas most commonly missing: training data documentation showing demographic representativeness, post-market monitoring plans, and accuracy metrics broken down by relevant demographic groups.
- Set a remediation deadline. The AI Office's enforcement posture suggests complaints will come before any informal warning.
If you use any biometric or emotion-analytic system:
- Map every tool in your stack that processes video, audio, facial images, or behavioral data to infer identity, demographics, or emotional state.
- For each tool, determine whether it falls under Article 5 as a prohibited practice or under Annex III as high-risk biometric categorization.
- For Article 5 systems: stop deployment and engage legal counsel on wind-down. There is no compliance path for prohibited practices.
- For Annex III biometric systems: the conformity assessment requirement applies, and third-party assessment (not self-assessment) is required for many biometric use cases.
The EU AI Act national enforcement framework guide explains how national authorities and the EU AI Office divide enforcement jurisdiction and what to do when you receive an information request from either.
What comes next
The August enforcement actions are not the ceiling. They are the floor.
The EU AI Act's Annex III high-risk system requirements apply to a long list of AI categories beyond hiring, credit, and emotion recognition -- medical devices, critical infrastructure, law enforcement tools, and key administrative AI systems all carry their own compliance obligations. The AI Office has indicated that additional enforcement actions are in progress, and national authorities across the EU are simultaneously pursuing cases within their own jurisdictions.
The practical implication for teams that haven't reviewed their AI systems against the EU AI Act in the past six months: the August cases show what "not compliant enough" looks like in enforcement terms. Three organizations that likely viewed their compliance posture as adequate (or believed enforcement was still prospective) are now paying a combined 47 million euros to update that view.
Related Reading
- EU AI Act Article 5: Prohibited AI Practices Guide
- EU AI Act August 2, 2026: What Changed and What to Do Now
- EU AI Act Annex III: High-Risk AI Systems Explained
- CNIL Opens 14 Credit Scoring Investigations: EU AI Act Enforcement in France
- EU AI Act: National Competent Authorities and How Enforcement Works
Sources: EU AI Office Issues First €47 Million in Fines Against Three Companies for High-Risk AI Violations, Commission starts enforcing AI Act rules and new transparency requirements on 2 August, EU AI Act Enforcement Phase Begins, EU AI Act Enforcement Is Live: Fines Now Real, AI Policy and Regulation: Key Updates from August 2026
