Skip to main content
53 days

Super Intelligence definition proposal due (60 days) · Nov 28, 2026 · See what changes

Guides

EU AI Act first enforcement actions in Q3 2026: what small teams should expect

EU AI Act first enforcement actions begin Q3 2026: which small teams face real risk, what triggers a complaint, and how to reduce it.

9 min readBy Johnie T YoungUpdated 81 days ago
Tagseu-ai-actenforcementpenaltiescomplianceq3-2026
EU AI Act first enforcement actions in Q3 2026: what small teams should expect

TL;DR: EU AI Act enforcement becomes operational in Q3 2026, but first fines are more likely in 2027. GPAI providers and large high-risk AI deployers face the most immediate scrutiny. Small teams that document their AI use and follow basic governance practices face very low enforcement risk.

The EU AI Act has been law since August 2024. Enforcement has been limited to prohibited AI practices (since February 2025) and the European AI Office's work on GPAI codes of practice. That changes in Q3 2026.

August 2, 2026 is the date by which every EU member state must have designated a national supervisory authority with the power to investigate, sanction, and fine AI system deployers and providers in their jurisdiction. When that deadline passes, the enforcement machinery is fully assembled.

This guide covers who faces enforcement first, what triggers investigations, how the penalty structure works, and what the realistic risk picture looks like for small teams.

The enforcement structure from August 2, 2026

National supervisory authorities

Each EU member state must designate at least one national supervisory authority (NSA) responsible for enforcing the AI Act for AI systems used in their jurisdiction. In practice, several member states are expected to designate existing data protection authorities or sector regulators, similar to GDPR implementation.

The NSAs will handle:

  • Market surveillance of AI systems made available or used within their territory
  • Investigation of complaints from individuals under Article 85
  • Audits and inspections of providers and deployers
  • Penalty proceedings

The 27 NSAs will not coordinate seamlessly from day one. Early enforcement is likely to be inconsistent across member states, with larger, better-resourced authorities in Germany, France, the Netherlands, and Ireland likely to act first.

The European AI Office

The European AI Office, established within the European Commission, has distinct authority for GPAI models made available in the EU. Unlike NSAs, which have jurisdiction bounded by their member state, the AI Office can investigate any GPAI provider globally.

The AI Office has been running the GPAI code of practice process throughout 2025 and 2026 and has more institutional readiness than most member state NSAs. GPAI enforcement actions are therefore more likely to emerge from the AI Office than from national authorities in the near term.

For a detailed rundown of GPAI obligations, see the EU AI Act GPAI compliance checklist August 2.

What will trigger early enforcement actions

Individual complaints under Article 85

Any person can lodge a complaint with a national supervisory authority about a suspected violation. This mirrors the GDPR Article 77 complaint right and is expected to be a significant enforcement driver.

The most likely complaint scenarios:

  • An individual denied a job, loan, or benefit believes an AI system made a discriminatory or opaque decision
  • A consumer discovers they were targeted by what they believe is prohibited manipulative AI
  • An employee files a complaint about AI-based workplace monitoring or performance assessment
  • A journalist or civil society organization systematically tests AI systems and files complaints about violations

Complaints must be investigated by the NSA. Even if no penalty follows, an investigation forces the subject to produce documentation and cooperate with regulators. The cost and reputational exposure of an investigation can be significant even without a fine.

Whistleblower reports

The AI Act creates a framework for whistleblower reports about AI Act violations. Employees, contractors, and others with inside knowledge of non-compliance can report to NSAs with legal protection. This channel is particularly relevant for HR screening tools, credit decisions, and other high-stakes automated decisions where employees may witness discriminatory outcomes.

Market surveillance spot checks

NSAs have the power to conduct market surveillance, including testing AI systems and requesting documentation without a prior complaint. Early spot checks are likely to target sectors with the highest Annex III concentration: financial services, employment, and healthcare.

A judge's gavel striking its sound block on a dark wooden desk, representing national supervisory authority enforcement

Non-compliance with GPAI obligations

The AI Office has regulatory tools to compel GPAI providers to demonstrate compliance with their obligations: technical documentation, copyright policy, training data summaries, and participation in the code of practice. Providers that have not engaged with the code of practice process or have not produced required documentation are the most obvious early targets.

How the penalty structure works

The AI Act uses a tiered penalty structure based on the severity of the violation.

Violation category Maximum fine
Prohibited AI practices (Article 5) EUR 35 million or 7% of global annual turnover
Most other violations (providers, deployers) EUR 15 million or 3% of global annual turnover
Incorrect or misleading information to regulators EUR 7.5 million or 1% of global annual turnover
GPAI model violations EUR 15 million or 3% of global annual turnover

The regulation specifies that the higher of the two figures applies. For a company with EUR 500 million in global turnover, the 3% threshold at EUR 15 million is the ceiling for most violations. For a startup with EUR 2 million in turnover, the fixed caps apply.

Penalty calculation follows Article 99, which lists factors including: the nature, gravity, duration, and intentionality of the infringement; whether the infringer has previously been in breach; the degree of cooperation with supervisory authorities; and the financial size of the infringer.

Crucially, documented good-faith compliance effort is a mitigation factor. A company that can show it maintained a risk management system, ran human oversight, and had a compliance program even if imperfect will receive significantly different treatment from one that had nothing.

Realistic enforcement risk assessment by company type

Company profile Enforcement risk in 2026 Primary risk driver
GPAI model provider (large, wide EU market) High EU AI Office capacity and focus
Large HR AI vendor (Annex III) High Individual complaint exposure
Financial services AI deployer (credit decisions) Medium-High FCA/sector regulator coordination + complaints
Small SaaS using AI internally Low NSA capacity constraints, not priority
Small team using third-party AI tools Very low Not primary enforcement target
Company using prohibited AI High regardless of size Prohibited = strict enforcement intent

The key variable is not company size. It is whether you fall into a high-risk Annex III category and whether your use is visible to affected individuals who might complain.

What happens during an investigation

If an NSA opens an investigation, the sequence typically follows:

  1. The authority notifies the company of the investigation
  2. Documentation is requested: risk management records, technical documentation, human oversight logs, transparency notices
  3. The authority may conduct interviews and technical testing
  4. A preliminary finding is issued with an opportunity to respond
  5. A final decision is issued: closure, corrective measures, or penalty proceedings
  6. Penalty proceedings result in a formal fine decision, which can be appealed to an administrative tribunal or court

GDPR enforcement has shown that investigations can take 12-24 months from opening to final decision, sometimes longer. The process gives companies time to produce documentation and demonstrate compliance improvements, but only if the documentation exists.

What small teams should do before enforcement begins

Priority 1: maintain an AI tool register

Document every AI tool your organization uses, what it processes, and who approved it. If an NSA asks what AI systems you use, having an organized register demonstrates governance intent and avoids appearing caught off guard. Our AI governance checklist 2026 includes a register template.

Priority 2: confirm you are not using prohibited AI

Article 5 prohibited AI has applied since February 2025. If your organization uses real-time remote biometric surveillance in public spaces, social scoring, or manipulative AI, cease use immediately. The prohibited category is where enforcement intent is sharpest and the penalty ceiling highest.

Priority 3: implement Article 50 transparency notices

Article 50 transparency obligations for AI-generated content and AI system disclosures apply from August 2026. These are relatively straightforward to implement and are visible: an investigator or complainant can easily check whether your chatbot, content generation, or AI-assisted service has appropriate disclosure. See the EU AI Act Article 50 watermarking and deepfake disclosure guide for specifics.

Priority 4: review vendor DPAs and instructions for use

Your deployer obligations include ensuring your AI vendors have appropriate documentation. Request your vendor's instructions for use (Article 13 documentation) and confirm your DPA covers AI processing. Gap analysis guidance is available in our EU AI Act deployer evidence gaps SME August 2026 article.

Priority 5: document human oversight processes

The most effective enforcement risk reducer for deployers of high-risk AI is documented human oversight. If a complaint is filed and you can show that a human reviewed the AI's recommendation before any consequential decision was made, the compliance picture is dramatically better.

The GDPR parallel

GDPR enforcement provides a useful calibration. The regulation came into force in May 2018. The first major fines appeared in 2019. Most small businesses did not receive GDPR enforcement actions in the first two years, even if they were not fully compliant. The first wave of fines targeted large platforms, data brokers, and companies that had specific incidents or complaints.

The same pattern is likely for the AI Act. The first years of enforcement will be shaped by the highest-profile, highest-harm cases. Small teams that have made reasonable good-faith efforts will not be the regulators' primary focus.

That said, GDPR also showed that enforcement capacity grows over time, and by 2023 investigations were reaching much smaller organizations. Building compliance habits now is significantly cheaper than emergency remediation when enforcement reaches your sector.

The practical signal to watch: when the first EU AI Act enforcement action is publicly announced, read what the complaint alleged and what documentation the organization failed to provide. Early cases tend to reveal the documentation patterns that regulators are specifically looking for, and adapting to that signal quickly is worth more than any generic compliance checklist written before enforcement begins.

For the broader timeline context, the AI regulation deadline calendar 2026 tracks enforcement dates across all major AI regulations.

Legal disclaimer

This article is published for informational and educational purposes only. It does not constitute legal, regulatory, or professional compliance advice and should not be relied upon as such. AI governance requirements vary by jurisdiction, industry, and organizational context. Always consult a qualified legal or compliance professional before implementing policies or making decisions with regulatory implications.

About the author

Johnie T Young

AI expert and governance practitioner helping small teams implement responsible AI policies. Specialises in regulatory compliance and practical frameworks that work without a dedicated compliance function.

  • AI governance practitioner
  • EU AI Act and GDPR specialist
  • AI risk management expert
  • Compliance frameworks for small teams