Policy & RegulationPolicy & Regulation 5 min read

EU AI Act Enforcement Powers Now Active

From 2 August 2026 the European Commission’s AI Office and national competent authorities can enforce AI Act rules on GPAI obligations, prohibited practices, and transparency, with penalties up to €35 million or 7% of worldwide turnover.

PC

PromptCrates Editorial

Staff Writer

0 0
EU AI Act Enforcement Powers Now Active

From 2 August 2026 the European Commission’s AI Office and Member State national competent authorities hold enforceable powers under the EU AI Act for general-purpose AI obligations, prohibited practices, and specified transparency rules. The Commission’s enforcement page caps penalties for prohibited practices at up to €35 million or 7 percent of worldwide annual turnover — whichever is higher — while other breaches, including GPAI duties, can reach €15 million or 3 percent.

Who enforces which AI systems

The Commission’s AI Act enforcement framework splits supervision. The AI Office covers providers of general-purpose AI models, including systemic-risk GPAI; AI systems built by the same provider or group as the underlying GPAI model; and AI systems integrated into very large online platforms or very large online search engines designated under the Digital Services Act. National competent authorities enforce rules for other AI systems. The European Data Protection Supervisor covers AI used by EU institutions.

That split matters for US and UK frontier labs that sell GPAI into Europe and for consumer chat products that also operate as DSA-designated search or platform surfaces. PromptCrates previously covered ChatGPT’s DSA very-large search-engine path; AI Act GPAI and transparency duties now sit beside that DSA track for the same corporate groups.

Powers penalties and live tools

Investigative tools include requests for information — simple or by Commission decision — with fines for incorrect, misleading, missing, or incomplete replies. For GPAI models, the AI Office can run model evaluations, issue requests for access, and ask providers to take measures including restricting public availability. For AI systems it can interview consenting witnesses and inspect provider premises. If intentional or negligent breaches are established, the Commission may adopt penalty decisions scaled to nature, gravity, and duration.

Prohibited-practice infringements sit at the top of the fine schedule (€35 million or 7 percent turnover). Other breaches, including GPAI obligations, top out at €15 million or 3 percent. Failure to comply with information requests on AI systems can reach €7.5 million or 1 percent turnover. Monitoring channels now include an AI Act Complaint Tool for alleged infringements by AI Office-supervised providers, a Whistleblower Tool for professionally connected individuals, and a complaints channel for downstream providers using someone else’s GPAI model under Articles 53–55.

Timeline beyond August twenty twenty six

August 2026 activates enforcement for already-applicable bans on unacceptable practices — manipulation, exploitation of vulnerabilities, certain social scoring, and individual predictive policing based solely on profiling — plus GPAI transparency and copyright-related duties, systemic-risk safety rules for the most advanced GPAI, and transparency for chatbots, deepfakes, and machine-readable marks on synthetic content. Codes of Practice operationalise GPAI and transparency obligations.

Later gates still loom. Prohibitions tied to generation or manipulation of non-consensual intimate material and child sexual abuse material apply from 2 December 2026. Annex III high-risk AI system rules apply from 2 December 2027; high-risk AI embedded in regulated products follows on 2 August 2028. Providers planning product roadmaps should not treat August 2026 as the finish line.

For builders, the practical message is documentation and escalation paths: know whether you are a GPAI provider, a downstream integrator, or a national-authority supervisee; map chatbot and synthetic-media labeling; and rehearse how you would answer an RFI or model-access request. Pair this regulatory clock with OpenAI Astra’s critical cyber framing when systemic-risk narratives overlap safety evals.

None of the Commission’s overview text replaces the AI Act’s legal provisions — the page itself is informational and non-binding — but the fine schedule and authority map are now the operating reality for compliance teams. Enforcement powers are no longer a future slide; since 2 August 2026 they are live.

Compliance calendars should mark three horizons. Immediate: chatbot disclosure, deepfake labeling, synthetic-content marks, GPAI transparency and copyright-related duties, and the ban on listed prohibited practices. December 2026: CSAM and non-consensual intimate-image prohibitions. December 2027 and August 2028: Annex III high-risk and product-embedded high-risk regimes. Missing any horizon is a board-level failure for GPAI providers and for platforms that also carry DSA designations.

National authorities will not move uniformly. Some Member States will staff quickly; others will lag, creating forum-shopping temptations that the AI Office’s GPAI and VLOP/VLOSE remit is meant to blunt for the largest players. Downstream providers that embed another company’s GPAI model finally have a formal complaints channel for Articles 53–55 issues — a quiet but important shift for startups that previously had little leverage over foundation-model vendors.

Whistleblower and public complaint tools raise the odds that enforcement starts from outside counsel memos rather than only from scheduled audits. Providers should assume employees and competitors know those channels exist. Investigative powers that include model evaluations and premises inspections mean paper policies without runnable evidence will not survive an RFI. The August 2026 switch is therefore less a symbolic date and more the start of a multi-year evidence race between regulators and labs.

For product and legal teams reading PromptCrates, the actionable takeaway is simple: map your systems to AI Office versus national supervision now, quantify exposure under the 7 percent and 3 percent fine caps, and rehearse document production for RFIs before the first formal letter arrives. Enforcement is active; the grace period of “rules on paper only” is over.

Sources

EU AI ActAI OfficeGPAIregulationenforcement

Related articles