Wiedza Case studies
Ethics Advisor

The AI Act enters the stage of practical enforcement

From 2 August 2026, EU supervisory authorities can exercise their investigative and sanctioning powers in relation to the provisions of the AI Act that have become applicable

On 2 August 2026, the implementation of the EU Artificial Intelligence Act entered another significant phase. The AI Act is no longer a regulatory framework viewed primarily through the lens of future obligations and compliance preparations. In relation to further groups of provisions, it is becoming the legal basis for concrete supervisory, investigative and enforcement action.

From that date, the enforcement powers of the European Commission and its AI Office, the European Data Protection Supervisor and the competent national authorities apply in relation to those provisions of the AI Act that have become applicable.

Responsibility for enforcing the Regulation is divided among several categories of authorities. The AI Office is primarily responsible for supervising providers of general-purpose AI models, including the most advanced models that may pose systemic risks. Its remit also covers certain AI systems developed by the provider of the underlying GPAI model, or by another provider belonging to the same corporate group, as well as AI systems integrated into very large online platforms or very large online search engines designated under the Digital Services Act.

National competent authorities enforce the rules applicable to other AI systems. The European Data Protection Supervisor is responsible for AI systems used by EU institutions, bodies, offices and agencies.

Which obligations can now be enforced?

The AI Act applies progressively. The date of 2 August 2026 does not mean that every obligation established by the Regulation can now be enforced in full.

At this stage, enforcement activity focuses in particular on three areas.

Prohibited AI practices

The provisions concerning practices regarded by the EU legislature as unacceptable because of their potential impact on fundamental rights, safety and the values of the European Union are enforceable.

The prohibitions cover, among other things, certain systems using manipulative or deceptive techniques, systems exploiting the vulnerabilities of particular persons or groups, certain forms of social scoring, and individual assessments of the risk of committing a criminal offence based solely on profiling or personality traits.

The precise scope of each prohibition must be assessed against the conditions established in the AI Act. The mere use of persuasive techniques, profiling or behavioural assessment does not automatically make a system prohibited. The purpose of the system, the way it operates, the category of persons affected and its potential or actual effects are all relevant.

Obligations of providers of general-purpose AI models

The second major area concerns the obligations imposed on providers of general-purpose AI models, or GPAI models.

These include requirements relating to the preparation and updating of technical documentation, the provision of information to providers of AI systems integrating the model, the adoption of a policy to comply with EU copyright law, and the publication of a sufficiently detailed summary of the content used to train the model.

Additional requirements apply to GPAI models with systemic risk. Their providers are subject to obligations relating to model evaluations, the identification and mitigation of systemic risks, the documentation and reporting of serious incidents, and the provision of an adequate level of cybersecurity.

In practice, enforcement may therefore concern not only the formal documentation of a model, but also the provider’s risk-management practices, its relationship with downstream providers, technical security and its ability to demonstrate that the measures adopted are proportionate to the nature and scale of the relevant risks.

Transparency obligations

The transparency requirements applicable to certain AI systems and to content generated or manipulated using AI also apply from 2 August 2026.

They include, in particular, informing individuals that they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person. They also concern the technical marking of certain synthetic content, disclosure of the operation of emotion-recognition or biometric-categorisation systems, and the labelling of deepfakes and certain AI-generated texts published for the purpose of informing the public on matters of public interest.

These obligations are not uniform. Their scope depends, among other things, on whether the organisation acts as a provider or deployer, the type of content being generated and the context in which the content is disclosed.

The AI Act also provides for exceptions, including in certain contexts connected with the detection of criminal offences, as well as specific rules for artistic, satirical, fictional and similar works. Not every use of AI to create text, images or recordings will therefore require the same type of disclosure.

Not all provisions of the AI Act are enforceable yet

Precision is essential when describing the current implementation stage. The application of enforcement powers from 2 August 2026 does not mean that all obligations under the AI Act are now enforceable.

Under the current timetable, the rules governing the high-risk AI systems listed in Annex III are to apply from 2 December 2027. These include selected systems used in employment, education, access to essential services, law enforcement, migration and the administration of justice.

The provisions concerning high-risk systems that are safety components of products covered by EU product-safety legislation are to apply from 2 August 2028.

Certain prohibitions related to the generation or manipulation of non-consensual intimate material and child sexual abuse material are to apply from 2 December 2026.

Organisations must therefore analyse the implementation schedule at the level of individual obligations. It is not sufficient to state generally that “the AI Act applies” or that “the deadline has been postponed”. Different parts of the Regulation apply from different dates, and the powers of the competent authorities are linked to the date on which the relevant provision becomes applicable.

What enforcement powers does the AI Office have?

The AI Office has both investigative and sanctioning powers.

It can send requests for information to providers in order to verify compliance with the AI Act. These may take the form of an ordinary request from the AI Office or a formal decision of the European Commission. The provision of incorrect or misleading information may result in a fine. In the case of a request issued by formal decision, failure to reply or providing an incomplete answer may also be sanctioned.

In relation to GPAI models, the AI Office can perform model evaluations and require access to a model. Evaluations may be conducted by the AI Office itself or by appointed independent experts. The Office may also require the provider to take appropriate measures, including, where necessary, restricting the public availability of the model.

In cases involving AI systems, the AI Office may interview persons who may have information relevant to an investigation, provided that they consent to being interviewed, and may conduct inspections at providers’ premises.

Where an intentional or negligent infringement of the AI Act is established, the European Commission may adopt a decision imposing a penalty on the provider of the relevant AI system or GPAI model. The nature, gravity and duration of the infringement are among the factors taken into account when determining the amount of the penalty.

The highest penalties apply to infringements involving prohibited AI practices. They may reach EUR 35 million or, in the case of an undertaking, 7% of its total worldwide annual turnover for the preceding financial year, whichever is higher. Other infringements, including breaches of obligations applicable to GPAI models, may result in fines of up to EUR 15 million or 3% of total worldwide annual turnover.

A new infrastructure for reporting potential infringements

Alongside the new enforcement phase, the AI Office has launched tools that allow individuals, organisations, whistleblowers and providers of systems integrating GPAI models to submit information about potential infringements.

These tools do not have the same scope. The appropriate reporting channel depends on the nature of the allegation, the status of the reporting person and the provisions that may have been infringed.

AI Act Complaints Tool

The AI Act Complaints Tool allows natural and legal persons to submit complaints concerning alleged infringements of the AI Act by providers or deployers of AI systems, where the case falls within the exclusive competence of the AI Office.

A complaint must fall within the scope of Article 85 of the AI Act. The form should not be used to report infringements of other provisions of EU law, infringements of national law or matters falling outside the scope of the AI Act.

It is also not the appropriate channel for complaints concerning the obligations established in Articles 53–55 of the AI Act in relation to GPAI models. A separate mechanism is available to downstream providers for such matters.

Complaints can be submitted in any official language of the European Union and may be supported by relevant documents. The submission should identify the country in which the incident occurred and include a detailed description of the alleged infringement.

The AI Act Complaints Tool is not an anonymous reporting channel. Complainants must provide identification and contact details so that the complaint can be properly assessed and processed. The AI Office treats complaints confidentially. Where a case falls outside its remit, it may inform the complainant and, with the complainant’s prior consent, refer the case to the relevant national market-surveillance authority or to an authority responsible for protecting fundamental rights.

AI Act Whistleblower Tool

The AI Act Whistleblower Tool is intended for persons professionally connected to providers or deployers of AI systems, or to providers of GPAI models.

It enables potential infringements to be reported securely, confidentially and anonymously. It may be particularly important where knowledge about the design, training, deployment or monitoring of a system exists within an organisation and is not available to users or other external parties.

From an organisational perspective, the availability of this external channel increases the importance of effective internal reporting arrangements. Employees, contractors, consultants and other persons with professional access to information about a system may report suspected infringements directly to the AI Office.

Complaints channel for downstream providers using GPAI models

A separate channel is available to providers of AI systems that integrate GPAI models supplied by another provider.

They can use this channel to submit complaints concerning potential infringements of Articles 53–55 of the AI Act. Such complaints may concern, in particular, insufficient information or documentation from the model provider that prevents a downstream provider from understanding the model’s capabilities and limitations or from complying with its own obligations under the AI Act.

This mechanism reflects the importance of relationships between the different participants in the AI value chain. The compliance of a final AI system may depend on the quality, completeness and accuracy of the information provided by the supplier of the underlying model.

What does the beginning of enforcement mean for organisations?

Until now, much of the work surrounding the AI Act has focused on mapping AI systems, identifying roles in the value chain, classifying risks and developing internal policies.

These activities remain necessary, but they are no longer sufficient.

An organisation must be prepared not only to demonstrate that it has formally adopted certain procedures, but also to provide evidence that those procedures are actually implemented. Authorities may expect information that makes it possible to reconstruct the decision-making process, the risk assessment, the tests carried out, the basis for selecting particular mitigation measures and the way in which the system has been monitored after deployment.

In practice, organisations should verify at least:

  1. which AI systems and GPAI models they use, provide or integrate;
  2. whether their role as provider, deployer, importer, distributor, product manufacturer or authorised representative has been correctly identified;
  3. which provisions of the AI Act already apply to each system or model;
  4. whether any system could fall within a prohibited category;
  5. whether the relevant GPAI or transparency obligations have been fulfilled;
  6. where the relevant documentation is held and who is responsible for keeping it up to date;
  7. who may receive a request for information from an authority and who will coordinate the response;
  8. whether documents, logs, test results and other evidence can be preserved and produced promptly;
  9. whether there is a procedure for handling AI-related complaints and reports;
  10. whether internal whistleblowing channels cover AI-related risks;
  11. whether contracts with model, system and service providers ensure access to the information required to demonstrate compliance.

Consistency between public statements, technical documentation, contractual provisions, terms of service, risk assessments and the system’s actual operation is becoming particularly important.

A discrepancy between a formally adopted policy and operational practice may be identified not only during an inspection but also following a complaint from a customer, user, business partner or downstream provider, or a report submitted by a whistleblower.

From compliance readiness to enforcement readiness

The application of enforcement powers changes how organisations should approach compliance with the AI Act.

Compliance readiness involves preparing policies, classifications, implementation plans and governance structures. Enforcement readiness additionally requires an organisation to be able to defend its decisions before a supervisory authority.

An organisation should be able to explain:

  1. why a system was classified in a particular way;
  2. what information was used to assess its risks;
  3. which individuals and organisational units participated in the decision-making process;
  4. what risk-mitigation measures were adopted;
  5. how the effectiveness of those measures was verified;
  6. what data, documents and test results demonstrate compliance;
  7. how incidents, complaints and warning signals were handled.

The AI Act is therefore moving from regulatory preparation to practical supervision. The launch of complaint and whistleblowing mechanisms, combined with the power to request information, evaluate models and impose penalties, makes regulatory risk more immediate.

For organisations, this is the point at which the relevant question changes from “Do we have an AI policy?” to “Can we demonstrate to an authority that our solutions comply with the AI Act and that our risk-management processes work in practice?”.

Sources

Case studies
Ethics Advisor