Analysis
The part of the EU AI Act that most companies assumed would slip has not slipped. As of Aug. 2, 2026, the Act reached general application, and the Commission's AI Office now has active enforcement powers over providers of general-purpose AI models, Axios reported. Article 50 transparency obligations came into force on the same date and apply broadly: users must be told when they are interacting with an AI system, and synthetic audio, image, video and text must be marked in a machine-readable format.
What actually applies, and what does not
This is where most compliance commentary gets it wrong. The Digital Omnibus on AI -- adopted by the European Parliament on June 16, 2026 and given final Council approval on June 29 -- deferred the substantive high-risk regime. Conformity assessment, registration, risk management systems, data governance, logging and human-oversight requirements for Annex III systems now land on Dec. 2, 2027, and for Annex I product-embedded systems on Aug. 2, 2028. So a startup selling an AI hiring screener has roughly sixteen more months. A company shipping a chatbot or a generative feature into the EU has zero.
“The Digital Omnibus on AI -- adopted by the European Parliament on June 16, 2026 and given final Council approval on June 29 -- deferred the substantive high-risk regime.”
The penalty math
Fines for prohibited practices reach EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Other breaches, including general-purpose model obligations, top out at EUR 15 million or 3% of worldwide turnover. For context, 3% of Alphabet's turnover is a materially larger number than the GDPR's 4% cap has ever produced in practice, and the AI Office -- unlike national data-protection authorities -- is centralized, which removes the forum-shopping that made GDPR enforcement slow and uneven.
The competitive read
Big model providers have been staffing for this since the GPAI code of practice landed in 2025. OpenAI, Anthropic, Google and Meta all have EU policy teams and can absorb documentation, copyright-policy and training-data-summary obligations as a line item. The companies genuinely exposed are the middle: Series A and B startups with EU revenue, a generative feature, and no compliance function. A UK think tank warned this week that Big Tech's market power will cost Britain the AI race; the mirror argument in Brussels is that compliance cost is itself a moat, and it is the incumbents who can afford it.
The counterweight
Two honest caveats. First, enforcement powers existing is not the same as enforcement happening -- the AI Office is new, understaffed relative to its mandate, and has signaled a preference for guidance before penalties. GDPR's first meaningful fines arrived roughly eighteen months after application. Second, the Digital Omnibus itself shows the regime is politically negotiable: the high-risk deferral was won by industry lobbying, and further softening is plausible if the EU's competitiveness anxiety keeps rising. Assuming the December 2027 date is fixed would be a mistake in either direction.
For US founders, the practical to-do list is short and cheap: label your bot, watermark your generated media, publish a training-data summary if you train a general-purpose model, and keep a copyright policy on file. The expensive work is the high-risk regime, and that bill does not arrive until late 2027.