EU AI Act: Durchsetzungsbefugnisse treten am 2. August in Kraft
- Was ist passiert
- The EU AI Act's enforcement phase activates August 2, 2026. The European Commission gains full penalty power over frontier model makers — fines up to 3% of global annual turnover, retroactive to August 2025. Article 50 transparency rules (chatbot disclosure, synthetic content watermarking, deepfake labeling) become enforceable the same day.
- Warum es wichtig ist
- This is the first jurisdiction with binding enforcement authority over frontier AI. Every foundation model provider — OpenAI, Anthropic, Google, Meta, xAI — now faces real financial consequences for non-compliance with training data disclosure, copyright policy, and systemic risk assessment obligations. The EU model is the framework every other regulator is watching.
- Was zu tun ist
- Audit Article 50 compliance immediately — every chatbot, voice agent, and generative AI tool needs disclosure and watermarking by August 2. GPAI providers must verify documentation against actual implementation, not just Code of Practice signatory status, since penalties are retroactive. Begin Annex III high-risk system inventory now for the December 2027 conformity assessment deadline.
On August 2, 2026, the EU AI Act stops being a paper framework and becomes the world's first enforceable AI law with real financial penalties. The European Commission gains full authority to fine general-purpose AI model providers — OpenAI, Anthropic, Google, Meta, and the roughly dozen labs building models above the 10²⁵ FLOPs threshold — up to 3% of global annual turnover. And those fines apply retroactively for violations dating back to August 2025.
For the first time, a government has binding enforcement power over frontier AI. Three mechanisms activate simultaneously: GPAI penalty enforcement, Article 50 transparency rules, and prohibited-practices penalties that have been in force since February 2025.
What happened
The EU AI Act has been phasing in since August 2024, but the enforcement machinery had a critical gap: the Commission could set rules but couldn't fine anyone. That ends August 2.
GPAI penalty enforcement. General-purpose AI model providers have been legally obligated since August 2025 to publish training data summaries, maintain copyright compliance policies, and conduct systemic risk assessments. But for the first year, the Commission lacked penalty authority. On August 2, it gains three graduated powers (Lawfare, 2026): the power to demand documentation including technical specs and training data summaries; the power to commission independent model evaluations with access to source code; and the power to compel mitigations — up to restricting a model's availability or pulling it from the EU market entirely.
The fines underpin all three: up to €15 million or 3% of global annual turnover, whichever is higher. For a company like Alphabet, 3% would exceed €9 billion. The same maximum applies whether a provider violates its substantive obligations or simply refuses to comply with an information request.
Article 50 transparency. Chatbots must disclose they are AI. Synthetic audio, images, video, and text must carry machine-readable watermarks. Deepfakes depicting real people must be visibly labeled. Emotion recognition and biometric categorization systems must disclose their nature to subjects. These rules are enforceable August 2 with fines of up to €15 million or 3% of global annual turnover (TechTimes, 2026). Legacy systems already on the EU market get a four-month grace period for watermarking — until December 2, 2026.
Prohibited practices. Social scoring, subliminal manipulation, indiscriminate biometric scraping, and most real-time biometric surveillance in public spaces have been banned since February 2, 2025. Penalties remain in force at up to €35 million or 7% of global turnover — the highest fine tier in EU digital regulation, deliberately set above GDPR's 4% maximum.
What got delayed (and why)
The most demanding obligations — conformity assessments, CE marking, and full technical documentation for high-risk AI systems in employment, education, credit scoring, and law enforcement — have been pushed to December 2, 2027, for standalone systems, and to August 2, 2028, for AI embedded in medical devices and industrial machinery.
The Digital Omnibus on AI, adopted by the European Parliament on June 16 and by the Council on June 29, made these extensions binding law (TechTimes, 2026). The reason is not political accommodation but a standards gap. The harmonized European technical standards that make self-certification possible — being developed by CEN/CENELEC's JTC 21 with over 1,000 experts — missed their April 2025 deadline and are now projected for Q4 2026 at the earliest. You can't certify compliance against standards that don't exist.
Two new prohibited practices were added in the Omnibus, effective December 2, 2026: AI-generated non-consensual intimate imagery and AI-generated child sexual abuse material. Both were added in response to a late-2025 incident in which xAI's Grok generated an estimated three million sexualized images, including approximately 23,000 appearing to depict minors, over eleven days (TechTimes, 2026).
Why it matters
The EU AI Act is the regulatory framework every other jurisdiction is watching. The EU model — broad, standardized, penalty-backed — is the most complete alternative.
The AI Office's choices in its first months will determine whether providers treat the Code of Practice as a serious compliance framework or a voluntary gesture. Approximately 24 organizations signed it, including Amazon, Anthropic, Google, IBM, Microsoft, and Mistral AI. Notably, Meta declined to sign entirely. xAI signed only the Safety and Security chapter — leaving its compliance with transparency and copyright obligations to be demonstrated through alternative means. That posture becomes significantly riskier once penalty powers are active.
The enforcement gap no one is talking about
The EU AI Office — responsible for supervising GPAI models — employs more than 125 staff across all functions, only a portion of whom work on general-purpose AI supervision. The office has over a hundred distinct responsibilities under the Act. A recommendation from the think tank Pour Demain calls for scaling GPAI supervisory capacity to at least 160 staff by 2030 (Lawfare, 2026). For comparison, the UK's AI Safety Institute employed around 250 people by August 2025.
National enforcement is even patchier. Article 50 transparency rules are enforced by national market surveillance authorities in each of 27 member states. At least twelve member states missed the August 2025 deadline to designate those authorities. France had not notified its national competent authorities to the Commission as of June 2026. Germany's implementing legislation was still moving through the Bundestag as of July 2026.
What this means in practice: enforcement in the first year will be geographically concentrated and inconsistent. A chatbot deployed in Ireland will face different scrutiny than one deployed in a member state without a designated authority.
As Harvard Kennedy School fellow Joel Christoph wrote in Lawfare: "The tools are on the table. The question is whether anyone picks them up."
What changes for you
If your AI systems touch the EU market in any way, three actions are urgent:
- Audit Article 50 compliance immediately. Every chatbot, voice agent, image generator, and content tool must disclose its AI nature by August 2. New systems entering the EU market on or after August 2 must implement machine-readable content marking from day one.
- Verify GPAI compliance retroactively. The Commission can now fine you for violations going back to August 2025. Compliance with the GPAI Code of Practice should be verified against actual documentation, not just signature status. Providers who relied on the Code's safe harbor should confirm their technical documentation, copyright policies, and training data summaries meet the Code's commitments in practice.
- Start the Annex III inventory now. The December 2027 deadline for high-risk system conformity assessments is not a pause. Industry surveys found 78% of organizations had not taken meaningful compliance steps as of April 2026. Conformity assessments, risk management systems, and technical documentation take substantial preparation time — and the standards they depend on aren't published yet.
FAQ
Does the high-risk delay affect the August 2 chatbot disclosure requirement?
No. The Digital Omnibus extended only the conformity assessment deadlines for high-risk AI systems (employment, credit scoring, law enforcement) to December 2027. Article 50 transparency obligations — chatbot disclosure, synthetic content watermarking, deepfake labeling — go live August 2 as originally scheduled.
Can a company outside the EU be fined under the AI Act?
Yes. The Act applies extraterritorially — any provider placing AI systems on the EU market, or whose AI outputs are used in the EU, falls within scope. The test is not where the company is incorporated but whether the system's outputs reach EU users. Non-EU companies deploying high-risk AI must appoint a written authorized EU representative.
What happens if the harmonized standards aren't ready by December 2027?
If CEN/CENELEC's standards arrive in Q4 2026 as projected, providers get approximately 14 months before the December 2027 deadline. If they arrive later, the implementation window compresses. The risk of another extension is real — but organizations that wait for it are gambling on a political process. The Freshfields analysis captured the reality: "Businesses in scope gain a meaningful runway, but that time should be used productively as the underlying obligations have not changed."
Was zu tun ist
- 1 Audit all EU-facing chatbots and generative AI tools for Article 50 compliance — disclosure, machine-readable watermarking, and deepfake labeling
- 2 Verify GPAI documentation (training data summaries, copyright policies, risk assessments) against actual implementation, not just Code of Practice signature status — penalties are retroactive to August 2025
- 3 Begin Annex III high-risk AI system inventory now — the December 2027 conformity assessment deadline requires substantial preparation time that 78% of organizations haven't started
Betroffene Tools & Modelle
Nie wieder etwas verpassen
Das wöchentliche Delta — nur Urteilsänderungen und dringende Punkte. Kein Füllmaterial.