Skip to content

NewsroomTechnology briefing

The EU AI Act's enforcement era begins — with a moved goalpost

EU AI Act enforcement began August 2, 2026: the European Commission can now fine GPAI providers, Article 50 transparency is live, and California's SB 942 took effect too.

The TailorAI teamAugust 3, 2026 · 4 min read

On August 2, 2026, the EU AI Act entered its enforcement era. The European Commission, acting through the EU AI Office, is now formally entitled to investigate providers of general-purpose AI (GPAI) models and to enforce the rules on prohibited AI practices — with fines behind it. Article 50 transparency obligations took effect the same day. So did California's SB 942, on a date deliberately aligned with the EU's. And six days earlier, the EU's Digital Omnibus pushed the Act's high-risk compliance deadlines back to December 2027. The goalpost moved — but the whistle blew anyway. Here is what changed for operators.

Key takeaways

  • Enforcement is live. The EU AI Office can demand documentation, evaluate models, order corrective measures, and impose fines — up to EUR 35 million or 7% of global turnover for prohibited practices.
  • The high-risk deadline moved. The Digital Omnibus pushed Annex III compliance from August 2, 2026 to December 2, 2027, days before it was due to bite.
  • Transparency did not. Article 50 is enforceable now: chatbots must disclose they are AI, deepfakes must be labelled, and AI-generated content needs machine-readable marks.
  • California matched the date. SB 942 became operative August 2, 2026, requiring latent disclosures in AI-generated media and a free public detection tool.
  • Build disclosure plumbing once. EU and California duties overlap enough that one provenance pipeline supports both.

What became enforceable on August 2

The Commission's new powers are concrete. The EU AI Office can now request documentation from GPAI providers (Article 91), conduct model evaluations (Article 92), require corrective measures (Article 93), restrict or withdraw models from the EU market, and impose fines under Article 101. Penalties run up to EUR 15 million or 3% of worldwide annual turnover for GPAI violations, and up to EUR 35 million or 7% of global turnover for prohibited AI practices.

Article 50 took effect the same day, and it reaches far beyond the model labs. Three duties matter for most operations teams:

  • Chatbots and interactive AI systems must disclose that users are dealing with AI.
  • Deepfakes must be labelled as such.
  • AI-generated content must carry machine-readable marks.

One transition softens the GPAI side: models placed on the market before August 2, 2025 have until August 2, 2027 to reach full compliance. Article 50 has no such runway. If a customer-facing assistant serves EU users today, the disclosure duty applies today.

The Digital Omnibus moved the high-risk goalpost

The deferral came down to the wire. The Digital Omnibus on AI was published in the EU Official Journal on July 24, 2026 and entered into force on July 27 — six days before the Act's original high-risk compliance date. The European Parliament endorsed the package on June 16 by a 423–57 vote with 174 abstentions; the Council of the EU gave final approval on June 29.

What moved:

  • Standalone high-risk systems under Annex III — recruitment tools, credit scoring, education, critical infrastructure, law enforcement — now have until December 2, 2027, a 16-month deferral.
  • AI embedded in products covered by EU product-safety law (Annex I) moves from August 2, 2027 to August 2, 2028.
  • Member-state regulatory sandboxes are now due by August 2, 2027.

What tightened: the package adds new Article 5 prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material, with a transitional period until December 2, 2026. And Article 50 was not deferred at all. Reading the Omnibus as a pause is the wrong lesson.

The deadline that moved is the one you could schedule around. The obligations that held are sitting in your chatbot configuration right now.

California's SB 942 lands on the same date

The alignment is deliberate. SB 942, signed in September 2024 and amended by AB 853 in October 2025, became operative on August 2, 2026 — the same day EU enforcement began. It applies to generative AI systems with more than 1 million monthly visitors or users that are publicly accessible in California. Covered providers must embed latent, machine-readable disclosures in AI-generated images, video, and audio, offer a manifest disclosure option, and make a free public AI detection tool available. Further obligations for GenAI hosting platforms, large online platforms, and capture-device manufacturers phase in during 2027 and 2028. Enforcement runs through civil penalties by state authorities; there is no private right of action.

The operational read: two major jurisdictions now converge on machine-readable provenance. Disclosure plumbing built once — at the pipeline level, not per app — supports both regimes.

Prohibited-practice violations now carry fines up to EUR 35 million or 7% of global turnover; GPAI violations up to EUR 15 million or 3%. Transparency failures are no longer theoretical exposure.

What operators should do this quarter

The advice from our governance briefings applies unchanged: inventory first.

  1. 01Map every AI touchpoint that reaches EU or California users. Chatbots, voice agents, generated marketing media, document generation. You cannot disclose what you have not catalogued.
  2. 02Turn on disclosure now. AI-identification notices for interactive systems and machine-readable marks for generated content are configuration and pipeline work, not a year-long program. Ship them.
  3. 03Put provenance in vendor contracts. If a GenAI vendor's outputs land in front of your EU or California users, ask whether those outputs carry compliant latent disclosures — and get the answer in writing.
  4. 04Keep the high-risk program running. December 2, 2027 buys sixteen months for data governance, logging, human oversight, and conformity evidence. Teams that shelve the work now will rediscover the original deadline crunch — with less sympathy from regulators the second time.

We made the inventory-first argument in our federal briefing this spring, and our own compliance posture is documented on our trust page. If Article 50 or SB 942 touches systems you run, we can help scope the disclosure work — book a consult.

Filed underEU AI Actgovernmentsecuritycompliance
Share

Where this lands in our work

Reading is free. So is the first call.

Wondering what this means for your workflow? That's a thirty-minute conversation, not a research project.