aiexpert
Home / News / Brief
Policy · Aug 10, 2026, 06:34 AM · 4 sources

EU AI Act enforcement live: transparency rules, €15M fines, sandboxes; high-risk obligations deferred

On August 2, 2026, the European Commission's AI Office and national member-state authorities began enforcing the EU AI Act. Article 50 transparency obligations immediately took effect, requiring providers and deployers of certain AI systems to disclose AI interactions, synthetic content labeling, and deepfake identification. Enforcement is backed by fines of up to €15 million or 3% of global annual turnover (whichever is higher), with proportionality applied to SMEs. Non-compliance need not include retroactive labeling of content generated before August 2.

Article 50 transparency rules mandate four compliance paths: (1) AI systems interacting directly with users must explicitly disclose machine-not-human status unless obvious from context; (2) providers generating or manipulating text, images, audio, or video must apply machine-readable marks to generated content; (3) deployers of deepfakes must label them; (4) certain AI-generated content on matters of public interest requires disclosure. These light-touch transparency obligations stood alone after a June 2026 Digital Omnibus package ("AI Omnibus") deferred heavier high-risk system requirements from August 2026 to December 2027 or December 2028 depending on system type. Prohibited practices under Article 5 (including new bans on non-consensual synthetic sexual content and child sexual abuse material generation) apply from December 2, 2026, with the highest penalty tier: up to €35 million or 7% of turnover.

Member states were also required by August 2 to establish at least one AI regulatory sandbox (Article 57) where companies can develop and test innovative systems under regulatory supervision. Several member states announced readiness; compliance rates vary. The AI Office gained expanded supervisory reach, now extending beyond general-purpose AI models to systems built on top of them when both come from the same provider. General-purpose AI provider rules (Articles 51–54) have been in force since August 2, 2025.

Architects care because this marks the transition from voluntary guidance to live enforcement by 27 national authorities plus Brussels. The transparency layer (Article 50) is broad and low-friction, but the deferred high-risk obligations (Annex III systems for HR, credit, law enforcement, critical infrastructure, education) move to late 2027, creating a soft regulatory grace period. Watch whether the AI Office pursues first-enforcement cases against GPAI providers for systemic-risk violations, and whether member-state sandbox programs become credible product development channels or regulatory friction.

Sources

Everything this brief rests on
  1. 01 Primary source commission.europa.eu
  2. 02 digital-strategy.ec.europa.eu digital-strategy.ec.europa.eu “From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act. On the same date, new transparency rules will start to apply, requiring certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it.”
  3. 03 cooley.com cooley.com “Non-compliance can trigger fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.”
  4. 04 technology.org technology.org “Stand-alone systems listed in Annex III – recruitment tools, credit scoring, education, law enforcement, border control, critical infrastructure – now face full compliance on 2 December 2027 rather than 2 August 2026.”