The European Commission's power to fine artificial intelligence companies up to €35 million or 7% of global annual turnover — whichever is higher — became fully enforceable this week, a ceiling that exceeds the EU's own GDPR privacy law by 75%. Only 3% of enterprises report having a comprehensive compliance framework in place, according to a survey by legal technology firm Casepoint reported by Legal Futures. Building a compliance program for a single high-risk AI system can cost between €193,000 and €330,000 up front, plus roughly €71,400 a year to maintain, according to a study commissioned for the European Commission's own impact assessment. And as of the enforcement date, no AI Act fine has ever actually been issued anywhere in the bloc.
What Actually Changed on August 2
August 2, 2026 marked the date on which the European Commission's supervision and enforcement powers over providers of general-purpose AI (GPAI) models — including the ability to demand documentation, run evaluations, and levy fines — came into force under Article 101 of the AI Act. Those GPAI obligations themselves, covering technical documentation and training-data transparency, had already applied since August 2, 2025; what changed this week is that Brussels can now act on non-compliance. Article 50 transparency duties — informing users when they are interacting with an AI system — also took effect broadly on August 2, 2026, though the more demanding synthetic-content watermarking rules under Article 50(2) were delayed until December 2, 2026 for systems already on the market. France's data protection authority, the CNIL, moved quickly, issuing information requests to financial institutions using credit-scoring algorithms, and denying extension requests on the grounds that companies had had a two-year runway to prepare — a claim consistent with the Act's 2024 entry into force but one this outlet could not independently verify against a primary CNIL statement at time of writing.
The Headline Rule That Didn't Actually Arrive
The story is more complicated than "high-risk AI rules take effect." Under the "Digital Omnibus" package the Commission and Parliament agreed in May 2026, the core Chapter III obligations for most high-risk AI systems — the rules requiring risk-management systems, human oversight, and conformity assessments for tools used in hiring, credit, education, and law enforcement — were pushed back to December 2, 2027 for Annex III systems and August 2, 2028 for AI embedded in regulated products like medical devices and vehicles. That delay was tied explicitly to the completion of harmonized technical standards the Commission had not finished drafting. In other words, the enforcement machinery that activated this week applies most concretely to foundation-model developers — companies like OpenAI, Google, Meta, Anthropic, and Mistral — which the Commission has previously named in guidance on systemic-risk models — rather than to the broader universe of companies deploying AI in day-to-day business decisions.
The Compliance Gap Regulators Are Stepping Into
Even with the highest-profile obligations deferred, the preparedness numbers are stark. The Casepoint-commissioned research found 82% of organizations consider AI regulation a significant concern, yet 52% report minimal or no preparation, despite already deploying AI in customer-facing tools, HR, and operational decisions. The gap is most pronounced at mid-sized firms with 500 to 5,000 employees — organizations large enough to run consequential AI systems but often without dedicated compliance teams. Estimates of the aggregate cost of compliance vary widely depending on methodology: industry group DIGITALEUROPE puts the AI Act's annual compliance burden at roughly €3.3 billion, the Centre for European Policy Studies has cited a €4–6 billion range for the first enforcement phase, and a widely circulated $36 billion figure from an earlier industry-funded estimate was disputed by CEPS researchers as a misreading of their own study, which found the true range closer to €1.6–3.3 billion under stated assumptions. That spread itself is instructive: five years after the Act was first proposed, independent analysts still cannot agree on its economic footprint within an order of magnitude.
An Enforcement Record That Is, So Far, Empty
Perhaps the most concrete fact about AI Act enforcement is what has not happened. As of the Article 101 activation date, not a single fine has been imposed under the AI Act by any Member State, the AI Office, or the European Data Protection Supervisor. That contrasts with the EU's General Data Protection Regulation, which has produced more than €7.1 billionin cumulative fines since 2018, including over €1.2 billion in 2025 alone, according to DLA Piper's annual GDPR fines survey. Legal analysts tracking both regimes note that GDPR also had a multi-year quiet period after 2018 before enforcement accelerated, and expect the AI Act's penalty regime — built explicitly on the GDPR's Article 83 framework — to follow a similar trajectory. For small and medium enterprises, the Act's penalty structure is inverted relative to large firms: fines apply at whichever amount is lower between the fixed euro ceiling and the turnover percentage, meaning a startup with €2 million in revenue faces a maximum exposure of €140,000 rather than €35 million.
The Broader Pattern: Regulation by Installment
The AI Act's rollout illustrates a structural reality of technology regulation that extends well beyond Brussels: comprehensive digital rules are rarely implemented as a single event, but as a sequence of dates, carve-outs, and delegated acts that can span half a decade or more between initial passage and full application. The Act was adopted in 2024, with prohibited practices taking effect in February 2025, GPAI transparency rules in August 2025, enforcement powers activating this week, and the most consequential high-risk system requirements now deferred to 2027 and 2028. That staggered timeline reflects a genuine tension regulators face: standards-writing bodies had not finished the technical specifications high-risk obligations depend on, and forcing compliance against unfinished standards risked penalizing companies for failing tests that did not yet exist. Whether the eventual 2027–2028 deadlines hold, or face further "omnibus" delays as industry lobbying continues, remains an open question — as does whether a regulatory model built around after-the-fact fines, rather than pre-market testing, can meaningfully change how the largest AI developers build and release systems before harm occurs rather than after.