Brussels: With less than three months remaining until the European Union’s Artificial Intelligence Act enters its most consequential application phase, regulators, member states and industry are racing to translate the world’s first comprehensive AI law into operational reality. From 2 August 2026, the bulk of the regulation’s obligations on high-risk AI systems will become directly enforceable, accompanied by the European Commission’s supervisory powers over providers of general-purpose AI models.
The AI Act entered into force on 1 August 2024, with prohibitions on unacceptable practices and AI literacy obligations applying from February 2025, and governance rules covering general-purpose models taking effect in August 2025. The remaining year was designed as a runway. Yet recent months have exposed gaps in member state preparedness, particularly regarding national competent authorities, conformity assessment bodies and the regulatory sandboxes that the law mandates as testing environments for novel systems.
In May 2026, the Council and the European Parliament reached a provisional agreement to streamline parts of the regime. The deal postpones the deadline for establishing national AI regulatory sandboxes to 2 August 2027 and modifies grace periods for transparency rules on artificially generated content, while introducing a new prohibition specifically targeting non-consensual intimate imagery generators, including those producing child sexual abuse material. The Commission has also clarified the division of competences between the European AI Office and national authorities for systems built atop general-purpose models, with explicit carve-outs for law enforcement, judicial bodies, border management and financial supervision.
For high-risk applications listed in Annex III of the Act, including biometrics, critical infrastructure, education, employment, essential public and private services, migration management and the administration of justice, operators face a demanding compliance architecture. Risk management systems, data governance protocols, technical documentation, record-keeping requirements, transparency obligations toward deployers, human oversight measures and accuracy and robustness standards must all be in place. Conformity assessments, CE marking and registration in the EU database represent the procedural threshold before market placement.
The penalties calibrate the seriousness of the regime. Non-compliance with the prohibitions can attract fines of up to 35 million euros or 7 percent of worldwide annual turnover. Other high-risk system breaches can trigger sanctions of up to 15 million euros or 3 percent of turnover. Misleading information supplied to authorities carries fines reaching 7.5 million euros or 1 percent of turnover. The structure deliberately mirrors and surpasses the General Data Protection Regulation in its deterrent ambition.
The political debate over the pace of enforcement has, however, intensified. Industry associations and several capitals have argued that the timetable risks pushing AI development outside Europe at a moment when competitiveness sits at the top of the political agenda. The Commission has responded by emphasising guidance, codes of practice and proportional enforcement, particularly during the first year of operation, but it has been careful to defend the substantive scope of the law against calls for deeper retrenchment.
There remains the broader question of regulatory coherence. The AI Act sits alongside the Digital Services Act, the Digital Markets Act, the Data Act, the Cyber Resilience Act, the GDPR and product safety legislation. For deployers, mapping overlapping obligations across these regimes is now a strategic exercise rather than a compliance afterthought. The European AI Office will play a central convening role in ensuring consistency, supported by the AI Board, the Scientific Panel and the Advisory Forum that the law established.
August 2026 will not mark the conclusion of the AI Act’s implementation but rather the beginning of a much longer process of judicial interpretation, regulatory practice and political contestation. The choices made by the European AI Office in its first enforcement cycles will shape the meaning of the law for years to come.




