Tallinn: The calendar has become the most-watched feature of Europe’s artificial intelligence rulebook. On 2 August the Commission’s enforcement powers under the AI Act switch on, and with them the ability to levy fines of up to three percent of global annual turnover, or fifteen million euros, whichever is larger. For the developers and corporate users gathered in Estonia’s startup quarter, the comfortable phase of voluntary cooperation is ending and the period of legal consequence is about to begin.
The obligations themselves are not new. Since August last year, providers of general-purpose AI models have had to publish technical documentation, supply instructions for use, respect copyright law and disclose a summary of the data used to train their systems. Models judged to carry systemic risk, defined by a training-compute threshold above ten-to-the-twenty-fifth floating-point operations, face heavier duties: adversarial testing, incident reporting and demonstrable cybersecurity. What changes this summer is not the rules but the consequences. Until now the AI Office has nudged and advised. From August it can punish.
Running in parallel is the most operationally demanding deadline in the whole regime, the one governing high-risk systems. These are the tools embedded in regulated products and in sensitive areas such as recruitment, credit scoring, education and critical infrastructure. From 2 August such systems must clear conformity assessment, be registered, and operate under documented regimes for risk management, data governance, logging and meaningful human oversight. Compliance teams describe it as the difference between writing a policy and rebuilding a product.
There is one notable softening. Under the AI omnibus simplification agreed earlier, the obligations for high-risk systems baked into already-regulated products, medical devices, machinery and the like, have been pushed out to 2 August 2028. The reprieve recognises that manufacturers cannot retrofit a conformity process onto a physical product overnight. It does not extend to the broader category of standalone high-risk software, which still faces the August 2026 wall.
For general-purpose model providers, the finalised code of practice offers a path to demonstrate compliance, a kind of pre-approved route through the documentation and risk requirements. Signing up is voluntary, but the alternative is to prove conformity case by case to a regulator that will soon hold the power to fine. Most large providers have signalled they will follow the code rather than improvise.
The wider question hanging over Tallinn and every other European tech hub is whether the regime tilts the field. Critics argue the compliance burden falls hardest on smaller European firms that lack the legal departments of the American and Chinese giants, and that the Union risks regulating a market it has not yet built. Defenders counter that clear rules are precisely what lets a fragmented single market scale, giving buyers confidence that a system certified in one member state is trusted across all of them. Both cases will be tested in practice within weeks. The grace period that defined the AI Act’s first year is nearly over, and the first enforcement decisions will reveal how sharp the teeth really are.




