EU AI Act Enforcement Begins: Bans Take Effect Immediately, While High-Risk Compliance Quietly Delayed to End of 2027

The EU AI Act enters its enforcement phase on August 2, 2026, with immediate bans on unacceptable-risk AI systems, while high-risk compliance obligations are postponed to December 2, 2027 via the Digital Omnibus Act amendment.

On August 2, 2026, the EU Artificial Intelligence Act (EU AI Act) entered its enforcement era. From this day forward, the European Commission's AI Office, together with market surveillance authorities in member states, gained legal power to issue real fines for violations—up to €35 million or 7% of a violating company's total global turnover in the previous fiscal year, whichever is higher.

But six days before enforcement began, the EU formally enacted the Digital Omnibus Act AI amendment (Regulation (EU) 2026/1744), which took effect on July 27. This amendment pushed back the high-risk AI system compliance obligations, originally due on August 2, to December 2, 2027.

What Is Actually Being Enforced, and What Has Been Delayed

Starting August 2, three categories of rules have entered mandatory enforcement: First, absolute prohibitions. Social credit scoring systems, AI that exploits psychological vulnerabilities to manipulate user decisions, and real-time biometric identification surveillance in public spaces are explicitly classified as "unacceptable risk" by the Act, with zero tolerance from day one; violators face maximum fines of up to 7% of global turnover. Second, transparency obligations (Article 50): Companies must clearly inform users when they are interacting with AI systems and embed machine-readable watermarks in AI-generated content; systems already on the market receive a four-month transition period, until December 2, 2026. Third, general-purpose AI (GPAI) model obligations: Large language model providers must comply with transparency, copyright compliance, and systemic risk assessment requirements, and obligations for companies such as OpenAI, Google, Anthropic, and Meta can now be enforced as of today.

What has been delayed, ironically, is the part that has been discussed the most: standalone high-risk AI systems under Annex III in areas such as recruitment screening, credit underwriting, law enforcement assistance, educational assessment, and infrastructure management. Their compliance deadline, originally set for August this year, has been moved in its entirety to December 2, 2027. High-risk AI embedded in physical devices governed by EU product safety regulations (Annex I) has been further extended to August 2, 2028.

According to Gibson Dunn's analysis of the amendment, the core reasons for the delay are: harmonized standards (technical specifications developed by CEN/CENELEC) are not yet ready, and most member states' regulatory sandboxes and national competent authorities have also failed to be in place on schedule. In other words, regulators themselves are not yet technically prepared for enforcement.

Why This Crack Deserves Close Attention

The EU AI Act is widely compared to a "GDPR moment" for AI. The analogy holds in terms of regulatory ambition, but there are key differences in the enforcement path.

GDPR had a two-year transition period from entry into force to full enforcement, with clear rules and uniform obligations. The AI Act, by contrast, builds a tiered risk system that assigns the most complex obligations—risk management documentation, data governance, human oversight mechanisms, and post-market monitoring for high-risk systems—to scenarios that require the most preparation time, while the enforcement standards for these scenarios themselves await technical guidelines and harmonized standards from the European Commission.

This is not entirely bad news. For companies deploying AI in recruitment and credit, the extra 16 months means a sufficient window to build out compliance systems, rather than being forced to act while the regulatory framework is still unclear. But it also creates a risk of perverse incentives: according to research by the Cloud Security Alliance (CSA), 78% of companies have yet to take substantive compliance action—and this figure could decline further after the high-risk deadline is pushed back.

The deeper problem is that the enforcement vacuum gives users of high-risk applications a false sense of security. Some companies may misread the signal, thinking "if I haven't been fined, my system must be risk-free"—but in reality, prohibition-type violations (social scoring, manipulative AI) can be pursued today. It's just that most AI practitioners are currently in a gray zone of compliance preparation, unaware of how their systems are classified.

Practical Impact on Chinese Companies Going Global

The AI Act applies the principle of territoriality plus effect: as long as an AI system is deployed within the EU or its outputs are used by EU users, compliance is required regardless of where the provider is registered. This means Chinese AI vendors expanding into the European market cannot claim exemption on the grounds of being "overseas companies."

The substantive pressures taking effect immediately as of today are concentrated in three areas: First, the transparency obligations for GPAI model providers mean Chinese companies offering large model APIs or applications to EU users must disclose summaries of model training data and copyright compliance status; second, any product design deemed "manipulative AI" (pushing content by exploiting user vulnerabilities, manipulating behavioral decisions) faces an immediate ban; third, if companies have already deployed recruitment or credit assessment products in Europe, they should establish risk classification dossiers now, even though formal high-risk enforcement won't begin until the end of 2027—otherwise they will be caught off guard.

The Structural Significance of Transparency Obligations

Among all the obligations taking effect immediately, Article 50's transparency provisions may be underestimated in their long-term impact. By requiring machine-readable markers embedded in AI-generated content, it essentially drives legal stakes into the ground for future AI content provenance infrastructure.

This requirement will hit content production platforms no less than model providers. If a media outlet uses AI to generate articles without disclosing this to readers and embedding provenance markers, it faces the same compliance risk. This is one of the few provisions in the AI Act that directly touches the content ecosystem, and its ripple effects are still unfolding.

Independent Assessment

The emergence of the Digital Omnibus Act amendment reveals a structural dilemma in EU AI regulation: the institutional ambition of the regulatory framework has outpaced the maturity of technical standards and the construction progress of member state enforcement agencies. This is not an accident, but a seed planted during the rulemaking stage—the high-risk system compliance obligations were written into the Act, while the technical standards defining "how to prove compliance" were left to working groups that would only begin their work after the Act took effect.

The result is a two-speed regulation: prohibition-type provisions, because their boundaries are clear, can be enforced from day one; complex obligation-type provisions, because their standards are vague, can only buy preparation time through delay.

This model is not without precedent—GDPR enforcement in its early days similarly featured a "big stick raised high, but with limited strikes" pattern. It wasn't until France's CNIL fined Google €50 million in 2019 that companies generally realized fines were not an empty threat. The AI Act will most likely follow the same path: real enforcement pressure will only arrive after 2027-2028, once high-risk obligations are fully in place and technical standards and national competent authorities are simultaneously ready.

The window for companies still exists, but with 78% of companies yet to take substantive action, 16 months is not generous. Those held accountable first will most likely not be ordinary companies that simply ran out of time to comply, but rather the highly visible players that have clearly deployed social scoring or manipulative AI—these cases will become the EU AI Office's first signals of establishing its authority.