- First letters sent. The European Commission’s AI Office has dispatched initial enforcement letters under the EU AI Act targeting high-risk systems in employment screening, credit scoring, and remote biometric identification — the first concrete regulatory actions since the world’s most comprehensive AI law became enforceable in August 2026.
- Penalties are serious. Violations involving prohibited AI practices face fines of up to €35 million or 7% of global annual turnover, whichever is higher; general-purpose AI model violations carry a ceiling of €15 million or 3% of turnover.
- Centralised enforcement. Unlike GDPR — whose fragmented national-authority structure enabled years of forum-shopping — the AI Act is enforced by a single body, the AI Office, which removes the ability to choose a lenient jurisdiction and sets a faster enforcement pace from the start.
The EU AI Act entered full enforcement on August 2, 2026, and by September the AI Office had begun sending formal letters to operators of high-risk AI systems in sectors where risks to individuals’ fundamental rights are most acute. Employment screening algorithms, automated credit-scoring models, and remote biometric identification systems — all classified as high-risk under the Act’s Annex III — are the first targets of the enforcement sweep, according to analysis published by ValueAdd VC.
What Obligations Are Now Live
Article 50 transparency requirements came into force alongside enforcement powers: any organisation deploying an AI system must inform users that they are interacting with artificial intelligence. Synthetic audio, images, video, and text must carry machine-readable markings so they can be identified as AI-generated content. For providers of general-purpose AI models — the large foundation models built and deployed by companies such as OpenAI, Anthropic, Google, and Meta — the Act now requires the publication of training data summaries and copyright compliance documentation.
All four of those companies have staffed EU compliance teams since the 2025 GPAI code of practice was finalised. The code set out industry-developed standards that now function as the compliance baseline against which the AI Office measures adherence. Companies that demonstrably met the code’s requirements are in a stronger position when enforcement letters arrive; those that did not have less room to negotiate.
Why This Enforcement Differs from GDPR
The AI Act’s enforcement architecture is deliberately unlike its privacy counterpart. GDPR assigned enforcement to national data-protection authorities, which varied enormously in resources, appetite, and speed. Ireland, which hosts European headquarters for most major US tech firms, became a particular bottleneck, processing cases over years rather than months. The AI Act concentrates enforcement in the AI Office, a Commission body, eliminating the forum-shopping dynamic and removing the ability to delay action by anchoring in a permissive member state. Analysts expect the first formal decisions — as opposed to letters — within six to twelve months.
While Europe regulates through transparency mandates and risk-based restrictions, China has taken a different approach, extending exit restrictions on AI executives and their families as a talent-retention and security measure. The divergence reflects two distinct theories of AI governance risk: Europe focuses on outputs and deployment harms; Beijing focuses on the movement of human capital and technical knowledge.
What Is Deferred
Not all of the Act’s requirements are live. The full conformity-assessment obligations for Annex III high-risk systems — requiring formal risk-management documentation, technical testing, and registration in an EU database — are deferred until December 2, 2027. Product-embedded high-risk systems, such as AI components in medical devices or vehicles, have until August 2, 2028. The practical implication is that the current enforcement phase targets transparency and disclosure failures, which are more straightforward to identify and verify, rather than the deeper technical compliance requirements that will govern deployment from late 2027. For startups with EU revenue, the immediate exposure is bot-disclosure costs; the more expensive conformity-assessment work is still 14 months away.