|
Brussels, |
|
EU AI Act enforcement
EU Starts Enforcing the AI Act: Greater Trust, Higher Costs
From 2 August 2026, new transparency and supervision rules promise greater trust and accountability in artificial intelligence, while imposing potentially significant annual compliance costs on platforms and AI providers.
By eEuropa
Brussels, 1st August, 2026
The European Union is moving from its AI legislation to practical enforcement. From 2 August 2026, the European Commission’s AI Office and the authorities designated by the Member States will begin supervising and enforcing key provisions of the Artificial Intelligence Act.
The new phase will affect developers of AI models, digital platforms, companies using generative AI, public administrations and organisations deploying automated systems to communicate with customers or citizens.
For businesses operating in the EU, AI Act compliance is therefore becoming an immediate operational obligation.
Transparency becomes mandatory. AI systems designed to interact directly with people must generally disclose that users are communicating with an artificial system, unless this is already obvious. The rule applies to chatbots, virtual assistants, customer-service agents and other automated interfaces that could be mistaken for human operators. Providers of systems generating or manipulating text, images, audio or video must also ensure that synthetic outputs can be identified. This may require metadata, provenance records, digital watermarks or other machine-readable marking systems. The objective is to make AI-generated content traceable and reduce the risk that users, platforms or public authorities mistake synthetic material for authentic content.
The obligation is especially relevant for media companies, advertising agencies, political communication, entertainment businesses and social platforms. Certain AI-generated texts published to inform the public on matters of public interest must also be labelled, unless they have undergone meaningful human review and an identifiable person or organisation assumes editorial responsibility.
The AI Act does not prohibit the use of AI in journalism or publishing. It requires responsibility for the final content to remain identifiable.
Biometric and emotion-recognition systems. People exposed to certain emotion-recognition or biometric-categorisation systems must be informed that the technology is being used. This may affect workplaces, schools, commercial environments, transport facilities and public spaces.
Organisations must also determine whether a system is merely subject to transparency requirements or falls within one of the prohibited or high-risk categories established by the AI Act.
The EU AI Office gains enforcement powers. From 2 August 2026, the European AI Office will be able to exercise its enforcement responsibilities for general-purpose AI models. It may request technical documentation, conduct evaluations, investigate suspected infringements, require corrective measures and impose penalties. National market-surveillance authorities will remain responsible for other AI systems and applications within their jurisdictions. The result will be a combined European and national enforcement structure covering both powerful general-purpose models and sector-specific AI systems.
Obligations for general-purpose AI providers. Providers of general-purpose AI models must maintain technical documentation and supply downstream companies with sufficient information about the models’ capabilities and limitations. They must also adopt policies to comply with EU copyright law and publish a sufficiently detailed summary of the content used for training. Providers of models placed on the EU market before 2 August 2025 have until 2 August 2027 to comply with certain obligations. Models introduced after that date are already covered.
Stricter rules for systemic-risk models. The most advanced general-purpose AI models may be classified as presenting systemic risks.
Their providers must conduct model evaluations and adversarial testing, assess and mitigate risks, report serious incidents and maintain adequate cybersecurity safeguards.
Relevant risks include:
- cyberattacks and offensive cyber capabilities;
- harmful manipulation and threats to democratic processes;
- discrimination and violations of fundamental rights;
- risks to health and public safety;
- chemical, biological, radiological or nuclear threats;
- loss or circumvention of effective human control.
Providers must consider not only intended uses but also reasonably foreseeable misuse and failures.
Greater trust, but higher costs
The new rules could improve public confidence in AI services by making synthetic content easier to recognise and by reducing deception, harmful manipulation and uncertainty. A common EU framework may also reduce regulatory fragmentation and give compliant businesses clearer rules across the Single Market.
The costs, however, could be significant.
Platforms may need to invest in labelling systems, provenance tools, legal review, technical documentation, staff training, monitoring and cybersecurity. A platform affected mainly by transparency duties could face recurring expenditure of approximately €50,000 to €250,000 per year. A large platform operating several AI services could spend between €500,000 and several million euros annually.
Providers of high-risk systems or general-purpose AI models subject to extensive documentation, testing, cybersecurity and risk-management duties may face still higher costs; estimates discussed in the EU policy debate indicate initial compliance expenditure of roughly €320,000–€600,000 for an individual high-risk AI product, followed in some cases by recurring costs of up to about €150,000 per year, although these amounts should be treated as indicative rather than as an official tariff applicable to every company.
These figures are indicative rather than official tariffs. Actual expenditure will depend on company size, the number of AI services, the volume of generated content and the complexity of the required technical controls. Large platforms may be able to absorb these costs more easily than smaller operators. Enforcement could therefore improve accountability while also reinforcing market concentration and slowing the launch of new AI services in Europe.
Codes, guidelines and complaints
The Commission’s General-Purpose AI Code of Practice is intended to help providers comply with transparency, copyright, safety and security obligations. Participation is voluntary, but companies following the Code may find it easier to demonstrate compliance. Providers using alternative methods will need to show that they offer an equivalent level of protection.
Individuals and organisations may also submit complaints to national authorities, while insiders can report possible infringements through the Commission’s AI Act whistleblower tool.
These channels increase the likelihood that non-compliant practices will be detected and investigated.
What businesses should do now
Businesses should begin by creating an inventory of the AI systems they provide or use.
For each system, they should identify:
- its intended purpose;
- the provider and contractual chain;
- whether it interacts directly with people;
- whether it generates or manipulates content;
- whether it uses biometric categorisation or emotion recognition;
- whether it may qualify as high-risk;
- which notices, markings and documentation are required.
Contracts with AI providers should be reviewed to ensure access to the information needed for compliance.
Responsibilities should also be allocated clearly between technical teams, legal departments, data-protection officers, communications staff and senior management. Labelling and disclosure obligations must be incorporated into product design and publication workflows. They should not be treated as an afterthought.