Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
August 2, 2026 marked the moment the EU AI Act’s enforcement powers over general-purpose AI (GPAI) providers became fully applicable — one year after the underlying obligations took effect. Fines now reach up to €35 million or 7% of global annual turnover for the most serious violations, and up to €15 million or 3% of turnover for GPAI-specific breaches. A February 2026 readiness survey found 78% of enterprises still unprepared, with most lacking a formal AI system inventory or a designated internal governance body. For corporate governance and compliance teams — inside and outside the EU — this is the point where “monitor the regulation” has to become “demonstrate the controls.”

Regulations rarely arrive with a single dramatic switch-flip moment. The EU AI Act is an exception. After more than two years of phased rollout — prohibited practices in February 2025, obligations for general-purpose AI providers in August 2025 — the Act crossed into a materially different phase on August 2, 2026: the European Commission’s enforcement powers over GPAI providers became applicable, and the penalty regime that had existed on paper became a penalty regime that can actually be used.

For boards and compliance functions, the practical question has shifted from “what does the AI Act require” to “can we prove, today, that we meet it.”

What Changed on August 2, 2026

The AI Act’s obligations for providers of general-purpose AI models — the large foundation models increasingly embedded inside enterprise software — took legal effect in August 2025. What changed a year later is enforcement: national market surveillance authorities and the EU AI Office gained the operational authority to investigate, demand documentation, and issue fines against GPAI providers found in breach. Penalties for GPAI-specific violations can reach €15 million or 3% of worldwide annual turnover, whichever is higher. For the Act’s more serious categories of violation — including breaches tied to prohibited practices — penalties scale up to €35 million or 7% of global turnover, a ceiling that exceeds even GDPR’s maximum.

High-risk AI system obligations — the category covering most internally deployed enterprise AI, from hiring tools to credit-scoring systems — were partly deferred under the EU’s Digital Omnibus package, with some requirements pushed to December 2, 2027. That deferral has led some companies to relax, but it is a timing extension, not an exemption, and the GPAI enforcement now live applies well beyond the handful of foundation-model vendors — it reaches any enterprise that has fine-tuned, deployed, or materially modified a general-purpose model for its own use.

The Readiness Gap Is Wider Than Most Boards Realize

A February 2026 compliance survey found that 78% of enterprises remain unprepared for AI Act enforcement. Two figures inside that number are worth sitting with:

Companies with no formal AI system inventory83%
Companies with no designated internal AI governance body74%

Both gaps point to the same underlying problem: most organizations cannot currently answer the basic regulatory question “list every AI system in use, its risk category, and who owns it” — and that inventory is the foundation every other compliance obligation sits on top of. Without it, a company cannot credibly demonstrate conformity assessments, cannot route incidents to the right owner, and cannot respond to a regulator’s document request on any reasonable timeline.

Why This Is a Governance Problem, Not Just a Legal One

It’s tempting to route the AI Act to the general counsel’s office and consider it handled. That undersells what enforcement actually tests. Market surveillance authorities are not simply checking whether a policy document exists — they are checking whether the organization’s actual operating structure matches what the policy claims. That means:

A named accountable owner for each high-risk or GPAI-derived system.

Not a committee — a person or function the board can point to.

Board-level visibility into the AI system inventory.

Increasingly expected as part of standard risk oversight reporting, alongside cyber and financial risk.

Documented incident response for algorithmic failures.

Distinct from a general cybersecurity incident plan — the AI Act expects AI-specific escalation paths.

This is squarely a corporate governance function, not a niche legal filing exercise. Boards that have spent the past few years building cyber-risk oversight muscle now need to extend the same discipline to algorithmic risk — and the August 2026 enforcement milestone is the forcing function that makes doing so non-optional for any company with meaningful EU exposure.

⚠️ Warning: The Act’s extraterritorial reach means non-EU companies are not exempt. Any organization offering an AI-enabled product or service to users in the EU, or whose AI system’s output is used within the EU, can fall within scope — regardless of where the company is headquartered.

A Practical First 90 Days

For governance and compliance teams starting from behind, the sequence that gets an organization defensible fastest tends to look like this: first, build the AI system inventory — every model, every vendor, every internal deployment, tagged by risk category. Second, assign named ownership to each entry, with an explicit escalation path. Third, stand up (or formally designate) an AI governance body with board-reporting lines, even if lightweight to start. Fourth, prioritize documentation for GPAI-derived systems first, since that is where enforcement authority is live today, before turning to the high-risk category obligations still phasing in through 2027.

What Happens Next

Early enforcement actions under a new regulatory regime tend to target the most visible, most clear-cut violations first — a pattern regulators followed with GDPR in its early years. Expect the first wave of AI Act enforcement to focus on large GPAI providers and obviously prohibited practices, with scrutiny of mid-market enterprise deployments increasing over the following 12 to 18 months as authorities build case law and enforcement capacity. Companies that use this window to close the inventory and ownership gaps now will be answering an audit request in 2027 instead of explaining a violation.

The Act’s enforcement phase-in was always going to arrive eventually. What August 2026 confirms is that “eventually” has a fine amount attached to it, and that the gap between regulatory text and operational readiness is now a board-level risk item rather than a compliance footnote.


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading