← Tous les articles

AI Governance · August 3, 2026 · 4 min de lecture

Europe's AI Office Just Got Real Enforcement Powers. Most Companies Missed It.

On August 2, 2026, the EU AI Office switched on real enforcement powers: fines, audits, and corrective orders for GPAI providers and transparency breaches. The high risk delay doesn't cover this part.

A leadership team we spoke with in July told us they had stopped worrying about the EU AI Act. They had read that the deadline got pushed. High risk obligations moved to December 2027, some to August 2028. Relief all around the table. Then, on August 2, something else happened that had nothing to do with that delay.

On August 2, 2026, the European Commission's AI Office and national authorities formally started enforcing the AI Act. Not later. Now. Two things went live that week. First, transparency obligations under Article 50: chatbots and other systems that interact with people have to disclose they are AI, not a human. Deepfakes and AI generated content have to be labelled, with machine readable marks so platforms and users can detect them. Second, the AI Office got real teeth over general purpose AI models: the authority to request technical documentation, evaluate a model, demand corrective measures, and issue fines. Up to 15 million euros or 3% of global turnover for GPAI breaches. Up to 35 million euros or 7% for broader breaches of the Act. None of this touches the high risk classification system, which is exactly the part the Digital Omnibus delayed in May.

Most companies read "delay" and concluded they had bought time. What actually happened is narrower and sharper than that. The delay applies to high risk system classification, the part built for hiring algorithms, credit scoring, medical devices, critical infrastructure. It does not apply to the transparency layer, and that layer is where most SMEs actually live. A customer service chatbot. A marketing team generating product images. A sales script drafted with an LLM and sent as though a person wrote it. None of those are high risk systems under the Act. They are exactly the systems Article 50 targets, and the enforcement mechanism for that layer went live on August 2, not December 2027.

The gap between what leadership believes ("we have until 2027") and what is actually enforceable right now ("part of this already applies") is the real risk. Not the fine itself: most SMEs are not the first target of a 15 million euro enforcement action. The risk is building your AI governance calendar around the wrong date, and finding out during an audit or a customer complaint instead of on your own terms.

What this means in practice.

First, audit every AI system that faces a customer directly. Chatbots, voice agents, conversational assistants on your site or in your app. If a person could reasonably think they are talking to a human, that is the system to check this week, not at the next leadership meeting.

Second, look at everything you generate and publish. Product images, marketing video, synthetic voiceovers, avatars. The labeling obligation is not about hiding that you use AI. It is about making that use detectable, which is a different bar than most marketing teams have set for themselves so far.

Third, if your stack runs on a general purpose model from a major provider (OpenAI, Anthropic, Google, Mistral), expect that provider's behavior to shift as the AI Office starts exercising its new powers. Model updates, added guardrails, new documentation requests passed down to you as a customer. Build slack into your workflows so those changes do not break things downstream.

Fourth, assign ownership. Not a project, a person. AI governance under this Act is not a single deadline you prepare for once and forget. It moves in stages, over several years, and the stage that applies to you is rarely the one making headlines.

This connects to something we keep coming back to in the Alignment dimension of the MAKIA framework: governance is not a milestone you hit and move past. It is a discipline that has to stay in sync with what is actually being enforced, not with what got the most press coverage.

If someone at your company had to answer right now whether your chatbot discloses that it is AI, would they know? That question is a better test of readiness than any deadline on a calendar.

Try this week

List every AI system your customers interact with directly: chatbot, email assistant, voice agent, generated content. For each one, check in under 30 minutes whether it currently discloses that it is AI generated or AI operated. Note the gaps in a simple table, with a name attached to each one. That is the deadline you may have already missed.

Sources

  • Commission starts enforcing AI Act rules and new transparency requirements on 2 August
  • Commission starts enforcing AI Act rules and new transparency requirements on 2 August, Shaping Europe's digital future
  • Artificial Intelligence: Council and Parliament agree to simplify and streamline rules, Council of the EU
Partager cet articleLinkedInFil RSS