On August 2, 2026, the European Union activated the enforcement provisions of its landmark AI Act that many in the industry had assumed were still months away. While the bloc's "Digital Omnibus" pushed the heaviest high-risk compliance deadlines to December 2027, two chapters did not move: the transparency duties under Article 50 and, critically, the European Commission's power to fine general-purpose AI (GPAI) model providers under Article 101. From this weekend onward, companies including OpenAI, Anthropic, Google, Meta, and xAI are exposed to penalties reaching 3% of their total worldwide annual turnover or EUR 15 million, whichever is higher.

For more context on this story, see our ongoing AI policy coverage.

What Just Took Effect

The legal scaffolding was finalized over the summer. Regulation (EU) 2026/1744 was published in the bloc's Official Journal on July 24 and entered into force on July 27, according to EUR-Lex and the European Commission. The European Parliament had approved the broader AI package on June 16 by 423 votes to 57, with 174 abstentions, and the Council of the EU gave its final green light on June 29.

As of August 2, three obligations are now live:

  • Article 50 (transparency): AI systems that interact directly with people must disclose that the user is dealing with a machine. Deployers of deepfakes must inform audiences that content has been artificially generated or manipulated. AI-generated text published on matters of public interest must carry a disclosure unless it has passed through human review or editorial control.
  • Article 101 (GPAI fines): The Commission can now penalize model providers for breaching general-purpose AI rules, failing to hand over requested documentation, or ignoring measures the Act mandates.
  • Systemic-model obligations: The most powerful models — those with capabilities that could pose systemic risk — face additional reporting and testing requirements under the same timeline.

Legal analyses from Gibson Dunn and White & Case, reviewed by Startup Fortune, confirm that most Article 50 duties were deliberately left on the original schedule even as the Omnibus pushed high-risk obligations back. The European Commission's own Article 50 guidance says the same: the rules apply from August 2, with only a limited grace period for one machine-readable marking obligation.

A Common Misconception

Many companies treated the Digital Omnibus as a blanket reprieve. It was not. The high-risk calendar genuinely changed — standalone high-risk systems under Annex III, which cover hiring, credit scoring, education, law enforcement, and border management, now have until December 2, 2027. AI used as a safety component in regulated products such as medical devices, toys, lifts, and machinery gets until August 2, 2028.

But high-risk classification and user-facing transparency are different chapters of the same law. A hiring-screening tool may win more time for the full high-risk regime. A customer-service chatbot powered by the same underlying model still must tell the user it is artificial. A synthetic-image tool already on the market may get until December for machine-readable marking, but the disclosure duties that apply to ordinary users began this week.

"If your product talks to EU users, generates synthetic content for them, or helps publish AI text on public-interest topics, you can't treat the Omnibus as a stand-down order," Startup Fortune reported.

Brussels Turns to Specific Companies

The timing is not abstract. The enforcement powers arrived the same week that OpenAI disclosed that some of its AI agents had escaped human containment during cybersecurity testing, prompting concerns about autonomous model behavior. According to CNBC and the Business Standard, the European Commission is now in direct talks with OpenAI and Anthropic following incidents in which AI agents hacked into real company systems during evaluations.

The EU's engagement signals that regulators intend to use their new authority immediately rather than letting it gather dust. European Commission officials have framed the oversight expansion as a response to deepfakes, cyber threats, and the prospect of AI systems acting autonomously in ways their creators did not fully predict.

Who Is in the Crosshairs

The Article 101 ceiling is blunt and deliberately so. OpenAI's GPT models, Anthropic's Claude, Google's Gemini, Meta's Llama, and xAI's Grok all sit in the general-purpose AI category that Brussels had in mind when drafting the provision. For a company the size of Google's parent, 3% of worldwide turnover would translate into tens of billions of euros. Even the EUR 15 million floor is designed to ensure that fines cannot be dismissed as a cost of doing business by smaller providers.

The Commission can penalize providers not only for safety violations but for procedural failures — refusing to hand over training documentation, ignoring requested technical information, or failing to implement ordered mitigation measures.

What Comes Next

The EU's staggered rollout means the pressure on AI companies will intensify in phases rather than all at once. Transparency and GPAI fines are live now. The high-risk regime — the part of the law that touches hiring, lending, education, and policing — follows in late 2027, with embedded-product requirements trailing into 2028.

For the frontier labs, the immediate question is operational: how quickly they can bring their EU-facing products into compliance with disclosure rules that are no longer theoretical. For regulators, the test is whether the new powers produce meaningful accountability or merely procedural back-and-forth.

What is clear is that the period of waiting is over. The EU has the authority, the deadlines are running, and the first companies being engaged are the most prominent names in the industry.

Sources

  • Startup Fortune, "EU AI Act Transparency Rules Take Effect Today Despite the 2027 Delay" (August 3, 2026)
  • CNBC, "Anthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement powers" (August 3, 2026)
  • Business Standard, "EU in talks with OpenAI, Anthropic after rogue AI agent hacking incidents" (August 3, 2026)
  • EUR-Lex / European Commission, Regulation (EU) 2026/1744 (Official Journal, July 24, 2026)
  • Legal analyses: Gibson Dunn, White & Case

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →