Skip to main content
Impact: 8governance-regulation

EU AI Act Enforcement: Prohibited Practices Live, No Public Fines Yet

EU AI Act enforcement is staged: prohibitions live since Feb 2025, GPAI obligations since Aug 2025, high-risk AI from Aug 2026. No public fines yet but investigations are active.

EU AI Act Enforcement: Where Things Stand

The EU AI Act entered into force on August 1, 2024, with enforcement activating in stages. As of early 2026, here is the factual status of enforcement:

Enforcement Timeline

| Date | Provisions in Force | | --- | --- | | August 1, 2024 | AI Act enters into force | | February 2, 2025 | Prohibited practices (Article 5) + AI literacy obligations | | August 2, 2025 | GPAI obligations; AI Office operational; member-state authorities designated | | August 2, 2026 | High-risk AI obligations (most provisions) | | August 2, 2027 | Full applicability including legacy high-risk AI in regulated products |

Current Enforcement Status

No public fines have been issued under the AI Act through Q1 2026. However, enforcement activity is underway:

  • Prohibited practices: Investigations opened against 2 EU-based providers for potential violations of Article 5 (social scoring, untargeted scraping for facial recognition). No public fines yet.
  • GPAI obligations: The AI Office (145 staff, 34 in regulation/compliance) is reviewing training-data summary disclosures from major providers including OpenAI, Google, Anthropic, Meta, Microsoft, and Mistral.
  • High-risk AI: Notified bodies are being designated; mock conformity assessments are being piloted in preparation for the August 2026 deadline.

Maximum Penalties

The AI Act provides three tiers of fines:

  1. Prohibited AI practices (Article 5): Up to €35 million or 7% of global annual turnover (whichever is higher)
  2. Other violations: Up to €15 million or 3% of global annual turnover
  3. Incorrect/misleading information: Up to €7.5 million or 1% of global annual turnover

SMEs and startups receive the lower of the two amounts (more lenient treatment).

What This Means for Employers

Companies using AI systems classified as high-risk — including AI in employment decisions — should prepare for the August 2026 deadline by:

  1. Conducting fundamental rights impact assessments
  2. Implementing adequate data governance practices
  3. Establishing meaningful human oversight mechanisms
  4. Preparing technical documentation and logging

Related Resources

Related News