EU AI Act Compliance: Deadlines, Fines & GPAI Rules

Last updated:

EU AI Act Compliance in 2026: The Complete Guide (Deadlines, Fines & Checklist)

TL;DR

  • As of 2 August 2026, the EU AI Office has full enforcement authority over general-purpose AI (GPAI) providers, with fines reaching €15 million or 3% of global turnover for most breaches - and up to €35 million or 7% for the most serious systemic-risk failures.
  • The Digital Omnibus on AI (Regulation 2026/1744), in force since 27 July 2026, pushed the biggest deadlines back: standalone high-risk systems (Annex III) now have until 2 December 2027, and product-embedded high-risk systems (Annex I) until 2 August 2028.
  • The delay is not a pass. Article 50 transparency rules - covering chatbots, deepfakes, and AI-generated content - are already in force. If your product talks to people or generates synthetic content, this affects you right now.
  • This guide covers every deadline, every fine tier, and a step-by-step checklist for getting compliant.
EU AI Act compliance 2026 guide — deadlines, fines, and GPAI obligations for AI companies

Reviewed by Imran Khan Pathan, Editor at AI Tech Safar. Every date and figure in this guide is checked against the actual regulation text and cross-referenced across multiple law-firm briefings (DLA Piper, Kinstellar, and others), rather than repeated from a single blog summary - a few widely circulated claims about this topic (like the "member states set the fine amount" line for minor breaches) turned out not to hold up against the regulation's own text, and are corrected here.

Last updated: September 2026. This is general information, not legal advice - consult qualified counsel for your specific situation.


The Short Version: Enforced, But Not All At Once

For a long time, AI regulation was mostly talk - hearings, ethics frameworks, nothing binding. That changed on 2 August 2026, when the European Commission's AI Office gained real legal authority: it can now investigate AI providers, demand documentation, access models for evaluation, and fine companies into the millions.

The twist that trips people up: the same law that became enforceable that day also had its toughest obligations pushed back to 2027 and 2028, weeks earlier, through an amendment called the Digital Omnibus. Both things are true at once - enforcement started, and the heaviest rules didn't. Understanding the gap between those two facts is most of what compliance planning comes down to right now.


What the EU AI Act Actually Covers

The Act (Regulation 2024/1689) sorts AI systems into four risk tiers:

Risk Level Examples Obligations
UnacceptableSocial scoring, manipulative techniques, untargeted facial scrapingProhibited entirely
HighBiometrics, critical infrastructure, education, employment, credit scoringStrict compliance requirements
LimitedChatbots, AI-generated content, deepfakesTransparency obligations
MinimalSpam filters, AI in video gamesNone beyond baseline

It applies to providers (who build and place AI on the market), deployers (who use it in a business context), importers, and distributors. Reach matters here: a company outside the EU that puts an AI model on the EU market - paid or free - is still covered, and third-country providers must appoint an EU authorized representative before entering the market.


The Digital Omnibus: What Actually Changed

The Commission tabled the Digital Omnibus on 19 November 2025 after it became clear the original timeline wasn't realistic - harmonized technical standards from CEN/CENELEC were running behind, and many member states hadn't yet stood up their national market surveillance authorities. Parliament and Council reached provisional agreement on 7 May 2026, Parliament formally endorsed it on 16 June, the Council gave final adoption on 29 June, it was signed 8 July, published in the Official Journal 24 July, and entered into force 27 July 2026 - just six days before the original high-risk deadline would have hit.

Category Original Date New Date
Annex III high-risk (biometrics, infrastructure, education, employment, migration, law enforcement)2 August 20262 December 2027
Annex I high-risk (embedded in regulated products - medical devices, machinery, toys)2 August 20272 August 2028

What the Omnibus left untouched: Article 5 prohibited practices (in force since 2 February 2025), GPAI obligations under Articles 51-56 (in force since 2 August 2025), Article 50 transparency duties (in force since 2 August 2026), and the Article 4 AI literacy requirement - though that last one was reworded to require "measures supporting" literacy rather than guaranteeing a specific standard. One genuinely new addition: a ban on AI systems generating non-consensual intimate imagery and child sexual abuse material, phasing in 2 December 2026. As more than one law firm has put it: the postponement bought time, not a reprieve.


The Full Timeline

Already in force

  • 2 February 2025 - Article 5 prohibited practices; AI literacy obligations
  • 2 August 2025 - GPAI model obligations (Articles 51-56); AI Office and governance structure established
  • 2 August 2026 - GPAI enforcement powers activated; Article 50 transparency obligations

Coming up

  • 2 December 2026 - Ban on AI-generated non-consensual sexual content and CSAM; grace period ends for machine-readable marking of AI content placed on the market before 2 August 2026
  • 2 August 2027 - National AI regulatory sandboxes must exist in every member state; full compliance deadline for GPAI models placed on the market before 2 August 2025
  • 2 December 2027 - Annex III high-risk obligations take effect
  • 2 August 2028 - Annex I high-risk obligations take effect

Fines: The Tier System, Corrected

Article 99 sets three tiers for national enforcement, plus a separate Article 101 track for GPAI providers enforced directly by the Commission:

Tier Violation Maximum Fine
Tier 1Prohibited practices (Article 5); GPAI systemic-risk failures€35 million or 7% of global turnover, whichever is higher
Tier 2Most other breaches - high-risk requirements, Article 50 transparency, other GPAI obligations€15 million or 3%
Tier 3Supplying incorrect, incomplete, or misleading information to authorities€7.5 million or 1%

One correction worth flagging: it's a common claim that Tier 3's exact amount is "left to member states." It isn't - the €7.5 million/1% figure is written directly into the regulation itself.

Fines are calculated on global turnover, not just EU revenue - for a company the size of OpenAI or Anthropic, 3% of worldwide turnover is a genuinely large number. There's relief for smaller players: the Digital Omnibus extended a "lower-of" rule (the smaller of the percentage or the fixed cap applies, rather than the larger) to SMEs and, for Tiers 2 and 3 specifically, to "small mid-cap" companies too - defined as under 750 employees and under €150 million turnover.


GPAI Models: What Providers Must Actually Do

A GPAI provider is anyone who develops a model - or has one developed on their behalf - and places it on the EU market under their own name. That covers foundation-model companies (OpenAI, Anthropic, Google DeepMind, Mistral), companies that substantially fine-tune a third-party model (where the added training compute exceeds a third of the original), and non-EU companies selling into the EU, who need an authorized representative.

Baseline obligations under Article 53 apply to every GPAI model: maintain technical documentation covering training methodology, data sources, and compute used; share the information downstream providers need to meet their own obligations; run a copyright-compliance policy that respects opt-outs; and publish a training-content summary using the AI Office's official template.

Models trained with more than 10²⁵ FLOPs of cumulative compute are presumed to carry systemic risk - a threshold that in practice only captures a handful of frontier models - and face additional Article 55 duties: adversarial testing, systemic risk assessment, incident reporting, and cybersecurity protections. The Commission can also designate a model below that threshold if other evidence suggests comparable risk.

Open-source isn't a blanket exemption. Models released under a genuinely open license with public parameters skip some documentation requirements, but if they cross the FLOPs threshold, the full Article 55 systemic-risk regime still applies.


Article 50: The Rule That Touches Almost Everyone

This is the provision that catches ordinary businesses, not just model labs. As of 2 August 2026: chatbots and conversational AI must disclose that a user is talking to AI unless it's obvious from context; emotion-recognition and biometric-categorization systems must inform the people affected; deepfake generators must label their output; AI-generated text on matters of public interest needs disclosure; and synthetic audio, image, video, and text need machine-readable marking - watermarks or metadata - though anything placed on the market before 2 August 2026 gets until 2 December 2026 to comply. The scope is intentionally broad: a newspaper publishing AI-drafted articles falls squarely inside it, right alongside customer-service bots and AI-generated marketing images.


A Practical Compliance Checklist

  1. Build a live AI system inventory. Every system you build, buy, or embed - owner, purpose, data inputs, who's affected, and the supplier if it's third-party. Refresh it quarterly; unapproved "shadow AI" tools are where unassessed risk quietly builds up.
  2. Work out your role for each system. Provider, deployer, importer, or distributor - and remember roles can shift. Substantially modifying a third-party system, or putting your own name on it, can turn you into a provider with the full documentation burden.
  3. Screen against Article 5 first. These prohibitions have applied since February 2025 and carry the top fine tier: social scoring, untargeted facial scraping, workplace or school emotion inference, manipulative techniques causing real harm.
  4. Classify against Annex I and III. Annex III covers biometrics, infrastructure, education, employment, migration, law enforcement, and justice administration; Annex I covers AI embedded in already-regulated products. Misclassification is one of the most common gaps compliance teams run into.
  5. Put together AI literacy training. The bar was softened by the Omnibus, but documented training for staff is still expected.
  6. Close the Article 50 gap - it's the cheapest fix on this list. Audit every user-facing surface: are chatbots disclosing they're AI, are deepfakes labeled, is generated content machine-readable?
  7. Stand up risk management for anything high-risk. A documented process covering identification, evaluation, and mitigation of foreseeable risks.
  8. Get data governance and documentation in order. High-risk providers need Annex IV documentation - design, training data, performance metrics, test results - kept for at least five years.
  9. Design human oversight and logging. A named person who can intervene or stop the system, plus logs sufficient for post-market monitoring.
  10. Re-paper vendor contracts. Clarify who's the provider vs. the deployer, what documentation the supplier owes you, and what happens if their model turns out non-compliant.

EU vs US: A Widening Gap

Feature EU AI Act US Approach
FrameworkSingle risk-based regulationSectoral laws plus voluntary guidance
EnforcementCentralized AI Office plus national authoritiesFTC, state AGs, sector regulators
PenaltiesUp to 7% of global turnoverVaries by sector, generally lower
Extraterritorial reachYes, applies to non-EU providersLimited

The gap has widened this year rather than narrowed. The Trump administration's 2025 executive order rolled back Biden-era federal AI safety requirements and moved toward preempting state-level rules - the opposite direction from the EU's centralized model. For companies operating in both markets, that divergence is a real compliance headache: a model that clears US requirements isn't automatically compliant in the EU, and vice versa.


FAQ

What is the EU AI Act?

Regulation 2024/1689, the world's first comprehensive AI regulation. It sorts AI systems by risk level and places obligations on providers, deployers, importers, and distributors, with reach extending to non-EU companies selling into the EU market.

When did enforcement actually start?

GPAI enforcement began 2 August 2026 - the AI Office can investigate, demand documentation, and fine providers. The Digital Omnibus separately pushed high-risk obligations to December 2027 (Annex III) and August 2028 (Annex I), so enforcement power and the toughest rules didn't arrive on the same date.

What are the fines?

Three tiers: up to €35 million or 7% of global turnover for prohibited practices and GPAI systemic-risk failures, €15 million or 3% for most other breaches, and €7.5 million or 1% for supplying misleading information to authorities.

What's the systemic-risk threshold for GPAI models?

Cumulative training compute above 10²⁵ FLOPs triggers a presumption of systemic risk, adding Article 55 obligations on top of the baseline Article 53 requirements.

Does this apply to US companies?

Yes. Placing an AI model on the EU market - regardless of where the company is based - brings it under the Act, and non-EU providers need an EU authorized representative.

What changed with the Digital Omnibus specifically?

Regulation 2026/1744 postponed high-risk obligations to December 2027 and August 2028, softened the AI literacy requirement, extended fine relief to small mid-cap companies, and added a new ban on AI-generated non-consensual sexual content and CSAM. It left Article 5 prohibitions, GPAI obligations, and Article 50 transparency rules untouched.

Where should compliance work start?

A live inventory of every AI system in use. Nearly every other step - role determination, risk classification, documentation - depends on first knowing which systems exist and who's responsible for them.


Related Reading on AI Tech Safar


Useful Sources

Comments

Popular Post

Meta Just Killed ChatGPT's Agent — Here's Why Muse Changes Everything (2026)

Anthropic Chooses Nasdaq for Blockbuster IPO

How to Use ChatGPT Agent Mode (Now Called Work): The Complete Step-by-Step Guide (2026)