Enterprise

EU AI Act enforcement begins today, with €15M fines and mandatory chatbot disclosure now live

The European Commission's AI Office gains its full enforcement toolkit against general-purpose model providers as transparency rules bite across the bloc.

Photo: Unsplash / Guillaume Périgois — European Union flags flying outside the Berlaymont, seat of the European Commission in Brussels

As of today, the European Commission can fine general-purpose AI providers up to €15 million or 3% of global annual turnover, and any chatbot operating in the bloc has to tell users it isn’t human. The Artificial Intelligence Act, in force since 1 August 2024, moves into its enforceable phase on 2 August 2026, and the transparency regime that governs consumer-facing AI switches on the same day.

The Commission’s AI Office now holds a full enforcement toolkit against providers of general-purpose AI models: it can request technical documentation, evaluate models, require corrective measures, and issue penalties. GPAI obligations started applying last year, but until today the Commission couldn’t investigate, order remedies, or impose fines. National market surveillance authorities and the European Data Protection Supervisor carry parallel powers, with lower ceilings for EU institutions and proportionality baked in for SMEs.

The transparency layer is broader than most enterprise legal teams have publicly acknowledged. It applies to any organisation putting its name or trade mark on an AI system that generates content, which explicitly captures the in-house chatbots that every mid-sized European bank, insurer, and telco has quietly rolled out over the past eighteen months. Deepfakes must be labelled. Commission-issued disclosure icons are voluntary. Content produced before the rules take effect doesn’t need retroactive labelling, and systems already on the market have until 2 December 2026 to introduce machine-readable marking.

What’s live today is real, but the perimeter is uneven. Member states were supposed to designate market surveillance authorities by 2 August 2025; several missed it, and some are still passing the national legislation that would give those authorities teeth. The AI Omnibus, in force since 27 July 2026, pushed the harder deadlines further out: rules for high-risk systems in biometrics, critical infrastructure, education, employment, migration and border control now apply from 2 December 2027, with product-integrated high-risk systems following in August 2028.

Brussels has spent two years being told its AI rulebook would arrive stillborn, overtaken by the frontier. It didn’t. It arrived slightly late, with the sharpest edges deferred, and with fine authority pointed squarely at the handful of firms that build the models everyone else uses.

Sources