EU AI Act Enters Enforcement Phase: Fines Are Live, but High-Risk Rules Pushed to 2027? What the AI Omnibus Really Changed
One-line takeaway: The EU AI Act entered its enforcement phase on August 2 — transparency obligations and fining powers took effect that day, while the AI Omnibus amendment pushed core high-risk AI obligations to December 2027; the "fines first, high-risk later" sequencing gives global companies a 16-month compliance runway.
On August 2, 2026, the EU AI Act officially entered its enforcement phase. This is not just "another effective date" — it is the first time regulators actually hold fining power: the AI Office begins overseeing providers of general-purpose AI models, national authorities start enforcing in parallel, and any company violating transparency obligations can be fined from that day forward. Just as notably, the EU simultaneously let the AI Omnibus amendment take effect, adjusting deadlines for high-risk AI — the enforcement door is open, but the clock on high-risk obligations has been wound back.
What Actually Went Live This Week? Article 50 Transparency First
The first wave of the enforcement phase is the transparency obligations under Article 50 of the AI Act. They apply to all AI systems regardless of risk level: chatbots and AI agents must disclose they are AI upfront — not buried in terms and conditions; deepfakes must be labeled as synthetic; emotion-recognition systems must be disclosed before use in certain contexts. Violations can cost up to 3% of global annual turnover or €15 million (whichever is higher) — for marketing, PR, and customer-service teams, these obligations are "live and finable" right now.
What the AI Omnibus Delayed: Two Sets of High-Risk Rules, 28 Months Total
What really lets companies exhale (or start puzzling) is how the AI Omnibus adjusted high-risk obligations. It moved two groups of deadlines:
- High-risk AI in hiring, education, and border management: delayed 16 months, from August 2026 to December 2027 — full compliance duties (conformity assessment, human oversight, audit trails) for AI screening résumés, grading students, or verifying identities at borders get a reprieve.
- High-risk AI embedded in regulated products (medical devices, vehicles, machinery): delayed 12 months, from August 2027 to August 2028.
But "delayed" is not "cancelled": the high-risk classification itself is unchanged. AI used to screen, rank, or evaluate job candidates still sits in a high-risk category, and candidates still have the right to understand the role AI played in significant decisions affecting them. In plain terms — "the algorithm rejected you" will no longer be a sufficient answer; companies just have 16 months to build the explainability.
Extraterritorial Reach Kicks In: No EU HQ, No Escape
Another signal of the enforcement phase is that extraterritoriality is now real. If your AI system serves EU users or places products on the EU market, the AI Act applies regardless of whether your headquarters is in Singapore, San Francisco, or Taipei; supply chains and customer data are covered too. Notably, algorithmic trading systems have been classified as high-risk AI — crypto exchanges and quant funds running automated strategies for European users face fines of up to €15 million or 3% of global annual turnover. Any company building AI — no matter where it is headquartered — must start syncing with Europe's compliance clock.
A 16-Month Runway: What Companies Should Do Now
The staggered timeline isn't "time off" — it's "setup time." For multinationals, now until December 2027 is the ideal window to take stock: map every high-risk AI system, build conformity assessments and audit trails, stand up human-oversight mechanisms, and get transparency obligations (already binding) in place first. Meanwhile, fold the differences between the EU, California SB 53, and Colorado's AI Act into product design — start from the "lowest common denominator," prepare to the highest standard, so when the full enforcement era arrives, you aren't caught off guard.
FAQ
Q1: Will companies be fined immediately after August 2?Fining power is live. The first targets are Article 50 transparency violations — chatbots that don't disclose they're AI, unlabeled deepfakes — while full high-risk obligations only begin enforcement in December 2027.
Q2: What exactly did the AI Omnibus change?It postponed two groups of high-risk AI duties: hiring/education/border AI to December 2027 (16 months), and AI in regulated products to August 2028 (12 months). The high-risk classification and fine framework itself are unchanged.
Q3: Which AI systems count as high-risk?Employment and hiring, education, credit scoring, law enforcement, border management, medical devices, critical infrastructure, and now explicitly algorithmic trading; algorithmic loan denials, hospital AI diagnostic suggestions, and résumé screening are all in scope.
Q4: Do non-EU companies have to comply?Yes. If your AI serves EU users or places products on the EU market, the AI Act applies — headquarters location is irrelevant; supply chains and customer data are covered too. That's extraterritoriality in practice.
Q5: How heavy are the fines?High-risk violations: up to 7% of global annual turnover or €35 million. Transparency violations: 3% or €15 million. For large multinationals, that's enough to elevate compliance from a legal issue to a board-level one.
留言
張貼留言