The EU AI Act One Year Later: Compliance Reality Check
By Justin Right & Sarah Deepsight | June 2026
Most companies treating the EU AI Act as a future problem are already late.
The Act entered into force on August 1, 2024. The first enforcement milestone — prohibited AI practices and AI literacy obligations — hit on February 2, 2025. That means companies have already been enforceable for months. The next wave lands August 2, 2026, when high-risk AI systems and transparency obligations under Article 50 become binding. And the penalty structure makes GDPR look like a parking ticket: up to €35 million or 7% of global annual turnover for prohibited practices.
Yet the compliance gap is wide. Many enterprises are still classifying their AI systems, still figuring out which Annex applies, still treating this as a legal project instead of a business-critical operating requirement. That gap is not just a regulatory risk. It is a competitive vulnerability.
Companies that get ahead of AI Act compliance will move faster in the EU market. Companies that lag will face enforcement, reputational damage, and the operational drag of retrofitting governance under pressure. The choice is not whether to comply. It is whether compliance becomes an advantage or a scramble.
Why the AI Act Penalties Dwarf GDPR

The fine structure alone should reset priorities.

| Tier | Violation | Maximum Fine |
|---|---|---|
| Highest | Prohibited practices (Article 5) | €35M or 7% global turnover |
| Mid-tier | Other obligations, high-risk systems, transparency (Article 50) | €15M or 3% global turnover |
| Lower | Incorrect, incomplete, or misleading information to authorities | €7.5M or 1% global turnover |
The top tier exceeds GDPR’s maximum of €20 million or 4% of global turnover. For a company with €1 billion in annual revenue, a prohibited practice violation could cost €70 million. That is not a compliance budget line item. That is an existential event.
SMEs receive reduced fines, which reflects the Act’s attempt to balance innovation with accountability. But the message is clear: the EU is treating AI governance with the same seriousness it applied to data protection, and the enforcement infrastructure is coming online fast.
The Enforcement Timeline: What Is Already Live and What Comes Next

Understanding the staggered timeline is the first compliance step.

February 2, 2025 — Already Enforced:
Prohibited AI practices and AI literacy obligations became applicable. Companies using manipulative AI, social scoring, or other banned practices are already subject to enforcement action. National Market Surveillance Authorities are conducting inspections and investigating complaints.
August 2, 2025 — GPAI and Governance:
General-purpose AI model rules, governance provisions, and national competent authority designations take effect. The EU AI Office assumes oversight for GPAI compliance, with powers to request documentation, conduct evaluations, and order corrective measures or market restrictions.
August 2, 2026 — High-Risk Systems and Transparency:
The majority of provisions come into force, including high-risk AI systems under Annex III — critical infrastructure, employment, law enforcement — and transparency obligations under Article 50. This is the deadline that should be driving board-level action right now.
Extended Deadlines (Digital Omnibus):
Stand-alone Annex III high-risk systems now have until December 2, 2027. Annex I embedded systems, including medical devices and machinery, have until August 2, 2028. These extensions were welcomed by industry but have also delayed full accountability for certain applications.
The extraterritorial reach matters too. The AI Act applies to any company offering AI systems in the EU market, not just EU-based companies. If your AI product touches European users, you are in scope. Full stop.
The Hybrid Enforcement Model
The AI Act does not rely on a single regulator. It deploys a hybrid model:
-
National Market Surveillance Authorities conduct inspections, investigate complaints, and implement corrective measures. Each Member State must designate at least one authority. That means 27+ enforcement bodies with local interpretation variation.
-
The EU AI Office centrally monitors, supervises, and enforces GPAI model compliance. It can request documentation, conduct evaluations, and order market restrictions.
-
Advisory bodies including the European Artificial Intelligence Board, a Scientific Panel of independent experts, and an Advisory Forum support governance and provide guidance.
This structure creates complexity. A company operating across multiple EU markets may face different enforcement styles, documentation expectations, and inspection frequencies. Compliance programs need to be robust enough to satisfy the strictest interpretation.
The Four Compliance Pitfalls Companies Keep Repeating
After reviewing enforcement guidance, corporate disclosures, and advisory opinions, four failure patterns stand out.
1. Inadequate risk classification
Companies routinely misclassify their AI systems. A recruitment tool that scores candidates is high-risk under Annex III. A customer service chatbot may trigger transparency obligations under Article 50. The classification exercise is not optional, and getting it wrong is not a defense.
2. Missing internal AI governance structures
The AI Act requires documented risk management systems, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, and cybersecurity. Most companies have some of these. Few have all of them in a structured, auditable format.
3. Insufficient documentation for high-risk systems
High-risk AI systems need conformity assessments, either internal or third-party. The documentation burden is significant: model cards, risk assessments, testing protocols, mitigation measures, and post-market monitoring plans. Teams that wait until enforcement begins will not have time to build this properly.
4. Unclear human oversight mechanisms
The Act requires meaningful human oversight for high-risk systems. That means humans who understand the system, can interpret outputs, and can override decisions. Simply having a human in the workflow is not enough. The human must have authority, competence, and contextual understanding.
The Enterprise Shift: Why Compliance Is Becoming a Competitive Signal
There is a less obvious dynamic at play. Enterprise AI spending is diversifying. Anthropic captured approximately 40% of enterprise LLM spend in 2025, surpassing OpenAI’s 27%. This shift signals enterprise caution and a preference for multi-model strategies. It also complicates compliance: different providers mean different risk profiles, different documentation standards, and different oversight requirements.
Companies that can demonstrate robust AI governance — not just compliance checklists, but integrated risk management — are becoming more attractive to enterprise buyers. Procurement teams are starting to ask about AI Act readiness, model cards, and governance frameworks. Compliance is becoming a sales qualification criteria.
A Practical Board-Level Compliance Checklist
Boards need a structured approach. Here is a framework that works.
1. Conduct an AI inventory
Map every AI system the company uses, develops, or deploys. Include third-party tools, embedded systems, and shadow AI usage. Classify each system under the AI Act’s risk tiers: prohibited, high-risk, limited risk, or minimal risk.
2. Assign clear ownership
Every AI system needs an accountable owner. That owner is responsible for classification, documentation, risk assessment, and compliance monitoring. Without named owners, accountability drifts.
3. Build documentation standards
Adopt Model Cards as a baseline. Document model characteristics, intended uses, limitations, performance metrics, and known risks. For high-risk systems, prepare conformity assessment documentation. Reference NIST AI RMF and ISO 42001 as complementary frameworks.
4. Implement human oversight protocols
Define what meaningful human oversight means for each high-risk system. Specify who has override authority, what training they need, and how oversight is documented. Test the protocol: can the human actually stop the system if something goes wrong?
5. Establish continuous monitoring
AI systems drift. Performance degrades. Bias emerges. Build continuous monitoring into the compliance program, not as an afterthought. Include audit trails, feedback loops, and regular reassessment schedules.
6. Prepare for multi-jurisdiction complexity
If you operate across EU Member States, map the national authorities in each jurisdiction. Understand their inspection practices, complaint handling, and enforcement history. The AI Act is harmonized at the EU level but enforced locally.
7. Integrate with enterprise risk management
AI risk should not sit in a separate silo. Integrate it into the company’s enterprise risk management framework. Board reporting on AI incidents, anomalies, and governance maturity should be as routine as cybersecurity reporting.
The US Contrast: Regulatory Fragmentation vs. European Certainty
While the EU builds a unified framework, the US is fragmenting. Over 1,200 state-level AI bills were introduced in 2025, with 145 enacted. Companies operating in both markets face a stark choice: build for the EU’s structured requirements and export that discipline to the US, or manage two separate compliance regimes.
The EU’s regulatory certainty is becoming an advantage. Companies that invest in AI Act compliance are building governance muscle that will serve them globally. The alternative — waiting for US federal legislation that may never come — is a strategy of permanent uncertainty.
Make Compliance Your Operating Advantage
The EU AI Act is not a legal hurdle to clear. It is a governance standard that separates serious AI operators from dabblers. Companies that treat compliance as a check-the-box exercise will struggle. Companies that embed governance into product design, decision-making, and culture will move faster and with more confidence.
The deadline is not theoretical. August 2, 2026 is the horizon. The time to act is now.
Content Factory helps enterprises build AI governance frameworks, compliance documentation, and board-ready risk assessments aligned with the EU AI Act, NIST AI RMF, and ISO 42001. If you need practical compliance support, not theoretical advice, talk to us.
Content Factory OÜ
AI-native, human-refined content production
https://contentfactory.ltd