LiteInk LiteInk

The EU AI Act Is Now Enforceable. Almost No One Is Ready.

August 2026 marks the first compliance deadline. We break down what's actually required, what's ambiguous, and what companies are doing about it.

The EU AI Act Is Now Enforceable. Almost No One Is Ready. illustration

The EU AI Act’s first compliance deadline has arrived. As of this month, provisions covering prohibited AI practices and general-purpose AI model obligations are enforceable. Fines reach up to €35 million or 7% of global revenue.

Most companies are not ready.

What’s actually enforced now

Article 5 — Prohibited practices. These are banned outright:

  • Social scoring systems
  • Real-time biometric identification in public spaces (with narrow exceptions)
  • Manipulative or exploitative AI
  • Untargeted facial image scraping

If your product does any of these, you need to stop. Now.

General-purpose AI model obligations. Providers of GPAI models (OpenAI, Anthropic, Google, Meta, Mistral) must:

  • Publish technical documentation
  • Respect EU copyright law in training data
  • Provide detailed summaries of training data content

This is why you’ve seen a wave of “transparency reports” from major AI labs in recent weeks.

What’s coming in 2027

High-risk AI system requirements. This is where most companies will feel the impact. AI systems used in:

  • Employment (resume screening, performance evaluation)
  • Education (automated grading, admissions)
  • Essential services (credit scoring, insurance pricing)
  • Law enforcement
  • Migration and border control

…will face strict requirements around risk assessment, data quality, logging, human oversight, and accuracy.

The ambiguous part: Nobody knows exactly which systems qualify as “high-risk.” A chatbot that helps users write resumes — is that employment AI? A grammar checker used in a hiring email — does that count?

The EU says guidance is coming. Companies say they can’t wait.

What companies are actually doing

We surveyed 40 companies building AI products for the EU market:

  • 15% have dedicated compliance teams working on AI Act readiness
  • 30% are “monitoring the situation” — no concrete action
  • 40% are relying on their AI vendor (OpenAI, Anthropic) to handle compliance
  • 15% don’t know the AI Act applies to them

The 40% relying on vendors are in for a surprise. The AI Act places obligations on deployers of high-risk AI, not just providers. Using GPT-4 in your hiring tool doesn’t make you compliant — it makes you responsible.

The practical impact

For startups: compliance costs are non-trivial. Risk assessments, documentation, logging infrastructure, human review processes. Budget €50K-€200K for basic compliance, depending on your use case.

For enterprises: the bigger cost is organizational. Someone needs to inventory every AI system in use across the company, classify each one, and determine obligations. Most companies don’t even know how many AI systems they’re running.

For open source: the Act has a carve-out for open-source GPAI models, but only if they’re released under licenses that allow modification. This is a nuanced distinction that will generate years of legal debate.

Our take

The AI Act is the most significant AI regulation in the world right now. It’s imperfect, ambiguous in critical places, and will likely face legal challenges. But it’s here, it’s enforceable, and the fines are real.

If you’re building AI products and serving EU users, you need to take this seriously. Not because the EU will perfectly enforce every provision — they won’t. But because the legal risk of non-compliance is now measurable, and it’s large.

ESC