Brussels Gains Teeth: EU AI Act Enforcement Powers Take Effect
For two years, Europe’s landmark Artificial Intelligence Act existed largely as a calendar of future deadlines. That changed this month, as the European Commission’s AI Office, working alongside national regulators, formally gained the authority to supervise and fine the companies behind the world’s most powerful AI models. The shift marks the end of a one-year grace period and the beginning of what officials describe as substantive, teeth-bearing enforcement of the world’s first comprehensive AI regulatory framework.
What Actually Changed
The AI Act has always rolled out in stages. Prohibitions on the most dangerous AI practices, including social scoring and certain forms of manipulative design, took effect back in February 2025, while obligations for developers of general-purpose AI models began the following August. This latest milestone hands the Commission direct supervisory and enforcement power over the companies building the most capable general-purpose models, with the ability to levy fines calculated as a percentage of global annual turnover for non-compliance.
Alongside the enforcement shift, a new set of transparency obligations under Article 50 of the Act has become legally binding. These rules require clearer disclosure when users are interacting with a chatbot rather than a human, mandatory labelling of synthetic or AI-generated content, and explicit marking of deepfakes. The European Commission has framed these measures as essential tools for helping the public distinguish authentic content from AI-manipulated material at a moment when generative AI tools have made such distinctions increasingly difficult to spot on sight.
High-Risk Systems Get More Time
Not every part of the Act is moving at full speed, however. Under a package known as the Digital Omnibus on AI, signed in early July, EU lawmakers agreed to push back the compliance deadline for a specific category of high-risk AI systems, including tools used in recruitment, credit scoring, education, law enforcement, and critical infrastructure. Those systems, originally expected to face full compliance obligations this month, now have until December 2027, a seventeen-month extension. AI embedded within products already regulated under separate EU product-safety law, such as medical devices and machinery, has been pushed even further, to August 2028.
Officials say the delay reflects practical rather than political concerns. Many EU member states have been slow to designate the national authorities responsible for AI oversight, and the harmonized technical standards that high-risk compliance depends on were not ready in time. Regulators, in effect, would have been demanding conformity against benchmarks that did not yet exist. Importantly, the underlying obligations for these high-risk systems have not been softened or reduced, only delayed.
A New Prohibition and Broader Reach
The Digital Omnibus package also expanded the Act’s list of banned practices, adding a specific prohibition on AI systems used to generate non-consensual intimate imagery, a response to growing concern over AI-generated harassment and abuse. The Commission’s AI Office has also been granted broader supervisory reach over companies that control AI systems across multiple layers of the technology stack, closing a gap that critics had warned could allow vertically integrated firms to sidestep scrutiny.
Stakes for Global Tech
The scale of the potential penalties has drawn close attention from technology companies well beyond Europe’s borders. Providers of high-risk systems that fail to comply face fines that can run into the tens of millions of euros or a meaningful percentage of global annual turnover, whichever proves larger. Because the AI Act applies to any company whose systems serve users within the EU’s roughly 450 million-person market, the regulation carries what analysts often describe as a “Brussels Effect,” pressuring firms as far away as Silicon Valley and Beijing to redesign their compliance practices rather than risk losing access to European users altogether.
Industry analysts estimate the market for AI compliance services alone could grow to as much as €38 billion by the end of the decade, as companies build out the internal systems needed to document training data, monitor model behavior, and respond to regulatory inquiries on an ongoing basis rather than through one-off assessments. For now, businesses operating in Europe are being urged to treat this month’s enforcement shift not as a single compliance deadline to clear, but as the start of a continuous regulatory relationship with Brussels.