TL;DR: EU AI Act enforcement becomes operational in Q3 2026, but first fines are more likely in 2027. GPAI providers and large high-risk AI deployers face the most immediate scrutiny. Small teams that document their AI use and follow basic governance practices face very low enforcement risk.
The EU AI Act has been law since August 2024. Enforcement has been limited to prohibited AI practices (since February 2025) and the European AI Office's work on GPAI codes of practice. That changes in Q3 2026.
August 2, 2026 is the date by which every EU member state must have designated a national supervisory authority with the power to investigate, sanction, and fine AI system deployers and providers in their jurisdiction. When that deadline passes, the enforcement machinery is fully assembled.
This guide covers who faces enforcement first, what triggers investigations, how the penalty structure works, and what the realistic risk picture looks like for small teams.
The enforcement structure from August 2, 2026
National supervisory authorities
Each EU member state must designate at least one national supervisory authority (NSA) responsible for enforcing the AI Act for AI systems used in their jurisdiction. In practice, several member states are expected to designate existing data protection authorities or sector regulators, similar to GDPR implementation.
The NSAs will handle:
- Market surveillance of AI systems made available or used within their territory
- Investigation of complaints from individuals under Article 85
- Audits and inspections of providers and deployers
- Penalty proceedings
The 27 NSAs will not coordinate seamlessly from day one. Early enforcement is likely to be inconsistent across member states, with larger, better-resourced authorities in Germany, France, the Netherlands, and Ireland likely to act first.
The European AI Office
The European AI Office, established within the European Commission, has distinct authority for GPAI models made available in the EU. Unlike NSAs, which have jurisdiction bounded by their member state, the AI Office can investigate any GPAI provider globally.
The AI Office has been running the GPAI code of practice process throughout 2025 and 2026 and has more institutional readiness than most member state NSAs. GPAI enforcement actions are therefore more likely to emerge from the AI Office than from national authorities in the near term.
For a detailed rundown of GPAI obligations, see the EU AI Act GPAI compliance checklist August 2.
What will trigger early enforcement actions
Individual complaints under Article 85
Any person can lodge a complaint with a national supervisory authority about a suspected violation. This mirrors the GDPR Article 77 complaint right and is expected to be a significant enforcement driver.
The most likely complaint scenarios:
- An individual denied a job, loan, or benefit believes an AI system made a discriminatory or opaque decision
- A consumer discovers they were targeted by what they believe is prohibited manipulative AI
- An employee files a complaint about AI-based workplace monitoring or performance assessment
- A journalist or civil society organization systematically tests AI systems and files complaints about violations
Complaints must be investigated by the NSA. Even if no penalty follows, an investigation forces the subject to produce documentation and cooperate with regulators. The cost and reputational exposure of an investigation can be significant even without a fine.
Whistleblower reports
The AI Act creates a framework for whistleblower reports about AI Act violations. Employees, contractors, and others with inside knowledge of non-compliance can report to NSAs with legal protection. This channel is particularly relevant for HR screening tools, credit decisions, and other high-stakes automated decisions where employees may witness discriminatory outcomes.
Market surveillance spot checks
NSAs have the power to conduct market surveillance, including testing AI systems and requesting documentation without a prior complaint. Early spot checks are likely to target sectors with the highest Annex III concentration: financial services, employment, and healthcare.
Non-compliance with GPAI obligations
The AI Office has regulatory tools to compel GPAI providers to demonstrate compliance with their obligations: technical documentation, copyright policy, training data summaries, and participation in the code of practice. Providers that have not engaged with the code of practice process or have not produced required documentation are the most obvious early targets.
How the penalty structure works
The AI Act uses a tiered penalty structure based on the severity of the violation.
| Violation category | Maximum fine |
|---|---|
| Prohibited AI practices (Article 5) | EUR 35 million or 7% of global annual turnover |
| Most other violations (providers, deployers) | EUR 15 million or 3% of global annual turnover |
| Incorrect or misleading information to regulators | EUR 7.5 million or 1% of global annual turnover |
| GPAI model violations | EUR 15 million or 3% of global annual turnover |
The regulation specifies that the higher of the two figures applies. For a company with EUR 500 million in global turnover, the 3% threshold at EUR 15 million is the ceiling for most violations. For a startup with EUR 2 million in turnover, the fixed caps apply.
Penalty calculation follows Article 99, which lists factors including: the nature, gravity, duration, and intentionality of the infringement; whether the infringer has previously been in breach; the degree of cooperation with supervisory authorities; and the financial size of the infringer.
Crucially, documented good-faith compliance effort is a mitigation factor. A company that can show it maintained a risk management system, ran human oversight, and had a compliance program even if imperfect will receive significantly different treatment from one that had nothing.
Realistic enforcement risk assessment by company type
| Company profile | Enforcement risk in 2026 | Primary risk driver |
|---|---|---|
| GPAI model provider (large, wide EU market) | High | EU AI Office capacity and focus |
| Large HR AI vendor (Annex III) | High | Individual complaint exposure |
| Financial services AI deployer (credit decisions) | Medium-High | FCA/sector regulator coordination + complaints |
| Small SaaS using AI internally | Low | NSA capacity constraints, not priority |
| Small team using third-party AI tools | Very low | Not primary enforcement target |
| Company using prohibited AI | High regardless of size | Prohibited = strict enforcement intent |
The key variable is not company size. It is whether you fall into a high-risk Annex III category and whether your use is visible to affected individuals who might complain.
What happens during an investigation
If an NSA opens an investigation, the sequence typically follows:
- The authority notifies the company of the investigation
- Documentation is requested: risk management records, technical documentation, human oversight logs, transparency notices
- The authority may conduct interviews and technical testing
- A preliminary finding is issued with an opportunity to respond
- A final decision is issued: closure, corrective measures, or penalty proceedings
- Penalty proceedings result in a formal fine decision, which can be appealed to an administrative tribunal or court
GDPR enforcement has shown that investigations can take 12-24 months from opening to final decision, sometimes longer. The process gives companies time to produce documentation and demonstrate compliance improvements, but only if the documentation exists.
What small teams should do before enforcement begins
Priority 1: maintain an AI tool register
Document every AI tool your organization uses, what it processes, and who approved it. If an NSA asks what AI systems you use, having an organized register demonstrates governance intent and avoids appearing caught off guard. Our AI governance checklist 2026 includes a register template.
Priority 2: confirm you are not using prohibited AI
Article 5 prohibited AI has applied since February 2025. If your organization uses real-time remote biometric surveillance in public spaces, social scoring, or manipulative AI, cease use immediately. The prohibited category is where enforcement intent is sharpest and the penalty ceiling highest.
Priority 3: implement Article 50 transparency notices
Article 50 transparency obligations for AI-generated content and AI system disclosures apply from August 2026. These are relatively straightforward to implement and are visible: an investigator or complainant can easily check whether your chatbot, content generation, or AI-assisted service has appropriate disclosure. See the EU AI Act Article 50 watermarking and deepfake disclosure guide for specifics.
Priority 4: review vendor DPAs and instructions for use
Your deployer obligations include ensuring your AI vendors have appropriate documentation. Request your vendor's instructions for use (Article 13 documentation) and confirm your DPA covers AI processing. Gap analysis guidance is available in our EU AI Act deployer evidence gaps SME August 2026 article.
Priority 5: document human oversight processes
The most effective enforcement risk reducer for deployers of high-risk AI is documented human oversight. If a complaint is filed and you can show that a human reviewed the AI's recommendation before any consequential decision was made, the compliance picture is dramatically better.
The GDPR parallel
GDPR enforcement provides a useful calibration. The regulation came into force in May 2018. The first major fines appeared in 2019. Most small businesses did not receive GDPR enforcement actions in the first two years, even if they were not fully compliant. The first wave of fines targeted large platforms, data brokers, and companies that had specific incidents or complaints.
The same pattern is likely for the AI Act. The first years of enforcement will be shaped by the highest-profile, highest-harm cases. Small teams that have made reasonable good-faith efforts will not be the regulators' primary focus.
That said, GDPR also showed that enforcement capacity grows over time, and by 2023 investigations were reaching much smaller organizations. Building compliance habits now is significantly cheaper than emergency remediation when enforcement reaches your sector.
The practical signal to watch: when the first EU AI Act enforcement action is publicly announced, read what the complaint alleged and what documentation the organization failed to provide. Early cases tend to reveal the documentation patterns that regulators are specifically looking for, and adapting to that signal quickly is worth more than any generic compliance checklist written before enforcement begins.
For the broader timeline context, the AI regulation deadline calendar 2026 tracks enforcement dates across all major AI regulations.
Related reading
- EU AI Act compliance guide for small teams
- EU AI Act deployer evidence gaps SME August 2026
- EU AI Act GPAI compliance checklist August 2
- EU AI Act August 2026 what is delayed vs what applies
- GDPR AI fines 2026 enforcement cases
- AI regulation deadline calendar 2026
- AI governance checklist 2026
- EU AI Act Article 50 watermarking and deepfake disclosure
- EU AI Act national competent authorities enforcement 2026
- EU AI Act prohibited AI practices Article 5 guide
- EU AI Act post-market monitoring Article 72 2026
- EU AI Act enforcement starts August 2, 2026: what it means and what to d
