
The EU AI Act Is Now Enforced: What Every Board Needs to Know About Real Fines and Transparency Obligations
The EU AI Act is now fully enforced. Real fines, documentation demands, and transparency rules apply to any company reaching EU users. Here's what your board must know now.
Your board did not choose to govern AI. The EU AI Act made that choice for them. As of August 2, 2026, the European Commission's AI Office and national market surveillance authorities across every EU member state activated full enforcement powers. Penalties are no longer theoretical. Documentation requests are no longer hypothetical. Any company whose AI outputs reach EU users, regardless of where the company is incorporated, is operating in a live enforcement environment right now.
The boards of US companies are discovering this mid-August, often through their legal counsel rather than their technology teams. The problem with that sequencing is significant: by the time lawyers are involved, the AI deployments are already running, the customer-facing chatbots are already un-labeled, and the AI-generated content is already live without required disclosures. That is not a compliance gap. That is an active regulatory exposure that a sitting board member can be held accountable for failing to prevent.
What Became Enforceable on August 2, 2026
Two parallel enforcement tracks activated simultaneously, and boards need to understand both.
Track 1: AI Office Powers Over General-Purpose AI Models.
On August 2, 2026, the European Commission's AI Office became formally entitled to exercise its powers to investigate and enforce EU AI Act obligations imposed on providers of general-purpose AI (GPAI) models. These powers are significant and include requesting information and documentation, obtaining access to models for evaluation, requiring corrective or risk-mitigation measures, and imposing fines of up to the higher of €15 million or 3 percent of the provider's worldwide annual turnover.
Track 2: Article 50 Transparency Obligations.
These obligations require providers and deployers of AI systems to be transparent about the use of AI in four key areas: direct interaction with individuals; AI-generated content; emotion recognition and biometric categorisation; and deepfakes and AI-generated text on public-interest matters.
The fine structure is not the only pressure point.
The AI Office is not limited to issuing guidance. It can compel a provider to hand over technical documentation under Article 91, require risk-mitigation measures under Article 93, and demand model access to conduct evaluations under Article 92. Refusing or stalling on any of those is itself a finable offense.
For boards, that last point deserves full attention. A company that lacks documentation infrastructure cannot simply delay its response to an AI Office request. Non-responsiveness is a separate violation with its own fine tier.
The Extraterritorial Reality That US Boards Are Underestimating
The most consistent mistake US boards make is assuming EU AI regulation applies to EU companies.
The AI Act applies globally to providers, deployers, importers and distributors of AI systems that place AI on the EU market or whose AI outputs are used within the European Union.
This is not an edge case.
The regulation reaches providers and deployers established outside the Union when the system's output is used inside it. A non-EU business running AI-generated campaigns aimed at European audiences, or operating an assistant that serves customers in the Union, is in scope.
Like the GDPR, the AI Act applies to any entity that places AI systems on the EU market or whose AI system outputs are used within the EU, regardless of where the provider is headquartered. This "Brussels Effect," documented extensively by Columbia Law professor Anu Bradford, means that the EU's standards will likely become the de facto global baseline, as companies find it more efficient to comply globally than to maintain separate systems for different jurisdictions.
A US company does not need a European office, a European data center, or a European employee to face a European fine. It needs only one customer chatbot that serves one EU user without an AI disclosure.
What the Transparency Rules Actually Require
Article 50 is more operationally demanding than most boards realize.
Under these rules, chatbots have to identify themselves as automated systems, deepfakes need a label, and machine-made or edited content must carry machine-readable marks so it can be detected automatically.
The disclosure standards are specific.
A statement buried in terms and conditions, a metadata watermark on its own, or a vague reference to an "assistant" does not satisfy the chatbot disclosure duty in Article 50(1); the information has to be perceivable in the interaction itself.
The split of responsibility between providers and deployers also creates a trap for companies that rely on vendor AI.
Even if the chatbot or the image generator belongs to an outside vendor, the organisation that puts it in front of EU customers, or publishes its output, is responsible for making sure the disclosure reaches the user. There is no automatic transfer of responsibility to the maker.
An organisation with no high-risk AI may still have significant obligations under Article 50: for example, because it develops a customer-facing chatbot, deploys an AI tool that generates news content for publication, or relies on a system that produces deepfake imagery. Transparency obligations are the second most common compliance trigger after AI literacy, affecting around 33% of all respondents.
The Fine Structure and Enforcement Priority Sectors
| Violation Category | Maximum Fine | Enforcement Authority |
|---|
| Prohibited AI practices (e.g., social scoring, manipulation) | €35M or 7% of global turnover | EU AI Office + national authorities |
| GPAI model violations / Transparency (Article 50) | €15M or 3% of global turnover | EU AI Office + national authorities |
| Incorrect or incomplete response to information request | €7.5M or 1% of global turnover | EU AI Office |
| High-risk AI system violations (Annex III) | Enforcement from December 2027 | National market surveillance authorities |
| Prohibited AI practices (nudification, CSAM) | €35M or 7% of global turnover | Effective December 2026 |
Financial services, healthcare, employment, and legal communication have all been flagged by EU national authorities as early enforcement priorities.
Companies operating AI in any of these sectors should treat this not as a future planning item but as a current audit trigger.
The Commission has already used other EU digital laws to scrutinise risks associated with generative AI. In January 2026, the Commission opened a formal investigation into X under the Digital Services Act over its Grok tool, after manipulated sexually explicit images and possible child sexual abuse material appeared on the platform.
That investigation signals both willingness and capacity to act against US-headquartered technology companies.
Framework Alignment: What Good Governance Looks Like
The AI Act's requirements do not exist in a vacuum. Two frameworks provide the structural foundation that boards need to demonstrate governance maturity: the NIST AI Risk Management Framework and ISO/IEC 42001.
Together, the EU AI Act and NIST AI RMF create a dual framework that enterprises must reconcile, one emphasizing regulatory evidence, the other operational maturity.
The NIST AI RMF's four functions (Govern, Map, Measure, Manage) map directly onto the AI Act's requirements for risk management systems, human oversight, and post-market monitoring.
Adopting NIST AI RMF practices does not satisfy EU AI Act obligations, but it produces documentation and processes that significantly reduce the marginal effort required for EU AI Act compliance.
For boards, the CISA AI Security Guidance provides parallel infrastructure-level controls that complement the Act's governance requirements. Aligning to both NIST AI RMF and the EU AI Act simultaneously is achievable through a unified program, and it is the only cost-effective path for companies serving both US and EU markets.
The Documentation Infrastructure Problem
Most US companies have never been asked to produce model documentation, training data summaries, or algorithmic transparency records on regulatory demand. The AI Office's request for information authority means that gap is now a timed risk.
Coverage includes documentation requests, technical evaluations of models, access to training data summaries, systemic risk assessments for high-compute models (above 10²⁵ FLOPs), and the ability to restrict or withdraw a model from the EU market.
The Vendor Dependency Trap
Every enterprise AI deployment that uses a foundation model via API sits downstream of GPAI model enforcement.
If you are a business deploying a major foundation model via API to serve EU customers, the providers of those models are now under active regulatory supervision. That scrutiny does not stay with the providers; it flows downstream through their terms of service and usage policies.
Your vendor's compliance posture is now part of your compliance posture.
The Board Accountability Gap
The AI Act's governance requirements (risk management systems, human oversight protocols, post-market monitoring) require structures at the C-suite and board level.
In the 2026 compliance environment, screenshots and declarations are no longer sufficient. Only operational evidence counts.
A board that delegated AI risk entirely to engineering or product teams, with no board-level oversight structure, does not have a governance program. It has a gap that is now documented in the enforcement framework.
Board Readiness Assessment: Eight Questions to Ask Now
Use this as a starting checklist before your next board meeting. If you cannot answer these with documented evidence, each one is an open exposure.
A "no" or "unsure" on any of these does not require panic. It requires a documented remediation plan with an owner and a deadline. Regulators do not expect perfection; they expect evidence of a functioning governance program. The distinction between a company that has a documented remediation plan and one that has nothing at all is the difference between a corrective measure and a fine.
How I Help
Secure AI Deployment is the service most boards need first right now. With 20+ years of experience translating regulatory obligations into operational controls, I conduct a full AI system inventory across your organization, implement access and model-level controls, run vendor AI compliance checks against the EU AI Act's deployer obligations, and build the board-ready evidence package aligned to NIST AI RMF and Article 50. The output is not a report that lives in a drawer. It is a documented governance program that can withstand an AI Office request for information the day it arrives.
For organizations that need ongoing security leadership without a full-time hire, my vCISO service provides the C-suite accountability structure the AI Act's governance requirements demand. If your board needs structured briefings and director-level accountability frameworks, Board Advisory brings AI risk governance directly into the boardroom agenda. For companies building or acquiring AI-enabled products, Security Architecture embeds compliance controls at the design stage rather than retrofitting them after deployment. And for organizations navigating the full regulatory stack across EU AI Act, ISO 42001, and US state laws, AI Compliance structures the unified program that serves all jurisdictions without duplication.
The enforcement clock started August 2. Board oversight of that clock is not optional.
Adil Karam
Security & AI Governance Advisor
Helping organizations navigate security leadership and AI governance challenges.
Related Articles
EU AI Act Enforcement Has Started: What U.S. Boards Must Do Before December
Shadow AI Is Now Your Biggest Breach Risk: What the IBM 2026 Report Means for the Board
AI Agent Sprawl: The Board Governance Crisis Your Org Chart Isn't Ready For
Ready to Put These Insights Into Action?
Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.