EU AI Act Enforcement: Prohibited Practices Live, No Public Fines Yet
EU AI Act enforcement is staged: prohibitions live since Feb 2025, GPAI obligations since Aug 2025, high-risk AI from Aug 2026. No public fines yet but investigations are active.
EU AI Act Enforcement: Where Things Stand
The EU AI Act entered into force on August 1, 2024, with enforcement activating in stages. As of early 2026, here is the factual status of enforcement:
Enforcement Timeline
| Date | Provisions in Force | | --- | --- | | August 1, 2024 | AI Act enters into force | | February 2, 2025 | Prohibited practices (Article 5) + AI literacy obligations | | August 2, 2025 | GPAI obligations; AI Office operational; member-state authorities designated | | August 2, 2026 | High-risk AI obligations (most provisions) | | August 2, 2027 | Full applicability including legacy high-risk AI in regulated products |
Current Enforcement Status
No public fines have been issued under the AI Act through Q1 2026. However, enforcement activity is underway:
- Prohibited practices: Investigations opened against 2 EU-based providers for potential violations of Article 5 (social scoring, untargeted scraping for facial recognition). No public fines yet.
- GPAI obligations: The AI Office (145 staff, 34 in regulation/compliance) is reviewing training-data summary disclosures from major providers including OpenAI, Google, Anthropic, Meta, Microsoft, and Mistral.
- High-risk AI: Notified bodies are being designated; mock conformity assessments are being piloted in preparation for the August 2026 deadline.
Maximum Penalties
The AI Act provides three tiers of fines:
- Prohibited AI practices (Article 5): Up to €35 million or 7% of global annual turnover (whichever is higher)
- Other violations: Up to €15 million or 3% of global annual turnover
- Incorrect/misleading information: Up to €7.5 million or 1% of global annual turnover
SMEs and startups receive the lower of the two amounts (more lenient treatment).
What This Means for Employers
Companies using AI systems classified as high-risk — including AI in employment decisions — should prepare for the August 2026 deadline by:
- Conducting fundamental rights impact assessments
- Implementing adequate data governance practices
- Establishing meaningful human oversight mechanisms
- Preparing technical documentation and logging