One month into the EU AI Act's enforcement era, the most powerful regulator in AI has not fined anyone. What it has done is make it illegal, across 27 member states, for a chatbot to pretend it is a person.

On 2 August 2026, the Commission's AI Office — working alongside national market surveillance authorities — gained formal power to investigate providers of general-purpose AI models and impose penalties of up to the higher of €15 million or 3% of worldwide annual turnover under Article 101 of the Act. For prohibited AI practices, the ceiling rises to €35 million or 7% of global turnover. The same date switched on Article 50, the transparency chapter, which requires that AI systems interacting directly with people tell those people they are talking to a machine, that deepfakes be labelled, and that synthetic audio, image, video and text carry machine-readable provenance marks.

"Chatbots and other interactive AI systems will have to tell users they are dealing with AI, not a human," the Commission wrote in the press release announcing the switch-on, published 31 July. Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, framed the moment as a balance rather than a crackdown, saying the Act gives "innovators legal certainty while protecting the public interest" and calling enforcement "an important step towards AI that people and businesses can understand and trust." She has also been blunt about why the GPAI powers exist at all: the most advanced models, she said, "create risks on an entirely new scale."

What actually happened in month one

Not much publicly — and that appears to be by design. In a FAQ on its service desk, the AI Office described "technical compliance dialogues" as its preferred first instrument for assessing compliance, and said those dialogues would continue and may intensify after 2 August. As of 1 September, no formal AI Act proceeding against a named GPAI provider had been publicly announced. The Commission has opened AI-adjacent cases under other instruments — a Digital Services Act investigation into X over its Grok tool, launched in January 2026 — but that is a different statute with a different evidentiary path.

The Brussels law firm bar reads the silence the same way. Wilson Sonsini's data and privacy team, in a 3 August client alert, noted that where dialogues "do not adequately resolve its concerns, the EU AI Office may turn to exercising its formal powers." The firm's advice to clients was less about litigation than paperwork: confirm the technical documentation, downstream-provider information, copyright compliance policy and training-data summary are complete and internally consistent, because failing to answer a formal request for information is itself a finable offence.

Industry's visible response has been to sign something. The Commission published a first list of more than 180 organisations adhering to the voluntary Code of Practice on Transparency of AI-Generated Content, which operationalises the marking and labelling duties and includes a standard icon set. Signing is not a legal shield, but it confers what Cooley described in an August alert as "a degree of presumption of conformity and a more favorable enforcement posture," while non-signatories "face closer scrutiny and must demonstrate compliance through other means."

Costs are real but not catastrophic. Advisory-market estimates circulating this summer put first-year compliance at roughly €5,000 to €25,000 for a small organisation that only deploys AI, €25,000 to €100,000 for a mid-sized company with candidate high-risk systems, and €100,000 to €500,000 or more for large enterprises placing high-risk systems on the market. The immediate Article 50 work — disclosure banners, watermarking pipelines, editorial-review procedures — sits at the cheaper end. One deadline is still open: providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation in Article 50(2). Legacy GPAI models placed on the market before 2 August 2025 have until 2 August 2027.

Why the teeth landed on disclosure

The reason enforcement now points at labels rather than at credit-scoring algorithms is a single piece of legislation. Regulation (EU) 2026/1744, the Digital Omnibus on AI — adopted 8 July 2026, published in the Official Journal on 24 July and in force from 27 July — pushed the Annex III high-risk conformity regime from 2 August 2026 to 2 December 2027, and high-risk systems embedded in products covered by sectoral product-safety law to 2 August 2028. It also thinned what providers must upload to the public EU database.

That is the deregulatory tell. The Act's most consequential machinery — risk management, human oversight, accuracy and robustness testing for AI in hiring, policing, education, credit and migration — is deferred by sixteen months, while what survived intact is cheap to implement and easy to observe from outside. A joint analysis by EDRi, Access Now, ECNL and Amnesty International argued the Omnibus "delays key protections, weakens transparency and creates a dangerous precedent for the EU digital rulebook," warning that if newly adopted laws can be reopened before they apply, "powerful actors can treat implementation as a second chance to weaken rules they dislike." The Omnibus did move faster in one direction: from 2 December 2026 it bans AI systems generating non-consensual sexually explicit content or child sexual abuse material.

The practical effect is a regulator with maximal formal power over frontier models and little near-term work to do with it, pointed at a transparency regime that is genuinely enforceable today. That is not nothing. It is also not the AI Act voted through in 2024.

Watch three things through the autumn. First, 2 December 2026, when the marking grace period closes and the first genuinely testable non-compliance appears — an unwatermarked generative system is a fact a regulator can establish without a subpoena. Second, whether any technical compliance dialogue converts into a formal Article 101 proceeding; the Commission has built complaint and whistleblower channels precisely to generate those referrals. Third, whether the December high-risk timetable holds, or whether a second Omnibus arrives to move it again.

“The AI Act gives innovators legal certainty while protecting the public interest.”
— Henna Virkkunen, Executive Vice-President for Tech Sovereignty, European Commission
3%
Max GPAI fine as share of worldwide turnover
7%
Max fine for prohibited AI practices
180+
Code of Practice signatories
Dec 2027
New Annex III high-risk deadline