EU AI Act Enforcement Begins August 2026: What Companies Must Do Now

By Jurista.ai Editorial

The Deadline Is Approaching

On 2 August 2026, the European Union begins enforcing the core obligations of the AI Act for high-risk AI systems. This is not a future possibility — it is a fixed legal deadline with real financial consequences. Companies that deploy or provide high-risk AI systems without meeting the Act’s requirements face fines of up to €35 million or 7% of global annual turnover, whichever is higher.

The AI Act entered into force on 1 August 2024, with a phased enforcement timeline. The first milestone — prohibitions on unacceptable-risk AI practices — took effect on 2 February 2025. General-purpose AI model rules followed on 2 August 2025. Now, the most substantial compliance burden arrives: the high-risk system framework.

Who Is Affected

The August 2026 deadline applies to two broad categories of organizations:

Providers (developers) of high-risk AI systems that place their systems on the EU market or put them into service in the EU, regardless of where the provider is established. This includes companies building AI for recruitment, biometric identification, critical infrastructure, education, employment, law enforcement, migration, and justice.

Deployers (users) of high-risk AI systems operating within the EU. Deployers have their own set of obligations, including using AI systems according to their intended purpose, conducting fundamental rights impact assessments where required, and maintaining human oversight.

Importers, distributors, and authorized representatives in the EU supply chain also bear compliance responsibilities.

What Must Be Done Before August 2026

1. Conduct a Full AI Inventory

Before anything else, identify every AI system your organization develops, uses, or has purchased. This includes machine learning models, rule-based decision systems, biometric tools, and any software that meets the AI Act’s broad definition of AI. You cannot comply with obligations for systems you don’t know exist.

For each system, document its purpose, the data it processes, where it was acquired, and who is responsible for it internally.

2. Classify Each System by Risk Level

The AI Act operates on a risk-based framework:

  • Unacceptable risk — prohibited entirely (e.g., social scoring, manipulative AI, real-time biometric identification in public spaces with limited exceptions)
  • High risk — subject to the full compliance regime (listed in Annex III or meeting the criteria in Article 6)
  • Limited risk — transparency obligations only (e.g., chatbots must disclose they are interacting with AI)
  • Minimal risk — no specific obligations

Classification is the most critical step. If you misclassify a high-risk system as limited-risk, you expose the organization to maximum penalties.

3. Implement the Quality Management System

High-risk AI providers must establish a quality management system (QMS) covering:

  • Regulatory compliance strategy
  • Design and development controls
  • Examination and testing procedures
  • Technical documentation standards
  • Data governance practices
  • Post-market monitoring

The QMS must be documented, maintained, and proportionate to the size of the organization.

4. Prepare Technical Documentation

Article 11 requires providers to maintain technical documentation demonstrating compliance before a high-risk AI system is placed on the market. This documentation must include:

  • A general description of the AI system
  • Detailed information about the development process
  • Specifications for monitoring, functioning, and control
  • Risk management measures (Article 9)
  • Data governance documentation (Article 10)
  • Information for deployers (Article 13)
  • Automatic logs and record-keeping

5. Register in the EU Database

High-risk AI systems (except those used in law enforcement, migration, and border control) must be registered in the EU database before being placed on the market. Registration requires a unique AI system ID and disclosure of provider information, system characteristics, and intended purpose.

6. Appoint an Authorized Representative

If your organization is not established in the EU but provides high-risk AI systems to the EU market, you must appoint an EU-authorized representative who serves as the point of contact for authorities.

7. Conduct Conformity Assessment

Before placing a high-risk AI system on the market, providers must complete a conformity assessment. For most systems, this involves internal control with the QMS and technical documentation. For systems used in biometrics, the assessment requires involvement from a notified body.

What Deployers Must Do

If you use (rather than build) high-risk AI systems, your obligations include:

  • Using the system strictly according to its intended purpose
  • Ensuring human oversight by individuals with appropriate competence
  • Monitoring system operation and reporting serious incidents
  • Conducting fundamental rights impact assessments (for certain public-sector deployers)
  • Keeping automatic logs for appropriate periods

Deployers cannot rely solely on provider assurances. You must understand the system’s risk classification, its limitations, and your specific regulatory duties.

Penalties for Non-Compliance

The penalty structure under Article 99 is severe:

ViolationMaximum Fine
Prohibited AI practices€35M or 7% of global turnover
High-risk obligation failures€15M or 3% of global turnover
Misleading information to authorities€7.5M or 1% of global turnover
Failure to cooperate with authorities€7.5M or 1% of global turnover

For SMEs and startups, the percentages apply rather than the absolute amounts.

Practical Next Steps

  1. Today: Assign internal ownership of AI Act compliance — identify a compliance lead or DPO extension.
  2. This week: Begin your AI system inventory and preliminary risk classification.
  3. This month: Gap-assess your documentation against Article 11 requirements.
  4. Q1 2026: Begin building your QMS and conformity assessment preparation.
  5. Q2 2026: Complete conformity assessments and register systems.
  6. Before August 2026: Finalize documentation, training, and governance controls.

The window between now and enforcement is not generous. Organizations that start late will struggle to complete conformity assessments, assemble technical documentation, and implement governance frameworks in time.


Jurista.ai automates the risk classification, gap assessment, and compliance tracking process for EU AI Act obligations. Start your compliance assessment.