EU AI Act's Core Obligations Now Applicable: What Businesses Need to Know

The EU AI Act's critical obligations and enforcement powers are now in effect, ushering in a new era of AI governance. Businesses face urgent compliance needs to avoid severe
Listen to the story
Ai and Sons Daily Brief
The EU AI Act's core obligations are now applicable, introducing stringent rules for high-risk AI systems, transparency, and General Purpose AI models, with severe penalties for non-compliance. Businesses face urgent compliance needs, but proactive adherence can offer a competitive advantage despite potential costs and delays.
Read the transcript
Maya: Welcome to the A.I. and Sons Daily Brief. I'm Maya, and joining me today, as always, is our lead analyst, Theo. Today, we're diving into a major development from the European Union that impacts businesses globally.
Theo: Thanks, Maya. It's a critical update. On August 2nd, the EU AI Act's most significant obligations and enforcement powers officially became applicable. This marks a foundational shift in how AI will be developed and used across the continent, demanding immediate attention from any business interacting with the EU market.
Maya: So, Theo, what exactly are these core provisions that are now in effect, and what kind of systems are primarily affected?
Theo: The Act introduces a comprehensive framework. Key provisions now mandate stringent rules for 'high-risk' AI systems, including those used in critical infrastructure, education, employment, and law enforcement. These systems face rigorous demands for data quality, human oversight, cybersecurity, and accuracy. Transparency obligations are also active, requiring users to be aware when interacting with an AI, especially for deepfakes. High-risk systems must undergo conformity assessments and require a CE marking. Crucially, the EU's AI Office has gained enforcement powers for General Purpose AI models like large language models, ensuring they meet specific risk management and transparency standards. Non-compliance can lead to severe financial penalties, potentially reaching 7% of a company's global annual turnover or 35 million Euros, whichever is higher.
Maya: Those penalties are substantial. What are the immediate implications for businesses and technology leaders, especially given the rapid pace of AI adoption?
Theo: The immediate applicability creates an urgent need for compliance, particularly for those involved with high-risk AI systems. A survey from April 2026 revealed a startling level of unpreparedness: 78% of organizations hadn't taken meaningful steps, and over 50% lacked even a basic inventory of their AI systems. This highlights the necessity for immediate action. The requirements for conformity assessments and CE marking will also directly influence the entire lifecycle of AI development and deployment within the EU. Businesses must integrate these mandates into early-stage planning, which could increase costs and time-to-market for high-risk applications.
Maya: So, while there are clear challenges, are there also opportunities for businesses that proactively embrace these new regulations?
Theo: Absolutely, Maya. For forward-thinking businesses, demonstrating compliance can become a significant competitive advantage. Adhering to strict ethical and safety standards fosters greater trust among customers, partners, and regulators, leading to a stronger market position, particularly in sectors where trust is paramount. However, risks are substantial. Beyond severe financial penalties, businesses face increased costs for documentation and technical adjustments, potential time-to-market delays, and operational disruption for bringing existing systems into compliance. There's also a caveat: while core obligations are applicable, fragmented national implementation, with 12 member states having missed deadlines for appointing competent authorities, could lead to initial inconsistencies in enforcement.
Maya: A lot to consider for businesses navigating this new landscape. Thank you, Theo, for breaking down these critical developments. For more details on the EU AI Act and its implications, including all the sources we've referenced, visit aiandsons.com. That's A.I. and Sons dot com. We'll see you next time on the A.I. and Sons Daily Brief.
DATELINE: 2026-08-12
Brussels, Belgium – On August 2, 2026, the European Union's landmark Artificial Intelligence Act officially marked a pivotal moment, with its most significant obligations and enforcement powers becoming applicable. This development signals a profound shift for any business developing, deploying, or providing AI systems within the EU, demanding immediate attention from business owners, founders, and IT/security leaders. The era of proactive AI governance has arrived, bringing with it both stringent requirements and the potential for substantial penalties for non-compliance.
Understanding the New Regulatory Landscape for AI Systems
The operationalization of the EU AI Act introduces a comprehensive framework designed to ensure AI systems are safe, transparent, and trustworthy. This isn't just another piece of legislation; it's a foundational shift in how AI will be developed and used across the continent, impacting global businesses that interact with the EU market.
What Happened: Key Provisions Now in Effect
The core of the EU AI Act's power now lies in its newly applicable provisions. These include:
- Requirements for High-Risk AI Systems: Articles 9-15 now mandate stringent rules for AI systems deemed high-risk, which typically include those used in critical infrastructure, education, employment, law enforcement, migration, and democratic processes. These systems face rigorous demands for data quality, human oversight, cybersecurity, and accuracy.
- Transparency Obligations: Article 50 introduces clear transparency requirements, ensuring users are aware when they are interacting with an AI system, particularly for deepfakes or emotion recognition systems.
- Conformity Assessments: Before being placed on the market or put into service, high-risk AI systems must undergo a conformity assessment, a crucial step to demonstrate compliance with the Act's requirements.
- CE Marking: Compliant AI products will now require a mandatory CE marking, signaling adherence to EU standards, similar to other regulated products.
- Enforcement Powers for GPAI: Crucially, the EU's AI Office has gained its enforcement powers for General Purpose AI (GPAI) models. This means models like large language models (LLMs) and generative AI systems will now be under direct regulatory scrutiny, ensuring they meet specific risk management and transparency standards.
The stakes are high. Non-compliance with the Act can lead to severe financial penalties, with maximum fines reaching 7% of a company's global annual turnover or EUR 35 million, whichever is higher. These figures significantly surpass those stipulated by GDPR, underscoring the EU's commitment to robust AI governance.
Why This Matters: Implications for Businesses and Technology Leaders
The immediate applicability of these provisions carries profound implications for organizations operating within or interacting with the EU market. For business owners and technology leaders, ignoring these changes is no longer an option.
Urgent Need for AI Compliance and Risk Management
The activation of the AI Act creates an immediate and urgent need for compliance, particularly for those involved with high-risk AI systems. The threat of severe financial penalties means that inaction could have catastrophic consequences for a company's bottom line and reputation. Beyond fines, the regulatory scrutiny introduced by the AI Office demands robust governance, comprehensive documentation, and stringent risk management frameworks for all AI systems.
A survey conducted in April 2026 revealed a startling level of unpreparedness: 78% of organizations had not yet taken meaningful steps toward compliance, and over 50% lacked even a basic inventory of their AI systems. This widespread unpreparedness highlights a critical market gap and the necessity for immediate, decisive action.
Impact on AI Development and Deployment Lifecycle
The requirements for conformity assessments and CE marking will directly influence the entire lifecycle of AI development and deployment within the EU. Businesses must now integrate these mandates into their early-stage planning, potentially increasing costs and time-to-market for high-risk applications. This means re-evaluating procurement processes, operational workflows, and overall AI strategies to embed compliance from the ground up. To navigate these complexities, many organizations are seeking expert guidance on AI consulting and implementation.
Navigating Opportunities and Risks in AI Regulation
While the EU AI Act presents significant challenges, it also creates opportunities for businesses that embrace compliance proactively. Understanding both sides is crucial for strategic planning.
Opportunities for Trust and Strategic Advantage
For forward-thinking businesses, demonstrating compliance with the EU AI Act can become a significant competitive advantage. Adhering to strict ethical and safety standards can foster greater trust among customers, partners, and regulators. Companies that prioritize responsible AI development and deployment will likely gain a stronger market position, particularly in sectors like healthcare, finance, and manufacturing, where trust and reliability are paramount. This regulatory push can also accelerate the adoption of best practices in AI governance, leading to more robust and secure AI systems overall. Exploring our resource hub can provide further insights into responsible AI practices.
Addressing the Risks: Penalties, Delays, and Operational Hurdles
The primary risks revolve around the substantial financial penalties for non-compliance, which, as noted, can reach up to EUR 35 million or 7% of global annual turnover. Beyond fines, businesses face:
- Increased Costs: Implementing the necessary documentation, risk assessments, and technical adjustments for compliance will incur significant costs.
- Time-to-Market Delays: The conformity assessment process and the need for CE marking can extend development cycles, delaying the launch of new AI products and services.
- Operational Disruption: For organizations without a clear inventory of their AI systems, the process of identifying, assessing, and bringing existing systems into compliance can be highly disruptive.
- Market Fragmentation: While the Act aims for harmonization, the current fragmented national implementation, with 12 member states having missed deadlines for appointing competent authorities, could lead to initial inconsistencies in enforcement.
It's important to note a caveat: while the core obligations are now applicable, the
Further reading
- European Union: AI Act | Shaping Europe's digital future
- RAIL - Responsible AI Labs: EU AI Act August 2026: your compliance countdown
- White & Case LLP: EU AI Omnibus enters into force, amending the AI Act
Want to put developments like this to work — securely — in your organization? Book a working session with Ai and Sons.



Discussion
0Join the conversation
Sign in with your Google account to participate in the discussion, ask questions, and share your insights.