bytevyte
bytevyte
Language
ai-beats

EU AI Act enforcement, three weeks in: action count is zero [Update]

EU AI Act enforcement

Three weeks into EU AI Act enforcement, the enforcement ledger is empty. The August 21 tracker covering every action since the August 2 general application date shows no entries at all: no penalty has been imposed, no information request issued, no model evaluation ordered, and no member state has issued a ruling on a prohibited practice. The regulatory machinery is switched on, and so far nobody has used it.

That blank scoreboard is the most consequential compliance fact in Europe right now, and I would argue it matters more than the headline fine ceilings. The obligations that became enforceable on August 2 are real: general-purpose AI providers are under Commission oversight, EU chatbots have to identify themselves as AI, and synthetic media must be labelled as such. As we previously reported, that date moved the EU from legislative text to an active regulatory regime. What the regime does not yet have is a track record.

The powers that went live on August 2

A first set of obligations moved from the statute books into active enforcement on August 2: the outright bans, the GPAI duties, and the transparency requirements. The Commission's new toolkit includes requiring model evaluations before public release, restricting access to the EU market, and issuing requests for information to verify compliance. Fines can reach €15 million or 3% of global annual turnover for GPAI breaches and €35 million or 7% of worldwide turnover for prohibited practices, and the channels for complaints and whistleblower reports are live.

The structure of those powers matters as much as their size. GPAI enforcement sits with the Commission, while prohibited practices fall to national authorities, so a single provider can face two different enforcers depending on the violation. Compliance teams now need to monitor two enforcement channels, with different escalation paths and different penalty regimes, and neither has produced a single formal action as of August 21.

The pre-release evaluation power deserves particular attention. The Commission can demand to evaluate a model before it reaches the EU market and, in the extreme case, restrict market access entirely. That combination gives the office leverage that fines alone cannot: a provider's release schedule can be disrupted even when no penalty is issued. For enterprises that depend on frontier models, this is a supply-chain risk as much as a compliance issue, because a delayed or restricted release in Europe carries into every downstream deployment.

Why EU AI Act enforcement has produced zero actions

Three structural reasons explain the silence, and each one is measurable. The AI Office has 145 people responsible for general-purpose providers across the entire single market. Only Cyprus, Ireland and Italy have fully designated national enforcement authorities, so most member states do not yet have a formally empowered watchdog. And the next hard deadlines are far enough out that nothing on the calendar forces a decision this quarter: December 2, 2026 for the transparency marking grace period, December 2027 for Annex III high-risk systems, and August 2028 for Annex I embedded systems.

The designation shortfall is not a procedural footnote. Designation is the legal precondition for a national authority to exercise its enforcement powers, which means most member states currently lack the capacity to act even where the will exists. The live intake routes for complaints and whistleblower reports compound the situation. Filings can arrive before the formal machinery is ready, so the first wave of actions, when it arrives, may look like a backlog rather than a trickle.

For a GPAI provider budgeting for documentation, evaluation runs and incident reporting, the expected cost of non-compliance today is close to zero, because the probability of being sanctioned this quarter is, on the current evidence, negligible. But the first enforcement action, whenever it arrives, will set the precedent that every later case cites. The quiet period is not proof that the Act is toothless; in my reading, it is the incubation phase of the case law. Providers treating the lull as a discount on compliance are making a bet on timing, not on substance.

The staffing constraint also shapes what EU AI Act enforcement will look like when it starts. With 145 people, the AI Office cannot continuously monitor every general-purpose provider, so it will work from complaints, notifications and targeted checks. That is why the OpenAI notification matters beyond its substance: it proves the intake side of the office is live and gives the office a first data point from which to calibrate expectations.

The one notification on the record

The single item logged so far is not an enforcement action at all. OpenAI has submitted the first known security notification to the AI Office, reporting a breach involving "GPT-5.6 Sol" that surfaced during internal evaluations. The filing shows that the incident-reporting channel works. It also frames the current state of play precisely: one voluntary notification, no regulator response, and nothing else on the public record.

The Act in force is not the Act being sold

There is a second gap worth naming, between the rules that bind today and the rules that dominate board-level risk reviews. For now, the rules that carry real consequences are the GPAI duties and the transparency duties. The high-risk Annex III regime, which draws most of the attention in enterprise planning, does not become applicable until December 2027, and Annex I embedded systems follow in August 2028. In my view, compliance programmes that spent their 2026 budgets on high-risk readiness have sequenced their spending against the wrong deadline.

The nearest milestone is the one easiest to underestimate. The Article 50 marking grace period ends December 2, 2026, but the underlying transparency duties have been enforceable since August 2. The grace period covers marking mechanics, not the obligation itself. Any enterprise running EU-facing chatbots or distributing synthetic content should audit its disclosure and labelling pipeline now, because once the grace period ends, an unmarked chatbot or unlabelled synthetic video is an observable, provable violation, and regulators looking for a first case will not have to look hard.

The enforcement calendar at a glance

DateWhat becomes applicableWho enforces
August 2, 2026Prohibitions, GPAI duties, Article 50 transparencyAI Office, national authorities
December 2, 2026End of transparency marking grace periodAI Office, national authorities
December 2027Annex III high-risk systemsNational authorities
August 2028Annex I embedded systemsNational authorities

What the designation gap changes for high-risk planning

The designation shortfall affects high-risk planning differently. The conformity assessment and registration machinery that Annex III and Annex I systems depend on has no obvious owner in most member states, since only Cyprus, Ireland and Italy are fully designated. Enterprises preparing high-risk deployments for 2027 should be asking their national regulators today who the designated authority will be and what the registration path looks like. A system with no owning authority is a system with no clear compliance clock.

There is also a procurement angle. With no enforcement history to consult, enterprises choosing AI vendors cannot benchmark providers against regulator findings. That raises the cost of due diligence and puts a premium on providers that can produce compliance documentation on demand, because in an enforcement vacuum documentation is the only evidence that exists.

Why this matters

EU AI Act enforcement is real and, three weeks in, completely untested. That combination makes the current window deceptive: the penalties are large enough to matter, the immediate risk is low enough to ignore, and December 2 is close enough that ignoring it is a choice. The companies that use this quiet period to finish their transparency work will be the ones with nothing to fear when the first enforcement action lands.

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.