Can Europe’s AI Firms Finish Compliance by August 2? The Penalty Says They Must
The EU AI Act’s core compliance obligations take effect on August 2 this year. They cover nearly every AI system sold or deployed in the European market.
That’s the broadest enforcement threshold in the regulation’s phased rollout.
General-purpose AI models, developers of high-risk systems, deployers of banned AI practices — the date applies to all of them alike.
Firms that haven’t finished their compliance work by then face fines of up to 35 million euros or 7% of global annual turnover, whichever is higher.
What The EU AI Act Actually Does
The EU AI Act, passed by the European Parliament in March 2024 and entered into force in August 2024, is the world’s first comprehensive legal framework for AI governance. It works by sorting each AI system into four risk tiers.
The top tier covers AI practices that are outright prohibited, such as social scoring by governments, real-time biometric surveillance in public spaces, and manipulation that exploits psychological vulnerabilities. The second tier covers high-risk systems, meaning applications that affect safety, health, employment, education, or access to essential services.
The third and fourth tiers cover limited-risk and minimal-risk systems, which face lighter transparency or no specific obligations.
The August 2 deadline is not the law’s first enforcement date. Prohibitions on banned AI practices took effect in February this year, six months after the law entered into force.
What changes on August 2 is far broader. General-purpose AI model rules kick in, covering large foundation models like those built by OpenAI, Anthropic, Google DeepMind, and Mistral.
High-risk AI system obligations also become enforceable across a wide set of sectors.
The Risk Tiers That Now Govern Every AI System
High-risk AI systems under the Act cover 14 named categories. They include AI used in critical infrastructure, credit scoring, hiring and HR decisions, law enforcement, border control, administration of justice, and biometric categorization.
Any developer or deployer of such a tool in the EU market must now maintain technical documentation, register with a new EU database, implement human oversight measures, and demonstrate that it was built with high-quality training data.
General-purpose AI models, a category that captures large language models and multimodal foundation models distributed via API or consumer product, face their own tier of obligations. Developers must provide detailed technical documentation to downstream deployers, maintain usage policies, and cooperate with authorities on safety incidents.
Models that the European AI Office determines to pose “systemic risk,” generally those trained on compute above 10^25 floating-point operations, face additional requirements including adversarial testing and incident reporting.
A user or business harmed by a high-risk AI system may pursue a legal path under existing EU product liability rules, which were updated in October 2024 to include software and AI systems among covered products.
From Brussels Proposal To Continental Law
The Act’s legislative journey took nearly four years. The European Commission first proposed a risk-based AI regulation in April 2021, drawing on earlier work on data governance and the 2020 White Paper on AI.
Negotiations between the Parliament and Council accelerated in late 2023 as foundation models emerged as a major political flashpoint, with France, Germany, and Italy initially pushing to exempt them from the strictest rules. The final compromise created the GPAI tier, which applies horizontal obligations to foundation model developers rather than regulating specific applications.
The phased rollout reflects those political tensions.
Prohibited practices came first in February. The August 2 package follows.
High-risk systems connected to regulated products, such as medical devices and vehicles, have until August 2027 to comply. The European AI Office, established inside the European Commission, is the primary supervisor for GPAI models, while national market surveillance authorities handle high-risk AI system enforcement in each member state.
Also Read: AI Models Face Shocking Kill Switch as Congress Declares Emergency
Who Bears The Most Immediate Pressure
US technology companies distributing an AI system or AI products in Europe face the sharpest immediate pressure.
Any firm offering a foundation model via API to European businesses or consumers must comply with GPAI documentation and transparency rules from August 2. Firms that sell AI-powered hiring tools, credit-decisioning software, or content-moderation systems to European clients are now operating under enforceable high-risk rules.
Small and medium enterprises get some accommodations.
The regulation allows national authorities to offer sandboxes for smaller developers to test compliance approaches. Fines are proportionate to company size for smaller firms.
Still, the documentation and human-oversight requirements are substantive regardless of company size, and many firms building on top of foundation models will need to assess whether their specific product tips into the high-risk category.
The EU AI Act’s August 2 enforcement date arrives at a moment when AI deployment is accelerating sharply across European enterprises. The Act does not slow that deployment but it does impose a legal accountability layer that did not exist a year ago.
For the firms that have prepared, August 2 is a formality. For those still assessing their risk tier, the deadline passed.
Read Next: Crypto Whales Just Got a Cleaner Way to Buy U.S.
Real Estate
