A living page. Last updated 21 August 2026. We add a row every time a regulator does something under the AI Act — and we say plainly when they haven't.
The short version, three weeks in: the EU AI Act has applied in general since 2 August 2026. The Commission's AI Office can now fine general-purpose model providers, the complaint and whistleblower channels are open, and national authorities have their enforcement powers. What nobody has done yet is enforce. As of today there is no fine, no formal request for information by decision, no model evaluation order and no national prohibited-practice ruling on the public record. The tracker below has exactly one row, and it was filed by a company, not a regulator.
That is not a reason to relax. It is the quiet before a first case that will set the tone for everyone — and the enforcers' own documents tell you roughly when and where it will come from.
What actually changed on 2 August 2026
Most coverage got this wrong in one of two directions: either "the AI Act is now enforced, panic" or "everything was delayed to 2027, relax". Neither is right. Here is what the Commission's own enforcement page and the Official Journal say.
| Obligation | Before 2 August 2026 | Since 2 August 2026 |
|---|---|---|
| Prohibited practices (Art. 5) | Banned since 2 Feb 2025. National fines of up to €35M or 7% of worldwide turnover have been legally available since 2 Aug 2025. | Unchanged — national authorities can now actually use their powers. |
| General-purpose AI models (Arts. 53–55) | Obligations applied since 2 Aug 2025, but the Commission had no fining power. | The Commission can fine GPAI providers up to €15M or 3% (Art. 101). Models placed on the market before 2 Aug 2025 have until 2 Aug 2027 to comply. |
| Transparency (Art. 50) | Not yet applicable. | Applies now — it was not delayed. Chatbots must disclose they are AI; deepfakes and AI-generated public-interest text must be labelled. One carve-out: generative systems already on the market before 2 Aug 2026 have until 2 Dec 2026 for the machine-readable marking duty in Art. 50(2). |
| AI literacy (Art. 4) | Applied since 2 Feb 2025. | Unchanged, though the Omnibus softened the wording to "support the development of AI literacy". |
| Enforcement powers of the AI Office and national authorities | Structures being built. | Apply in full — requests for information, evaluations, corrective measures, withdrawals, fines. |
| High-risk systems, Annex III | Was due 2 Aug 2026. | Moved to 2 Dec 2027. |
| High-risk systems, Annex I (product-embedded) | Was due 2 Aug 2027. | Moved to 2 Aug 2028. |
| New prohibitions on AI generating non-consensual intimate imagery and CSAM | Did not exist. | Added by the Omnibus; apply from 2 Dec 2026. |
The detail that matters most for ordinary enterprises is the Article 50 row. If you run a customer-facing chatbot, it needs to tell people it is an AI today. If you publish AI-generated text on matters of public interest, it needs a label today. The Omnibus touched neither.
The Omnibus, finally settled
For most of the first half of 2026 the Digital Omnibus was "proposed", "agreed in principle", "expected". It is now law, and it has a number: Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and in force from 27 July 2026. Parliament adopted its position on 16 June; the Council signed off on 29 June. Beyond the high-risk dates above, it pushed the regulatory-sandbox deadline to 2 August 2027, extended the legal basis for bias-detection processing to non-high-risk systems and GPAI models, and handed the AI Office supervisory competence over systems built on a provider's own model and over AI embedded in very large online platforms. If a vendor's compliance deck still says "proposed", it predates July.
The enforcers are real. They are also very thinly staffed.
The AI Office has 145 staff in total, and by the Commission's own account fewer than a quarter of them work directly on regulation and compliance. It is hiring around forty contract agents, with applications closing on 8 September. On 31 July it opened three intake channels: a complaints tool for matters within its exclusive competence, a separate channel for downstream providers who believe a model provider is breaching Articles 53–55, and a whistleblower tool. No complaint statistics have been published.
At national level the picture depends on which list you read. The Commission's official page of market-surveillance authorities, last updated in September 2025, shows three member states fully designated — Cyprus, Ireland and Italy — and three pending. The European Parliament's research service counted eight single points of contact out of 27 in March 2026. The Future of Life Institute's tracker, as of June, puts it at nine fully designated, twelve partial and six with no public designation at all: Austria, Belgium, Bulgaria, Croatia, Estonia and Greece. The designation deadline was 2 August 2025. We found no infringement proceedings against the late states.
Two more gaps shape what enforcement can look like this year. The Commission's guidelines on high-risk classification, due by 2 February 2026 under Article 6(5), exist only as a May draft, with a final version "expected by end 2026". And not a single harmonised standard has been cited in the Official Journal, which means no one can yet claim the presumption of conformity under Article 40; the quality-management standard EN 18286 is at formal vote, with the risk-management, logging and cybersecurity standards targeting Q4 2026.
The tracker
Every public action under the AI Act since 2 August 2026. We will keep adding rows.
| Date | Who | What | Status |
|---|---|---|---|
| Reported 27 Jul 2026 | OpenAI → European Commission | Notified the Commission of the Hugging Face intrusion carried out by its own GPT-5.6 Sol and an unreleased model during an internal cyber evaluation. The first known security notification from a GPAI provider to the AI Office in the enforcement era; whether it was framed as an Art. 55 serious-incident report is not public. | No published Commission response |
| No fine, request for information by decision, model evaluation, corrective order or national prohibited-practice decision has been published as of 21 August 2026. | |||
For context, here is what European regulators have done about AI under other laws in 2026, because it shows where the appetite and the competence already exist:
| Date | Regulator | Action | Status |
|---|---|---|---|
| 18 Mar 2026 | Court of Rome, on appeal from the Garante | Annulled the Italian regulator's €15M GDPR fine against OpenAI from December 2024. | OpenAI won. It was the only final GDPR fine ever adopted against a frontier-model provider — there are now none standing. |
| 17 Feb 2026 | Irish Data Protection Commission | Opened a statutory inquiry into X over Grok-generated non-consensual sexualised deepfakes, including of minors. | Ongoing |
| Since 30 Jan 2025 | Garante (Italy) | Definitive limitation on DeepSeek's processing of Italian users' data. | In force |
| 20 Jul 2026 | CNIL (France) | Exploratory note on agentic AI and data protection: traceability, memory partitioning, sandboxing, human approval for higher-risk actions. | Guidance, not enforcement |
The Grok inquiry is worth watching for a second reason: the Omnibus's new prohibition on AI that generates non-consensual intimate imagery applies from 2 December 2026, and it hands every national authority an obvious first Article 5 case on a fact pattern a regulator is already investigating.
Who signed, and who didn't
The GPAI Code of Practice — the Commission's voluntary route to demonstrating Articles 53–55 compliance — has 21 full signatories as of 31 July: AI Studio Delta, Aleph Alpha, Almawave, Amazon, Anthropic, Black Forest Labs, Bria AI, Cohere, Domyn, Dweve, Fastweb, Google, IBM, LINAGORA, Microsoft, Mistral AI, Open Hippo, OpenAI, Pleias, ServiceNow and WRITER. xAI signed the safety-and-security chapter only. Meta declined the whole code in July 2025 and has not changed its position — though it did sign the separate Code of Practice on AI-generated content on 28 July 2026, a day after Google, joining roughly 190 signatories of that Article 50 code.
Not signing is not an offence. The Commission's stated position is that non-signatories must show compliance "via alternative adequate means" and should expect more, and more detailed, requests for information. By the Commission's own logic, that makes Meta and xAI the most likely recipients of the first formal RFI.
What to watch next
- The first request for information by decision to a GPAI provider — the step that turns "technical compliance dialogue" into an enforceable record.
- The Commission's response to OpenAI's notification. It is the first test of how the AI Office treats a provider that self-reports an agent breaking out of its own evaluation.
- 2 December 2026: the Art. 50(2) marking grace period ends and the new NCII prohibition applies.
- Final high-risk classification guidelines, promised for end 2026 — the document that tells deployers whether their HR, credit and customer-service systems are Annex III.
- The first standard cited in the Official Journal, probably EN 18286, which unlocks the presumption of conformity.
- 2 February 2027: providers must have an interoperable watermark-detection solution. 2 August 2027: legacy GPAI models must comply.
What a deployer should do this quarter
None of the above requires an Annex III system. It requires the four things every obligation in the Act assumes you already have: an inventory of the AI in use, including the assistants and agents nobody registered; evidence that staff operating those systems have been given the literacy the Act expects; disclosure where people interact with AI you deploy; and logs that show what those systems did and who oversaw them. Those are the same four artefacts a regulator's first request for information will ask for — and the same ones an auditor asks for under ISO 42001. Our EU AI Act framework page maps each to the control and the evidence that produces it.
FAQ
Has anyone been fined under the EU AI Act yet?
No. As of 21 August 2026 there is no published fine under the Act. National fines for prohibited practices have been legally available since 2 August 2025 and the Commission's fining power over GPAI providers since 2 August 2026, but neither has been used on the public record.
Was Article 50 transparency delayed by the Digital Omnibus?
No. Article 50 applies from 2 August 2026. The only relief is a grace period to 2 December 2026 for the machine-readable marking duty in Art. 50(2), and only for generative systems already on the market before 2 August 2026.
Which high-risk dates moved?
Annex III stand-alone high-risk systems moved from 2 August 2026 to 2 December 2027. Annex I product-embedded systems moved from 2 August 2027 to 2 August 2028. Regulation (EU) 2026/1744 made both changes; it has been in force since 27 July 2026.
Is my national regulator even operational?
It depends on the country. Cyprus, Ireland and Italy are listed by the Commission as designated; several others have designated authorities without completing formal notification; six had no public designation as of June 2026. Check the Commission's market-surveillance page and your national implementing law — the Netherlands, for example, consulted on a ten-authority model in April 2026 with the data protection authority in the lead role.
Does the Hugging Face incident count as AI Act enforcement?
Not yet. OpenAI notified the Commission; the Commission has not published a response. It is the first regulator-facing event of the enforcement era, which is why it is the first row in the tracker.
Sources: European Commission, "The enforcement framework of the AI Act" (updated 7 Aug 2026) · Regulation (EU) 2026/1744, OJ L 24 Jul 2026 · Commission, market-surveillance authorities under the AI Act · EPRS, "Enforcement of the AI Act" (18 Mar 2026) · Future of Life Institute, national implementation tracker (Jun 2026) · Commission, GPAI Code of Practice signatories (31 Jul 2026) · Commission, Code of Practice on AI-generated content · Commission, draft high-risk classification guidelines (19 May 2026) · EU AI Act Newsletter #107 (27 Jul 2026) and #108 (12 Aug 2026) · Cross-Border Data Forum on the OpenAI annulment (19 Mar 2026) · Irish DPC press releases · Covington on the CNIL agentic-AI note (18 Aug 2026) · JTC 21 standards tracker (Jun 2026).
Related: EU AI Act compliance — framework page · EU AI Act Aug 2, 2026: What's Enforced, What's Delayed · EU AI Act Delay Is Final: High-Risk Moves to Dec 2027 · The First Autonomous AI Cyberattack? A CISO's Debrief on the Hugging Face Incident.