EU AI Act Fines for GPAI Start August 2, High-Risk Rules Pushed to December 2027
The EU AI Act's high-risk obligations slipped to December 2027, but from August 2 the Commission can fine GPAI providers up to 3% of global revenue.
- What happened: from August 2, 2026 the European Commission and the AI Office can fine general-purpose AI (GPAI) model providers directly.
- The GPAI obligations themselves have been in force since August 2, 2025. Only the enforcement power was held back, for a one-year adaptation period that ends now.
- The cap is 3% of global annual turnover or 15 million euros, whichever is higher (Article 101).
- Starting the same day: Article 50 transparency duties. Chatbots must disclose that they are AI, and AI-generated or manipulated content must be marked.
- Machine-readable marking such as watermarks is deferred to
2026-12-02. Human-visible disclosure applies today, with no grace period.
- Machine-readable marking such as watermarks is deferred to
- What moved: obligations for Annex III high-risk systems (hiring, credit scoring, law enforcement) slipped 16 months to December 2, 2027.
- Product-embedded systems (Annex I) go to August 2, 2028. Regulatory sandboxes go to August 2, 2027.
- The stated reason: member states were late designating competent authorities, and the harmonised standards behind conformity assessment are unfinished.
- Practical read: if you place a model or a feature on the EU market, August 2 is a real enforcement start date, not a paper deadline.
August 2, 2026 is the EU AI Act's second major application date, and the heaviest item scheduled for it is missing. Obligations for high-risk AI systems used in hiring, credit scoring, and law enforcement moved 16 months out, to December 2, 2027. The "Digital Omnibus on AI" amendment, in force since July 2026, moved the date.
Most coverage stopped there and filed the day under "EU delays its AI rules." Two provisions did not move, and both attach directly to teams shipping AI products: the Commission's power to fine GPAI model providers, and the disclosure duties on chatbots and AI-generated media.
Two things that actually switch on August 2
First, the AI Office can now compel model providers. GPAI provider obligations (technical documentation, copyright policy, training-data summaries, systemic-risk management) have been law since August 2, 2025. What was held back was the Commission's supervision and enforcement power, deferred by a year to give providers an adaptation period. That grace period ends today.
Four instruments become available:
- Request technical documentation (Article 91).
- Access the model and evaluate it directly (Article 92).
- Order risk mitigation measures (Article 93).
- Restrict or withdraw the model from the EU market, and impose fines.
Second, Article 50 transparency duties apply with no grace period. Users must be told they are interacting with an AI system, except where that is obvious from context, and AI-generated or manipulated images, audio, and video must be marked as such. AI-generated text on matters of public interest is in scope too, unless a human editor takes editorial responsibility. Deepfakes are named explicitly.
The deadline splits by marking method. Disclosure a person can see applies today. Machine-readable marking, meaning watermarks and provenance metadata, is deferred to December 2, 2026 for systems already on the market before August 2, 2026. What is needed now is the notice on screen. The signal embedded in the file has four more months.
| Scope | Original date | Current date |
|---|---|---|
| GPAI enforcement and penalties | 2026-08-02 | 2026-08-02 (unchanged) |
| Article 50 disclosure duties | 2026-08-02 | 2026-08-02 (unchanged) |
| Machine-readable marking (watermarks) | 2026-08-02 | 2026-12-02 |
| Regulatory sandboxes | 2026-08-02 | 2027-08-02 |
| High-risk standalone (Annex III) | 2026-08-02 | 2027-12-02 |
| High-risk product-embedded (Annex I) | 2027-08-02 | 2028-08-02 |
Why high-risk moved to December 2027
The official reason is that there is no way to comply yet. Providers of high-risk systems must pass a conformity assessment and affix CE marking before placing a product on the market. The harmonised standards that assessment is measured against are unfinished, and member states were late designating the competent authorities and notified bodies that would run it. The deadline existed. The criteria and the assessors did not.
Below is the Commission's own diagram of the conformity path for high-risk AI. The entire four-step sequence is what moved to December 2027.

The amendment itself moved fast. The Commission proposed the Digital Omnibus package in November 2025, trilogue talks broke down once on April 28, 2026, and a provisional deal followed in early May. Parliament adopted it on June 16, the Council on June 29, and it entered into force in July.
The package was not only delay. AI systems that generate non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM) were added to the prohibited practices in Article 5. Technical safeguards have until December 2, 2026, but prohibited-practice fines top out at 35 million euros or 7% of global turnover, the highest tier in the Act. The legal basis for processing sensitive personal data for bias detection and mitigation was also widened, resolving a standing conflict where fairness testing needs the sensitive attributes GDPR kept blocking.
The objections are on record. EDRi and 60 civil society organisations, independent oversight bodies, and individuals filed a joint letter against weakening the transparency provisions, and ECNL's June analysis called the amendment a rollback of safeguards that had not yet applied. Corporate Europe Observatory tracked how big-tech lobbying landed in specific articles. Malta and other member states asked for more review time.
Who gets fined, and how much
The cap is the higher of 3% of global annual turnover and 15 million euros. For a company with $10B in revenue that lands around $300M per violation type. Article 101 also splits the routes to a penalty four ways: breaching a substantive obligation, refusing to produce documentation, refusing evaluation access, and ignoring a corrective order are each independently sanctionable. Failing to cooperate with an investigation is itself a separate finable act.
Coverage depends on release date. GPAI models placed on the EU market after August 2, 2025 are enforceable today, and models released before that have until August 2, 2027 to comply. Training compute above 1025 FLOP creates a presumption of systemic risk, which adds adversarial testing, serious-incident reporting, and cybersecurity duties, and requires notifying the Commission within two weeks of crossing the threshold.
Signing the GPAI Code of Practice changes how enforcement is applied. The Commission has said it will focus supervision of signatories on code compliance, and treat adherence as a mitigating factor when calculating fines. A signature is not immunity, but the investigative posture differs. Most companies building frontier models signed. Meta and China-based companies did not. If you place a model on the EU market, signatory status is the first thing worth checking.
What to check today
Jurisdictions outside the EU are on slower clocks, which is a trap for teams that calibrated against a local timeline. Korea's AI Framework Act took effect on January 22, 2026 and already carries a labeling duty for generative AI output, but the government is running a guidance period of at least a year, so the maximum 30 million won administrative fine is not expected to land before 2027.
| Item | EU AI Act | Korea AI Framework Act |
|---|---|---|
| Output labeling | Visible disclosure August 2, machine-readable marking December 2 | Visible label or watermark/metadata, provider's choice; deepfakes need a visible label |
| Penalty cap | 3% of turnover or 15M euros; 7% or 35M euros for prohibited practices | Corrective order, administrative fine up to 30M won |
| Enforcement start | August 2, 2026 | Guidance period running, fines expected 2027 or later |
For engineering teams, today's work narrows to four checks.
- Do chatbots and assistants exposed to EU users disclose that they are AI? One line in an onboarding screen is not enough. It has to be verifiable at the point where the conversation starts.
- Are AI-generated images, audio, and video marked? Watermarks embedded in the file have until December 2, but the indication on screen is needed now.
- If you serve your own model in the EU, is training compute below the 1025 FLOP threshold, and are technical documentation and a training-data summary ready to hand over?
- If you fine-tune another company's model, what is your contractual status? Substantial modification can pull provider obligations onto you, and the moment the base model version moves to a post-August 2025 generation, the compliance deadline jumps from 2027 to today.
Avoiding a high-risk classification and meeting the duties that started today are separate problems. Regulation is usually felt first as a documentation request rather than a classification argument, and a documentation request is what the AI Office is most likely to send first after August 2.