AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Enforcement ActionEnforcementEUHigh riskLimited riskMinimal riskUnacceptable risk

EU AI Act: Transparency Obligations and General-Purpose AI Enforcement (August 2026)

Issued by

European Commission, AI Office

liveEffective 2026-08-02EUAIAct-T2Verified August 2026
Official document →

As of 2 August 2026, the EU AI Office and Member State authorities hold active enforcement authority over transparency obligations and General-Purpose AI model oversight under the EU AI Act. The regulation applies to enterprises that develop, deploy, or place AI systems on the EU market, including organizations using GPAI models in their products or services. Covered entities must now meet transparency labeling requirements, maintain technical documentation, and comply with AI Office requests for model evaluation and corrective action.

Applies To

Large enterpriseSMBAI developerAI deployer

Overview

The EU AI Act entered its enforcement phase for transparency obligations and General-Purpose AI oversight on 2 August 2026, following the broader legislative timeline that began with the Act entering into force in August 2024. The AI Office holds primary enforcement jurisdiction over GPAI model providers, with powers that include demanding technical documentation, ordering model evaluations, imposing corrective measures, and issuing financial penalties. Member State market surveillance authorities run parallel enforcement for deployers and operators of AI systems subject to transparency requirements under Article 50. Transparency obligations require that AI systems interacting with natural persons, generating synthetic content, or making consequential decisions disclose their AI nature to affected individuals. Enterprises that fail to maintain required documentation, notify incidents, or respond to AI Office inquiries within prescribed timeframes face escalating enforcement action. Penalties for GPAI-related violations can reach 3 percent of global annual turnover, while transparency infringements carry fines of up to 15 million EUR or 3 percent of global turnover, whichever is higher.

Key Requirements

  • Comply with Article 50 transparency labeling: AI systems interacting with natural persons must disclose their automated nature at the point of interaction, with no grace period as of 2 August 2026.
  • GPAI model providers must maintain up-to-date technical documentation and make it available to the AI Office upon request, with response timelines set by the Office on a case-by-case basis.
  • GPAI providers classified as posing systemic risk must conduct adversarial testing, report serious incidents to the AI Office within timeframes specified in the Act, and implement cybersecurity safeguards.
  • Enterprises deploying third-party GPAI models must ensure contractual access to documentation sufficient to demonstrate downstream compliance obligations are met.
  • Non-compliance with AI Office corrective measures or documentation requests can result in fines of up to 3 percent of global annual turnover for GPAI providers.
  • Transparency violations, including failure to label AI-generated content such as deepfakes and synthetic audio or video, carry penalties of up to 15 million EUR or 3 percent of global annual turnover.

What Your Organization Must Do

  • Audit all AI-facing customer touchpoints to confirm transparency disclosures are live and legally compliant with Article 50 language requirements before the next supervisory review cycle.
  • Map every GPAI model in your technology stack, identifying which providers hold GPAI status under the Act and whether any carry systemic risk designation.
  • Request and archive technical documentation from all GPAI vendors, and insert contractual clauses requiring vendors to supply updated documentation within a defined timeframe upon any model change.
  • Establish an AI incident response protocol that routes serious incidents involving GPAI models to a designated compliance lead who can coordinate AI Office notification within required timelines.
  • Assign ownership of ongoing AI Office correspondence to a named senior compliance officer with authority to engage external counsel and produce documentation on short notice.
  • Review synthetic content pipelines, including marketing, customer service, and internal automation tools, to confirm watermarking or disclosure mechanisms meet the AI Office's current technical guidance.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does the August 2026 EU AI Act enforcement deadline apply to companies headquartered outside the EU?
Yes. The EU AI Act applies to any enterprise that places an AI system on the EU market or whose AI outputs affect EU users, regardless of where the company is headquartered. Non-EU GPAI model providers and deployers must comply with transparency and documentation obligations by 2 August 2026.
What are the specific penalties for violating Article 50 transparency labeling requirements under the EU AI Act?
Transparency violations carry fines of up to 15 million EUR or 3 percent of global annual turnover, whichever is higher. This applies to failures such as not disclosing an AI system's automated nature at the point of interaction or omitting required labels on synthetic content like deepfakes.
How does EU AI Act enforcement for GPAI models differ from enforcement for AI system deployers?
The AI Office holds primary jurisdiction over GPAI model providers, with authority to demand documentation, order evaluations, and impose corrective measures. Member State market surveillance authorities run parallel enforcement for deployers subject to Article 50 transparency obligations, creating a two-track enforcement structure.
What documentation must enterprises obtain from third-party GPAI vendors to satisfy EU AI Act compliance?
Enterprises must secure contractual access to technical documentation sufficient to demonstrate their own downstream compliance obligations are met. Compliance teams should insert vendor clauses requiring updated documentation within a defined timeframe whenever the underlying model changes.
Does the systemic risk designation under the EU AI Act trigger additional requirements beyond standard GPAI obligations?
Yes. GPAI providers classified as posing systemic risk must conduct adversarial testing, implement cybersecurity safeguards, and report serious incidents to the AI Office within timeframes specified in the Act. These obligations are layered on top of baseline documentation and transparency requirements.
Is there a grace period for Article 50 transparency disclosures after the 2 August 2026 enforcement date?
No grace period applies as of 2 August 2026. AI systems interacting with natural persons must disclose their automated nature at the point of interaction from that date forward, and enforcement authorities can act on violations without any transitional accommodation.