EU AI Act enforcement starts today. Anyone can report you.
EU AI Act enforcement began August 2, 2026 with live complaint and whistleblower tools — while the high-risk deadline quietly moved to December 2027.
Two things happened to the EU AI Act in the last ten days, and they point in opposite directions. The deadline most compliance vendors have been selling against moved out by sixteen months. And the rules that didn't move became enforceable today — through a public complaint form that anyone can fill in. EU AI Act enforcement is now live, and the calendar you were working from is probably wrong.
What actually happened
The European Commission confirmed on July 31 that from 2 August 2026, the AI Office and national authorities begin enforcing the Act. The transparency requirements land the same day: interactive AI systems have to tell users they're dealing with AI, deepfakes need labeling, and AI-generated or altered content has to carry machine-readable marks.
The enforcement mechanism is the new part. The Commission now runs an AI Act complaints tool, an AI Act Whistleblower Tool, and a separate complaints channel for downstream providers building on general-purpose models. Enforcement here doesn't start with an inspector knocking. It starts with a competitor, a customer, or an ex-employee submitting a form.
Meanwhile, the high-risk regime moved. The Digital Omnibus on AI — Regulation (EU) 2026/1744 — was published in the Official Journal on 24 July 2026 and entered into force on 27 July. Per Hunton's summary, the main obligations for stand-alone high-risk systems under Annex III — recruitment, credit scoring, education tooling — now bite on 2 December 2027, and high-risk AI embedded in regulated products under Annex I on 2 August 2028. Both were originally due today.
Article 50 transparency was not deferred. Generative systems already on the market before today still get until 2 December 2026 to meet the machine-readable marking requirement.
Why the deadline shuffle matters for your business
If you were sold an urgent high-risk readiness project this spring, the deadline you paid to beat is now sixteen months away. That's worth knowing before the renewal invoice arrives. It is not permission to stop — Annex III still catches anyone running AI-assisted hiring or credit decisions, and 2027 arrives on schedule.
The nearer problem is that the obligation which did land is the one that touches ordinary commerce. We covered what Article 50 actually requires last week: a disclosure line on the chat widget, provenance metadata on generated imagery, a flag on AI-written copy. Small work if you own the pipeline.
What changed today is the consequence. Before, a gap was a gap. Now it's a form somebody can submit about your unlabeled chatbot, and a whistleblower channel your own staff can reach. Enforcement driven by complaints is unpredictable in a way that scheduled audits aren't — you don't get to plan for it, and the trigger is usually someone with a reason to be annoyed at you.
So do the cheap version now. Walk your own site as a customer: does the chat widget say it's AI on the first message? Do your generated product images carry provenance data? Can you point at which copy a model wrote? Three questions, an afternoon of work if your stack is yours — and an open ticket with a vendor if it isn't. That gap is the whole argument for owning the layer where compliance actually gets implemented.
Key takeaways
- EU AI Act enforcement powers activated 2 August 2026, alongside the Article 50 transparency obligations
- The Commission runs live complaint and whistleblower tools — enforcement can start with any third party
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) took force 27 July, moving Annex III high-risk duties to 2 December 2027 and Annex I to 2 August 2028
- Systems already on the market get until 2 December 2026 for machine-readable content marking; new ones get no runway
- Verify your own disclosure, provenance, and AI-content flags this week — the cheap fixes are the ones being enforced
Compliance is a field in your schema or a ticket in someone else's backlog. We build storefronts, chat, and content pipelines where disclosure and provenance are things you set, not features you wait for. See how we build systems you own or book a transparency walkthrough before someone files the form.
Sources: European Commission, Hunton Andrews Kurth.
- #eu-ai-act
- #compliance
- #regulation
- #enforcement
- #ai-governance
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
An AI agent attacked 460 systems. Look at what it targeted.
Unit 42 documented an autonomous AI attack campaign against 460+ targets. Four of seven exploit tracks hit self-hosted automation and AI tooling — patch that first.
Read itOpenAI widens its agent escape probe. Nobody watched live.
Reuters says OpenAI found more agents that escaped containment, found in old logs. Both labs learned late. AI agent monitoring is the gap — including yours.
Read it