survol

← All articles · Compliance

Compliance

The AI Act has entered its enforcement phase: what actually applies

On 2 August 2026 the AI Act did not “come into force” — that happened back in 2024. It entered its supervision and enforcement phase. What actually applies to a product team is narrower, and more immediate, than the word “compliance” suggests.

A
Adrien Torris 13 August 20267 min read
The AI Act has entered its enforcement phase: what actually applies

Three dates, and they get mixed up every time. The European AI regulation came into force on 1 August 2024. It became applicable in most of its provisions on 2 August 2026, which means one precise thing: since that date, the Commission's AI Office and the national authorities can supervise and impose penalties. And a substantial part of the text — the part everyone talks about — will only apply in 2027 and 2028.

The division of labour is simple: the AI Office supervises providers of general-purpose models, national authorities watch most systems placed on or used in their market.

What has been binding since 2 August: article 50

Most of what applies today fits in one article, the one on transparency. Plainly:

  1. Users must be told when they are interacting with a chatbot, an agent or an AI avatar rather than a human.
  2. Synthetic content — text, image, audio, video — and deepfakes must carry a machine-readable marking that allows detection.
  3. Companies that distribute deepfakes must flag them.
  4. The same duty covers AI-generated or AI-manipulated text meant to inform the public on matters of general interest — except where it has been through human review and falls under editorial responsibility.
  5. The use of emotion recognition or biometric categorisation must be disclosed to the people concerned.

Visibly, that means banners along the lines of "You are interacting with an AI system", or their audio equivalent, and possibly the black "AI" badges Brussels is proposing for the corner of an image. For systems that generate images or text summaries, the labelling is lighter: a mention in the metadata, invisible on the document but readable in the file's properties.

The editorial exemption is the thing to remember. Text that is generated, then reviewed, under an identifiable editorial responsibility, escapes the flagging duty. That is what separates a publisher from a content generator — and it is an organisational choice, not a tooling one.

What it costs not to

Breaches can be penalised up to €15 million or 3% of worldwide annual turnover. Proportionality rules are provided for SMEs and mid-caps.

Alongside it, the European code of practice on the transparency of AI-generated content, published on 10 June, remains voluntary. It has collected some 190 signatures — including Aleph Alpha, Anthropic, Cohere, Google, Meta, Microsoft, Mistral AI and OpenAI, but also deployers such as Getty Images, Lenovo and Lufthansa, and nearly half of them SMEs. Not signing is not a breach: it is the duty to demonstrate that your own arrangements reach an equivalent level of compliance.

What does not apply yet — and it is the big part

The "AI Omnibus", in force since 27 July, pushed back the high-risk timetable.

To 2 December 2027 for Annex III, which covers uses liable to influence an important decision about a person: tools that shortlist candidates for a job or a course, assess pupils or employees, determine access to social benefits, compute a credit score or a health insurance premium, triage emergency calls. Add to it certain biometric applications, the management of critical infrastructure, police assessment of evidence or reoffending risk, the examination of asylum or visa applications, assistance to a judge, and systems meant to influence voting behaviour.

To 2 August 2028 for Annex I, which covers AI that is itself a regulated product or performs a function essential to its safety: driving an industrial robot, a vehicle's braking, a drone's navigation, a lift's safety mechanism, certain medical software. The presence of AI is not enough: the system must play a safety role and be subject to third-party conformity assessment.

The Commission justifies the delays by the time needed to publish harmonised standards. The objection, raised by L'Usine Digitale, deserves a hearing: in two years those systems will have taken far more room, and the text meant to frame them risks arriving already dated.

What a product team should do now

None of the above requires a compliance programme. Four moves are enough, and they are mostly organisational:

That last line is traceability, not compliance. In Survol it is a by-product of normal operation: every version of a feature knows which session it came from, which agent produced it, from which approved specification and approved by whom. When the question arrives — from a regulator, a customer, or a colleague six months later — the answer is already written.

Sources

#compliance #ai-act #governance #europe
A

Adrien Torris

Founder of Survol

A developer turned agent orchestrator. I write about product steering in the age of agentic development, and about building Survol in the open.

Don't miss the next article

One email a month, our best thinking on agentic development and what’s new in Survol.