The EU AI Act’s Enforcement Phase Starts August 2. What Can Your Company Prove?

The EU AI Act reaches a different stage on August 2, 2026. The European Commission's AI Office and national authorities begin enforcing the parts of the Act now in application, including new Article 50 transparency duties.

That does not mean every AI Act obligation suddenly applies. The high-risk system timetable has been extended. It also does not mean the AI Office will handle every case. National market-surveillance authorities will carry much of the enforcement load, while the AI Office has direct powers in areas such as general-purpose AI models.

The practical change is simpler. Companies are moving from planning around future duties to answering questions about current controls. A policy deck will not be enough. The useful question now is whether the company can retrieve evidence showing what systems it operates, which legal roles it assigned, what controls it implemented, and whether those controls work.

August 2 Is An Enforcement Date, Not One Universal Deadline

The AI Act has always used a staggered timetable. That matters even more now because the Digital Omnibus changed the schedule for high-risk systems while other duties continued on their existing path.

Article 50 transparency obligations apply from August 2. They cover direct interactions with certain AI systems, machine-readable marking of AI-generated or manipulated content, labels for deepfakes, and disclosures for some AI-generated or manipulated text published to inform the public on matters of public interest.

There is a narrow transition for the Article 50(2) marking and detection duty. Providers of systems placed on the market before August 2, 2026 have until December 2, 2026 to comply with that part of Article 50. The Commission's FAQ says the grace period does not extend to the rest of Article 50.

Enforcement of the AI-literacy obligation also becomes real. Article 4 has applied since February 2025, but the Commission explains that national market-surveillance authorities begin supervising and enforcing it in August 2026.

The rules for general-purpose AI models are already in application, subject to transition periods for some existing models. The AI Office can request documentation, conduct model evaluations, require corrective measures, and impose fines within its area of responsibility.

Meanwhile, the amended timetable delays the main high-risk requirements. The Commission currently identifies December 2, 2027 for systems in areas such as employment, education, biometrics, critical infrastructure, and migration, and August 2, 2028 for high-risk systems embedded in regulated products.

Any internal update that says simply "the AI Act applies August 2" is likely to create confusion. The company needs a provision-by-provision map.

Who May Ask The Questions

Enforcement is divided.

National competent market-surveillance authorities will be the main enforcers for Article 50 and Article 4. The European Data Protection Supervisor has a role for EU institutions. The AI Office's Article 50 role is narrower and can arise when an AI system is built on a general-purpose AI model supplied by the same entity or is integrated into a very large online platform or search engine covered by the Digital Services Act.

For general-purpose AI models, the AI Office has the central enforcement role. That includes authority to seek technical information, evaluate models, investigate possible infringements, and require corrective action.

This split has an operational consequence. A company should not prepare one generic "EU regulator" file. It should know which entity is likely to have jurisdiction over each product, model, or deployment and which records that authority could reasonably request.

The First Test Is Scope

Most companies will not fail because they forgot the name of an AI Act article. They will struggle because their inventory does not match the way the business actually uses AI.

An effective scope record should identify:

  • each AI system and general-purpose AI model the organization provides, deploys, imports, or distributes in the EU;
  • the legal entity responsible for the product or use case;
  • whether the organization is acting as provider, deployer, importer, distributor, or more than one role;
  • when the system or model entered the EU market;
  • which AI Act provisions are currently applicable; and
  • the factual basis for any exclusion, exception, or transitional period.

That last item matters. A spreadsheet that labels a system "out of scope" without explaining why is a conclusion, not an evidence record.

Article 50 Evidence Has To Follow The Output

Clearon's earlier coverage examined the final Article 50 guidelines and the continuing August 2 deadline. The enforcement phase changes the focus from interpreting the guidance to proving that the workflow works.

For an interactive AI system, the record should show where users are informed that they are interacting with AI, when an exception applies, and how the notice was tested across devices and languages.

For generated or manipulated content, providers should be able to describe the marking method, its technical limits, the system versions covered, and the results of testing for effectiveness, interoperability, and durability. Deployers responsible for deepfakes or covered public-interest text should be able to show where labels appear, who approved any exception, and whether the disclosure survives publication and redistribution.

Screenshots help, but they are not enough by themselves. A stronger file connects the legal classification to the product requirement, implementation ticket, test result, release date, and current production behavior.

AI Literacy Needs Its Own Record

Article 4 is easy to reduce to annual training. The text calls for measures that take account of technical knowledge, experience, education, training, and the context in which AI systems will be used.

A company should be ready to show:

  • which personnel and other people operating AI systems on its behalf were covered;
  • how training differed by role and risk;
  • what instructions or restrictions applied to specific systems;
  • when the material was delivered and updated;
  • how completion or competence was recorded; and
  • what the company changed after incidents, audits, or product updates.

A generic webinar may be part of the answer. It is unlikely to be the whole answer for teams making consequential decisions, publishing synthetic content, operating customer-facing systems, or evaluating model risk.

General-Purpose AI Providers Need Retrieval, Not Just Retention

The AI Office's powers make document retrieval a governance issue. Keeping records somewhere is different from being able to produce the right version, explain it, and connect it to the model that was actually offered in the EU.

Providers should know who can assemble technical documentation, copyright-compliance materials, training-content summaries, evaluation results, systemic-risk records where applicable, incident information, and downstream-provider information. They should also preserve the dates and model versions that determine which transition rules apply.

The same discipline helps downstream companies. Contracts with model and system vendors should support access to the information needed to meet the downstream company's own duties. A promise that a vendor "complies with the AI Act" will not answer a regulator's product-specific question.

A Sensible Enforcement File

The most useful near-term project is a compact enforcement file for each material system or model. It should contain:

  • the system and role classification;
  • the applicable-duty and transition-date analysis;
  • the named business, legal, and technical owners;
  • the control description and implementation evidence;
  • testing results, known limitations, and approved exceptions;
  • training and AI-literacy records;
  • vendor documents and relevant contract rights;
  • incident and complaint escalation routes; and
  • a retrieval index showing where the current records live.

This does not require predicting the first enforcement case. It requires being able to answer a basic request without starting an internal investigation from scratch.

The Bottom Line

August 2 does not switch on the entire AI Act at once. It does switch on a more demanding phase for the rules already in application.

Companies should separate active duties from delayed high-risk requirements, map the correct enforcement authority, and test whether their evidence can be retrieved at the level of a specific system, model, version, and workflow.

The strongest compliance posture is not a claim that the company has an AI governance program. It is the ability to show what the program did for the product or use case a regulator is asking about.

Sources and Related Clearon Coverage