The EU AI Act is moving from legislation to enforcement. Since entering into force on 1 August 2024, the regulation has already triggered two compliance deadlines, activated a new enforcement body, and produced draft codes of practice that will define what “compliance” actually looks like in practice. If you are tracking EU AI Act news today, the picture is clear: the regulatory machinery is operational, and the pace is accelerating.
This article covers the latest developments — what has changed, what the AI Office is doing, and what your organisation needs to act on now.
À retenir
- Two compliance deadlines have already passed: banned practices (February 2025) and AI literacy (August 2025)
- The EU AI Office is publishing codes of practice for general-purpose AI models — these will define compliance standards
- National authorities across the EU are standing up enforcement bodies with investigation and fining powers
- The next major deadline is 2 August 2026: full obligations for high-risk AI systems
Where the EU AI Act stands right now
The implementation timeline is not theoretical — it is already well underway. Two critical dates have passed, and the next is approaching fast.
2 February 2025 marked the prohibition of unacceptable-risk AI practices. Social scoring, subliminal manipulation, emotion recognition in workplaces, and predictive policing based solely on profiling are now illegal across the EU. Any organisation still operating these systems is in breach.
2 August 2025 brought Article 4 into force — the AI literacy obligation. Every organisation that deploys or provides AI systems must ensure its staff have a sufficient level of AI literacy. This is not aspirational guidance; it is a legally binding requirement with fines of up to 15 million euros or 3% of global annual turnover.
2 August 2026 is the next major milestone. This is when the full obligations for high-risk AI systems take effect — risk management, data governance, technical documentation, human oversight, and conformity assessments.
5 months
until high-risk AI system obligations become enforceable on 2 August 2026
Source : EU AI Act implementation timeline
The EU AI Office: what it is doing
The European AI Office, established in February 2024 within the European Commission, is the central enforcement and coordination body for the AI Act. Its role has expanded rapidly, and its output in early 2026 signals where enforcement priorities lie.
Codes of practice for general-purpose AI (GPAI). The AI Office has been developing codes of practice for providers of general-purpose AI models — think foundation models like GPT, Claude, Gemini, and Mistral. These codes cover transparency obligations, copyright compliance, safety evaluations, and systemic risk management. The first drafts were published for consultation in late 2025, with final versions expected by mid-2026. For organisations building on or deploying GPAI models, these codes will become the practical benchmark for compliance.
Guidance documents. The AI Office has issued guidance on the definition of AI systems under the Act, on the scope of the prohibited practices, and on how Article 4’s AI literacy requirement should be interpreted. These documents do not carry the force of law, but they signal how enforcement bodies will interpret ambiguous provisions.
International coordination. The AI Office is actively engaging with the UK, US, Canada, Japan, and other jurisdictions to align regulatory approaches. For multinational organisations, this coordination matters — it shapes whether compliance efforts in one jurisdiction transfer to another.
The AI Office’s codes of practice for GPAI models are not optional in practice. While formally voluntary, organisations that follow them benefit from a presumption of conformity. Those that don’t must demonstrate equivalent compliance through other means — a significantly harder burden. For more on AI governance frameworks, see our dedicated guide.
National enforcement: where it stands
The EU AI Act requires each member state to designate one or more national competent authorities and a national supervisory authority by 2 August 2025. As of March 2026, the picture is uneven but progressing.
France has designated the CNIL (its data protection authority) as the lead authority, alongside sector-specific regulators. The CNIL has already begun issuing compliance questionnaires to organisations deploying high-risk AI systems, signalling an audit-first enforcement approach.
Germany has split responsibility across the Federal Commissioner for Data Protection and sector regulators, with the Federal Network Agency (BNetzA) playing a coordination role.
The Netherlands has established a dedicated AI authority within its existing digital infrastructure ministry, with an explicit mandate to enforce AI literacy requirements.
Spain created its AI supervisory agency (AESIA) early — one of the first in Europe — and is actively developing sector-specific guidance, particularly for AI in financial services.
Italy has designated the Agency for Digital Italy (AgID) and the data protection authority (Garante) as co-regulators, with sectoral responsibilities.
The practical implication: enforcement is not waiting for 2027. National authorities are already building their capabilities, and some have begun compliance checks. Organisations operating across multiple EU member states face the additional complexity of navigating divergent enforcement approaches.
27
EU member states required to have enforcement bodies operational — with fines up to €35M or 7% of global turnover
Source : EU AI Act, Articles 70-74
What the latest developments mean for UK organisations
The EU AI Act’s extraterritorial scope means UK organisations are not exempt. If your AI system’s output affects people in the EU — whether through automated hiring decisions, credit scoring, content recommendations, or customer service — the Act applies to you.
The UK government’s own approach to AI regulation remains principles-based and sector-led. The ICO, FCA, CMA, and other regulators are developing AI-specific guidance within their existing mandates. But the UK has not enacted equivalent horizontal AI legislation.
This creates a compliance asymmetry. UK organisations serving EU markets must comply with the AI Act. UK organisations operating purely domestically face lighter obligations — but this is changing. The UK’s AI Safety Institute is expanding its remit, and industry pressure for clearer domestic rules is growing.
Do not assume that the UK’s lighter regulatory approach means you can ignore the EU AI Act. Any UK business whose AI systems affect EU residents — through hiring, lending, content moderation, or customer interactions — falls within the Act’s scope. Non-compliance carries the same penalties regardless of where your headquarters are located.
Codes of practice: the compliance detail that matters
The codes of practice being developed under the AI Act deserve special attention because they translate abstract legal requirements into concrete compliance steps.
For general-purpose AI providers, the codes cover:
- Transparency: what technical documentation must be published, how to describe training data, and what information downstream deployers need
- Copyright compliance: how to demonstrate respect for copyright in training data, including the EU’s text and data mining opt-out regime
- Safety testing: what evaluation and red-teaming protocols are expected for systemic-risk models
- Incident reporting: timelines and formats for reporting serious incidents to the AI Office
For deployers of high-risk systems, the Act’s Annex III requirements are being supplemented by harmonised standards developed by CEN and CENELEC. These standards will define what conformity assessments look like in practice.
Organisations that engage with the codes of practice early — and align their internal AI governance processes accordingly — will be better positioned when enforcement begins in earnest.
What your organisation should do today
The EU AI Act news today points in one direction: enforcement is real, timelines are binding, and preparation cannot be deferred.
1. Confirm Article 4 compliance. The AI literacy obligation is already in force. If you have not trained your staff, you are non-compliant today. Brain delivers AI literacy training designed for EU AI Act compliance — practical, role-specific modules with documented completion records.
2. Map your AI systems. Conduct a thorough AI audit to identify every AI system in use, including shadow AI. Classify each system by risk level.
3. Prepare for August 2026. If you deploy high-risk AI systems, the compliance requirements taking effect in five months are extensive. Start your conformity assessment preparation now.
4. Monitor the codes of practice. If you use or build on general-purpose AI models, the GPAI codes of practice will define your compliance obligations. Track the AI Office’s publications and consultation rounds.
5. Build an AI risk management framework. Document your risk assessments, governance decisions, and compliance measures. In any enforcement scenario, documentation quality determines outcomes.
Test your EU AI Act knowledge
Stay ahead of EU AI Act enforcement with Brain
The EU AI Act is not slowing down — and neither should your compliance efforts. Brain is the AI training platform built for regulatory readiness. Role-specific training modules covering AI literacy, responsible AI use, and GDPR and AI compliance — with a compliance dashboard that generates the audit-ready reports regulators expect.
Whether you need to close the Article 4 gap or prepare your teams for the high-risk obligations ahead, Brain gets your organisation ready. See our plans to get started.
Related articles
AI Regulation News 2026: Global Updates You Need Now
Stay current on the EU AI Act, US state-level AI laws, and UK regulatory changes. Concise global roundup for business leaders in 2026.
EU AI Act News: April 2026 Updates + Enforcement Timeline
Latest EU AI Act updates — enforcement dates, GPAI Code of Practice, fines and what your business must do before August 2026.
EU AI Act Summary: Risk Tiers, Deadlines + Penalties (2026)
EU AI Act in plain English — 4 risk categories, obligations by tier, compliance deadlines, penalties up to €35M, and Article 4 literacy rules.