Logo
FrontierNews.ai

The EU AI Act Enforcement Begins in Days. Here's What Companies Need to Know About Those Massive Fines.

The EU's artificial intelligence regulation will begin enforcement on August 2, 2026, with the power to impose fines up to 35 million euros or 7 percent of a company's global annual turnover for violations. This marks a critical moment for how Europe will enforce its landmark AI Act, but there's a catch: regulators are still working out exactly how they'll calculate those penalties, and the process is far from transparent.

The EU AI Act, adopted in 2024, represents one of the world's most comprehensive attempts to regulate artificial intelligence. Unlike earlier regulatory frameworks that focused on specific sectors or technologies, the AI Act takes a broad approach, classifying AI systems by risk level and imposing different requirements based on that classification. Now, with enforcement just weeks away, the bloc faces a practical challenge: how do you fairly penalize companies that break these rules when the fines can reach billions of euros ?

How Does the EU Actually Calculate AI Fines?

The AI Act lists several factors that regulators must consider when determining fine amounts. These include the gravity and duration of the infringement, as well as the extent to which offenders have collaborated with authorities. However, the law doesn't provide a rigid formula, leaving significant discretion to enforcement bodies.

This flexibility mirrors how the EU has handled fines under other tech regulations. For comparison, the bloc's Digital Markets Act (DMA), which targets anti-competitive behavior by large tech platforms, uses a percentage of annual revenue as a starting point. When Google was fined 890 million euros in July 2026 for DMA violations, the penalty amounted to just 0.22 percent of parent company Alphabet's annual revenue, far below the 10 percent maximum the law allows.

The challenge is that this discretion creates room for inconsistency and, critics argue, political influence. A Commission official, speaking anonymously, said that calculating fines under the Digital Services Act (DSA), another major EU tech law, includes consideration of factors like "gravity, nature, duration and mitigating circumstances." But without a transparent methodology, companies and observers struggle to predict what penalties they might face.

"The EU always follows due process," said Thomas Regnier, a European Commission spokesperson, noting that "numerous objective criteria" help "ensure that fines remain proportional under all circumstances."

Thomas Regnier, European Commission Spokesperson

In practice, however, the numbers tell a different story. When the Commission started issuing multi-million euro fines under the DMA in 2025, it pointed to the short duration of the conduct as one reason why penalties came far below the legal maximum. Yet critics question whether such reasoning is applied consistently or whether political considerations play a role.

Why Should Companies Care About AI Act Enforcement?

For AI developers, cloud providers, and any company deploying AI systems in Europe, the August 2 enforcement date marks a shift from regulatory guidance to active enforcement. Unlike earlier phases of the AI Act, which focused on compliance preparation, enforcement means regulators can now investigate violations and impose penalties.

The stakes are particularly high because the AI Act applies to a broad range of AI systems. High-risk applications, such as those used in hiring, criminal justice, or critical infrastructure, face the strictest requirements. Medium-risk systems, including general-purpose AI models, must meet transparency and documentation standards. Even low-risk systems are subject to basic requirements.

In most cases, national authorities rather than the European Commission will impose fines, though the Commission will oversee the penalty regime. This decentralized approach creates another layer of complexity: companies may face different enforcement priorities and fine calculations depending on which EU member state investigates them.

Steps Companies Should Take Before August 2 Enforcement

  • Audit AI Systems: Companies should conduct a comprehensive review of all AI systems they operate or deploy in Europe to determine their risk classification under the AI Act and identify any compliance gaps before enforcement begins.
  • Document Compliance Efforts: Maintaining detailed records of compliance measures, including risk assessments, testing results, and governance decisions, can demonstrate good faith efforts and potentially reduce penalties if violations are discovered.
  • Establish Collaboration Channels: Building relationships with relevant national regulators and demonstrating willingness to cooperate with investigations may qualify companies for cooperation discounts when fines are calculated.
  • Review Transparency Requirements: Ensure that AI systems meet documentation and transparency standards, particularly for high-risk applications, since these are among the first areas regulators are likely to scrutinize.

The broader context matters here too. The EU is simultaneously rolling out other tech regulations and industrial policies designed to strengthen European technological sovereignty. In June 2026, the European Commission adopted a comprehensive Tech Sovereignty Package that includes the Chips Act 2.0, the Cloud and AI Development Act (CADA), an EU Open Source Strategy, and a Strategic Roadmap for Digitalisation and AI in Energy. These initiatives are explicitly designed to work together, creating an interconnected governance architecture for control over the digital value chain.

This systemic approach means that AI Act enforcement doesn't exist in isolation. Companies operating in Europe must navigate not just the AI Act but also how it interacts with cloud infrastructure rules, semiconductor policies, and open-source requirements. The Commission frames this as building Europe's capacity to become an "AI continent" while reducing dependence on non-EU digital suppliers.

What Makes AI Act Fines Different From Other EU Tech Penalties?

The AI Act's fine structure differs from earlier EU tech regulations in important ways. Under the General Data Protection Regulation (GDPR), which governs data privacy, fines go to national governments rather than the EU budget. Under the DMA and Digital Services Act (DSA), fines flow into the EU's central budget, reducing what member states must contribute.

This distinction matters politically. The U.S. Trump administration has criticized EU fines as a hidden tax on American companies. U.S. Under Secretary of State for Economic Affairs Jacob Helberg argued that Brussels "wields regulation as a broadsword against American ingenuity" and that Google has become an "involuntary" major contributor to the EU's budget through penalties.

For the AI Act specifically, the law allows fines up to 35 million euros or 7 percent of global annual turnover, whichever is higher. This is a steeper maximum than the DMA's 10 percent threshold, reflecting the Commission's view that AI risks warrant stronger enforcement tools. However, whether regulators will actually impose penalties near that ceiling remains to be seen.

The question of proportionality is already contentious. Some critics argue that even large fines are negligible for major tech companies. Alexandra Geese, a Green member of the European Parliament from Germany, said the 890 million euro fine against Google is "akin to an accounting error for a company of its size," adding that "the EU is still incentivizing tech companies to build monopolies and kill competition".

Yet enforcement orders to change products, services, or legal practices often carry more weight than fines themselves. For AI systems, this could mean being forced to redesign algorithms, add transparency features, or withdraw products from the European market entirely. Those operational changes can be far more costly than any financial penalty.

As August 2 approaches, the real test will be how regulators balance the EU's ambition to lead in AI governance with the practical challenges of enforcing rules fairly and consistently across 27 member states. The fines that follow will reveal whether the AI Act's enforcement becomes a credible tool for protecting European interests or, as critics fear, a performative exercise that leaves the biggest players largely unscathed.