← Back to writing

EU AI Act Enforcement Starts in 2026. Most Companies Aren't Ready.

The EU AI Act reaches general application on August 2, 2026. Colorado’s AI Act takes effect June 30, 2026. These aren’t proposals — they’re enforceable law.

And enforcement has already begun. Italy fined OpenAI €15M for GDPR violations in training data processing. The FTC launched “Operation AI Comply” targeting deceptive AI marketing. Cyber insurers now require “AI Security Riders” — documented red-teaming and model-level risk assessments as prerequisites for coverage.

The era of “we’ll figure out governance later” is over.

What’s Being Enforced

The EU AI Act classifies AI systems by risk level and imposes requirements accordingly:

  • High-risk AI systems must comply with transparency, documentation, and oversight requirements
  • General-purpose AI models face reporting obligations
  • Foundation models have stringent transparency requirements
  • All AI systems need decision traceability and audit trails

This isn’t aspirational ethics. Companies deploying high-risk AI without documented governance face fines of up to €35 million or 7% of global annual turnover.

The Enforcement Precedents

Regulators aren’t waiting for August:

  • Italy: €15M fine to OpenAI for GDPR violations in training data
  • FTC: “Operation AI Comply” — enforcement actions against deceptive AI marketing
  • Insurance: Carriers introducing “AI Security Riders” requiring documented evidence of adversarial red-teaming and model risk assessments
  • Colorado: State-level AI Act taking effect June 30, 2026

These establish that regulators expect documented controls, technical safeguards, and evidence of compliance — not aspirational ethics statements.

The Technical Checklist

Most companies have an AI policy document. What they don’t have — and what regulators actually audit — are systems:

1. Model Inventory

Catalog every AI system with its purpose, risk classification, data inputs, model versions, and deployment history. You can’t govern what you can’t see.

2. Risk Classification Pipeline

Automated classification against the Act’s risk tiers: unacceptable, high, limited, minimal. Each classification triggers specific compliance requirements.

3. Bias Detection in Production

Continuous monitoring, not one-time pre-deployment testing. Models drift. Data distributions shift. Fairness metrics must be tracked in real time.

4. Data Lineage

From training set to model to prediction. End-to-end traceability. When a regulator asks “how did your AI make this decision?”, you need the complete chain.

5. Model Monitoring

Drift detection, performance degradation alerts, anomaly detection. Models that worked at deployment can silently degrade. Monitoring catches this before users or regulators do.

6. Incident Response

Documented procedures for AI failures, including notification requirements. When (not if) something goes wrong, you need a playbook — not a scramble.

7. Re-validation Schedules

Periodic reassessment of model performance and compliance. Annual review at minimum; quarterly for high-risk systems.

8. Audit Logging

Every AI decision with its inputs, outputs, and confidence scores. This is the foundation of regulatory compliance and the hardest thing to retrofit.

ISO/IEC 42001: The New SOC 2 for AI

ISO/IEC 42001 is emerging as the de facto standard for AI management systems. It covers:

  • AI management system requirements
  • Risk assessment methodology
  • Controls and control objectives
  • Monitoring and measurement
  • Continual improvement

Think of it as SOC 2 but for AI. Companies pursuing certification now will have a compliance moat — especially for enterprise sales where customers increasingly require governance documentation.

Governance as Growth Strategy

The World Economic Forum framed it well: in 2026, AI governance is becoming a growth strategy, not a cost center.

Companies that build governance early gain:

  • Competitive moat in trust-sensitive markets
  • Faster AI scaling — governance removes friction, not adds it
  • Enterprise customer acquisition accelerated by compliance readiness
  • Reduced insurance costs with documented AI controls

The companies building governance infrastructure now won’t just avoid fines. They’ll outcompete organizations that treated compliance as an afterthought.

The Timeline

  • Now: Build model inventory, start risk assessments
  • April 2026: Implement monitoring pipelines and audit logging
  • June 30, 2026: Colorado AI Act enforcement begins
  • August 2, 2026: EU AI Act general application

Five months isn’t a lot of time to build model registries, monitoring pipelines, and audit systems from scratch. But it’s enough time to start — especially with frameworks like ISO 42001 providing structure.

Policies don’t pass audits. Systems do.