From 2 August 2026, the European Commission’s AI Office and the authorities of EU member states became responsible for implementing, supervising and enforcing the EU AI Act, according to the European Union’s own digital strategy pages. The AI Office holds enforcement powers over general-purpose AI (GPAI) models: it can request technical documentation, evaluate models, and require action.
The Act is a risk-tiered law. It sorts AI systems into categories, from prohibited uses to high-risk, limited-risk and minimal-risk, with obligations scaling accordingly. The prohibitions have been in force since 2 February 2025, and organisations still operating banned systems face the highest penalty tier, reported as up to €35 million or 7% of global turnover.
Why this is not just a European story
Rules written in Brussels travel. Any company that wants to sell AI-powered products into the EU, or that builds on a general-purpose model offered by a provider serving the EU, inherits compliance questions whether it is based in Berlin, Nairobi or Mbabane. This “Brussels effect” is why the AI Act is widely treated as the global high-water mark for AI regulation, even by firms outside Europe.
Governance frameworks in the United States, including executive orders and a growing patchwork of state laws, add a second layer of complexity. Providers serving multiple markets increasingly have to design for the strictest rule they touch.
What changes in practice
For GPAI providers, the enforcement window means transparency paperwork is no longer theoretical. Technical documentation, model evaluation and reporting obligations now have an authority behind them. For businesses deploying AI in products, the practical work is mapping which of their systems fall into higher-risk categories and what evidence they can show.
The opportunity for smaller markets
Compliance is often framed as a cost. It is also a market. African developers and consultancies that understand the Act early can serve European clients who need local help, and can build products that are “EU-ready” from the start rather than retrofitted. The companies that treat regulation as a design constraint from day one tend to move faster than those that wait for the first letter from a regulator.
Sources
- European Commission, AI Act — Shaping Europe’s digital future — https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- EU Artificial Intelligence Act, Implementation Timeline — https://artificialintelligenceact.eu/implementation-timeline/
- Collibra, “AI regulatory compliance in 2026: EU AI Act, US orders and state laws” — https://www.collibra.com/blog/ai-regulatory-compliance-in-2026-eu-ai-act-us-orders-and-state-laws-and-how-to-operationalize-them
Leave a Reply