← All posts

EU AI Act Enforcement Gap: The Law Is Live, Now What?

EU AI Act Enforcement Gap: The Law Is Live, Now What?
TL;DR

The EU AI Act is now fully in force as of August 2, 2026, but enforcement capacity across 27 member states remains thin and uneven. This creates a perverse incentive where early compliers are at a competitive disadvantage. However, enterprise procurement teams are filling the enforcement gap faster than regulators, demanding governance documentation before deals reach the shortlist. Smart vendors are treating governance as a commercial signal, not a regulatory burden.

The Week After

August 2, 2026 came and went. The EU AI Act is now fully in force. Every AI system placed on the EU market or affecting people in the Union is subject to its requirements. The obligations are legally binding. The fines are real: up to €35 million or 7% of global annual turnover for prohibited practices, up to €15 million or 3% for most other violations (Article 99).

And yet, nothing happened.

No dawn raids. No headline fines. No enforcement actions announced by the European AI Office. The Act is law, but the machinery to enforce it is still warming up. That gap between legal obligation and practical consequence is the real AI governance story of August 2026.

The Enforcement Architecture Nobody Talks About

When people say "the EU AI Act," they picture a single Brussels regulator with sweeping powers. The reality is more fragmented. The Act requires each of the 27 EU member states to designate at least one notifying authority and at least one market surveillance authority (Article 70). The EU AI Office coordinates, but it does not replace national bodies.

This is enforcement by committee. Twenty-seven countries, each with their own budget cycle, their own hiring pipeline, their own interpretation of what "market surveillance" means in the context of software that updates weekly. The AI Office in Brussels has roughly 140 staff. Even if every member state matched that headcount tomorrow, you are looking at a few thousand people regulating an industry worth hundreds of billions.

The math does not add up. And it was never designed to. The EU AI Act is a framework regulation: it sets the rules, then relies on member states to operationalise them. The problem is that operationalisation takes time. Some member states had their authorities designated and staffed by the August 2 deadline. Others are still working through their legislative processes. The result is a patchwork where a vendor violating the same provision might face investigation in Berlin but complete indifference in Bratislava.

The Perverse Incentive

This enforcement gap creates an uncomfortable dynamic. The vendors who invested early in compliance, who built their AI governance frameworks against NIST AI RMF and ISO 42001, who hired compliance officers and commissioned external audits, are now competing against vendors who did none of those things. And for the next 12 to 18 months, while enforcement capacity ramps up, there may be no regulatory consequence for the laggards.

That is a perverse incentive. It punishes good actors and rewards those who wait. If you are an AI vendor with limited runway and an enterprise sales cycle that already takes six months, the rational short-term move is to defer compliance spending and see whether enforcement actually materialises. Every euro spent on governance is a euro not spent on product, on sales, on survival.

This is not theoretical. We saw the same pattern with GDPR. The regulation took effect in May 2018, but the first major fine, the €50 million against Google by CNIL, did not land until January 2019. The first cross-border enforcement action under the one-stop-shop mechanism took until 2021. Early GDPR compliers spent millions while competitors watched and waited. Some of those early spenders are no longer in business. The ones who waited are still here.

The Real Enforcers Are Not Regulators

But here is where the AI Act story diverges from the GDPR parallel. GDPR was, for most companies, a cost centre. AI governance is different. Enterprise buyers of AI are asking questions that did not exist in 2018. They are asking for DPAs that cover AI-specific use cases. They are asking for system registries and model cards. They are asking vendors to demonstrate compliance with ISO 42001 or NIST AI RMF before the RFP even reaches the shortlist.

The real enforcement of the EU AI Act is not coming from Brussels. It is coming from procurement departments. Enterprise buyers have learned, sometimes expensively, that an AI vendor without governance documentation is a liability waiting to surface. Security reviews that used to take two weeks now take two months. Deals stall. Champions inside the buyer organisation go quiet. And the vendor never hears why.

This is the commercial enforcement mechanism. It is slower than a regulator's fine but, in many ways, more punishing. A €15 million fine is a line item. Losing three enterprise deals in a row because your governance platform cannot produce evidence is an existential threat.

What Smart Vendors Are Doing Right Now

The vendors who understand this dynamic are not waiting for the EU AI Office to knock. They are treating governance as a commercial signal. They are putting their ISO 42001 certification on their pricing page. They are publishing their AI system registry. They are submitting to independent verification, not because Article 70 requires it but because enterprise RFPs reward it.

The gap between "the law exists" and "the law has teeth" is a window. It will close, probably within 18 to 24 months as member states build enforcement capacity and the first major cases work through the system. Vendors who treat the window as a free pass are betting that enterprise buyers will not notice the gap. That is a bad bet. Buyers notice everything. They just do not always tell you what they noticed.

The EU AI Act is live. The enforcement gap is real. But the market is already enforcing what the regulators have not yet had time to reach.

If you are an AI vendor building for the enterprise, the question is not whether regulators will eventually catch up. The question is whether your next RFP response includes evidence of governance or a promise to get around to it. Buyers can tell the difference. If you want to see what enterprise procurement teams actually check, our sample AI audit report shows the framework they use. Or reach out if you want to understand where your governance documentation stands against what buyers expect in 2026.

Written by David Swan, reviewed and fact-checked against primary regulatory sources. AI-assisted but human-directed.

Frequently asked questions

When did the EU AI Act take full effect?

The EU AI Act took full effect on August 2, 2026. The prohibitions on unacceptable-risk AI practices had already applied since February 2, 2025, but the full set of obligations for high-risk AI systems, transparency requirements, and general-purpose AI model rules became enforceable on August 2, 2026 under Article 113.

Who enforces the EU AI Act?

Enforcement is split between the EU AI Office in Brussels and national competent authorities in each of the 27 member states. Each member state must designate at least one notifying authority and one market surveillance authority under Article 70. The AI Office coordinates but does not replace national bodies.

What are the fines for violating the EU AI Act?

Under Article 99, fines range up to €35 million or 7% of global annual turnover for prohibited practices, up to €15 million or 3% for most other operator obligations, and up to €7.5 million or 1% for supplying incorrect information. For SMEs and startups, the lower of the percentage or amount applies.

Is there an enforcement gap with the EU AI Act?

Yes. While the legal obligations are now in force, enforcement capacity varies significantly across member states. Some have fully staffed authorities while others are still building theirs. The EU AI Office has roughly 140 staff coordinating across 27 countries. First major enforcement actions may take 12 to 18 months to materialise, similar to the pattern seen with GDPR.

Should AI vendors wait to see if enforcement actually happens?

No. While regulatory enforcement may take time, enterprise procurement teams are already demanding governance documentation. Vendors without demonstrable compliance with ISO 42001, NIST AI RMF, or EU AI Act requirements are losing deals before they reach the shortlist. The commercial enforcement of the Act by buyers is happening faster than regulatory enforcement.

How does the EU AI Act enforcement compare to GDPR?

The pattern is similar: a regulation takes effect, enforcement capacity ramps up slowly, and early compliers spend while competitors wait. GDPR took effect in May 2018 but the first major fine did not land until January 2019. The key difference is that AI governance has commercial value, enterprise buyers demand it, while GDPR compliance was primarily a cost centre.