AI Regulation
The AI Act stopped being a deadline and became an enforcement regime
From 2 August the Commission's AI Office and national authorities began enforcing. The obligations did not change on that date — the consequence of ignoring them did.
On 2 August the European Commission's AI Office, with national authorities, began enforcing the AI Act, and the remaining provisions became applicable — some immediately, others phased over six to thirty-six months.
For three years this has been a compliance programme with a future deadline. It is now a supervisory relationship with a present one.
What changes in practice
Enforcement brings powers rather than guidance. The AI Office can request technical documentation, evaluate models itself, require corrective measures and fine. National market surveillance authorities and the European Data Protection Supervisor enforce the transparency rules.
The distinction that matters operationally: you are no longer assessing yourself against a text. Someone else can now assess you, on their timing, and ask for artefacts you either have or do not.
A deadline asks whether you are ready. An enforcement regime asks what you can produce today.
The phasing is where organisations will get caught
Obligations landing across six to thirty-six months is the genuinely difficult part, because it means compliance is not a state you reach. A system compliant today may not be in eighteen months without any change to the system, because the applicable obligations will have moved.
That argues for treating this as a recurring control rather than a project. The programmes we would bet on have an owner tracking which obligations apply to which systems on which dates, reviewed on a cycle. The ones that will struggle closed their AI Act workstream in August.
Where to spend the next quarter
Inventory first, because every obligation is scoped to a classification and you cannot classify what you have not enumerated — including the systems procured as features of other software, which is where most unclassified AI hides.
Then documentation, in the form a supervisor would accept: what the system does, what data it uses, how it was evaluated, what its limits are, who owns it. Most organisations have this knowledge distributed across people and cannot produce it as a document on request, which is the only form in which it counts.
Sources
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission
- Safer and more transparent AI — European Commission
- EU Artificial Intelligence Act — developments and analyses — artificialintelligenceact.eu
Written by the Devence Lab research team.