AI Act: Europe can finally start fining from Sunday
Europe's rules for big AI models have been on the books for a year. What was missing was the power to punish. That arrives Sunday.

The EU rules that apply to OpenAI, Google, Anthropic, and Mistral have been in force since August 2, 2025. A year already. What was missing that entire year was the fine.
A year of rules with no penalty
Article 113 of Regulation (EU) 2024/1689 sets the rollout schedule, and it hides a caveat almost nobody flags. The chapters covering obligations for general-purpose AI models have applied since August 2, 2025, "with the exception of Article 101."
Article 101 is what gives the Commission the power to fine providers of those models: up to 15 million euros or 3% of global annual turnover.
The rules existed, the penalty didn't. A speed limit with no radar gun. The radar switches on Sunday, and that's the single most concrete consequence of a deadline everyone's been talking about for weeks.
What else kicks in that day
The other piece of text coming into force is Article 50, the transparency rules. It comes down to four requirements.
Providers of systems designed to interact with people have to disclose that users are talking to a machine, unless doing so is obvious given the context and circumstances of use. Generated content has to carry a machine-readable mark. Deployers who publish a deepfake must disclose that the content was generated or manipulated. And text published to inform the public on matters of public interest has to be flagged, unless it went through human editorial review.
Here's the most common misreading: there is no blanket requirement to slap a "made with AI" label on every piece of generated content. The mark required by the second obligation is machine-readable, not human-readable: a technical signature embedded in the file, invisible to the eye, and it's the tool provider's responsibility, not the user's. A visible disclosure only becomes mandatory in two cases, covered by the fourth obligation: a deepfake, and text published to inform the public on a matter of public interest. Your AI-generated marketing visual doesn't need a visible label.
Here too, the fine isn't symbolic: a breach of Article 50 falls under Article 99, capped at 15 million euros or 3% of global turnover, whichever is higher. For a small business, the lower cap applies.
The four-month grace period is narrower than it looks
The Digital Omnibus, published in the Official Journal on July 24 and in force three days later, grants a delay until December 2, 2026. That much is true, and most coverage stops right there.
The exception is actually tiny. It covers only the machine-readable marking obligation, Article 50 paragraph 2, and only for systems already placed on the market before August 2. The Commission spells it out plainly in its FAQ: the grace period applies "only for AI systems placed on the market before 2 August 2026" and "only as regards the marking and detection obligation."
So the grace period doesn't cover the deadline, it covers one paragraph. A tool launched on August 3 gets no delay at all, and the rest of Article 50 applies to everyone on Sunday.
If you're deploying AI, here's what it means
Say you've put a chatbot on your website: it has to announce it's an AI from the very first exchange. A "talk to an advisor" button that quietly routes to a model without saying so isn't defensible anymore.
Say you're publishing a news piece largely written by a model: either a human reviews it and takes editorial responsibility, or you label it. A company newsletter generated in three clicks falls into scope the moment it informs the public on a matter of public interest.
The scope stops at your front door, though. The Commission excludes "personal, non-professional" use from the definition of a deployer: an image generated to make your friends laugh doesn't count. The same image published by an agency for a client does.
What doesn't happen Sunday
The part of the regulation that would have actually had teeth covers high-risk systems: hiring, credit scoring, education, biometrics, critical infrastructure. Mandatory documentation, risk management, human oversight, registration.
That whole block has slipped. The Digital Omnibus pushes Annex III back to December 2, 2027, and Annex I, AI embedded in products already regulated elsewhere, to August 2, 2028. We covered the mechanism, its carve-outs, and the lobbying behind it in a separate piece.
So the radar goes up before the road is finished. Enforcement against big models arrives Sunday; oversight of the systems that decide who gets hired or who gets credit will wait another sixteen months.
Not everyone reads that as simplification. EDRi, in a November 2025 statement written back when this was still a proposal, wrote that "the Digital Omnibus on AI tears the AI Act apart, undermining its key protections." That's one viewpoint, predating the final text, and it's worth knowing about.
In France, nobody's been named yet
One local oddity remains. The regulation takes effect Sunday, but France still hasn't legally designated the authority in charge of market surveillance: the legislative vehicle, the DDADUE bill, is still under discussion. The CNIL is positioning itself to take on a large share of that role, particularly around biometrics and employment, pending confirmation by lawmakers.
Europe's radar switches on Sunday. In France, the name of whoever will be writing up the violations hasn't been decided yet.



