The Challenge
With the EU AI Act's enforcement starting on August 2, organizations worldwide faced a compliance puzzle. They had to navigate three enforcement bodies, staggered deadlines extending to 2028, and no clear precedent for interpreting requirements for General-Purpose AI Models.
The challenge wasn't just understanding the Act's requirements. It was determining which enforcement body had jurisdiction over your AI system, which deadlines applied to your specific use cases, and how to document compliance when guidance was sparse.
For providers of General-Purpose AI Models, the stakes were high. The AI Office now holds enforcement authority over these models, including those posing systemic risk. But what constitutes adequate evidence of compliance? How should providers interpret transparency obligations when technical details are still under discussion? And how do you demonstrate compliance to an enforcement body that's still building its own scientific advisory capacity?
The Enforcement Structure
The enforcement landscape introduces a three-tier authority structure that directly impacts your compliance strategy:
The AI Office enforces rules for General-Purpose AI Model providers and for AI systems offered by the same provider as the underlying model. If you're both the model developer and the system deployer, you're dealing with a single enforcement authority. However, that authority is still ramping up its scientific capacity. Prof. Alessandro Abate was appointed Lead Scientific Adviser just as enforcement began.
National competent authorities across all 27 Member States enforce rules for AI systems built on third-party models. This creates a compliance fragmentation risk: your AI system could face different interpretations of the same requirement depending on which Member State's authority has jurisdiction.
The European Data Protection Supervisor handles enforcement for AI systems used by EU institutions, bodies, and agencies. If you're a vendor to EU governmental entities, you're operating under a separate enforcement regime entirely.
This fragmented structure means you can't build a single compliance playbook. Your enforcement obligations depend on your role in the AI value chain and your customers' locations.
The Digital Omnibus on AI adds another layer of complexity with a multi-year compliance timeline. Transparency obligations and prohibited AI practices enforcement started immediately. But watermarking obligations under Article 50.2 don't apply until December 2, 2026. High-risk AI systems listed in Annex III get a reprieve until December 2, 2027. And Annex I high-risk systems face enforcement starting August 2, 2028.
This staggered timeline creates a planning paradox: you need compliance systems in place now for transparency obligations, but you're designing them without knowing how authorities will interpret requirements for high-risk systems years down the line.
Immediate Actions Taken
Organizations with the clearest compliance path took three immediate actions on August 2:
They mapped their systems to enforcement bodies. This wasn't just an organizational chart exercise. They documented the technical architecture of each AI system: which General-Purpose AI Model it uses, whether that model comes from the same provider or a third party, and whether the system serves EU institutional customers. This mapping determines which of the three enforcement bodies has jurisdiction.
They established reporting channels before they needed them. The EU launched three enforcement tools on August 2: a Complaint Tool for alleged infringements by AI Office-supervised providers, a Whistleblower Tool for employees to confidentially report violations, and a channel for system providers to report infringements by model providers. Forward-thinking organizations didn't wait for an incident. They documented these channels in their compliance procedures and trained relevant staff on when and how to use them.
They prioritized transparency obligations over future deadlines. With transparency rules enforceable immediately but high-risk system rules delayed until 2027 or 2028, the smart move was building transparency documentation that would serve both purposes. Technical Documentation under Annex IV, for example, becomes enforceable for high-risk systems in 2027. Starting that documentation now, while addressing immediate transparency obligations, avoids a compliance sprint later.
Results and Metrics
The staggered enforcement timeline created measurable compliance windows:
Organizations have until December 2, 2026, to implement watermarking obligations under Article 50.2 for AI systems already on the market. That's 28 months from the start of enforcement to build watermarking capabilities and integrate them into existing systems.
For high-risk AI systems listed in Annex III, the compliance deadline is December 2, 2027, giving organizations 40 months to align with requirements like conformity assessments and Technical Documentation.
Annex I high-risk systems have until August 2, 2028, providing a full 48-month implementation window from the start of enforcement.
These aren't arbitrary grace periods. They're recognition that retrofitting compliance into production AI systems requires architectural changes, validation evidence, and documentation that can't be assembled overnight.
Lessons Learned
Organizations that moved quickly on August 2 share a common regret: they wish they'd pressure-tested their enforcement body mapping earlier.
Here's why that matters: if you're a system provider using a third-party General-Purpose AI Model, you're subject to national competent authority enforcement. But if that model provider later offers a competing system, they fall under AI Office jurisdiction. Your compliance burden doesn't change, but your competitor's enforcement authority does. Organizations that discovered this dynamic after August 2 found themselves at a structural disadvantage.
The second common regret centers on the Whistleblower Tool. Several organizations treated it as an HR issue rather than a compliance signal. They didn't establish processes for evaluating whistleblower reports against their AI Management System controls. When an employee flags a potential violation, you need a documented process for investigating it, determining whether it represents a genuine compliance gap, and reporting it to the appropriate authority if required. Building that process after receiving a whistleblower complaint is too late.
Takeaways for Your Team
Don't wait for your deadline to start building evidence. If you're deploying high-risk AI systems under Annex III, your enforcement deadline is December 2, 2027. But the Technical Documentation you'll need then should be capturing design decisions, validation results, and risk assessments now. Retroactive documentation is both harder to produce and less credible to auditors.
Map your systems to enforcement bodies in writing. Create a register that documents, for each AI system: the underlying model, the model provider, whether you're also the model provider, and which of the three enforcement bodies has jurisdiction. Update this register every time you deploy a new system or change model providers. When an enforcement action happens, you'll need to know immediately which authority to engage with.
Treat the Complaint Tool as an early warning system. If someone files a complaint about your AI system through the EU's Complaint Tool, you won't necessarily know about it before the AI Office or national authority contacts you. But you can monitor for patterns: customer questions about transparency obligations, requests for information about your General-Purpose AI Model, or confusion about how your system makes decisions. These are leading indicators that a formal complaint might follow.
Build your compliance timeline backward from 2028, not forward from today. August 2, 2028, is when Annex I high-risk system enforcement begins. If your system falls into that category, you have 48 months. But conformity assessment, Technical Documentation, and Post-Market Monitoring aren't tasks you complete in month 47. Work backward: when does your conformity assessment need to be complete? When do you need to start collecting Post-Market Monitoring data to have a meaningful evidence base? When do you need to finalize your Technical Documentation to allow time for internal review? The organizations that will meet the 2028 deadline are the ones building compliance milestones now.
The EU AI Act's enforcement didn't arrive with fanfare or a flood of penalties. It arrived with jurisdictional complexity, staggered deadlines, and a three-tier enforcement structure that rewards organizations who mapped their compliance obligations precisely. If you're still treating August 2 as a distant deadline, you're already behind.



