What Changed in Brussels on 2 August
On 2 August 2026, a year of voluntary codes of practice and compliance dialogues in Brussels turned into a fine-issuing regime. Article 50 transparency obligations, requiring chatbots to disclose their automated status, deepfakes to carry labels, and machine-generated content to carry machine-readable marks, entered into legal force alongside enforcement powers over general-purpose AI models. The European Commission's AI Office and 24 national competent authorities across the member states can now request technical documentation, run their own evaluations, demand corrective action, and issue fines directly, rather than negotiating compliance informally.
European Commission Executive Vice-President Henna Virkkunen framed the shift as protective, not adversarial, saying the rules give "innovators legal certainty while protecting the public interest" and calling the moment "an important step towards AI that people and businesses can understand and trust." She also called artificial intelligence "a transformative technology," while warning that the most advanced models "create risks on an entirely new scale," a distinction that signals where enforcement attention is likely to concentrate first.
CNIL's First Move: 14 Banks, Zero Extensions Granted
The first live test of the new regime came within 48 hours. On 4 August 2026, France's data protection authority, the CNIL, issued formal Article 11 technical-documentation requests to 14 financial institutions running AI-based credit-scoring algorithms, demanding the Annex IV documentation that high-risk AI systems are required to maintain. Three of the fourteen institutions asked for more time to respond.
CNIL denied all three extension requests, pointing to the two years companies have had to prepare since the AI Act passed in 2024. That is the detail worth sitting with: a regulator's first move under live enforcement powers was not a warning letter or an informal inquiry, it was a formal documentation demand with a hard no on extra time. Any EU business in a high-risk category, lending, hiring, or another Annex III use case, now has a concrete precedent for what a first-contact audit actually looks like, not a hypothetical one.
How the Fines Actually Work
The penalty structure is tiered by the type of violation, not a single flat number. Breaches of the Article 50 transparency obligations, the deepfake-labeling and AI-disclosure rules, carry fines of up to EUR 15 million or 3% of a company's global annual turnover, whichever figure is higher. Prohibited AI practices, the small set of uses the Act bans outright, carry a steeper ceiling: up to EUR 35 million or 7% of global turnover.
The percentage-of-turnover structure matters more than the euro figures for any sizeable company, since it scales with revenue rather than capping exposure at a fixed number. Corrective-action orders add a second layer of pressure: once a national authority finds a system non-compliant, it can set a compliance window as short as 15 working days to fix, withdraw, or recall it, which is little time for a company that has not already prepared its technical documentation in advance.
The Question Every EU Business Now Has to Answer
For a year, the operative question for any EU company using or deploying AI has been whether it is broadly AI Act compliant, answered in good faith through internal reviews and voluntary codes. As of this week, that question has changed. The operative question now is whether a company can produce Annex IV technical documentation on demand, inside the regulator's own clock, because CNIL has just shown it will not extend that clock on request.
The CNIL credit-scoring sweep is a useful preview specifically for companies in lending, hiring, and other high-risk Annex III categories, since it is the first concrete example of what a high-risk documentation audit looks like in practice rather than in the text of the regulation. Any business in those categories that has not already assembled its technical file should treat this month, not some future compliance deadline, as the point at which the paperwork needs to already exist.
Read next: August 2 Is When the EU AI Fines Become Real | The US Frontier AI Threshold Is Now Classified



