EU AI Act Enforcement Begins — What It Means for Developers
The first wave of EU AI Act obligations kicked in this month. Here's which applications are affected and what compliance looks like in practice.
The European Union's AI Act has moved from legislation to enforcement, with the first wave of obligations now active for AI systems deployed within the EU. The regulation, which passed in 2024 after years of negotiation, takes a risk-tiered approach: stricter requirements apply to "high-risk" AI applications, while general-purpose AI tools face transparency obligations. For developers, the question is no longer whether to comply, but how.
What's in force now
The current enforcement wave covers prohibited AI practices — systems that manipulate people through subliminal techniques, exploit vulnerabilities, or enable mass surveillance — as well as obligations for general-purpose AI models above a certain capability threshold. Models with sufficiently large training compute must now provide technical documentation, comply with EU copyright law, and publish summaries of training data. These requirements fall primarily on model developers, not on downstream application builders.
High-risk applications: what counts
The more demanding tier of compliance applies to "high-risk" AI systems, a category that includes AI used in hiring, credit scoring, education, critical infrastructure, and law enforcement. Companies deploying AI in these contexts must conduct conformity assessments, register their systems in a public EU database, implement human oversight mechanisms, and maintain logs sufficient to audit decisions. The breadth of this category has surprised some developers who didn't expect their applications to qualify.
What developers should do now
For most application developers building on top of foundation models via API — the majority of the AI startup ecosystem — the immediate compliance burden is relatively modest. The heavy obligations fall on model providers. Developers should focus on three things: documenting what AI capabilities their product uses and why, implementing a human review mechanism for any consequential automated decisions, and ensuring their privacy practices align with GDPR requirements that were already in effect. Legal counsel familiar with both AI Act and GDPR is worth engaging early.
Penalties and enforcement timeline
Violations of prohibited practices carry fines of up to €35 million or 7% of global annual turnover. High-risk system violations carry up to €15 million or 3% of turnover. National market surveillance authorities in each EU member state are responsible for enforcement, which means enforcement intensity may vary across the bloc in the early years. The full set of requirements, including those for high-risk systems not yet in force, phase in through 2027.