AI Act Enforcement Started on 2 August. Read the Deferral Carefully
- From 2 August 2026 the European Commission's AI Office, with national authorities, began enforcing the AI Act. The Commission announced it on 31 July 2026 in IP/26/1714.
- Three things became enforceable at once: obligations on providers of general-purpose AI (GPAI) models, the transparency rules, and the prohibited practices.
- Transparency now bites in public: interactive systems must tell users they are dealing with AI, deepfakes must be labelled, and AI-generated or altered content must carry machine-readable marks. More than 180 organisations have signed the accompanying Code of Practice.
- The systemic-risk obligations for the most advanced models explicitly name loss of control and cyber offence, alongside CBRN and manipulation risks. Agent autonomy is now a named regulatory category, not a research topic.
- Enforcement is split three ways: the AI Office for systems from the same provider as the underlying GPAI model and for systems inside DSA-designated platforms, national competent authorities for everything else, and the EDPS for EU institutions.
- The AI Omnibus pushed high-risk system rules to 2 December 2027, and high-risk systems inside regulated products to 2 August 2028. New prohibitions on AI-generated non-consensual sexual content and CSAM apply from 2 December 2026.
- The deferral is the trap. The evidence a high-risk classification requires - an inventory, a record of what agents did, and a defensible chain from policy to enforcement - takes longer to build than the runway that is left.
On 31 July 2026 the European Commission announced that from 2 August 2026 its AI Office, together with national authorities, would begin enforcing the AI Act. Three separate blocks became live on the same date: the obligations on providers of general-purpose AI models, the transparency rules, and the prohibited practices. EU AI Act enforcement is now an operational fact rather than a compliance calendar entry, and the most consequential detail for enterprise security teams is buried in the section headed Next steps.
What actually switched on
| Block | Who it lands on | In force since |
|---|---|---|
| GPAI model provider obligations: documentation to authorities and downstream providers, copyright policy, public summary of training content | Providers of general-purpose AI models | 2 August 2026 |
| Additional systemic-risk obligations for the most advanced models | Providers of GPAI models judged to pose systemic risks | 2 August 2026 |
| Transparency: disclose AI interaction, label deepfakes, machine-readable marks on generated or altered content | Providers and deployers of the relevant systems | 2 August 2026 |
| Prohibited practices: manipulation, harmful exploitation of vulnerabilities, unfair social scoring | Everyone | 2 August 2026 |
| Prohibitions on AI-generated non-consensual sexual content and CSAM | Everyone | 2 December 2026 |
| High-risk AI system obligations | Providers and deployers of high-risk systems | 2 December 2027 (AI Omnibus) |
| High-risk systems integrated into regulated products | Providers and deployers | 2 August 2028 (AI Omnibus) |
Read that table from the perspective of an enterprise that deploys rather than builds models, and most of the immediate weight falls elsewhere. The GPAI obligations are a model provider's problem. What reaches a deployer on day one is the transparency layer: any customer-facing interactive system has to say it is AI, synthetic media has to be labelled, and generated or altered content has to carry machine-readable marks so it can be detected downstream. The Commission published a first list of more than 180 organisations that have signed the Code of Practice on transparency of AI-generated content, which operationalises those rules.
That is a real obligation and, for most security teams, not the interesting one. The interesting one is what the deferral does to planning.
The deferral is the trap
The AI Omnibus moved the high-risk system rules to 2 December 2027, and high-risk systems integrated into regulated products to 2 August 2028. For a lot of enterprise deployments, particularly in financial services, HR, and healthcare, those are the rules that were going to require actual engineering work. Sixteen extra months reads like relief.
It is relief on the wrong axis. The obligations that eventually arrive are documentation-shaped: demonstrate what the system is, what it did, who was accountable, and that the controls you described were in force at the time. Every one of those is downstream of two capabilities that take months of organisational work rather than a procurement cycle - an inventory of what is actually deployed, and a durable record of what it did. Neither compresses. A team that starts in mid-2027 will be reconstructing a period it was not recording, and reconstruction is exactly what an auditor discounts.
This is the same argument the AI governance framework for enterprises makes about control design generally, and it is why ISO 42001 for AI agent governance and the NIST AI RMF applied to agents both start with inventory rather than with policy. The EU AI Act for AI agents maps the risk tiers and the obligations by role in detail.
A deferred obligation moves the deadline for the paperwork. It does not move the deadline for the evidence, because the evidence has to have existed all along.Anomity Research
Loss of control is now a named category
The systemic-risk obligations for the most advanced models are worth reading closely even if you will never be a GPAI provider. The Commission lists the risks those obligations address as large-scale harms including chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, harmful manipulation, and threats to fundamental rights, and specifically calls out risks to European cybersecurity and to AI acting outside human control.
Two of those terms have been research vocabulary for years and are now regulatory vocabulary. The practical consequence for deployers is second-order but real: the way model providers answer for loss of control and cyber offence will shape what downstream deployers get asked to demonstrate about the agents they build on top. The Commission also notes that GPAI models are used in a wide range of tools and services, including AI agents, which is as close as a press release gets to saying the agent layer is in scope.
If you want the technical version of what regulators have started naming, autonomous security agents are agents too covers the self-governance problem, agent autonomy covers what unbounded action looks like in a database, and the lethal trifecta covers the exfiltration path that turns an autonomous system into a cyber-offence question.
Enforcement is fragmented, and that changes the risk profile
Responsibility for the transparency rules and prohibited practices is shared across three bodies. The AI Office covers AI systems offered by the same provider as the underlying GPAI model, plus systems integrated into very large online platforms or search engines designated under the Digital Services Act. National competent authorities cover other AI systems. The European Data Protection Supervisor covers systems used by EU institutions, bodies, and agencies.
The Commission adds, plainly, that effective enforcement will depend on Member States ensuring national competent authorities are properly designated and adequately resourced. That is an acknowledgement that enforcement intensity will vary by jurisdiction for some time. The wrong conclusion to draw is that a lightly resourced regulator means low risk, because the Office also launched three reporting channels that do not depend on regulator-initiated review: a Complaint Tool for natural and legal persons, a Whistleblower Tool for people working with providers, and a dedicated channel for downstream providers to report alleged infringements by the model providers they build on. All treated confidentially.
A whistleblower channel changes the threat model for compliance in a specific way: the trigger is no longer an audit you can schedule around, it is an employee with an opinion about a system they work on. The organisations that handle that well are the ones whose internal records already match their external claims, which is an evidence problem before it is a legal one. The AI agent audit trail and logging guide covers what that record needs to contain, and how to audit AI agent activity covers the practice.
The scientific capacity question
Enforcement is backed by a Scientific Panel of 60 independent AI experts, which recently held its first meeting, and the Office has appointed Professor Alessandro Abate of Oxford's Department of Computer Science as Lead Scientific Adviser, with a background in safety, verification, and control of AI-enabled systems. Verification and control is a notably specific specialism to put at the top of the advisory structure, and it is consistent with a regulator that expects to be arguing about model evaluation rather than about documentation formatting.
For deployers, the read-across is that technical evaluation evidence is likely to carry more weight over time than policy attestation. That favours organisations that can show measurements over organisations that can show intentions.
What a security team should do in the next quarter
- Separate the two clocks. Transparency and prohibited practices are live now; the high-risk obligations are a December 2027 deadline with a much earlier evidence start date.
- Audit customer-facing surfaces for the disclosure requirement first. Any interactive system that could be mistaken for a human needs to say otherwise, and any generated or altered content you publish needs machine-readable marking.
- Start the inventory now regardless of tier. Classification arguments in 2027 will be decided on records, and you cannot retroactively record what agents, MCP servers, and skills were running in 2026.
- Map which of your systems sit under the AI Office versus a national authority versus neither, because the escalation path and the practical enforcement posture differ.
- Assume a report can originate internally. Align what your controls actually do with what your documentation says they do, before someone else compares them.
- Track what your GPAI providers publish under the new documentation obligations. The training-content summaries and downstream-provider documentation are inputs to your own risk assessment, and they are now mandatory rather than discretionary.
Where the evidence comes from
The gap most organisations will hit is not policy authorship. It is that the agent layer is the least documented part of the estate. Developers and employees install agents, MCP servers, and skills without a ticket, which is the dynamic in AI agents are the new shadow IT, and a governance programme can be fully documented while the actual population of AI artifacts on endpoints remains unknown. That mismatch is survivable in a self-assessment and is not survivable in an evidenced one. It is the same enumeration gap that leaves enterprises choosing between identity and isolation without knowing the population either control binds to, measured in the agent containment gap.
Anomity addresses that layer directly. A lightweight, unprivileged Endpoint Sensor inventories eight AI artifact types per machine - agents, MCP servers, skills, extensions, plugins, hooks, CLIs, and secrets - provider-agnostically, so the inventory covers the tools people actually installed rather than the ones on the architecture diagram. Metadata only leaves the endpoint over HTTPS, with secrets redacted locally, which is the posture a data protection review expects. On agents that expose a hook, such as Claude Code's PreToolUse, runtime governance returns allow, deny, or log on each tool call before it executes, which is the difference between a control you can describe and a control you can demonstrate.
Every added, changed, and removed artifact lands in a queryable 90-day audit trail, and policy violations route to your SIEM, Slack, email, and Jira through continuous policy evaluation. For the wider control-mapping work, the CSA AI Controls Matrix and GDPR for AI agents cover the adjacent regimes most European deployments have to satisfy simultaneously.
The Act's enforcement phase has started and the hardest obligations are sixteen months out. That is a comfortable-looking position which depends entirely on whether the intervening period is being recorded. To see which agents, MCP servers, and skills are running across your fleet today, and what runtime governance would have denied, book a 30-minute demo.
Frequently asked questions
What became enforceable on 2 August 2026?
Three blocks at once. First, the AI Office can now enforce the AI Act's rules for providers of general-purpose AI models, including the additional obligations that apply to the most advanced models judged to pose systemic risks. Second, the transparency obligations apply, requiring interactive AI systems to disclose that users are dealing with AI, deepfakes to be labelled, and AI-generated or altered content to carry machine-readable marks. Third, enforcement begins for the prohibited practices, which ban systems that manipulate people, exploit vulnerabilities harmfully, or score people unfairly in ways that threaten their rights.
Does this apply to my company if we only deploy AI, not build models?
Partly, and less than the headlines suggest. The GPAI obligations land on model providers. What reaches a deployer immediately is the transparency layer, which applies to any customer-facing interactive system, any deepfake or synthetic media you publish, and any AI-generated content that needs machine-readable marking. The obligations that most enterprise deployers were preparing for, the high-risk system requirements, were postponed by the AI Omnibus to 2 December 2027, or 2 August 2028 for high-risk systems integrated into regulated products.
Who enforces what?
Responsibility for transparency rules and prohibited practices is shared across three bodies. The AI Office enforces for AI systems offered by the same provider as the underlying general-purpose AI model, and for systems integrated into very large online platforms or search engines designated under the Digital Services Act. National competent authorities enforce for all other AI systems. The European Data Protection Supervisor enforces for AI systems used by EU institutions, bodies, and agencies. The Commission notes that effective enforcement depends on Member States designating and adequately resourcing those national authorities, which is a fairly direct acknowledgement that capacity varies.
Why does 'loss of control' in the systemic-risk list matter?
Because it moves agent autonomy from a research concern into a named regulatory risk category. The Commission's framing lists risks of large-scale harm including chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, harmful manipulation, and threats to fundamental rights, and it explicitly mentions risks to European cybersecurity and AI acting outside human control. Providers of the most capable models now carry obligations tied to that category, and their answers will shape what downstream deployers are asked to demonstrate about the agents they build on top.
What are the new complaint and whistleblower channels?
The AI Office launched three. A Complaint Tool lets natural and legal persons report alleged infringements by providers of AI systems the Office supervises. A Whistleblower Tool lets people working with providers of AI systems or GPAI models report possible violations securely. And a dedicated channel lets downstream providers that build on general-purpose models report alleged infringements by those model providers. The Office says information received will be treated confidentially. The practical effect is that enforcement no longer depends solely on regulator-initiated review.
If the high-risk rules slipped to 2027, what should we do now?
Build the evidence layer, because it is the long pole and it does not compress. A high-risk classification eventually requires you to demonstrate what your systems are, what they did, and that your stated controls were actually in force. Inventory and logging are prerequisites for all of that, and both take months of organisational work rather than a procurement cycle. Teams that treat December 2027 as a start date rather than a deadline will be assembling records retroactively for a period they were not recording.




