← Insights / Compliance

European AI Office enforcement live: 7% penalty exposure

The European Union's AI Act has moved from policy document to enforcement reality. As of 2 August 2026, the European AI Office formally activated its investigative and enforcement powers, and the implications extend well beyond EU borders. For professional services businesses — accountants, solicito

Compliance 9 August 2026 6 min read

AI Act Enforcement Begins: What Professional Services Firms Must Do Now

The European Union's AI Act has moved from policy document to enforcement reality. As of 2 August 2026, the European AI Office formally activated its investigative and enforcement powers, and the implications extend well beyond EU borders. For professional services businesses — accountants, solicitors, HR consultancies, and marketing agencies operating in the UK, US, Canada, the Middle East, and Asia-Pacific — the question is no longer whether this regulation affects you. It is whether you are ready for it.

What Has Actually Changed

The AI Act has been in force since August 2024, but its application has rolled out in phases. The most significant threshold was crossed on 2 August 2026. The European AI Office can now demand documentation, access AI models for evaluation, require corrective action, and issue substantial fines. This is not a consultation period. Enforcement is live.

Alongside this, Article 50 transparency obligations are now in effect. Any AI system interacting with users must disclose that the user is engaging with AI. AI-generated or AI-altered content must carry provenance signals — watermarks, metadata, or equivalent markers. For marketing agencies producing AI-assisted content, and for HR consultancies using AI-driven candidate screening tools, this has immediate operational consequences.

The July 2026 "AI Omnibus" package did push back some deadlines. High-risk AI systems listed under Annex III now face a compliance deadline of 2 December 2027, and Annex I systems have until 2 August 2028. However, these deferrals apply only to those specific categories. They do not affect enforcement of prohibited AI practices, GPAI model obligations, or the transparency requirements that are already active. Businesses that interpret the Omnibus delay as breathing room across the board are misreading the regulation.

The Penalty Exposure Is Significant

The fine structures under the AI Act are structured to command attention at board level. Violations of prohibited AI practices — systems that manipulate users, exploit vulnerabilities, or engage in impermissible social scoring — can attract fines of up to €35 million or 7% of global annual turnover, whichever is higher. Infringements related to General-Purpose AI model obligations carry penalties of up to €15 million or 3% of global turnover.

These figures sit alongside GDPR exposure, not instead of it. GDPR fines passed €7.1 billion cumulatively since 2018, with €1.2 billion issued in 2025 alone — the fastest single-year pace on record. The AI Act introduces what regulators have described as a second penalty layer: where an AI system processes personal data, businesses may face simultaneous enforcement under both frameworks. Transparency failures under GDPR Articles 12 to 14 remain the most commonly cited category, and the European Data Protection Board has made them a priority in its 2026 coordinated enforcement framework.

For any professional services firm using AI tools that touch client data — which is most of them — the combined exposure is material.

Why This Matters Beyond the EU

Professional services businesses outside the EU cannot treat this as someone else's problem. The AI Act applies to any provider or deployer placing AI systems on the EU market or affecting EU users, regardless of where the organisation is headquartered. A US-based HR consultancy screening European candidates, a Canadian accounting firm using AI-driven audit tools for EU clients, a UAE marketing agency running AI content campaigns targeting European audiences — all of these businesses sit within scope.

The UK, having departed the EU before the AI Act was finalised, is developing its own framework. The UK government has opted for a principles-based, sector-led approach rather than a single statute, but this does not insulate UK firms from EU obligations where their work touches EU users or markets. UK professional services businesses with European client bases face dual exposure and should not conflate the UK's lighter-touch domestic approach with a green light on EU compliance.

Courts across Europe have been active on AI-related disputes, and the outcomes are shaping the compliance environment in ways that go beyond the AI Act itself.

In May 2025, the Cologne Higher Regional Court declined to prevent Meta from using publicly shared Facebook and Instagram data from adult users to train a large language model. This ruling offers some clarification on what constitutes a permissible basis for AI training data. However, the Court of Rome's March 2026 annulment of a fine against OpenAI illustrates that GDPR enforcement in AI contexts remains legally contested. Businesses should not assume consistency across jurisdictions.

On copyright, the Munich courts have been examining whether AI-generated content can attract copyright protection and under what conditions. For marketing agencies and content studios producing AI-assisted work for clients, this has direct implications for ownership, licensing, and client contracts. If your standard terms have not been reviewed with AI-generated content in mind, they should be.

What Firms Need to Do Now

The compliance actions required are not theoretical. They are practical, time-sensitive, and increasingly difficult to defer.

Audit your AI tool stack. Identify every AI system in use across the business — client-facing and internal. Categorise each by function and assess whether it falls under current enforcement scope: prohibited practices, GPAI model obligations, or Article 50 transparency requirements.

Implement disclosure mechanisms. Where AI systems interact with users or generate content, disclosure is not optional. Review client communications, automated outputs, and any AI-assisted deliverables. Watermarking and metadata requirements for AI-generated content need to be built into workflows, not added as an afterthought.

Map your data flows. Any AI system processing personal data sits at the intersection of GDPR and AI Act obligations. Conduct a gap analysis against Articles 12 to 14 of the GDPR. Ensure your privacy notices, data subject rights processes, and records of processing activities reflect your actual AI usage.

Review supplier contracts. If you are using third-party AI tools — which most firms are — your contractual position with those providers needs scrutiny. Who bears liability for non-compliance? What documentation can the supplier provide if a regulator requests it?

Train your people. AI literacy obligations have been in effect since February 2025. Staff need to understand the basics of how AI systems work, their limitations, and the compliance obligations attached to their use. This is a regulatory requirement, not optional professional development.

Monitor the horizon. From 2 December 2026, new prohibitions on AI systems generating child sexual abuse material and non-consensual intimate imagery come into force. High-risk system deadlines follow in 2027 and 2028. Build a compliance roadmap, not a one-off review.

The Compliance Window Is Narrowing

The AI Act is not a future obligation. Parts of it are being enforced today, and regulators have demonstrated both the appetite and the tools to act. Combined GDPR and AI Act exposure, active court decisions reshaping the boundaries of AI law, and the extraterritorial reach of EU regulation mean that professional services businesses in any major market need a clear compliance position.

Ops Intel works with professional services firms globally to navigate AI compliance — from initial audits and gap analyses to ongoing regulatory monitoring. If you are uncertain about your obligations under the EU AI Act, GDPR, or the emerging frameworks in your jurisdiction, contact our team to discuss how we can help you build a compliance position that is proportionate, practical, and audit-ready.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit