EU AI Act enforcement begins: deployer liability rules live
The EU's AI Act has moved from policy document to live enforcement. As of 2 August 2026, the European Commission's AI Office and national authorities began actively enforcing key provisions of the legislation — and if your firm uses AI tools in client-facing work, internal operations, or decision-ma
AI Act Enforcement Is Live: What Professional Services Firms Must Do Now
The EU's AI Act has moved from policy document to live enforcement. As of 2 August 2026, the European Commission's AI Office and national authorities began actively enforcing key provisions of the legislation — and if your firm uses AI tools in client-facing work, internal operations, or decision-making processes, this is no longer a future compliance problem. It is a present one.
For professional services businesses — accountants, solicitors, HR consultancies, and marketing agencies — operating across the UK, EU, US, Canada, the Middle East, and Asia-Pacific, the implications are significant and immediate. The Act has extraterritorial reach. If your firm deploys AI systems that affect people in the EU, or if you work with clients who do, the regulatory perimeter extends to you.
What Is Now Enforceable — And What Is Coming
The provisions that took effect on 2 August 2026 centre on transparency obligations. Any AI system that interacts with users must clearly disclose that it is not human. Chatbots used in client communications, automated document review tools, and AI-generated content must carry appropriate labels and disclosures. For marketing agencies, this means AI-generated copy, images, or video assets distributed to EU audiences require clear identification. For legal and HR firms, any AI-driven client-facing interface must make its non-human nature explicit.
Deployer obligations relating to emotion recognition systems, biometric categorisation, and deepfake technology are fully active with no transition period. If your firm uses any such systems — even as part of a third-party platform — you are the deployer in the eyes of the law, and you are responsible for compliance.
Rules governing General-Purpose AI (GPAI) models — the category that covers large language models such as GPT-4 and its successors — have been enforceable since August 2025. The AI Office can now request technical documentation from providers, evaluate model behaviour, mandate corrective actions, and issue fines. This matters for professional services firms that integrate GPAI models into their workflows, because your obligations as a deployer are tied directly to the compliance posture of the models you use.
The broader high-risk AI provisions, covering systems used in employment, education, biometrics, and critical infrastructure, apply from 2 December 2027. That timeline may feel comfortable, but given the scale of preparation required — documentation, conformity assessments, human oversight mechanisms — firms that wait until 2027 will be starting too late.
The Fines Are Larger Than GDPR
One figure deserves particular attention: maximum penalties under the AI Act reach up to €35 million or 7% of global annual turnover, whichever is higher. This exceeds GDPR's ceiling of €20 million or 4% of global turnover. The EU has deliberately set these penalties at a level that makes non-compliance economically irrational, regardless of firm size.
This is not a regulatory regime designed to issue warnings first and enforcement notices later. The infrastructure for active enforcement is now in place.
GDPR and AI: The Intersection Is Already Active
The AI Act does not operate in isolation. GDPR enforcement concerning AI systems has been building momentum for several years, and recent cases illustrate the dual compliance burden that firms must navigate.
In September 2024, the Dutch Data Protection Authority fined Clearview AI €30.5 million for illegally harvesting facial images to build a biometric database — a reminder that using AI to process personal data without a lawful basis carries serious consequences. In the same year, a German HR software provider was fined €4.75 million for failing to conduct a Data Protection Impact Assessment (DPIA) before deploying an AI-powered employee performance monitoring system. This case is directly relevant to HR consultancies and any firm using AI to evaluate employee behaviour or productivity.
The AI Act itself requires that certain high-risk AI systems undergo a GDPR Article 35 DPIA. These two regulatory frameworks are designed to work in parallel, and compliance with one does not mean compliance with the other. Firms need to address both simultaneously.
The Court of Rome's decision in March 2026 to annul Italy's €15 million fine against OpenAI introduces some judicial complexity, but it would be a mistake to read this as a weakening of regulatory intent. The Hamburg DPA's prohibition on OpenAI processing German users' data for training purposes, and the Irish Data Protection Commission's legal action against X over the use of EU users' posts to train the Grok model, demonstrate that enforcement activity is intensifying across multiple jurisdictions.
Copyright Risk Is an Emerging Exposure
European courts are also beginning to define the copyright implications of AI — a dimension of compliance that professional services firms using AI-generated content cannot afford to ignore. German courts addressed the question of whether AI training on copyrighted material without a licence is permissible under national law in a November 2025 case involving GEMA and OpenAI. The outcome of cases such as this will shape the legal risk attached to AI-generated outputs used in client deliverables.
For marketing agencies producing content at scale using generative AI, and for legal firms advising clients on intellectual property matters, this is an area requiring active monitoring. The law here is not settled, but the direction of travel is clear: courts are not treating AI-generated content as a copyright-free zone.
What Firms Outside the EU Need to Understand
The reach of the AI Act is not confined to EU-headquartered businesses. If your firm is based in the UK, US, Canada, the Gulf, or Asia-Pacific and you deploy AI systems that interact with EU users, provide services to EU-based clients, or process the personal data of EU residents, you fall within scope.
UK firms, in particular, should note that post-Brexit divergence from EU standards does not create a compliance exemption when serving EU markets. The UK is developing its own AI governance framework, but firms with EU exposure must meet EU standards regardless of what domestic UK regulation requires. Operating in multiple jurisdictions means managing multiple compliance frameworks simultaneously — and the EU's is currently the most demanding.
The Practical Steps Your Firm Should Be Taking Now
Transparency obligations are live. Begin by auditing every AI tool your firm uses — internally and client-facing — to confirm that appropriate disclosures are in place. Map your AI use against the Act's risk categories to understand where high-risk classification may apply. Review your data processing agreements with AI vendors to establish where deployer liability sits. Conduct or update DPIAs for any AI system that processes personal data. Assign clear internal ownership for AI compliance.
These steps are not optional. They are the baseline.
Ops Intel works with professional services firms across the UK, EU, North America, the Middle East, and Asia-Pacific to build practical, proportionate AI compliance programmes. Whether you need a full AI Act readiness assessment, GDPR alignment review, or ongoing compliance support, our team can help you move from uncertainty to clarity.
Get in touch with Ops Intel today to find out where your firm stands — and what needs to happen next.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.