← Insights / Compliance

EU AI Act: Staff literacy now a compliance risk

The EU AI Act is no longer a future obligation. Enforcement has begun, deadlines are shifting, and the penalties for non-compliance are material. For professional services firms — whether you are an accountancy practice in London, a law firm in Dubai, an HR consultancy in Toronto, or a marketing age

Compliance 16 August 2026 6 min read

EU AI Act Enforcement Timeline 2025–2028: What Professional Services Firms Need to Know Now

The EU AI Act is no longer a future obligation. Enforcement has begun, deadlines are shifting, and the penalties for non-compliance are material. For professional services firms — whether you are an accountancy practice in London, a law firm in Dubai, an HR consultancy in Toronto, or a marketing agency in Singapore — understanding what applies to you and when is now a core business risk question, not a legal curiosity.

This briefing sets out the current enforcement timeline, summarises the most significant GDPR enforcement activity linked to AI, and draws out the practical implications for your firm.

What Has Already Come Into Force

The EU AI Act's phased implementation means that several provisions are already live.

As of February 2025, the Act's prohibited AI practices became enforceable. These include social scoring systems, AI that exploits vulnerabilities to manipulate behaviour, and real-time biometric identification in public spaces under most circumstances. Fines for deploying prohibited systems reach up to €35 million or 7% of global annual turnover — whichever is higher. Critically, obligations around AI literacy also took effect at this point, meaning firms that deploy or use AI tools must ensure their staff have a sufficient level of understanding of those systems.

For many professional services firms, this is where the first compliance gap tends to appear. Deploying a third-party AI tool — whether for contract analysis, CV screening, or client communications — does not mean you have discharged your obligations. If your staff do not understand how that tool works, what it cannot do, and where human judgement must intervene, you are already exposed.

The August 2025 Threshold: GPAI Models and the Penalty Regime

2 August 2025 marked a further significant escalation. Rules governing General-Purpose AI (GPAI) models — the category that covers large language models such as those underpinning many popular AI tools — became applicable on this date, alongside the Act's full penalty regime.

Providers of new GPAI models must now maintain technical documentation, support downstream providers with adequate information, implement copyright compliance policies, and publish summaries of training data where required. If your firm is building bespoke AI solutions or integrating AI capabilities into your own products or services, these obligations may apply to you directly.

Even if you are purely a user rather than a provider, the full penalty framework is now active. Competent authorities across EU member states can issue administrative fines for GPAI-related infringements of up to €15 million or 3% of global annual turnover. This is not a warning period. Enforcement is live.

High-Risk AI Systems: Deadlines Have Moved — But Not Disappeared

One development that has offered some businesses temporary breathing room is the postponement introduced by the Digital Omnibus on AI (commonly referred to as Omnibus VII). The original August 2026 compliance deadline for standalone high-risk AI systems has been pushed back to 2 December 2027. High-risk AI embedded in regulated products — medical devices and machinery, for example — now faces a deadline of 2 August 2028.

Do not mistake delay for de-prioritisation. Regulators have been explicit that the extended timeline is intended to support proportionate and effective implementation, not to signal reduced ambition. Firms that wait until late 2027 to begin preparing for high-risk AI obligations will find themselves significantly under-resourced when the deadline arrives.

The Omnibus also introduced new prohibitions effective from 2 December 2026, targeting AI systems used to generate non-consensual sexual or intimate content and child sexual abuse material. These are absolute prohibitions with no transition period.

GDPR Enforcement Is Running in Parallel

The AI Act does not operate in isolation. GDPR enforcement involving AI-related data processing has intensified substantially, and the fines are significant.

In 2024 alone, notable penalties included a €310 million fine against LinkedIn from Ireland's Data Protection Commission for unlawful behavioural analysis and targeted advertising, a €290 million fine against Uber by the Dutch DPA for transferring EU driver data to the US without adequate safeguards, and a further €30.5 million fine against Clearview AI — a company that has now accumulated over €100 million in EU fines for illegal facial recognition data collection.

The European Data Protection Board and the European Data Protection Supervisor have both published guidance on AI models and data protection, clarifying that AI models trained on personal data are only considered anonymous if personal data genuinely cannot be extracted or reproduced. This has direct implications for any firm using AI tools trained on client data, employee data, or any other personal information processed under GDPR.

For non-EU firms serving EU clients or processing EU residents' data — which describes the majority of internationally active professional services businesses — these obligations apply to you regardless of where your firm is headquartered.

The Courts Are Also Shaping the Landscape

Judicial decisions are adding further complexity. In March 2026, the Court of Rome annulled a €15 million fine that Italy's data protection authority, the Garante, had imposed on OpenAI over ChatGPT-related GDPR violations. The ruling illustrates that the application of existing data protection law to novel AI systems remains genuinely contested legal territory — and that outcomes are not always predictable.

At the same time, European courts are increasingly active on AI-related copyright questions. The direction of travel is clear: AI-generated and AI-assisted outputs are attracting legal scrutiny across multiple jurisdictions, and the position is evolving quickly.

What This Means for Your Firm

The compliance picture for professional services firms can be summarised straightforwardly. If your firm:

  • uses AI tools in any client-facing or internal process
  • processes personal data using AI systems
  • provides services to EU-based clients or handles EU residents' data
  • is considering building or customising AI-based tools

...then EU AI Act and GDPR obligations are relevant to your business now, not in 2027.

The immediate priorities are: assessing which AI systems your firm currently uses and how they are classified under the Act; ensuring your staff meet AI literacy requirements; reviewing your data processing agreements with AI tool providers; and beginning your documentation and governance processes before enforcement activity reaches your sector.

Take the Next Step With Ops Intel

The regulatory environment surrounding AI is moving faster than most compliance teams can track alongside their day-to-day responsibilities. Ops Intel works with professional services firms globally to translate complex AI regulation into clear, actionable compliance programmes — from initial risk assessments through to governance frameworks and staff training.

If you are unsure where your firm stands against the current EU AI Act requirements, or you need support preparing for the 2027 and 2028 high-risk AI deadlines, we can help.

Contact Ops Intel today to arrange a compliance review and find out exactly what your firm needs to do, and when.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit