The AI Act's Enforcement Era Began. Most Companies Read It Backwards.
On 2 August 2026 the EU AI Act crossed from preparation into enforcement. The European Commission's AI Office and the national market surveillance authorities activated their full powers, and the fines became real: up to 3% of global annual turnover or €15 million, whichever is higher, for providers of general-purpose AI models. That was the date the whole market had circled for two years. And yet, three weeks in, we keep having the same conversation with Greek and EU companies, because most of them have the picture exactly backwards.
The thing everyone feared got more time. The things almost everyone ignored are enforceable today. Getting those two facts the right way round is the difference between a calm quarter and an avoidable incident, so this piece sorts what actually changed on 2 August, what quietly moved, and what a deployer of AI agents should do about it this month.
What is enforceable now, or nearly
Three sets of obligations bite in 2026, two of them live as of this month and one landing in December, and none of them is the one that dominated the conference talks.
Fines for general-purpose model providers
GPAI providers have been under obligations since August 2025, but for the first year the Commission could not fine anyone. That grace ended on 2 August. The Commission can now penalise breaches of the GPAI duties, and it can reach back to conduct since the obligations began. If you build on top of a major model provider, this is mostly their problem rather than yours, but it is the reason the model vendors have been updating their documentation and usage terms all summer, and some of those changes flow down into your contracts. Worth a read before renewal.
Transparency duties for anyone running a chatbot or agent
This is the one that touches almost every company we work with. Any AI system that interacts with people in the EU must make clear, at the start of the interaction, that the user is dealing with AI rather than a person. A customer-facing support agent, a booking assistant, a voice agent on the phone line, all of them owe the disclosure now. It costs one sentence in the greeting and an honest label in the interface, and the number of deployed chatbots in Greece that still do not carry it is remarkable.
Machine-readable marking of AI content, due 2 December 2026
The third duty is close rather than live. AI-generated or AI-manipulated content, deepfakes included, must carry machine-readable marking so it can be detected as such, and the deadline for that marking duty is 2 December 2026, three and a half months out. If your marketing team ships AI-generated imagery or video, the pipeline that produces it needs to embed the marking by then, and most of the mainstream generation tools now do this by default. The exposure is home-built pipelines that strip metadata in post-processing without anyone deciding to. Start the check now, because the fix is trivial in September and a scramble in November.
The two-speed AI Act: transparency and GPAI fines are live now; high-risk conformity moved to December 2027.
What quietly moved to 2027
Here is the half of the story that got far less coverage than it deserved. The Digital Omnibus package extended the conformity assessment deadline for high-risk AI systems to 2 December 2027. The August 2026 date that two years of compliance marketing was built around, the full high-risk regime with its quality management systems, conformity assessments and technical documentation, now lands sixteen months later than most companies have in their planning documents.
For smaller vendors and deployers this is genuine relief, and the concession was aimed at exactly them. The proportionate-compliance pathway that was originally reserved for SMEs has also been extended to mid-caps, which covers a large share of the Greek enterprises we work with. If your 2026 budget contained a line item for a rushed high-risk conformity project, you just got the time to do it properly instead of expensively.
There is a trap inside the relief, though. A deadline that moves twice teaches organisations that deadlines move, and the temptation is to stand the whole programme down. The companies that will be comfortable in December 2027 are the ones that keep the governance layer they built, the audit trails, the named accountable humans, the scope reviews, and simply run it as operations rather than as a compliance sprint. The requirements did not shrink. They rescheduled.
The backwards map, corrected
Put the two halves together and the correct picture looks like this. If you run customer-facing AI, your exposure today is transparency, and fixing it is measured in days, not quarters. If you build or fine-tune general-purpose models, your exposure is live and financial, and your lawyers already know. If you deploy high-risk systems, hiring, credit, essential services, critical infrastructure, your deadline is December 2027, and the right response is a steady programme rather than a panic or a pause.
Most of the companies we talk to had this inverted: paralysed about high-risk paperwork that is now sixteen months away, while running undisclosed chatbots that are out of compliance today. One afternoon of work on the disclosure and labelling duties buys more real risk reduction this quarter than any amount of premature conformity documentation.
What this means for Greek enterprises
Three practical moves for this month. First, sweep your customer-facing surfaces. Every chatbot, voice agent and assistant your company runs should open with a plain disclosure that it is AI, in the language of the interaction. Our own customer support deployments ship with the disclosure built into the greeting, and retrofitting it into anything else is a one-day change. Second, check your content pipeline ahead of the 2 December 2026 marking deadline. If AI-generated media leaves your building, confirm the machine-readable marking survives your export and compression steps. Third, reschedule rather than cancel the high-risk work. Take the December 2027 date, work backwards through conformity assessment, documentation and testing, and you will find the comfortable start date is mid-2027, with everything before that being the operational governance you should be running anyway.
The full documentation and classification detail lives in our EU AI Act compliance guide, which we keep aligned with the current deadlines. And the deeper point, the one that outlasts every schedule change, is the one we made in the governance gap: the controls the Act requires are the controls a well-run agent deployment needs regardless. Regulation keeps converging on operational common sense.
We build AI agents with the disclosure, the audit trail and the oversight designed in from day one, so enforcement dates are calendar entries rather than emergencies. The agents we ship (AI Customer Support, AI Contract-to-Cash, Enterprise AI Search and the rest of the product family) were compliant with the August duties before August arrived. If you are not sure which side of the two-speed regime your systems sit on, get in touch at inbusiness.gr and we will map it with you in an afternoon.