Incode: Livingstone Blog

Enforcement of the AI Act began on 2 August. Here is your starting point.

Written by Livingstone Content Team | Aug 7, 2026, 12:58:08 PM

By Seb Burrell, Head of Enterprise AI, Livingstone

Enforcement of the EU AI Act began on 2 August. This is a practical starting point for organisations that buy and deploy AI rather than build it and an argument that the first move is an asset management job, not a legal one.

Somewhere in your organisation there is an AI tool nobody formally approved. Someone expensed it, or found it already bundled inside a product you licensed last year, or simply turned it on because the free tier did not need a purchase order. It is processing something. You could not name it, and you certainly could not describe what data it touches.

Until last Sunday, that was a cost problem and a GDPR problem. It is now also a compliance problem, with a supervisory regime and a penalty schedule attached.

On 2 August, the European Commission’s AI Office, working with national authorities, began enforcing the AI Act. The regulation has stopped being a future date on a compliance roadmap and become a live enforcement regime.

What changed on 2 August

Three things.

First, the Commission can now fine providers of general-purpose AI models. The obligations themselves, including transparency, copyright and safety, have applied since August last year, but Article 101, the power to issue penalties of up to €15m or 3% of worldwide annual turnover, whichever is higher, only switched on this weekend.

Second, the transparency duties in Article 50 became enforceable: chatbots must tell people they are talking to a machine, deepfakes must be labelled, and AI-generated content must carry machine-readable marks.

Third, the machinery to act on all of it is now in place: a complaints tool, a whistleblower tool, and a dedicated channel for downstream providers building on someone else’s model. Prohibited practices sit at the top of the scale, at up to €35m or 7% of turnover.

Worth noting that more than 180 organisations have already signed the Commission’s Code of Practice on Transparency of AI-generated Content, published in June. The market started moving on this before anyone was made to.

The deadline that did not land

Here is the part I suspect a lot of people missed while they were watching 2 August. The high-risk obligations were supposed to bite this month. They did not.

Six days before the deadline, the Digital Omnibus entered into force, Regulation (EU) 2026/1744, moving standalone high-risk requirements from 2 August 2026 to 2 December 2027, with AI embedded in regulated products following in August 2028.

So, if you were braced for classification work this month, you have just been handed sixteen months. That is the good news and the trap in the same sentence. Sixteen months is enough time to do the work properly. It is also enough time to forget about it until next summer and then do it badly in a fortnight.

Why this lands on the buy side, not just the build side

It is tempting to read the AI Act as a problem for the model providers. Look closer and a great deal of it lands on the organisations deploying AI.

If your customer service runs on a chatbot, the disclosure duty is yours. If your marketing team generates images or video, the labelling duty is yours. And if a tool is quietly processing customer data somewhere in your estate that nobody has recorded, you have exposure you cannot describe, let alone defend.

The scale of that is worth sitting with. Zscaler’s ThreatLabz team measured 18,033 terabytes of enterprise data sent to AI applications last year, up 93% year on year, and 410 million data-loss policy violations tied to ChatGPT alone. Under GDPR that was risk you could not see. Under an enforced AI Act it is also compliance posture you cannot evidence.

There is a procurement dimension too. Your vendors’ compliance is now part of your due diligence. When the next renewal arrives with an AI assistant bundled into it, the questions are no longer only commercial: is the provider meeting its transparency obligations, is generated content marked, has the vendor signed the Code of Practice, and what does the contract actually say about who carries the regulatory risk?

The starting point is a list, not a lawsuit

Here is the encouraging part. The first thing a regulator, an auditor or your own board will ask for is the same thing good cost governance has always needed: an accurate picture of what is in use.

Three columns. The tool, the owner, the data it touches.

The AI Act does not change that list. It raises the price of not having one.

From there, three moves in order. Classify what you find: which tools face customers, which generate content, which touch personal or sensitive data. Ask your vendors the compliance questions at the next renewal, in writing, and keep the answers. And put ownership somewhere real: every AI tool gets a named owner who answers for its use, its spend and now its compliance.

A word on frameworks, because I get asked about this constantly. ISO/IEC 42001 is useful scaffolding for building that evidence, but be careful how you sell it internally. The Commission is explicit that its goals and definitions are not aligned with the quality management system the Act requires, and it confers no presumption of conformity. The harmonised standards are still in development at CEN-CENELEC.

Use 42001 because it makes you organised. Do not use it because you think it makes you compliant.

One inventory, two jobs

Across $4bn of client savings, I have never once seen an estate where the honest answer to “what are we running?” turned out to be “less than we thought.”

It is always more.

That was true when the gap only cost money. It is a good deal more uncomfortable now the same gap is also a regulatory question.

Which is the actual point of this piece. The inventory that tells you what you are spending is the inventory that evidences what you are complying with. The owners are the same owners. The renewal conversation is the same conversation, with two more questions in it.

That is not two programmes competing for one budget. It is one discipline doing double duty, and most organisations already employ the people who know how to run it.

You have sixteen months on high-risk and none on transparency. The inventory serves both, and you can start it this quarter in a spreadsheet.

If you want a clearer view of where your own estate stands against the Act, what you are running, who owns it, and what it is touching, that is exactly what our AI Governance & Policy Assessment is built for, and it is a conversation worth having. 

The wider evidence on where estates are losing commercial control is in our briefing, The Enterprise Software ReckoningDownload The Enterprise Software Reckoning >>

Explore our AI Cost Management & Governance services: 
https://livingstone-tech.com/ai-cost-management-governance/

Author

Seb Burrell is the Head of Enterprise AI at Livingstone.Specialising in AI strategy, governance and enterprise adoption. He works with senior leaders to turn AI ambition into practical roadmaps, prioritised use cases and measurable value.

His experience spans public sector, healthcare, financial services and commercial organisations, with a particular focus on bridging board-level strategy with technical delivery across GenAI, agentic AI, Azure AI, Copilot Studio and IBM watsonx.