Everyday Data Science
Latest
Agentic workflows now power a third of surveyed enterprise automationAfrica's AI startup ecosystem posts record funding yearNew benchmark results reshape the coding-agent leaderboardNigeria launches national AI strategy with major investment planRwanda's sovereign AI cloud enters public betaThe future of AI agents: from tools to teammates
ML & Data SciencePolicy Brief

The EU AI Act Is Already Enforcing. The Deadline Everyone Watched Was the One That Moved.

Brussels deferred high-risk obligations to December 2027, and compliance teams exhaled. But Article 50 transparency duties and GPAI enforcement with real fines went live on August 2, 2026. Then Maryland started policing AI-set grocery prices on October 1.

Ibrahim Denis FofanahIbrahim Denis FofanahData Scientist & AI Researcher12 min read·Regulation in Force · Policy Brief

In late July, the European Commission told the press it would begin enforcing the AI Act on Sunday, August 2, 2026. Then it did. Documentation requests went out. The AI Office gained the power to evaluate models, order risk-mitigation measures, and fine. None of this was secret. The press release was public, the Commission's enforcement page was updated, and an initial list of more than 180 signatories to the Code of Practice on Transparency of AI-Generated Content was published alongside it.

And yet almost every compliance conversation I have seen this year tracked a different story: the Digital Omnibus pushing the high-risk obligations to December 2027. That extension was real, and it was loud. It just was not the whole law. The parts that affect the widest range of builders, the transparency duties and the model-provider rules, are the parts that switched on. This is a policy brief about the enforcement that is already here, the one deadline that actually moved, and the US state laws that started biting this month.

Three dates already in the rear-view mirror

1. August 2, 2026: Brussels got its fining power

The AI Act, Regulation (EU) 2024/1689, has switched on in phases set by its Article 113 since it entered into force in August 2024. The general-purpose AI chapter took effect on August 2, 2025, but with one deliberate carve-out: Article 101, the fines article, was held back a further year. That year ended on August 2, 2026.

From that date, the Commission's AI Office can request technical documentation under Article 91, evaluate models directly under Article 92, order corrective or risk-mitigation measures under Article 93, and impose fines under Article 101. The fine tiers are steep: up to 35 million euros or 7 percent of global annual turnover for prohibited practices, up to 15 million euros or 3 percent for most other violations including GPAI breaches, and up to 7.5 million or 1.5 percent for supplying incorrect information to authorities. These are higher maximums than GDPR.

The underlying GPAI duties bind every provider placing a general-purpose model on the EU market: draw up and keep current technical documentation, give downstream companies the documentation they need to comply themselves, maintain a copyright policy that respects EU law, and publish a sufficiently detailed summary of training content on the AI Office's template. Models released before August 2, 2025 have until August 2, 2027 to reach full compliance. More than 180 organizations, including Anthropic, Google, Microsoft, OpenAI, Amazon, and IBM, had already signed the Code of Practice on GPAI transparency, which the Commission treats as evidence of conformity and a mitigating factor in enforcement proceedings. In September, the AI Office began sending formal enforcement requests to AI firms, turning transparency into an administrative task with a deadline.

2. August 2, 2026: Article 50 transparency became enforceable

This is the deadline most builders actually missed, because it reaches far beyond the model labs. Article 50 applies to providers and deployers, and two of its duties bite immediately.

First, providers of AI systems designed to interact with people must tell those people they are interacting with an AI system. That covers any organization that has put its own name on a branded in-house chatbot, which by now is most large employers and a great many non-European companies selling into the bloc.

Second, providers generating synthetic content must mark it in a machine-readable, detectable format. Almost no company can satisfy this alone; it depends on what the upstream model provider exposes. There is a narrow transition window to December 2, 2026 for this marking obligation, and only for systems that were already on the market before August 2, 2026. New systems must comply now.

Deployers have their own set: disclose deepfakes, and inform people when emotion recognition or biometric categorization is in use. The scope rule is the part US teams keep getting wrong: these obligations apply based on where the end users are located, not where the deploying company is headquartered. A US company with no EU physical presence but with EU residents using its AI-powered customer service chatbot is in scope.

3. October 1, 2026: Maryland started policing algorithmic prices

Across the Atlantic, a different kind of AI enforcement began this month. On April 28, 2026, Maryland Governor Wes Moore signed House Bill 895, the Protection From Predatory Pricing Act, making Maryland the first state to restrict surveillance pricing in the food industry. The law took effect October 1, 2026, and the Attorney General's Consumer Protection Division can now pursue violations.

The law applies to food retailers operating establishments of at least 15,000 square feet and to third-party grocery delivery services. It prohibits using dynamic pricing to set the price of groceries, or to set a higher price for specific consumers. Dynamic pricing is defined broadly: offering or setting a personalized price specific to a consumer based on the consumer's personal data, regardless of whether the seller collected or purchased the data. The law separately prohibits using the personal data of members of legally protected classes to offer, advertise, or sell consumer goods or services where that use results in a consumer being denied an accommodation, advantage, or privilege given to others.

Penalties run up to 10,000 dollars per violation, with a 25,000 dollar surcharge for repeat offenders. The exceptions matter for anyone building pricing tools: promotional pricing, loyalty program benefits, temporary discounts, and cost-based price differences are not covered. The core of the ban is personalization by data, not price changes in general.

Maryland moved first, but it is not alone. Connecticut and New Jersey passed their own surveillance-pricing measures in the weeks after Maryland's enactment. New Jersey's Fair Price Protection Act, effective August 1, 2027, is reportedly the sharpest of the three: a private right of action with treble damages and no cure period. A state-by-state pricing patchwork is now forming, and pricing algorithms sit in the middle of it.

The one deadline that actually moved

To be fair to everyone who watched the wrong deadline, the Digital Omnibus did move something large. Regulation (EU) 2026/1744 deferred the standalone high-risk obligations under Annex III to December 2, 2027. The Omnibus also made two additions that cut the other way: new prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition period for technical safeguards running to December 2, 2026. It softened the AI literacy duty to supporting training rather than guaranteeing competence, but it did not remove it.

The honest reading: the extension bought time for the compliance category with the heaviest paperwork, high-risk systems in hiring, education, and critical infrastructure. It did not pause anything else. Prohibited practices have been enforceable since February 2025. The GPAI rules have applied since August 2025. Article 50 has been enforceable since August 2026.

And one more US datapoint for the patchwork file: Connecticut's S.B. 5, the C.A.R.T. Act, signed June 2, 2026 by Governor Lamont and in effect October 1, bars AI companies with subscription services from renewing subscriptions without written notice and proof the consumer agreed to the terms, and it protects frontier-developer employees who anonymously report AI development or outputs that could pose catastrophic risk, defined as materially contributing to the death or serious injury of more than 50 people, or more than one billion dollars in damage from a single incident. Colorado's Automated Decision-Making Technology Act, meanwhile, is functionally frozen: the enforcement date is stayed by the federal district court in xAI v. Weiser, the Department of Justice intervened on xAI's side in April 2026, and the Attorney General's proposed rules are in a comment period running to October 26. The patchwork is not just forming; it is being litigated.

What this means for data and AI practitioners

  1. If your chatbot serves EU users, it must say it is AI. At the start of the interaction, clearly, not buried in a terms page. This has been enforceable for two months.
  2. If you generate synthetic content for EU audiences, it needs machine-readable marking. Check what your model provider exposes, because you cannot mark content alone. Systems already on the market get until December 2, 2026 for the marking piece; everything else is immediate.
  3. If you wrap or fine-tune a foundation model for hiring, credit, education, or a similar use case with EU users, you are a deployer with your own obligations. Using ChatGPT, Claude, or Gemini via API does not make you the model provider, but deploying them in a high-risk-shaped use case gives you independent compliance duties.
  4. Inventory first. The one piece of advice every compliance source agrees on: you cannot classify what you have not identified. List every AI system in use, who owns it, and what data feeds it.
  5. African builders selling into the EU: this reaches you too. The AI Act asserts jurisdiction over providers and deployers outside the EU when their systems are placed on the EU market or their outputs are used there. A team in Lagos, Accra, or Freetown with one EU client relationship is in scope. The Brussels effect applies here: providers rarely build separate versions of the same model for different continents, so EU settings tend to become the defaults everywhere. Build to the stricter standard once.
  6. Pricing teams: audit the personalization layer. Any US algorithm that adjusts prices using personal data now needs a state-by-state review. The Maryland definition does not care whether you collected the data or bought it.

In favour

The transparency duties are cheap to implement and hard to argue against: telling a user they are talking to a chatbot is basic honesty, and marking synthetic content is infrastructure the internet needs. Maryland targets a concrete consumer harm with a bounded scope, grocery prices from personal data, rather than banning a technology outright. The phased rollout gave everyone years of notice, and the Code of Practice gives providers a documented path to deference. If the first enforcement lands on AI washing and marketing deception rather than honest engineering teams, the regime will have started in the right place.

Against

The capacity gap makes early enforcement selective by necessity, which punishes the visible while the invisible continue. Machine-readable marking standards are still forming; the Commission itself points organizations to a Code of Practice and labeling icons that are being developed in practice, which means companies are being asked to comply with a standard that does not fully exist yet. Maryland's definition of personal data is broad enough to sweep ordinary analytics into the ban's orbit, and the cost of a state-by-state pricing review falls hardest on smaller retailers, not the platforms. Colorado shows the preemption risk is real: the first federal intervention in a state AI law challenge is already on the docket. And the heaviest compliance burden lands on deployers, the companies wrapping models, rather than the labs building them.

What would make me wrong

  1. If the high-risk obligations move again past December 2027, the "the extension was the exception" framing fails.
  2. If the AI Office announces a substantial GPAI fine in Q4 2026, the paper-tiger reading in the warning above dies on the spot, and I will update this brief to say so.
  3. If Maryland brings no enforcement action by mid-2027, the pricing ban reads more as signal than substance.
  4. If courts strike down the Article 50 marking requirements as technically unworkable before the December 2, 2026 transition ends, the compliance advice in this piece is wrong.
  5. If Colorado's law survives the xAI challenge intact, the patchwork hardens faster than I expect, and pricing teams should budget accordingly.

Sources

Which of these deadlines caught you by surprise, and what is your team actually doing about the ones that are already live?

Related on Everyday Data Science: African-language AI is a data-pipeline problem, not a scale problem, UNDP and GSMA bet on African-language AI, Africa's 12,000 GPUs and the compute gap

About the writer

Ibrahim Denis Fofanah
Ibrahim Denis Fofanah

Data Scientist & AI Researcher

3 followers

Data scientist and AI researcher at Pace University. I coined Artificial Frictional Unemployment, and built the first machine learning model for crop yield prediction in Sierra Leone. Author of Understanding Agentic AI. I write about agentic systems and applied ML, with a bias toward what actually works, and who gets left out when it doesn't.

Share

Found this useful? Passing it on to someone who builds is the best way to help the publication grow.

Built something worth sharing? Write it up for us →