You've had a year to prepare. August 2, 2025 brought GPAI transparency obligations — user disclosure, content labeling, documentation. Most companies did the bare minimum or nothing at all.
August 2, 2026 is different. That's when enforcement powers fully activate. Fines become real. Regulators get teeth. The €15M–€35M penalties aren't theoretical anymore — they're in the enforcement queue.
If you use OpenAI, Anthropic, Claude, Gemini, or any foundation model in your product, you have 90 days. Here's what changes, who's exposed, and exactly what to do about it.
What Actually Changes on August 2, 2026
The EU AI Act has been live since August 2024, but GPAI obligations weren't enforced — regulators could issue guidance but not fines. That changes August 2, 2026.
From that date, the European AI Office and national competent authorities can impose penalties at scale. The gap between "technically non-compliant" and "actually at risk" closes permanently.
The obligations that became enforceable August 2, 2025 — and have been sitting unpenalized since — now have consequences:
- User disclosure: Users must be informed when they're interacting with AI on first contact
- Output labeling: AI-generated text, images, audio, or video must be disclosed as such
- Model inventory: Internal documentation of which GPAI models you use, for what, and under what version
- AI literacy training: Employees working with AI systems need documented training
- AI usage policy: A governing document for how employees use AI tools in their work
Prohibited practices (social scoring, subliminal manipulation, real-time biometric surveillance in public spaces) have been illegal since February 2025. Full enforcement of those penalties is also active from August 2, 2026.
Who's Affected — And It's More Than You Think
The EU AI Act has extraterritorial reach. If your AI systems process inputs or outputs for people in the EU, the Act applies — regardless of where your company is headquartered.
That means a US-based SaaS with EU customers, a UK company selling to the continent, a Canadian fintech with European users — all in scope.
The Act draws a key distinction:
- Provider: The company that builds the foundation model (OpenAI, Anthropic, Google). They handle model-level obligations.
- Deployer: Anyone who puts an AI system into service for their own purposes. If you integrate a model via API, SDK, or embedded tool — you are a deployer and the obligations are yours.
Using OpenAI's API in your customer support? Deployer. Embedding Claude in your writing tool? Deployer. Running Gemini through your analytics pipeline? Deployer.
The math is simple: if you've added any AI feature in the last 18 months, you have work to do.
The Compliance Reality Check
We scanned 100 mid-market SaaS, fintech, and healthtech companies publicly across GDPR, EU AI Act, CCPA, HIPAA, and SOC 2. Here's what we found:
| Metric | Value |
|---|---|
| Average compliance score | 66 / 100 |
| Companies failing (<50) | 2 out of 100 |
| Top failing framework | EU AI Act (47 of 50 worst scorers) |
| AI-using sites with no disclosure | 60% |
| Cookie pre-consent tracking | 78% |
The EU AI Act is not theoretical. It's the primary compliance gap in the market right now. Companies aren't failing on security or data retention — they're failing on AI-specific obligations that barely existed 18 months ago.
And the penalties aren't proportional to company size:
| Violation | Maximum Penalty |
|---|---|
| Prohibited AI practices (Art. 5) | €35M or 7% of global annual turnover |
| Violating GPAI obligations (Art. 50) | €15M or 3% of global annual turnover |
| Supplying incorrect information to authorities | €7.5M or 1.5% of global annual turnover |
For a €50M revenue company, a 3% GPAI fine floor is €1.5M. That's not a rounding error — that's a liquidity event.
The Five Gaps We See Most
Running thousands of automated scans across compliance frameworks, these are the five EU AI Act gaps that show up most frequently:
- No AI disclosure on first user interaction. Chat interfaces, content generation tools, AI-assisted search — users aren't told they're interacting with AI. This is the single most common violation.
- AI-generated outputs go unlabeled. Blog posts, support replies, generated images, AI-assisted summaries — displayed without any disclosure that they're AI-generated.
- No model inventory exists. "We're using AI" but no one can produce a document listing which models, for what purpose, with what versions. Regulators can request this.
- AI usage policy is a document that exists but isn't enforced. Slack screenshot from a compliance audit doesn't count.
- No AI literacy training on record. Employees using AI daily with no formal training, documentation, or acknowledgment of the company's AI Act obligations.
None of these are technically complex to fix. They're documentation and disclosure problems — and disclosure problems are exactly what automated compliance monitoring catches before regulators do.
90-Day Compliance Action Plan
Here's the sequence. Do it in order.
Run the automated scan
Before you fix anything, know what's broken. WatchSuit's free scanner runs 25 checks across GDPR, EU AI Act, CCPA, HIPAA, and SOC 2 against your live site — no login, no cost, 30 seconds.
Scan your site free →You want the scored report with specific failing checks, not a general estimate. The gap between "we think we're compliant" and "our site fails these five items" is where companies get into trouble.
Review your model inventory
List every AI model in use — API integrations, embedded tools, third-party features. For each: which model, which version, what's it used for, is the output displayed to users?
If you're using any foundation model via API and that output is shown to users, you have a disclosure obligation. Inventory first, then you can see the gap.
Fix the disclosure gaps
The highest-frequency violations are also the fastest to fix:
- Add "This response was generated by AI" to your chatbot or AI support tool
- Add AI disclosure to your content generation tool's output
- Label AI-generated images or video
- Update your AI usage policy and document it with a named owner
These don't require legal counsel. They require someone noticing the gap and closing it.
Get the deep-dive report
For €99, WatchSuit's Premium Compliance Report runs a 25-page deep crawl of your site, maps every failing check to the specific regulation, and gives you a step-by-step remediation roadmap — not generic guidance, your actual violations with your actual URLs.
Get the Premium Compliance Report — $99For the 90-day window, this is the fastest path from "unclear risk" to "specific checklist I can hand to a developer."
Set up continuous monitoring
Compliance isn't a one-time fix. Your site changes — new pages, new features, new AI integrations. Every change is a potential new violation.
Weekly automated scans with violation alerts catch drift before regulators do. At $499/month, it costs less than one hour of legal counsel — and legal counsel doesn't run continuous automated scans.
See continuous monitoring pricing →The Bottom Line
90 days sounds like a long time until you factor in development cycles, legal review, and sign-off. Then it doesn't.
The companies that will be fine on August 2, 2026 are the ones that started their gap assessment in Q1. The companies that will be scrambling in late July are the ones still saying "we'll get to it."
Run the free scan. See what's failing. Fix the disclosure gaps first — they're the fastest and highest-leverage changes you can make. Then move to documentation, policy, and monitoring.
The fine is the last thing you want to be surprised by on a Monday morning.