You've had a year to prepare. August 2, 2025 brought GPAI transparency obligations — user disclosure, content labeling, documentation. Most companies did the bare minimum or nothing at all.

August 2, 2026 is different. That's when enforcement powers fully activate. Fines become real. Regulators get teeth. The €15M–€35M penalties aren't theoretical anymore — they're in the enforcement queue.

If you use OpenAI, Anthropic, Claude, Gemini, or any foundation model in your product, you have 90 days. Here's what changes, who's exposed, and exactly what to do about it.

What Actually Changes on August 2, 2026

The EU AI Act has been live since August 2024, but GPAI obligations weren't enforced — regulators could issue guidance but not fines. That changes August 2, 2026.

From that date, the European AI Office and national competent authorities can impose penalties at scale. The gap between "technically non-compliant" and "actually at risk" closes permanently.

The obligations that became enforceable August 2, 2025 — and have been sitting unpenalized since — now have consequences:

Prohibited practices (social scoring, subliminal manipulation, real-time biometric surveillance in public spaces) have been illegal since February 2025. Full enforcement of those penalties is also active from August 2, 2026.

Who's Affected — And It's More Than You Think

The EU AI Act has extraterritorial reach. If your AI systems process inputs or outputs for people in the EU, the Act applies — regardless of where your company is headquartered.

That means a US-based SaaS with EU customers, a UK company selling to the continent, a Canadian fintech with European users — all in scope.

The Act draws a key distinction:

Using OpenAI's API in your customer support? Deployer. Embedding Claude in your writing tool? Deployer. Running Gemini through your analytics pipeline? Deployer.

The math is simple: if you've added any AI feature in the last 18 months, you have work to do.

The Compliance Reality Check

We scanned 100 mid-market SaaS, fintech, and healthtech companies publicly across GDPR, EU AI Act, CCPA, HIPAA, and SOC 2. Here's what we found:

MetricValue
Average compliance score66 / 100
Companies failing (<50)2 out of 100
Top failing frameworkEU AI Act (47 of 50 worst scorers)
AI-using sites with no disclosure60%
Cookie pre-consent tracking78%

The EU AI Act is not theoretical. It's the primary compliance gap in the market right now. Companies aren't failing on security or data retention — they're failing on AI-specific obligations that barely existed 18 months ago.

And the penalties aren't proportional to company size:

ViolationMaximum Penalty
Prohibited AI practices (Art. 5)€35M or 7% of global annual turnover
Violating GPAI obligations (Art. 50)€15M or 3% of global annual turnover
Supplying incorrect information to authorities€7.5M or 1.5% of global annual turnover

For a €50M revenue company, a 3% GPAI fine floor is €1.5M. That's not a rounding error — that's a liquidity event.

The Five Gaps We See Most

Running thousands of automated scans across compliance frameworks, these are the five EU AI Act gaps that show up most frequently:

  1. No AI disclosure on first user interaction. Chat interfaces, content generation tools, AI-assisted search — users aren't told they're interacting with AI. This is the single most common violation.
  2. AI-generated outputs go unlabeled. Blog posts, support replies, generated images, AI-assisted summaries — displayed without any disclosure that they're AI-generated.
  3. No model inventory exists. "We're using AI" but no one can produce a document listing which models, for what purpose, with what versions. Regulators can request this.
  4. AI usage policy is a document that exists but isn't enforced. Slack screenshot from a compliance audit doesn't count.
  5. No AI literacy training on record. Employees using AI daily with no formal training, documentation, or acknowledgment of the company's AI Act obligations.

None of these are technically complex to fix. They're documentation and disclosure problems — and disclosure problems are exactly what automated compliance monitoring catches before regulators do.

90-Day Compliance Action Plan

Here's the sequence. Do it in order.

Weeks 1–2

Run the automated scan

Before you fix anything, know what's broken. WatchSuit's free scanner runs 25 checks across GDPR, EU AI Act, CCPA, HIPAA, and SOC 2 against your live site — no login, no cost, 30 seconds.

Scan your site free →

You want the scored report with specific failing checks, not a general estimate. The gap between "we think we're compliant" and "our site fails these five items" is where companies get into trouble.

Weeks 3–4

Review your model inventory

List every AI model in use — API integrations, embedded tools, third-party features. For each: which model, which version, what's it used for, is the output displayed to users?

If you're using any foundation model via API and that output is shown to users, you have a disclosure obligation. Inventory first, then you can see the gap.

Weeks 5–8

Fix the disclosure gaps

The highest-frequency violations are also the fastest to fix:

  • Add "This response was generated by AI" to your chatbot or AI support tool
  • Add AI disclosure to your content generation tool's output
  • Label AI-generated images or video
  • Update your AI usage policy and document it with a named owner

These don't require legal counsel. They require someone noticing the gap and closing it.

Weeks 9–10

Get the deep-dive report

For €99, WatchSuit's Premium Compliance Report runs a 25-page deep crawl of your site, maps every failing check to the specific regulation, and gives you a step-by-step remediation roadmap — not generic guidance, your actual violations with your actual URLs.

Get the Premium Compliance Report — $99

For the 90-day window, this is the fastest path from "unclear risk" to "specific checklist I can hand to a developer."

Weeks 11–12

Set up continuous monitoring

Compliance isn't a one-time fix. Your site changes — new pages, new features, new AI integrations. Every change is a potential new violation.

Weekly automated scans with violation alerts catch drift before regulators do. At $499/month, it costs less than one hour of legal counsel — and legal counsel doesn't run continuous automated scans.

See continuous monitoring pricing →

The Bottom Line

90 days sounds like a long time until you factor in development cycles, legal review, and sign-off. Then it doesn't.

The companies that will be fine on August 2, 2026 are the ones that started their gap assessment in Q1. The companies that will be scrambling in late July are the ones still saying "we'll get to it."

Run the free scan. See what's failing. Fix the disclosure gaps first — they're the fastest and highest-leverage changes you can make. Then move to documentation, policy, and monitoring.

The fine is the last thing you want to be surprised by on a Monday morning.

About this article: This article is maintained by WatchSuit and updated as enforcement patterns evolve. Last updated: May 2026. For questions about specific compliance gaps, contact privacy@polsia.app.

This article does not constitute legal advice. EU AI Act compliance requirements are fact-specific. Consult a qualified legal professional for advice applicable to your situation.