SkycrumbsSkycrumbs
AI Regulation

EU AI Act July 2026: First Major Fines and How to Comply

July 21, 2026·7 min read

EU AI Act July 2026: First Major Fines and How to Comply

The EU AI Act's enforcement phase has moved from warnings to financial penalties. The European AI Office announced the first major fines this week, marking a shift in how seriously companies should treat compliance. Here is what happened, which rules triggered the actions, and what your organization needs to do if it has not already built a compliance process.

Which Companies Were Fined and Why

The two enforcement actions announced this week both involve the EU AI Act's prohibited practices list — the category of AI applications the Act bans outright, regardless of how the system is designed or documented.

The first case involves a retail analytics company that deployed a system classifying customers by purchasing behavior patterns in a way the AI Office determined constituted social scoring based on personal characteristics. The company had argued the system was a standard business intelligence tool rather than an AI system under the Act's definition. The AI Office rejected that argument, finding that the system met the Act's definition of an AI system and that its outputs were used in ways that affected individuals' access to services.

The second case involves a building security firm that used a biometric AI system in shared public spaces to identify individuals by facial recognition and link that identification to databases of "persons of interest." This practice is explicitly banned under Article 5 of the EU AI Act, with no exemption pathway available.

Both companies have 30 days to appeal. The fines are not publicly disclosed, but sources familiar with the proceedings describe them as multimillion-euro penalties that reflect the seriousness of operating prohibited systems rather than technical compliance failures.

The Prohibited Practices List: What Is Actually Banned

The EU AI Act's Article 5 creates an outright prohibition on certain AI practices. These are not regulated uses requiring compliance documentation — they are banned. The full list includes:

  • Subliminal manipulation: AI systems that manipulate people through techniques operating below conscious awareness, causing harm
  • Exploitation of vulnerabilities: Systems targeting groups based on age, disability, or social or economic situation in ways that cause harm
  • Social scoring by public authorities: Governments or public entities evaluating individuals based on social behavior or personal characteristics for purposes unrelated to the original data collection
  • Real-time remote biometric identification in public spaces: With narrow law enforcement exceptions that require judicial authorization
  • Biometric categorization: Inferring sensitive characteristics (race, political opinion, religion, sexual orientation) from biometric data
  • Emotion recognition in workplaces and schools: AI that infers emotions of workers or students in these specific contexts

The two enforcement actions this week fall squarely into the biometric categorization and social scoring categories. Neither company can cure the violation by improving documentation or adjusting the system — the applications themselves are prohibited.

High-Risk AI Requirements That Are Catching Companies Off Guard

Most companies are not operating prohibited AI systems. But many are operating high-risk AI systems without the required compliance documentation, and that is where the AI Office's next enforcement wave is expected to focus.

The Act defines high-risk AI categories in Annex III, including AI used in:

  • Hiring and employment: Candidate screening, CV evaluation, interview tools, performance monitoring
  • Credit and insurance: Creditworthiness assessment, risk evaluation
  • Education and vocational training: AI that determines access to educational institutions or evaluates students
  • Critical infrastructure: Systems managing electricity, water, transport, and similar services
  • Law enforcement: AI tools used by police and judicial authorities
  • Migration and border control: Visa processing, border management tools
  • Essential private and public services: Social benefit eligibility, emergency services AI

High-risk AI systems must meet requirements including: a risk management system, data governance documentation, technical documentation, automatic logging of operations, transparency to users, human oversight provisions, accuracy and robustness standards, and cybersecurity measures. These must be in place before the system is deployed, not added after.

The EU AI Act compliance overview for 2026 covers the full documentation requirements for each high-risk category.

The 90-Day Remediation Window: When It Applies

Earlier this year, the AI Office indicated it would issue corrective notices with 90-day remediation windows before imposing fines on companies with technical compliance gaps — incomplete documentation, missing risk assessments, inadequate logging systems. That approach was intended for organizations making good-faith compliance efforts that were not yet complete.

The fines issued this week did not come with remediation windows because both violations involve prohibited practices. Prohibited practices have no compliant version — there is no documentation or process change that makes a prohibited AI system permissible. The 90-day window applies to high-risk AI compliance gaps, not prohibited practice violations.

What this means in practice: if you are operating a system that might fall into the prohibited category, you cannot fix your way out of the problem. The application needs to stop. If you are operating a high-risk system without required documentation, a remediation window may be available, but only if the AI Office considers your compliance efforts genuine.

What US and UK Companies Need to Know

EU AI Act enforcement applies to AI systems that affect EU residents, regardless of where the company deploying the system is located. A US company whose AI application is used by EU customers, or a UK company whose AI affects employees in EU member states, is subject to the Act.

The practical implications for non-EU companies:

  • Map which AI systems you operate that affect EU users or employees
  • Determine whether any of those systems fall into prohibited or high-risk categories
  • For high-risk systems, initiate the documentation and risk management process immediately

The EU AI Act official text is available from EUR-Lex and is the authoritative source for the specific regulatory requirements.

UK companies should note that the UK has not adopted the EU AI Act but is developing its own framework. Companies operating in both markets should monitor UK AI regulation developments, which are moving faster since the current government committed to a regulatory framework by end of 2026.

How to Build an AI Compliance Checklist

For companies that have not started their EU AI Act compliance process, a practical first step is an AI system inventory:

  1. List every AI system your organization deploys or relies on that makes or influences decisions affecting individuals — customers, employees, or users
  2. Classify each system against the prohibited practices list (if prohibited, stop deployment immediately) and the high-risk categories in Annex III
  3. For high-risk systems, assess your current documentation against the Act's requirements: risk management, data governance, technical documentation, logging, transparency, human oversight
  4. Prioritize gaps by risk of enforcement action — systems directly in high-enforcement-priority categories (hiring, credit, biometric) first
  5. Implement the required documentation and processes — this typically takes 2-6 months for a well-resourced compliance team, more for organizations starting from scratch

Most compliance teams are finding that the biggest practical challenges are: defining what counts as "AI" under the Act's definition (broader than many expected), mapping data sources for the data governance documentation, and building human oversight procedures that actually function in production workflows.

Looking Ahead: More Enforcement Expected

The AI Office has signaled that the July enforcement actions are the beginning of a broader enforcement push, not isolated incidents. The Office has been reviewing complaints received from individuals and civil society organizations since the Act became fully enforceable.

Priority enforcement categories for H2 2026, based on AI Office public statements and complaint volume:

  • Employment AI (hiring screening, performance monitoring)
  • Biometric systems in public and semi-public spaces
  • AI used in financial services decisions affecting individuals

Companies in these categories should treat compliance as urgent, not aspirational. The corrective notice approach the AI Office has used for high-risk compliance gaps gives a window, but waiting until you receive a notice means having a documented violation on record even if you cure it within 90 days.

The most important thing organizations can do right now is start the inventory process. You cannot comply with a regulation you have not mapped against your actual AI deployments.

Comments

Loading comments...

Leave a comment