The EU AI Act became generally applicable on 2 August 2026, the date from which its enforcement rules take effect.
The regulation is not fully in force, however — the European Parliamentary Research Service has assessed that, given the staggered application of individual chapters and articles, the Act should be fully effective only by 2027. Compliance leads entering this market now must navigate a framework that is simultaneously live and still rolling in. [EUR-Lex] [European Parliamentary Research Service]
The structural tension is that two major regulatory instruments — the AI Act and the Digital Services Act — are now both in application, each with its own supervisory architecture, each with its own penalty regime, and each generating real enforcement activity. The Commission imposed a €120 million fine on X under the DSA in December 2025. While the AI Act's enforcement machinery is newer and its notified-body infrastructure is still being established, the DSA precedent makes clear that compliance gaps carry material financial risk. [EUCRIM]
Regulation (EU) 2024/1689, the Artificial Intelligence Act, and Regulation (EU) 2022/2065, the Digital Services Act, are both in application as of 2026 — creating a layered compliance environment for operators of AI-enabled digital services.
The Artificial Intelligence Act was adopted on 13 June 2024 and published as Regulation (EU) 2024/1689. Its stated objective is to encourage the development and uptake of safe and trustworthy AI systems across the EU single market while ensuring health, safety, and fundamental rights protection. The regulation applies from 2 August 2026 — the date from which its enforcement chapter takes effect — though individual provisions carry different application dates that push full effectiveness to 2027. [EUR-Lex] [European Parliamentary Research Service]
The AI Act's staggered implementation is material. Provisions on prohibited AI practices became applicable from 2 February 2025. Rules relating to most penalties became applicable from August 2025. The general application date of 2 August 2026 covers the enforcement framework, but further provisions continue to phase in through 2027. For compliance leads, this means the framework is live but not static: the obligations in force today are not the full set that will apply in eighteen months. [European Parliamentary Research Service]
The Digital Services Act, Regulation (EU) 2022/2065, establishes a single market for digital services and has applied from 17 February 2024. It creates a tiered obligation structure: all online platforms must meet baseline requirements, while very large online platforms (VLOPs) and very large online search engines (VLOSEs) — those with more than 45 million monthly active users in the EU — face the heaviest obligations including annual risk assessments, mandatory audits, and enhanced transparency reporting. An information-sharing system underpinning the DSA's enforcement architecture is governed by Commission Implementing Regulation (EU) 2024/607. [EUR-Lex (via Eurlexa reproduction)] [Streamlex] [EUR-Lex]
For operators of AI-enabled digital services, both regulations will typically apply simultaneously. A recommender system embedded in a large platform will be subject to DSA content-moderation and transparency obligations by virtue of platform size, and to AI Act obligations by virtue of being a high-risk or general-purpose AI system. The supervisory architectures are distinct: the AI Act works through national competent authorities and, for general-purpose AI, the AI Office at Commission level; the DSA works through Digital Services Coordinators in each Member State and the Commission for VLOPs and VLOSEs. Neither framework overrides the other.
The AI Act's phased application dates require a compliance calendar approach: an operator must track which obligations were live from February 2025, which from August 2025, which from August 2026, and which from 2027. Baker McKenzie's analysis of the staggered timeline provides a reliable working reference. [Baker McKenzie]
Under the AI Act, placing a high-risk AI system on the EU market requires a Certificate of Conformity from an accredited notified body — valid for a maximum of four years, subject to annual surveillance — but the notified-body ecosystem is nascent.
The AI Act imposes mandatory third-party conformity assessment by a notified body for high-risk AI systems used in biometric identification — specifically, remote real-time and post biometric identification of natural persons. A notified body is an independent conformity assessment body designated by an EU Member State to assess whether products comply with EU regulations before they can be placed on the market. When it completes an audit, it issues a Certificate of Conformity valid for a maximum of four years, subject to annual surveillance. [Glocert International] [Future of Privacy Forum] [Sota.io]
To become a notified body, an organisation must be established under the national law of a Member State and have legal personality. It must demonstrate independence, absence of conflicts of interest, and technical competence across AI technologies, data science, machine learning, cybersecurity, and the relevant application domain. It must also hold appropriate professional liability insurance and comply with the organisational, quality management, resource, process, and cybersecurity requirements set out in Article 31 of the AI Act. [EU Artificial Intelligence Act (artificialintelligenceact.eu)] [Glocert International]
The route to designation begins with an application to the national notifying authority — the body in each Member State responsible for assessing, designating, notifying, and monitoring conformity assessment bodies. Each Member State must designate or establish at least one notifying authority. The application must include a description of the conformity assessment activities, the relevant assessment modules, the types of AI systems for which competence is claimed, and an accreditation certificate where one exists. Where no accreditation certificate is available, the applicant must provide all documentary evidence necessary for verification and ongoing monitoring. [European Commission AI Act Service Desk] [EU Artificial Intelligence Act (artificialintelligenceact.eu)] [WilmerHale]
Once an application is notified to the Commission and Member States, the conformity assessment body may begin operating as a notified body if no objections are raised within two weeks for accreditation-based notifications, or within two months for documentary-evidence-based notifications. The Commission is required to publish and maintain a public list of all notified bodies, their identification numbers, and the activities for which they have been notified. [European Commission AI Act Service Desk]
The practical implication for high-risk AI providers is a double dependency: market entry requires a notified body, and notified bodies require national designation infrastructure that is still being established. The AI Act required national regulatory sandboxes to be operational by 2 August 2026. The conformity assessment body ecosystem is developing in parallel with the regulation itself, which means capacity constraints for third-party assessment are a near-term market-entry risk, particularly for providers in biometric and other high-risk AI categories. [EUR-Lex]
The notified-body designation process described here draws on both the AI Act's primary text and secondary guidance. No public registry of currently designated AI Act notified bodies was retrieved in available source material — the Commission list required by Article 35(2) had not yet been publicly available in a form captured by retrieval at the time of research.
Providers and deployers of high-risk AI systems face lifecycle-long logging and impact assessment duties under the AI Act; digital platform operators face a separate stack of six-monthly and annual reporting obligations under the DSA — and the two stacks can run simultaneously for AI-enabled platforms.
| Regulation | Covered Entity Type | Recurring Obligation | Frequency / Timeline | Evidence Type |
|---|---|---|---|---|
| EU AI Act | Providers of high-risk AI systems | Implement and maintain activity logging throughout the system's lifecycle; keep logs when under provider's control | Ongoing (lifecycle); applicable from 2 December 2027 | Record-keeping, audit and assurance |
| EU AI Act | Deployers of high-risk AI systems | Carry out, document, and maintain a fundamental rights impact assessment; inform national authority of results | Ongoing (where applicable) | Record-keeping, audit and assurance |
| DSA | Very large online platforms (VLOPs) and very large online search engines (VLOSEs) | Publish transparency reports (Article 15 reports) | At least every 6 months | Disclosure, transparency duties; recurring regulatory reporting |
| DSA | Very large online platforms (VLOPs) and very large online search engines (VLOSEs) | Transmit and publish risk assessment results following each audit report | Within 3 months of receipt of each audit report | Record-keeping, audit and assurance |
| DSA | Very large online platforms (VLOPs) and very large online search engines (VLOSEs) | Identify, analyse, and report on systemic risks (e.g. illegal content, disinformation, risks to minors) and mitigation measures | At least once a year | Record-keeping, audit and assurance |
| DSA | All online platform providers (excluding small and micro-enterprises) | Publish and update number of monthly active users in the EU | Every 6 months | Disclosure, customer-information and transparency duties |
| NIS2 | Essential and important entities | Early warning of significant incident to CSIRT or competent authority | Within 24 hours of awareness | Cybersecurity and incident-reporting duties |
| NIS2 | Essential and important entities | Full incident notification to CSIRT or competent authority | Within 72 hours of awareness | Cybersecurity and incident-reporting duties |
| NIS2 | Essential and important entities | Final incident report to CSIRT or competent authority | No later than 1 month after incident notification | Cybersecurity and incident-reporting duties |
Under the AI Act, providers of high-risk AI systems must design their systems for automatic logging of events relevant to health, safety, and fundamental rights risks, substantial modifications, and post-market monitoring — and must retain those logs for as long as the system remains under their control. Deployers — organisations that put high-risk AI systems into operational use — must, where applicable, carry out, document, and maintain a fundamental rights impact assessment and inform the national authority of its results. These obligations create a standing compliance burden that runs for the system's full operational lifecycle, not just at the point of market entry. [ArtificialIntelligenceAct.eu] [Latham & Watkins]
Cybersecurity obligations layer on top of AI Act duties for digital service providers through the NIS2 Directive. Essential and important entities — categories that encompass cloud computing providers, online marketplaces, and search engines — must report significant incidents in a three-stage sequence: an early warning within 24 hours of becoming aware, a full incident notification within 72 hours, and a final report not later than one month after the incident notification. Providers of key digital services, including cloud computing and search engines, must also comply with security and notification requirements under the NIS2 framework. [NIS2-Directive.com] [Advisera] [European Commission]
The DSA imposes a separate reporting regime for very large online platforms and very large online search engines. VLOPs and VLOSEs must publish transparency reports — including content on algorithm use, advertising, and content moderation — at least every six months. They must also publish the results of mandatory annual risk assessments, including risks related to illegal content, disinformation, and protection of minors, alongside the mitigation measures deployed. Following each audit, they must transmit the risk assessment results to the Digital Services Coordinator and the Commission, and make them publicly available, at the latest three months after receipt of the audit report. [European Commission] [EU-Digital-Services-Act.com]
All online platform providers — except small and micro-enterprises — must publish the number of monthly active users of their services in the EU and update that figure every six months. The DSA reporting cycle thus creates a minimum of two public transparency disclosures per year for covered platforms, alongside the annual risk assessment and audit-linked reporting. For a VLOP operating an AI-enabled recommender system, the concurrent AI Act logging duty and DSA risk assessment obligation will frequently cover overlapping subject matter, requiring coordinated compliance governance rather than siloed responses. [European Commission]
The NIS2 incident-reporting timelines (24-hour, 72-hour, one-month) are drawn from the directive's text as reproduced in secondary legal sources. NIS2's transposition deadline was October 2024; implementation status varies by Member State and is not covered in the retrieved corpus.
A €120 million fine against X in December 2025 marked the first DSA non-compliance decision. The Commission had 14 open investigations into VLOPs and VLOSEs as of November 2025, demonstrating that enforcement activity is now routine, not exceptional.
On 5 December 2025, the European Commission imposed a €120 million fine on X, finding that the platform had breached several transparency duties under the DSA. This was the first DSA non-compliance decision. A new formal investigation against X was subsequently launched under the DSA. The significance of this action is structural: the Commission demonstrated both the willingness and the institutional capacity to carry a case from formal investigation to a fine decision against a major platform within the DSA's early years of full application. [EUCRIM] [European Commission]
| Period | Cumulative DSA investigations opened (VLOPs/VLOSEs) | Fines imposed under DSA |
|---|---|---|
| Nov 2025 | 14 count | 0 count |
| Dec 2025 | 14 count | 1 count |
The DSA enforcement framework authorises the Commission to impose fines of up to 6% of a company's global annual turnover following an official determination of infringement, and periodic penalties of up to 5% of average daily worldwide turnover for each day of delay in complying with remedies, interim measures, or commitments. These are not nominal caps: applied to the global revenues of a major platform, they represent material financial exposure. The Commission also holds powers to conduct on-premises inspections of VLOPs and VLOSEs under investigation and to order access to data and algorithms. [EDAA] [European Commission] [Wikipedia]
As of November 2025, the Commission had started 14 investigations into DSA compliance of VLOPs or VLOSEs. The breadth of that caseload, alongside a concluded fine, indicates that DSA enforcement is operating as an active supervisory regime rather than a transitional grace period. For compliance leads, the DSA precedent is the most useful near-term signal for what AI Act enforcement will eventually look like: the Commission has shown it will use its tools, and it will do so publicly. [Wikipedia]
The figure of 14 investigations as of November 2025 is sourced from Wikipedia, which is classified below the tier threshold for primary factual claims. It is included as a directional indicator only; the precise investigation count should be verified against the Commission's official DSA enforcement page before relying on it for formal compliance purposes.
Full AI Act effectiveness is assessed by the European Parliamentary Research Service as a 2027 milestone. In the meantime, the implementation pipeline includes national regulatory sandboxes, a scientific panel of independent AI experts, and completed consultations on general-purpose AI model rules.
The AI Act entered into force in 2024 and reaches general application on 2 August 2026 — including its enforcement chapter. However, the European Parliamentary Research Service has assessed that, given the different application dates attached to individual chapters and articles, the Act should be fully effective only by 2027. Compliance leads should treat this as a rolling timeline: obligations already in force are not the complete picture of the framework they will eventually operate under. [European Parliamentary Research Service]
Two infrastructure elements are central to the near-term implementation schedule. First, Member States were required to ensure that at least one national AI regulatory sandbox was operational by 2 August 2026. These sandboxes are intended to allow providers to test AI systems in a controlled environment under regulatory supervision before market deployment. Second, the Commission consulted in late 2024 on a draft implementing act to establish a scientific panel of independent AI experts, which the AI Act foresees as supporting the AI Office and national authorities in implementation and enforcement. The feedback period ran from 18 October to 15 November 2024. The Commission also concluded a separate consultation on implementing rules for general-purpose AI models — covering transparency, copyright-related provisions, systemic risk taxonomy, and codes of practice — with submissions closing on 18 September 2024. The outputs of these consultations will shape how the framework applies to general-purpose AI models in practice, but the retrieved corpus does not confirm the final implementing measures adopted. [EUR-Lex] [European Commission]
The corpus covers consultation launch and deadline dates but does not include the final implementing acts that followed. The state of national sandbox operationalisation across Member States is not covered in the retrieved corpus.
The AI Act creates a single set of obligations but requires each Member State to set its own penalty rules — meaning the same prohibited AI practice can attract different financial consequences depending on where the deployer is established.
The AI Act requires each Member State to set out its own rules on penalties and enforcement measures. Rules on most penalties became applicable from August 2025. This structure parallels the GDPR model, where a single regulation co-existed with national supervisory authorities that brought different resourcing, priorities, and enforcement cultures to bear. The practical result for a multi-market EU operator is that regulatory exposure is not uniform: the same AI system, operated in the same way, may face materially different enforcement risk depending on the Member State whose national competent authority has jurisdiction. [Baker McKenzie]
| DSA | DMA | AI Act | |
|---|---|---|---|
| National Mandates & Powers | New national-level mandates, functions and powers added at country level | New national-level mandates, functions and powers added at country level | New national-level mandates, functions and powers added at country level |
| Penalty & Enforcement Rules | Not specified in facts | Not specified in facts | Each member state sets own penalty & enforcement rules; most penalties applicable from August 2025 |
| Coordination Structure | Not specified in facts | Not specified in facts | European AI Board advises Commission; national authorities implement and enforce within each member state |
| Category | DSA | DMA | AI Act |
|---|---|---|---|
| National Mandates & Powers | New national-level mandates, functions and powers added at country level | New national-level mandates, functions and powers added at country level | New national-level mandates, functions and powers added at country level |
| Penalty & Enforcement Rules | Not specified in facts | Not specified in facts | Each member state sets own penalty & enforcement rules; most penalties applicable from August 2025 |
| Coordination Structure | Not specified in facts | Not specified in facts | European AI Board advises Commission; national authorities implement and enforce within each member state |
Three major EU digital regulations — the DSA, the Digital Markets Act, and the AI Act — all require national-level implementation of new mandates, functions, and powers to regulate the digital and AI sphere, co-ordinated with the European Commission. This layering creates a structural workload for national authorities that are simultaneously implementing obligations under multiple frameworks. The AI Act addresses this coordination challenge by establishing the European Artificial Intelligence Board as a permanent coordination platform and advisory body to the Commission, composed of representatives from national authorities. The Board is designed to promote consistent application, but advisory coordination is a weaker harmonisation instrument than a single supervisory authority — the GDPR experience suggests national divergence in enforcement intensity will persist. [OECD]
The cross-border divergence analysis draws on OECD and Baker McKenzie published materials alongside the AI Act's primary text. The corpus does not contain comparative data on specific Member States' penalty frameworks or enforcement resourcing levels.
Analyst view The evidence presents a regulatory environment moving from legislative enactment to active enforcement faster than many compliance functions anticipated. The DSA moved from application to a nine-figure fine within less than two years of full applicability, while the AI Act is entering general application with its notified-body ecosystem still forming. [EUR-Lex] [EUCRIM] The risk profile is asymmetric: obligations are immediate, but the institutional capacity to support compliance — accredited notified bodies, national regulatory sandboxes, a functioning scientific panel — is being constructed in parallel.
The condition that would change this view is the pace of notified-body designation. If Member States designate notifying authorities quickly and accreditation bodies certify conformity assessment bodies at scale, the compliance pathway for high-risk AI providers becomes clearer and more predictable. Until then, third-party conformity assessment for biometric and other high-risk AI applications will face capacity constraints that could delay market entry. [European Commission]
This report covers the regulatory framework governing AI systems and digital services in the European Union, including the AI Act and the Digital Services Act, their compliance obligations, enforcement mechanisms, and the trajectory of change through 2027.
It is written for compliance leads assessing regulatory exposure and scoping legal review in the EU AI and digital services market.
The report was built through structured retrieval of primary legislative texts, official regulatory guidance, and secondary legal analysis, synthesised against a verified fact corpus.
Primary sources date from 2022 to mid-2026; available source material reflects the regulatory position as of 2026. Industry technical standards and a forward regulatory pressure outlook returned no citable primary data and are noted as gaps.
Figures appear in euros (€). No currency conversions have been applied.
Research conducted 05 Sep 2026. All statistics carry inline citation markers.
This report is produced for informational purposes only. It does not constitute financial, legal, or investment advice. All data is sourced from publicly available information as at the date of research. Renatus Ventures makes no representations as to the completeness or accuracy of third-party data.
Industry technical standards: no citable primary data was retrieved on harmonised technical standards developed under the AI Act (e.g. CEN-CENELEC work). This is a meaningful gap for high-risk AI providers determining conformity pathways.
Regulatory pressure outlook: no citable primary data was retrieved establishing a quantified or directional forecast of regulatory pressure trajectory beyond 2027. The EPRS full-effectiveness assessment (2027) is the closest available anchor.
Current notified body registry: the Commission's public list of designated AI Act notified bodies, required under Article 35(2), was not retrieved in a form confirming any designations as of 2026. The ecosystem's operational state at report date is therefore unconfirmed.
NIS2 national transposition status: the corpus does not contain a comparative assessment of which Member States had transposed NIS2 by their October 2024 deadline or the state of national CSIRT designation.
DSA investigation count: the figure of 14 Commission DSA investigations as of November 2025 is sourced from Wikipedia, which falls below the tier threshold for primary factual claims; the exact count should be verified against the Commission's official enforcement tracker.
National AI regulatory sandbox operationalisation: the corpus states the 2 August 2026 deadline for national sandboxes but does not confirm how many Member States had sandboxes operational at that date.
Final implementing measures for general-purpose AI models: the corpus covers the consultation process (deadline September 2024) but does not include the final codes of practice or implementing rules adopted following that consultation.