Skip to content

reportEU AI ActAI Governance

EU AI Act obligations for law firms and legal-AI vendors, by date, article and enforcer, after the Omnibus

Every AI Act duty that reaches a law firm or legal-AI vendor, dated after Regulation 2026/1744: 5 in force, 6 deferred to 2027, 27 national enforcers mapped.

Edited and verified by Cognesio LLP

Researched with AI assistance · sources verified by Cognesio LLP · How this was made ↓

In the European Union, a law firm that uses an AI system in its work is a deployer under Article 3(4) of Regulation (EU) 2024/1689, and a company that sells that system is a provider. This report sets out, for both, which obligations of the AI Act apply on 5 September 2026, which were deferred by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), under which article each duty sits, who enforces it and what the fine ceiling is. It does not say how to comply. It says what the rule is, from which date, and who can act on a breach.

The question this report answers is narrower than the one the general trackers answer. Those trackers describe the Act. Practitioners search for the deployer’s version of it: the six-month log rule, whether a research tool is high-risk, whether a chatbot on a firm’s website needs a notice, whether a client memo drafted with AI needs a label, and which authority in which member state would ever ask. As of 5 September 2026, five obligations that reach a firm or vendor are in force, six are deferred to December 2027 or later, and the enforcement layer that will apply them is, in 15 of 27 member states, still being built.

Key findings

  1. As of 5 September 2026, five AI Act obligations reach a law firm or legal-AI vendor in force: Article 4 (AI literacy, since 2 February 2025, text rewritten 27 July 2026), Article 5 (prohibited practices, since 2 February 2025), Article 50(1) (chatbot disclosure by providers, since 2 August 2026), Article 50(2) (machine-readable marking of synthetic output by providers, since 2 August 2026, with a grace period to 2 December 2026 for systems already on the market) and Article 50(4) (deployer disclosure of deepfakes and of AI-generated public-interest text, since 2 August 2026).
  2. Six obligations were deferred by Regulation (EU) 2026/1744 from 2 August 2026 to 2 December 2027 for Annex III systems: the Article 26 deployer duties (instructions, human oversight, input data, monitoring, the six-month log retention in Article 26(6), worker information), the Article 27 fundamental-rights impact assessment, the Article 86 right to explanation, the Article 25 rule that turns a modifying deployer into a provider, the Article 49 registration duty and the Chapter III provider requirements. The “log retention 6 months” query has a dated answer: it binds deployers of high-risk systems only, and for a stand-alone Annex III system not before 2 December 2027.
  3. The only Annex III entry that names legal work is point 8(a), “AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution”. A firm’s own research or drafting tool is outside that wording; a vendor’s system supplied to a court or an arbitral body is inside it. The route by which the high-risk regime reaches most firms is not legal work but recruitment and HR (Annex III point 4).
  4. Article 4 carries no fine tier of its own. Article 99(4) lists Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50; Article 4 is not among them, so a literacy breach is punishable only under whatever national rules a member state adopts under Article 99(1). The rewritten Article 4 states that the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”.
  5. The fine ceilings that can reach a firm or vendor are three: EUR 35 million or 7% of worldwide annual turnover for a prohibited practice (Article 99(3)); EUR 15 million or 3% for a breach of Article 26 or Article 50 (Article 99(4)); EUR 7.5 million or 1% for incorrect, incomplete or misleading information to an authority (Article 99(5)). For SMEs each ceiling is the lower of the two figures (Article 99(6)); the Omnibus extends the lower-of rule to “small mid-cap enterprises” for the 3% and 1% tiers (new Article 99(6a)).
  6. Enforcement is split. The Commission’s AI Office enforces the rules for providers of general-purpose AI models, for AI systems built by the same provider or group on those models, and for systems in very large online platforms and search engines; national market surveillance authorities enforce everything else, including every deployer duty. Its powers applied from 2 August 2026. By 5 September 2026 no fine under the Act had been published by the AI Office or by any national authority; the first reported enforcement step is a set of requests for information sent by the AI Office to general-purpose model providers in late August 2026, asking for documentation of internal security practices, cybersecurity testing, safeguards against unsanctioned model actions and incident-response protocols, reported by a law-firm round-up and not, as of 5 September, on a Commission page.
  7. The national layer is uneven. On the community tracker’s count of 17 June 2026, nine member states had designated both a market surveillance and a notifying authority, twelve had partial designations or pending bills and six had none. Since that count, Poland’s act of 3 July 2026 (Dz.U. 2026 poz. 1003, published 27 July), Germany’s KI-MIG of 22 July 2026 (BGBl. 2026 I Nr. 223, in force 29 July) and Greece’s Law 5321/2026 (20 July) have moved three more states into the designated column, and Ireland, designated since S.I. 366 of 2025, added a national AI Office under its Regulation of Artificial Intelligence Act 2026 (signed 21 July; office announced 30 July). The table below counts 12 designated, 10 with a bill or formal proposal and 5 with none.
  8. The next dated events are 2 December 2026 (the new Article 5(1)(ba) and (bb) prohibitions on non-consensual intimate imagery and child sexual abuse material apply; Article 50(2) marking becomes mandatory for generative systems already on the market), 2 August 2027 (Commission delegated acts under new Article 2(13) due), 2 September 2027 (post-market monitoring guidance due) and 2 December 2027 (Annex III high-risk obligations apply).

Why the general trackers do not answer the deployer question

The Act is written by operator role and risk tier. A reader who wants to know what a law firm must do has to hold four things at once: which role the firm occupies (deployer for the tools it uses; provider if it builds or substantially modifies one), which tier each tool falls into (prohibited, high-risk, transparency-only, or none), which application date attaches to that tier after the Omnibus, and which authority enforces it. The general trackers are organised by article, not by reader, and most were written before the dates moved.

The search record shows the gap. In the 5 September 2026 Semrush pull for the US database, the query “eu ai act deployer obligations log retention 6 months” carries 720 searches a month at a difficulty score of 25; “eu ai act compliance” 320; “eu ai act summary” 1,000 at a difficulty of 70. The first page for the head terms is held by the community tracker at artificialintelligenceact.eu, the Commission’s own pages, IAPP and law-firm client alerts. None of them answers the log-retention query with a date, because the honest answer is a conditional: six months, for high-risk systems, from 2 December 2027 for Annex III, and only for logs “under their control”.

The milestones page on this site carries the timeline and the September 2026 update the month’s changes; the UK explainer covers the extraterritorial test. This report is the matrix those pages refer to.

Method and data

Primary documents, read on 5 September 2026 from EUR-Lex: Regulation (EU) 2024/1689 (OJ L, 12 July 2024) and Regulation (EU) 2026/1744 (OJ L, 24 July 2026), the latter read article by article for every amendment that touches an obligation on a deployer or provider of an AI system. Every application date in this report is quoted from Article 113 as amended by point (40) of Article 1 of the Omnibus, and every fine from Article 99 as amended by point (38). Commission documents: the Guidelines on the transparency obligations under Article 50 (C(2026) 5054 final, 20 July 2026), the AI literacy Q&A, the draft high-risk classification guidelines (19 May 2026), the enforcement-framework page (last updated 24 August 2026) and the 31 July 2026 enforcement announcement. National instruments: Denmark’s Law 467 of 14 May 2025, Italy’s Law 132/2025, Malta’s S.L. 591.05, Slovenia’s ZIUDHPUI, Greece’s Law 5321/2026, Germany’s KI-MIG (gesetze-im-internet.de), Poland’s act of 3 July 2026 (Dziennik Ustaw PDF), Ireland’s 30 July 2026 announcement.

Datasets: the SafeLegalAI Regulation Tracker, 324 records as of 5 September 2026 (/regulation/documents.json), of which 13 are EU-level records and 43 are member-state records; the country collection, 130 records, with a record for each of the 27 member states (one, Bulgaria, provisional); the tools directory, 129 records (/tools/tools.json), of which 47 are verified independent tools, 8 are headquartered in a member state and 35 list a member state or the EU among their markets. National designation status is taken from the community tracker maintained by the Future of Life Institute (last updated 17 June 2026) and updated from the four national instruments above where a primary document was read after that date.

Classification. An obligation is “in force” if its application date under amended Article 113 has passed; “deferred” if the Omnibus moved it; “not deferred” if the date was 2 August 2026 before and after. “Reaches a firm” means the duty binds a deployer of an AI system used in legal work or in the running of a firm; “reaches a vendor” means it binds a provider of an AI system sold to lawyers or courts. Obligations on providers of general-purpose AI models (Chapter V) are summarised, not tabulated: no legal-AI vendor in the tools directory is recorded as a model provider in that sense, and the Commission’s 18 July 2025 guidelines put the threshold for a downstream fine-tuner becoming a model provider at a training-compute level no legal-tech product in the directory approaches.

Limits. The Act’s high-risk classification is fact-specific and the final classification guidelines are not yet published; the Annex III point 8(a) reading in this report follows the wording and the draft guidelines, not a decided case. National penalty rules under Article 99(1) were read for Germany, Poland, Denmark, Italy, Slovenia, Greece and Malta only. The enforcement register relies on Commission pages for what has been published and on law-firm and trade reports for what has been reported; where no primary page was found that is stated. Nothing in this report is advice on compliance.

The matrix: obligations by date, article and enforcer

The table lists every obligation that reaches a law firm as deployer or a legal-AI vendor as provider, in order of application date. “MSA” is the national market surveillance authority under Article 70; “AI Office” is the Commission’s. The fine column gives the ceiling under Article 99 as amended; where an article is not listed in Article 99(3) to (5), the fine is whatever national law provides under Article 99(1).

Applies fromArticleObligationWhoEnforcerFine ceilingOmnibus change
2 Feb 2025Art. 4Take measures to support the development of AI literacy of staff and others operating AI systems on the deployer’s or provider’s behalfFirms and vendorsMSANone specific (Art. 99(1) national rules)Text replaced; “does not require … any specific level”
2 Feb 2025Art. 5(1)(a) to (h)Prohibited practices (manipulation, exploitation of vulnerability, social scoring, untargeted facial scraping, emotion recognition at work, and others)Firms and vendorsMSA (AI Office for its providers)EUR 35m or 7%New points (ba), (bb) added, applying from 2 Dec 2026
2 Aug 2025Arts. 53 to 55General-purpose AI model obligations (documentation, copyright policy, training-data summary; systemic-risk duties)Model providers onlyAI Office (powers from 2 Aug 2026)EUR 15m or 3% (Art. 101)None
2 Aug 2026Art. 50(1)Design systems that interact with people so that people are told they are dealing with AI, unless obviousVendorsMSAEUR 15m or 3%None
2 Aug 2026Art. 50(2)Mark synthetic audio, image, video or text output in a machine-readable, detectable way; exception for an “assistive function for standard editing” that does not substantially alter the deployer’s inputVendors (including general-purpose systems)MSA (AI Office for its providers)EUR 15m or 3%New Art. 111(4): systems on the market before 2 Aug 2026 have until 2 Dec 2026
2 Aug 2026Art. 50(3)Inform people exposed to an emotion-recognition or biometric-categorisation systemFirms (if deploying such systems)MSAEUR 15m or 3%None
2 Aug 2026Art. 50(4), first subpara.Disclose that image, audio or video content is a deepfakeFirmsMSAEUR 15m or 3%None
2 Aug 2026Art. 50(4), second subpara.Disclose that text “published with the purpose of informing the public on matters of public interest” is AI-generated, unless it has undergone human review or editorial control and a person holds editorial responsibilityFirmsMSAEUR 15m or 3%None; guidelines of 20 Jul 2026 define the exception
2 Aug 2026Art. 50(5)Provide the Art. 50 information clearly, at the latest at first interaction or exposureFirms and vendorsMSAEUR 15m or 3%None
2 Aug 2026Art. 99(5)Do not supply incorrect, incomplete or misleading information to an authorityFirms and vendorsMSA or AI OfficeEUR 7.5m or 1%SMC lower-of rule added
2 Dec 2026Art. 5(1)(ba), (bb)Prohibition on systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse materialFirms and vendorsMSAEUR 35m or 7%Inserted by Reg. 2026/1744
2 Dec 2027Arts. 8 to 21Provider requirements for high-risk systems (risk management, data governance, documentation, record-keeping, transparency to deployers, human oversight design, accuracy, conformity assessment, registration)Vendors whose system is Annex IIIMSAEUR 15m or 3% (Art. 16)Deferred from 2 Aug 2026
2 Dec 2027Art. 25A deployer that puts its name on, substantially modifies, or changes the intended purpose of a system so that it becomes high-risk is treated as its providerFirmsMSAEUR 15m or 3% (new Art. 99(4)(da) for Art. 25(2), (4))Deferred
2 Dec 2027Art. 26(1) to (7)Deployer duties: use per instructions; assign competent human oversight; ensure relevant input data where controlled; monitor and report risks and serious incidents; keep automatically generated logs “for a period appropriate to the intended purpose … of at least six months”; inform workers before use at the workplaceFirms whose system is Annex IIIMSAEUR 15m or 3%Deferred
2 Dec 2027Art. 27Fundamental-rights impact assessment before deploying an Annex III systemBodies governed by public law, private entities providing public services, and deployers under Annex III points 5(b) and (c)MSANot listed in Art. 99(4)Deferred; Art. 27(4) now lets a DPIA be cross-referenced
2 Dec 2027Art. 49Register the system in the EU databaseVendors; deployers only if public authoritiesMSAArt. 16 tierDeferred
2 Dec 2027Art. 86Give an affected person a clear explanation of the system’s role in a decision with legal or similarly significant effectFirms whose system is Annex IIIMSANot listed in Art. 99(4)Deferred
2 Aug 2028Chapter III for Annex IHigh-risk obligations for AI embedded in regulated productsNot legal-AI vendors, in practiceMSAArt. 16 tierDeferred from 2 Aug 2027
2 Aug 2030Art. 111(2)High-risk systems for public authorities already on the market must complyVendors supplying courts and public bodiesMSAArt. 16 tierRestated

Two features of the table are the ones a practitioner most often gets wrong. First, the Article 26 duties, including the six-month log rule, sit entirely in the deferred column, and they attach only to a system that is high-risk. A firm’s contract-review tool, research assistant or drafting model is not high-risk by reason of being used by lawyers; it becomes high-risk only if it falls within an Annex III use case, which for legal work means point 8(a) and for the firm’s own operations means point 4 (employment). Second, the Article 50 duties that did apply on 2 August 2026 are split between provider and deployer: the chatbot notice and output marking are the vendor’s; the deepfake and public-interest-text disclosures are the firm’s.

Annex III point 8(a) is the only entry that names the administration of justice. Its wording is quoted in key finding 3. Three readings follow from the text and the draft guidelines of 19 May 2026.

The system must be “intended to be used by a judicial authority or on their behalf”. A court that licenses a research or drafting system is deploying an Annex III system, and the vendor that supplies it is a provider of one; the judges’ record on this site sets out which courts have done so. A law firm using the same product to prepare a submission is not a judicial authority and is not acting on one’s behalf. The draft guidelines describe point 8(a) as covering AI “intended to assist judicial authorities in researching and interpreting law”; they do not extend it to parties.

The phrase “or to be used in a similar way in alternative dispute resolution” reaches arbitration and mediation. A vendor whose product is intended for use by an arbitral tribunal in applying law to facts is within the entry; a firm’s use of a tool to prepare for an arbitration is not.

Article 6(3) removes a system from Annex III where it “does not pose a significant risk of harm … including by not materially influencing the outcome of decision making”, and lists four conditions, among them a system “intended to perform a narrow procedural task” or “to improve the result of a previously completed human activity”. Case-management routing, anonymisation and summarisation for a court can fall here; a system that profiles natural persons never does (Article 6(3), last subparagraph). A provider that relies on the derogation must document the assessment (Article 6(4)).

The Annex III route that does reach ordinary firms is point 4: systems “intended to be used for the recruitment or selection of natural persons”, for decisions on promotion and termination, task allocation “based on individual behaviour or personal traits” and monitoring of performance. A firm that deploys such a tool for its own staff is a deployer of a high-risk system, and from 2 December 2027 the Article 26 duties, including the six-month log rule and the Article 26(7) duty to inform workers’ representatives, will apply to it in that capacity. None of that depends on what the firm’s lawyers do with AI for clients.

Deployer duties in practice

AI literacy. Article 4 has applied since 2 February 2025 to every deployer of any AI system, high-risk or not. The Omnibus replaced its text on 27 July 2026: deployers “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”, and the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The Commission’s Q&A of May 2025 says measures should be proportionate to roles and that “national market surveillance authorities may consider AI literacy when enforcing other obligations”. No fine tier names Article 4. Bar-level instruments have carried the duty into professional rules: the Law Society of Ireland’s guidance requires firms to meet it, the German federal bar’s guidance confirms that law firms are normally deployers, and the Slovak bar’s 2025 rules frame continuing education on AI as literacy; the regulation tracker links each.

Logs. Article 26(6) obliges a deployer of a high-risk system to keep the logs the system generates “to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data”. Article 19 places a matching six-month duty on the provider, and Article 12 requires the system to be capable of logging in the first place. The duty applies from 2 December 2027 for Annex III systems. For a system that is not high-risk, the Act imposes no retention period on the deployer; retention of prompts and outputs is then a matter of data-protection law and professional rules, which is the subject of the note-taker and chat-log report.

Human oversight. Article 26(2) requires deployers of high-risk systems to “assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support”, and Article 26(1) to use the system “in accordance with the instructions for use”. Article 26(5) adds monitoring, a duty to suspend use and inform the provider and the authority where the system presents a risk, and immediate reporting of serious incidents. All are deferred to 2 December 2027 and all attach only to Annex III systems.

Public-interest text. Article 50(4), second subparagraph, has applied since 2 August 2026 to any deployer. It obliges a deployer of a system that “generates or manipulates text which is published with the purpose of informing the public on matters of public interest” to disclose that the text is AI-generated, unless the content “has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication”. The Commission’s guidelines of 20 July 2026, as read for the September 2026 update and quoted in the tracker record, count “the administration of justice and law enforcement” among public-interest matters (paragraph 131), give client advice on regulatory compliance as an example outside scope, and say text is not published where it is “private, interpersonal correspondence (for professional purposes)”. Paragraph 134 defines human review as “the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement”, with fact-checking “a minimum requirement”; paragraph 135 rules out “spell-checking or grammatical correction” and “cursory editorial approval”; paragraph 136 says AI edits after sign-off void the exception. The line runs between a client memo, which is not published, and a firm’s website note on a judgment, which is.

Deepfakes and biometrics. Article 50(4), first subparagraph, and Article 50(3) apply to deployers from 2 August 2026. Neither is a typical law-firm activity; both are listed in the matrix because they are deployer duties with a live date and a 3% fine tier.

Prohibited practices. Article 5 has applied since 2 February 2025 to the “use” of a prohibited system as well as to placing it on the market. The Commission’s guidelines of 4 February 2025 interpret each practice. The two prohibitions inserted by the Omnibus, points (ba) and (bb), apply from 2 December 2026 and, under new Article 5(1a), reach the placing on the market of a system only where the generation is its intended purpose or “a reasonably foreseeable and reproducible outcome” absent adequate safeguards.

A legal-AI vendor is a provider of an AI system. Unless it also develops a general-purpose model, Chapter V does not apply to it; the Commission’s 18 July 2025 guidelines set the threshold at which fine-tuning a third-party model makes the modifier a model provider, and the tools directory records no legal-tech product at that scale. What applies now is Article 50.

Article 50(1) requires a system “intended to interact directly with natural persons” to tell them so, “unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect”. A drafting assistant used by a lawyer inside a document editor is a system interacting with a natural person; whether the AI nature is “obvious” is a question the guidelines address by context, and the duty is on the provider’s design, not on the deploying firm.

Article 50(2) requires providers of systems “generating synthetic audio, image, video or text content” to mark output “in a machine-readable format and detectable as artificially generated or manipulated”, with the technical solutions “effective, interoperable, robust and reliable as far as this is technically feasible”. The exception matters for legal drafting: the duty “shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof”. A tool that rewrites a clause the lawyer supplied is closer to the exception than one that drafts a memo from a prompt. Providers whose systems were on the market before 2 August 2026 have until 2 December 2026 (new Article 111(4)). The Code of Practice on Transparency of AI-generated Content, found adequate by the Commission in its opinion of 8 July 2026 and by the AI Board on 9 July (dates as recorded in the tracker record from the Commission opinion page), commits signatories to interoperable watermark detection by 2 February 2027; about 190 organisations had signed by the end of July, per the Commission’s 31 July news item.

Chapter III arrives for a vendor only if its system is high-risk, and then from 2 December 2027: risk management (Article 9), data governance (Article 10), technical documentation (Article 11), logging capability (Article 12), transparency to deployers (Article 13), human-oversight design (Article 14), accuracy and robustness (Article 15), conformity assessment and registration (Articles 43 and 49). The vendor documentation audit on this site records what 47 vendors publish today on the questions those articles will ask.

Article 25 works in the other direction. A firm that puts its own name on a high-risk system, substantially modifies one, or changes the intended purpose of a system so that it becomes high-risk “shall be considered to be a provider” and takes on Article 16; the Omnibus adds a fine tier for Article 25(2) and (4) (new Article 99(4)(da)). The provision applies from 2 December 2027 with the rest of Chapter III.

Who enforces: the AI Office and 27 national systems

The Commission’s enforcement-framework page, updated 24 August 2026, states the division. The AI Office enforces the rules for providers of general-purpose AI models, for AI systems developed by the same provider or group as the model, and for systems integrated into very large online platforms and search engines under the Digital Services Act; “the national competent authorities enforce the rules for other AI systems”; the European Data Protection Supervisor covers EU institutions. Every deployer duty on a law firm, and every Article 50 duty on a legal-AI vendor that does not itself build a general-purpose model, is therefore a matter for the member state where the firm or vendor is established or where the system’s output is used.

Article 70 requires each member state to designate at least one notifying authority and at least one market surveillance authority, and the deadline for doing so was 2 August 2025. The table gives the position for each of the 27 states: the status on the community tracker’s last update of 17 June 2026, corrected where a primary document read for this report post-dates it. “Designated” means both authorities are named in an adopted instrument.

Member stateStatus, 5 Sep 2026Market surveillance authority (lead) and single point of contactInstrument and dateSource basis
AustriaNot designatedAI Service Desk in RTR (support only; no MSA appointed)KOG § 20c, TKG § 194a (BGBl. I Nr. 6/2024) create the Service DeskTracker 17 Jun 2026; country record
BelgiumNot designatedBIPT expected per the 2025 to 2029 coalition agreementNone adoptedTracker 17 Jun 2026
BulgariaNot designatedMinistry of Electronic Governance coordinatesNone adoptedTracker 17 Jun 2026
CroatiaNot designatedCentral State Office for the Development of Digital Society coordinatesNone adoptedTracker 17 Jun 2026
CyprusDesignatedCommissioner of Communications (MSA, notifying authority, SPOC)Designation recorded by the trackerTracker 17 Jun 2026
CzechiaPartial (bill)Czech Telecommunication Office proposed as MSA; standards office as notifying authorityLegislative proposalTracker 17 Jun 2026
DenmarkDesignatedAgency for Digital Government (MSA, notifying, SPOC); Data Protection Authority and Court Administration also MSAsLaw 467 of 14 May 2025, in force 2 Aug 2025Tracker; tracker record
EstoniaNot designatedMinistry of Economic Affairs and Communications represents EstoniaNone adoptedTracker 17 Jun 2026
FinlandDesignatedTraficom (SPOC) with sectoral MSAs; four notifying authoritiesLaw 1377/2025, in force 1 Jan 2026Tracker 17 Jun 2026
FrancePartial (bill)DGCCRF proposed as coordinating MSA and SPOC; CNIL lead on data-protection aspectsLegislative proposalTracker 17 Jun 2026; country record
GermanyDesignatedBundesnetzagentur (MSA “soweit in diesem Gesetz nichts anderes bestimmt ist”, § 2(1)); coordination centre and complaints officeKI-MIG of 22 Jul 2026, BGBl. 2026 I Nr. 223, in force 29 Jul 2026gesetze-im-internet.de; Bundestag vote 11 Jun 2026
GreeceDesignatedHellenic DPA leads market surveillance; EETT notifying authority; Special Secretariat for AI coordinates (roles as recorded in the tracker from the Special Secretariat’s announcement; the Gazette record sits behind a script-rendered search page and was not re-opened for this report)Law 5321/2026, FEK A 114, 20 Jul 2026tracker record
HungaryDesignatedMinister for Enterprise Development (MSA, SPOC); National Accreditation Authority notifyingGovernment Decree 344/2025Tracker 17 Jun 2026
IrelandDesignatedAI Office of Ireland (SPOC, announced 30 Jul 2026, operational by 2 Aug); 15 sectoral MSAs under S.I. 366 of 2025Regulation of Artificial Intelligence Act 2026, signed 21 Jul 2026enterprise.gov.ie 30 Jul 2026; tracker
ItalyDesignatedNational Cybersecurity Agency (ACN) MSA and SPOC; AgID notifyingLaw 132/2025, in force 10 Oct 2025Tracker; tracker record
LatviaPartial (report)Consumer Rights Protection Centre proposed as SPOC among 12 to 14 MSAsMinistry report, no actTracker 17 Jun 2026
LithuaniaDesignatedCommunications Regulatory Authority (MSA, SPOC); Innovation Agency notifyingDesignation recorded by the trackerTracker 17 Jun 2026
LuxembourgPartial (bill)CNPD proposed as main MSA and SPOCDraft law of Dec 2024Tracker 17 Jun 2026
MaltaDesignatedMalta Digital Innovation Authority (lead MSA, SPOC, notifying); IDPC also MSAArtificial Intelligence Regulations, S.L. 591.05, 10 Oct 2025tracker record
NetherlandsPartial (bill)RDI (SPOC) and Autoriteit Persoonsgegevens coordinating among ten sectoral authoritiesDraft legislation, Apr 2026Tracker 17 Jun 2026
PolandDesignatedKomisja Rozwoju i Bezpieczenstwa Sztucznej Inteligencji (KRiBSI) as supervisory body (Art. 5); minister for informatisation as notifying authority (Art. 86)Act of 3 Jul 2026, Dz.U. 2026 poz. 1003 (27 Jul 2026), in force 14 days after publication with exceptions (Art. 127)Dziennik Ustaw PDF
PortugalPartial (announcement)ANACOM announced as MSA and SPOC, Sep 2025; notifying authority not identifiedAnnouncementTracker 17 Jun 2026; country record
RomaniaPartial (memorandum)ANCOM proposed as MSA and SPOC; ADR as notifyingGovernment memorandum, Mar 2026Tracker 17 Jun 2026
SlovakiaPartial (bill)Office for Digital Integrity proposed as MSA and SPOC; Ministry of Justice among sectoral MSAsDraft legislationTracker 17 Jun 2026
SloveniaDesignatedAKOS (SPOC, MSA); Information Commissioner supervises justice-related high-risk systemsZIUDHPUI, in force 21 Nov 2025tracker record
SpainPartial (bill)AESIA (MSA, SPOC, established 2023); DG for AI proposed as notifyingDraft lawTracker 17 Jun 2026; country record
SwedenPartial (proposal)Post and Telecom Authority proposed as coordinating MSA and SPOCSOU 2025:101 proposalTracker 17 Jun 2026; country record

On this count 12 states are designated, ten have a bill or formal proposal, and five have not designated. Two entries are the ones a law firm should read closely: Slovenia assigns justice-related high-risk systems to its Information Commissioner, and Slovakia’s draft gives the Ministry of Justice a sectoral role, which are the only two instances in the record of a justice body being named as an AI Act enforcer.

Enforcement so far

The register below lists every enforcement event with a date, the authority and the source, from the AI Office’s first powers to 5 September 2026.

DateAuthorityEventSource status
2 Feb 2025National MSAsProhibited practices and Article 4 apply; no published enforcement action locatedCommission timeline
2 Aug 2025AI OfficeChapter V obligations apply to model providers; enforcement powers not yet in forceArt. 113(b)
31 Jul 2026CommissionAnnounces that from 2 August the AI Office “together with national authorities” begins enforcing the ActCommission news page, read 5 Sep 2026
2 Aug 2026CommissionNews item “Safer and more transparent AI” puts fines for transparency breaches at “up to €15 million, or 3% of global annual turnover”Commission news page, as read for the September 2026 update
2 Aug 2026AI Office; national MSAsEnforcement powers apply; Article 50 applies; AI Act Complaint Tool, Whistleblower Tool and downstream-provider complaints channel availableCommission enforcement-framework page, updated 24 Aug 2026
Late Aug 2026AI OfficeRequests for information reported sent to providers of general-purpose AI models seeking documentation of internal security practices, cybersecurity testing, safeguards against unsanctioned model actions and incident-response protocols; recipients reported to include OpenAI, Anthropic and Google DeepMindReported (Fladgate AI round-up, August 2026; Help Net Security, 4 Aug 2026, describes the powers). No Commission page located on 5 Sep 2026
To 5 Sep 2026Any authorityFines or decisions under the Act publishedNone located

Two things were checked and not found. First, no market surveillance authority in any of the 12 designated states had published a decision, fine or formal notice under the Act by 5 September 2026; the enforcement powers of national authorities applied from 2 August 2026, and the deployer duties most likely to generate a case are deferred to December 2027. Second, several content sites assert that the AI Office issued fines “totalling EUR 85 million” in March 2026 for recruitment, biometric and credit-scoring systems. No Commission page, press release or Official Journal entry supports that, the AI Office’s sanctioning powers did not apply until 2 August 2026, and the Article 86 right of explanation cited in those pieces does not apply until 2 December 2027. The claim is recorded here only so that a reader who meets it knows it was checked.

Firms outside the EU

Article 2(1)(c) applies the Act to “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union”. A UK, US or Indian firm whose AI-assisted work product is used in the Union is within scope for the duties that bind deployers; the UK explainer sets out the test. Which authority would act is the one in the member state where the output is used. Article 99(4)(b) fines authorised representatives under Article 22, a role that only high-risk providers outside the Union must appoint, from 2 December 2027.

Timeline

DateEventSource
12 Jul 2024Regulation (EU) 2024/1689 published, OJ LEUR-Lex
1 Aug 2024Entry into force (Art. 113, first para.)EUR-Lex
2 Nov 2024Deadline for member states to publish fundamental-rights authorities (Art. 77(2)); all 27 haveCommunity tracker
2 Feb 2025Articles 4 and 5 applyArt. 113(a)
4 Feb 2025Commission guidelines on prohibited practicesCommission library
14 May 2025Denmark’s Law 467, first national supplementTracker record
10 Jul 2025General-Purpose AI Code of Practice publishedCommission
18 Jul 2025Commission guidelines on the scope of GPAI provider obligationsCommission
2 Aug 2025Chapter V applies; deadline for national authority designation (Art. 70)Art. 113(b)
25 Sep 2025Italy’s Law 132/2025 published (in force 10 Oct)Tracker record
10 Oct 2025Malta’s Artificial Intelligence Regulations in forceTracker record
19 Nov 2025Commission proposes the Digital Omnibus on AICommission
21 Nov 2025Slovenia’s ZIUDHPUI in forceTracker record
1 Jan 2026Finland’s Law 1377/2025 in forceCommunity tracker
19 May 2026Draft high-risk classification guidelinesCommission
8 Jul 2026Reg. 2026/1744 signed; Commission opinion on the transparency codeEUR-Lex; Commission
3 Jul 2026Poland’s act on AI systems dated (published 27 Jul)Dziennik Ustaw
20 Jul 2026Article 50 guidelines C(2026) 5054 final; Greece’s Law 5321/2026Commission; FEK
21 Jul 2026Ireland’s Regulation of Artificial Intelligence Act 2026 signedenterprise.gov.ie
22 Jul 2026Germany’s KI-MIG dated (in force 29 Jul)BGBl. 2026 I Nr. 223
24 Jul 2026Reg. 2026/1744 published, OJ LEUR-Lex
27 Jul 2026Reg. 2026/1744 in force; Article 4 text replacedArt. 4 of Reg. 2026/1744
2 Aug 2026Article 50 applies; AI Office and national enforcement powers applyArt. 113
Late Aug 2026AI Office requests for information to model providers on security practices (reported)Law-firm round-up
2 Dec 2026Art. 5(1)(ba), (bb) apply; Art. 50(2) marking mandatory for existing generative systemsAmended Art. 113(a); Art. 111(4)
2 Feb 2027Transparency-code signatories’ watermark-detection commitmentCode of Practice
2 Aug 2027Delegated acts under new Art. 2(13) dueReg. 2026/1744
2 Sep 2027Post-market monitoring guidance and template due (Art. 72(3))Reg. 2026/1744
2 Dec 2027Chapter III, Sections 1 to 3 apply to Annex III systems; Arts. 25, 26, 27, 49, 86Amended Art. 113(c)(i)
2 Aug 2028Chapter III applies to Annex I systemsAmended Art. 113(c)(ii)
2 Aug 2030Public-authority high-risk systems already on the market must complyAmended Art. 111(2)

What to watch

The Commission’s two September 2026 task forces on the transparency code will produce the first practical detail on how Article 50(2) marking is to be read for text, which is the output legal-AI systems produce. The final high-risk classification guidelines, expected by the end of 2026, will settle how far point 8(a) extends to systems used by parties. No harmonised standard had been cited in the Official Journal by 5 September 2026; the Commission’s standardisation page, updated 3 August 2026, records prEN 18286 in public enquiry since October 2025.

On the national side, the Netherlands, France, Spain, Sweden and the remaining partial states have bills or proposals that would complete the enforcement map before the December 2027 date; Belgium, Austria, Bulgaria, Croatia and Estonia have none on record. The regulation tracker will carry each designation as it is adopted, and the monthly EU AI Act updates the enforcement events.

The open question is which duty produces the first published decision. The deployer duties are deferred, so the candidates are Article 50 and Article 5, and the authorities with a live case would be the AI Office for a model provider and a national authority for a system provider or deployer. Nothing in the record on 5 September 2026 says which it will be.

Three sentences journalists can quote

As of 5 September 2026, five EU AI Act obligations reach a law firm or legal-AI vendor in force and six were deferred to 2 December 2027 by Regulation (EU) 2026/1744, including every deployer duty in Article 26 and the six-month log rule.

Twelve of 27 member states have designated their AI Act enforcement authorities in an adopted instrument, ten have a bill or proposal, and five have none; Germany, Poland and Greece completed theirs in July 2026 and Ireland added a national AI Office.

No fine or decision under the AI Act had been published by the Commission’s AI Office or by any national authority by 5 September 2026; the first reported step is a set of requests for information to general-purpose model providers in late August.

Appendix A: data tables

A1. Article 99 fine ceilings as amended by Regulation (EU) 2026/1744

TierConductCeilingSME ruleSMC rule (new)
Art. 99(3)Prohibited practice (Art. 5)EUR 35m or 7% of worldwide annual turnover, whichever higherLower of the twoNot extended
Art. 99(4)Breach of Arts. 16, 22, 23, 24, 25(2) and (4) (new), 26, 31, 33(1), (3), (4), 34, 50EUR 15m or 3%, whichever higherLower of the twoLower of the two (Art. 99(6a))
Art. 99(5)Incorrect, incomplete or misleading information to a notified body or authorityEUR 7.5m or 1%, whichever higherLower of the twoLower of the two (Art. 99(6a))
Art. 101GPAI model provider breaches (Commission)EUR 15m or 3%n/an/a

A2. Articles reaching a firm or vendor with no dedicated fine tier

ArticleDutyConsequence of breach
Art. 4AI literacy measuresNational penalties under Art. 99(1), if any; may be considered by an MSA when enforcing other duties (Commission Q&A)
Art. 27Fundamental-rights impact assessmentNot listed in Art. 99(4); national rules
Art. 86Right to explanationNot listed in Art. 99(4); national rules and other remedies

A3. Regulation Tracker records used

RecordTypeDate of current version
eu-ai-actStatute27 Jul 2026 (as amended)
eu-digital-omnibus-ai-2026-1744Statute24 Jul 2026
eu-commission-article-50-transparency-guidelinesGuidance20 Jul 2026
eu-code-of-practice-ai-generated-contentGuidance9 Jul 2026
eu-commission-draft-guidelines-high-risk-classificationConsultation19 May 2026
eu-commission-guidelines-prohibited-ai-practicesGuidance4 Feb 2025
eu-commission-guidelines-gpai-providersGuidance18 Jul 2025
eu-commission-ai-literacy-qaGuidance1 May 2025
eu-gpai-code-of-practiceGuidance10 Jul 2025
dk-lov-467-2025-ai-supplementary-provisionsStatute14 May 2025
it-legge-132-2025-intelligenza-artificialeStatute25 Sep 2025
mt-artificial-intelligence-regulations-sl-591-05Regulation10 Oct 2025
si-ziudhpui-ai-act-implementationStatute21 Nov 2025
gr-law-5321-2026-ai-act-implementationStatute20 Jul 2026

Germany’s KI-MIG, Poland’s act of 3 July 2026 and Ireland’s Act 2026 were read from their official sources for this report and are queued for tracker records.

Appendix B: sources

Appendix C: changes to this report

None since first publication.