EU AI Act: on 2 August 2026, Europe switches on penalties for the most powerful AI models
From 2 August 2026, the grace period of the EU AI Act ends for general-purpose AI (GPAI) models: the Commission can now fine the providers of the most powerful models — both for how they were trained and for what their systems do once deployed. For companies in regulated sectors — aerospace, defence, energy, O&G, industry — this is not a distant legal matter but an immediate governance constraint that flows up the entire AI supply chain. Cardan-AI analysis: the 2026 challenge is no longer to adopt AI, but to prove that its adoption is traceable, documented and compliant.
The AI Act timeline reaches a decisive milestone. Since 2 August 2025, the obligations on general-purpose AI (GPAI) models have been in force; from 2 August 2026, the European Commission gains the power to sanction non-compliance. In practice, providers of the most capable models — those posing systemic risk — face fines covering both training data and methods and the behaviour of their systems once deployed. The period when compliance rested on goodwill is over.
For a company that uses AI, the mistake would be to assume this only concerns model providers. Liability travels along the chain: as soon as you embed a foundation model in a product, an industrial process or a decision-support tool, you become accountable for documentation, risk classification and monitoring of your use cases. In high-risk sectors — aviation safety, defence systems, energy-plant supervision — this requirement stacks on top of already dense certification frameworks.
The real cost is not the theoretical fine, but the standstill: an AI deployment paused for lack of a compliance file, a supplier unable to provide the expected contractual guarantees, a strategic project stuck in legal review. Organisations that planned ahead hold a concrete advantage: a map of their AI use cases, a register of the models in use, compliance clauses in supplier contracts, and internal governance clarifying who validates what.
Cardan-AI analysis: regulation, often experienced as a brake, is in fact an accelerator for those who address it early. Structuring AI governance — a use-case inventory, risk classification, a chain of responsibility, supplier requirements — turns a compliance constraint into a foundation of trust for customers, regulators and partners. This is exactly the work we do with industrial and innovation leaders: making AI adoption not only high-performing, but defensible.
Analysis by
Cardan-AI Intelligence
Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.
Let's talk about your next competitive edge
Thirty minutes to identify the two or three use cases in your operations that pay for themselves within the first year.
