The EU AI Act Enters Enforcement: What Businesses in Europe, the GCC, and Central Asia Should Be Doing Now

On 2 August 2026, enforcement of the European Union's Artificial Intelligence Act begins at national and EU level for the provisions already applicable. The transparency, marking and labelling obligations for AI systems that interact with people or generate synthetic content become applicable. Governance, penalty, and general-purpose AI provisions that entered into application in August 2025 pass from grace period to active supervision. The full institutional architecture of European AI regulation, which the Union has been assembling since Regulation (EU) 2024/1689 entered into force on 1 August 2024, is operational.
Under the AI Omnibus, adopted by the co-legislators in June 2026 and entering into force on 27 July 2026, the substantive obligations for high-risk AI systems have been postponed. Standalone high-risk systems under Annex III, which cover the sensitive use cases most organisations associate with the Act, will apply by 2 December 2027 at the latest. High-risk systems embedded as safety components in regulated products under Annex I will apply by 2 August 2028 at the latest. The obligations were not withdrawn. The timeline was restructured, tied to the availability of harmonised standards, and given fixed backstop dates.
For businesses in the European Union, the compliance question has now split into two tracks. The provisions applicable from 2 August 2026, including the transparency framework under Article 50, the general-purpose AI regime with its full enforcement powers, and the penalty architecture, require compliance from that date. The high-risk obligations require compliance work to begin now, calibrated to backstop dates in December 2027 and August 2028.
For businesses headquartered outside the European Union but operating within its economic perimeter, the Act reaches further than many assume, and the strategic implications extend well beyond compliance.
The broader pattern is equally consequential. In the GCC and Central Asian jurisdictions in which Pnyx Hill advises, there are growing signs of convergence around risk-based AI governance principles, with local frameworks, ethics documents, and national programmes drawing selectively on elements of the European architecture while adapting emphasis and enforcement to national strategic priorities. The pattern is familiar. It played out with data protection under the General Data Protection Regulation, and there are indications that it is now playing out with artificial intelligence.
This article examines the structure of the EU AI Act, the compliance timeline as revised by the AI Omnibus, the obligations and penalties businesses now face, the extraterritorial reach that pulls non-EU operators into scope, the emerging convergence of AI regulation across the GCC and Central Asia, and the strategic work senior leadership teams should be doing in the period ahead. It builds on our earlier analysis of Dubai's agentic AI initiative, which examined the same structural question from the opposite regulatory pole: accelerated adoption rather than regulatory restraint.

The Architecture of the EU AI Act
The AI Act was formally adopted as Regulation (EU) 2024/1689 and published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024. As a regulation, it applies directly and uniformly across all twenty-seven Member States, though Member States retain responsibility for designating market surveillance authorities and adopting national penalty regimes within the parameters set by the Act.
The framework organises AI systems into four risk categories, each carrying a distinct set of obligations.
Unacceptable risk. Eight practices are prohibited outright under Article 5, applicable since 2 February 2025. These include social scoring, real-time remote biometric identification for law enforcement in publicly accessible spaces, emotion recognition in workplaces and educational institutions, untargeted scraping of the internet or CCTV material to build facial recognition databases, harmful AI-based manipulation and exploitation, individual criminal offence risk assessment, and biometric categorisation to deduce protected characteristics. The AI Omnibus introduces a further prohibition on AI systems used to generate child sexual abuse material and non-consensual intimate or sexually explicit content.
High risk. AI systems that pose serious risks to health, safety, or fundamental rights are subject to a comprehensive set of obligations covering risk management, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy, robustness, and cybersecurity. This category splits into two branches: standalone high-risk systems used in the sensitive areas set out in Annex III, and AI systems that are safety components of, or constitute, products covered by the Union harmonisation legislation set out in Annex I.
Transparency risk. Systems that interact with individuals, generate synthetic audio, image, video, or text content, or perform emotion recognition or biometric categorisation are subject to transparency, marking and labelling obligations under Article 50. These include disclosure that a person is interacting with an AI system, machine-readable marking of AI-generated or manipulated content, and clear labelling of deep fakes and certain AI-generated text on matters of public interest.
Minimal or no risk. The majority of AI applications fall into this category and are not subject to specific obligations under the Act, though voluntary codes of conduct are encouraged.
A separate horizontal regime applies to providers of general-purpose AI models. This regime, set out in Chapter V and applicable from 2 August 2025, addresses transparency, copyright compliance, and, for the most advanced models classified as carrying systemic risk, additional obligations covering model evaluation, adversarial testing, incident reporting, and cybersecurity. The voluntary General-Purpose AI Code of Practice, published on 10 July 2025, provides a formally endorsed pathway for demonstrating compliance with these obligations.
Institutional oversight is shared between the European Commission, which supervises providers of general-purpose AI models directly through the European AI Office, and Member State market surveillance authorities, which enforce the rules applicable to specific AI systems within their jurisdictions.
The Compliance Timeline as Revised by the AI Omnibus
Several phases of the Act are already active, and the sequence has been modified by the AI Omnibus, which was politically agreed by the co-legislators on 7 May 2026, adopted by the European Parliament plenary on 16 June 2026, and entered into force on 27 July 2026.
2 February 2025. The prohibited practices under Article 5 and the original AI literacy requirements under Article 4 entered into application. Under the AI Omnibus, the binding corporate obligation on providers and deployers to ensure AI literacy among their staff has been replaced by a non-binding approach, with the European Commission and Member States responsible for encouraging AI literacy through training opportunities, informational resources, and exchanges of good practice. The obligation on deployers of high-risk AI systems under Article 26(2) to assign human oversight only to staff with the necessary training, competence, and support remains in place.
2 August 2025. The obligations for providers of general-purpose AI models under Chapter V entered into application. The rules governing notified bodies, governance under Chapter VII, confidentiality under Article 78, and the penalty framework under Article 99 became applicable on the same date. Member States were required to have national penalty rules in place by this date.
2 August 2026. Enforcement of the AI Act begins at national and EU level for the provisions already applicable. The transparency, marking and labelling obligations under Article 50 become applicable. Measures supporting innovation come into effect, and under Article 57(1) each Member State must have at least one AI regulatory sandbox operational at national level by this date. The Commission's enforcement powers over providers of general-purpose AI models, including the ability to impose fines under Article 101, also become applicable.
2 December 2026. The marking obligations under Article 50 apply to AI systems generating audio, image, video, or text content that were placed on the market before 2 August 2026 and require technical adaptations for machine-readable detectability.
2 December 2027. The substantive obligations for standalone high-risk AI systems classified under Article 6(2) and Annex III apply. This date operates as a backstop. If the Commission adopts a decision confirming that adequate measures in support of compliance are available earlier, the obligations may apply six months after that decision.
2 August 2028. The substantive obligations for high-risk AI systems classified under Article 6(1) and Annex I apply. This date also operates as a backstop, with earlier application possible twelve months after a Commission decision confirming standards availability.
2 August 2027. Providers of general-purpose AI models placed on the EU market before 2 August 2025 must be in compliance with the AI Act obligations by this date.
Two features of the revised timeline warrant emphasis.
Enforcement of the Act begins on 2 August 2026 even though the high-risk obligations do not yet apply. The framework becomes an operational regulatory instrument on that date for the provisions in force.
The postponement of high-risk obligations is not a suspension. It responds to the delayed availability of harmonised standards developed by CEN and CENELEC and to the need to complete the network of notified bodies and national competent authorities. The obligations themselves remain, and the backstop dates apply regardless of whether the supporting infrastructure is ready.
Business Obligations and the Cost of Non-Compliance
The Act allocates obligations across four principal categories of economic actor. Providers, meaning organisations that develop AI systems or general-purpose AI models and place them on the EU market under their own name, carry the most extensive obligations. Deployers, meaning organisations that use AI systems in the course of their professional activity, carry a more focused but still substantive set of duties. Importers and distributors carry compliance verification and information provision obligations along the supply chain.
For high-risk AI systems, once the applicable date arrives, provider obligations include establishing a documented risk management system across the lifecycle of the system, ensuring appropriate data governance and quality, producing and maintaining detailed technical documentation, implementing logging and record-keeping, providing transparency and information to deployers, designing systems to enable effective human oversight, and ensuring appropriate levels of accuracy, robustness, and cybersecurity.
Providers must subject high-risk systems to conformity assessment before placing them on the market and, in defined cases, must register them in the EU database maintained by the AI Office.
Deployer obligations include using systems in accordance with the provider's instructions, ensuring appropriate human oversight, monitoring operation and reporting incidents, and, for certain public-sector and essential-service deployers, conducting a fundamental rights impact assessment before deployment.
For providers of general-purpose AI models, obligations under Chapter V include preparing and keeping up to date technical documentation of the model, providing information to downstream providers who integrate the model, complying with Union copyright law, and publishing a sufficiently detailed summary of the content used for training.
Providers of GPAI models with systemic risk face additional obligations covering model evaluation, adversarial testing, systemic risk mitigation, serious incident reporting, and adequate cybersecurity protection of the model and its physical infrastructure.
The Act's penalty framework was established from 2 August 2025, when Member States were required to have national penalty rules in place. From 2 August 2026, enforcement begins at national and EU level for the provisions already applicable, including the Commission's power to impose fines on providers of general-purpose AI models under Article 101.
Under Article 99, non-compliance with the prohibitions in Article 5 attracts administrative fines of up to EUR 35 million or, for undertakings, up to 7 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. Non-compliance with the obligations of providers, authorised representatives, importers, distributors, deployers, notified bodies, or the transparency obligations under Article 50 attracts fines of up to EUR 15 million or 3 per cent of turnover.
The supply of incorrect, incomplete, or misleading information to notified bodies or national competent authorities attracts fines of up to EUR 7.5 million or 1 per cent of turnover.
For small and medium-sized enterprises, including start-ups, the applicable fine is the lower of the amount or the percentage. Under Article 101, the Commission may impose fines of up to EUR 15 million or 3 per cent of worldwide turnover on providers of general-purpose AI models directly.
The financial exposure is only part of the picture. Non-compliance also carries the risk of enforced withdrawal of products from the EU market, reputational consequences in a jurisdiction whose supervisory authorities publish enforcement decisions, and downstream contractual exposure to customers and business partners who require regulatory conformity as a condition of engagement. For businesses in regulated sectors, particularly financial services, healthcare, and critical infrastructure, an AI Act enforcement action may also trigger sector-specific supervisory attention.
Extraterritorial Reach: Why Non-EU Businesses Are Already in Scope
The scope of the Act, defined in Article 2, extends well beyond providers established in the European Union. It applies to providers placing AI systems on the EU market or putting them into service in the Union irrespective of where the provider is established. It applies to deployers of AI systems located in the Union. And, most consequentially for businesses in the GCC, Central Asia, and beyond, it applies to providers and deployers established or located outside the Union where the output produced by the AI system is used in the Union.
This third limb of the scope test is the mechanism through which the Act reaches non-EU operators. A financial services provider in Abu Dhabi using an AI system to score credit applications from customers within the EU falls within scope. A logistics operator in Almaty using a scheduling system whose outputs affect operations at an EU port falls within scope. A software vendor in Riyadh licensing an AI-enabled product to EU-based customers falls within scope. The legal test is not the location of the provider or deployer, but whether the output is used in the Union.
Article 22 requires providers of high-risk AI systems established in third countries to appoint an authorised representative established in the Union before placing the system on the EU market.
The authorised representative is responsible for verifying that the required documentation has been prepared, cooperating with competent authorities, and, where necessary, terminating its mandate if it considers the provider to be acting in breach of the Act. For providers of general-purpose AI models, a similar authorised representative requirement applies under Article 54.
Where an organisation places an AI system or model on the EU market, deploys AI within the Union, or falls within the Act's extraterritorial scope because AI-generated output is used in the Union, relevant obligations under the Act may apply depending on the organisation's role and the system or model concerned. For senior leadership teams in the GCC and Central Asia with material European exposure, whether through direct sales, licensing, cross-border data flows, or investor commitments, the prudent operating assumption should be that EU AI Act applicability requires formal assessment rather than being dismissed on the basis of establishment outside the Union.
Regulatory Convergence Across the GCC and Central Asia
The Brussels Effect, the tendency of EU regulatory frameworks to become de facto reference standards internationally, has been observed across other areas of technology and data regulation. In the AI space, there are growing signs of convergence around risk-based governance principles. Jurisdictions across the GCC and Central Asia are moving quickly, and while national frameworks reflect distinct strategic priorities, elements of the European risk-based logic are increasingly influencing international AI governance approaches.
The United Arab Emirates is the most advanced case. The country's National Strategy for Artificial Intelligence 2031 frames AI as a national economic priority. In 2026, the UAE launched a federal programme to transition at least fifty per cent of government services and operations to Agentic AI models within two years, supported by a Cabinet-approved governance and implementation framework. In parallel, HH Sheikh Hamdan bin Mohammed bin Rashid Al Maktoum launched a two-year initiative to accelerate the transition of Dubai's private sector toward Agentic AI, including training tracks administered through the Dubai Chamber of Commerce, government-funded incubators, and dedicated investment vehicles. This is an initiative and enabling framework rather than a general statutory obligation on Dubai companies. Alongside these adoption programmes, the UAE has been developing governance mechanisms that reflect risk-based logic while emphasising economic acceleration rather than restraint.
The Kingdom of Saudi Arabia has taken a parallel path through the Saudi Data and Artificial Intelligence Authority (SDAIA). SDAIA's AI Ethics Principles establish a framework of fairness, privacy and security, humanity, social and environmental benefits, reliability and safety, transparency and explainability, and accountability and responsibility. The structure reflects the fundamental rights orientation of leading international frameworks, calibrated to national data protection legislation and the Kingdom's Vision 2030 strategic priorities. SDAIA also administers the country's Personal Data Protection Law and coordinates AI governance across public sector entities.
Kazakhstan has moved to formalise its digital and AI regulatory environment through legislative reform and the Astana International Financial Centre's ongoing work on financial technology and digital asset frameworks. The country's Digital Kazakhstan agenda and the Astana Hub innovation ecosystem provide the operational platform, while a national AI development framework has been under active development. The pattern is consistent with the broader Central Asian trajectory: adopting the substantive logic of leading international frameworks while calibrating enforcement and sector emphasis to national economic strategy.
The convergence is not accidental.
Jurisdictions with strong ambitions to attract international AI investment and to integrate into global technology supply chains have a clear commercial interest in aligning with the framework that governs the largest single regulated market for AI.
Divergence carries the cost of market access. Alignment carries the benefit of interoperability. The direction of travel is discernible even where specific national laws are still in formation.
What Leaders Should Be Doing in the Period Ahead
For senior leadership teams, the work required over the next twenty-four months is not primarily legal. It is structural. Regulatory readiness at this scale is an operating capability, not a document exercise. Four workstreams should be underway.
AI inventory and risk classification. Every AI system in use across the organisation, whether developed internally, procured from vendors, or embedded in third-party products, should be identified, documented, and classified against the risk categories of the Act. Without a complete inventory, no compliance judgment is defensible. For transparency-risk systems, the inventory needs to be operational now, given the 2 August 2026 date. For high-risk systems, it needs to be operational well before the December 2027 and August 2028 backstops.
Governance architecture. The Act requires human oversight, accountability, documentation, and lifecycle risk management for high-risk systems, and defined disclosure and content-marking practices for transparency-risk systems. These are governance functions, not compliance artefacts. Leadership teams should establish or reinforce the internal structures that make ongoing compliance possible: an AI governance committee, defined ownership at senior management level, clear escalation paths for incidents, and documented processes for pre-deployment assessment. Under the AI Omnibus, the horizontal AI literacy obligation on providers and deployers has been softened, but the training and competence obligation for staff exercising human oversight over high-risk systems under Article 26(2) remains.
Supplier and model-chain due diligence. Most organisations do not build their AI systems from first principles. They procure, integrate, and fine-tune. Under the Act, compliance obligations flow through the supply chain, and provider obligations cannot be discharged without cooperation from upstream model developers and downstream deployers. Contractual arrangements, information flows, and technical documentation requirements need to be aligned across the chain well before enforcement affects the operational relationship.
Strategic positioning for the jurisdictions that will follow. For businesses operating across the GCC, Central Asia, or other emerging AI regulatory environments, the operating principle should be to design for the highest applicable standard. Building governance and compliance infrastructure to EU standards positions the organisation for whatever regional framework arrives next, without requiring successive rebuilds. It also becomes a market-access differentiator when regulators, investors, or institutional customers assess AI maturity.
The organisations that will handle the transition best are those that treat the AI Act as an operating question first, a legal question second, and a documentation question third. The organisations that will struggle are those that reverse the order.
Synthesis: Compliance as Strategic Infrastructure
The EU AI Act should not be read in isolation. It represents the most comprehensive binding risk-based AI regulatory framework to date, and elements of its architecture are increasingly visible in AI governance approaches developing across major international markets. Businesses subject directly to the Act face a defined compliance perimeter with defined deadlines and defined penalties. Businesses not directly subject to it are nevertheless operating in an environment in which its risk-based logic sets the reference point.
For senior leadership teams, three implications follow.
Regulatory readiness is becoming a form of market-access infrastructure. Institutional customers, regulated counterparties, and increasingly investors are treating documented AI governance as a threshold requirement rather than a value-add. The ability to demonstrate a coherent AI governance posture, aligned with the standards set out in the EU framework, is moving from optional to expected.
The compliance work and the strategy work are not separate. The AI inventory, the risk classification, the governance architecture, and the supplier due diligence produce the underlying information base on which strategic decisions about AI investment, deployment, and positioning are made. Organisations that build these capabilities as compliance-only exercises leave the strategic value unrealised. Organisations that build them as decision-support infrastructure convert regulatory cost into strategic capability.
The cross-jurisdictional dimension is not incidental. For businesses operating across the EU, GCC, and Central Asia, or considering expansion into any of these regions, the ability to design once and adapt locally is a structural advantage. Fragmenting compliance approaches by jurisdiction produces avoidable cost and avoidable inconsistency. Aligning to the highest applicable standard, with local calibration where required, produces both regulatory conformity and operational coherence.
Pnyx Hill advises boards and senior leadership teams navigating this class of decision across the GCC, Europe, and Central Asia. The firm's Strategy, Governance, Risk and Compliance practice operates directly at the intersection of the regulatory frameworks that shape AI adoption and the strategic decisions that determine how organisations position themselves under them. Regulatory readiness is delivered as an institutional capability, not a document set. Strategic advisory is grounded in the operational and governance realities that make regulatory readiness possible. Principals engage directly, without the layered delivery models that separate senior judgment from execution in larger structures.
The next twenty-four months will define AI regulatory practice across Europe, and the convergence pattern across the GCC and Central Asia will develop in parallel. Organisations that treat this period as a compliance sprint will finish it with documents. Organisations that treat it as strategic infrastructure will finish it with a durable competitive position.
