A bright sunlit European courthouse with a digital AI compliance checklist projected on the facade, blue and gold EU colours, vibrant morning light, no text visible
News

The Grace Period Is Over: EU AI Act Enforcement Begins as US Stalls and China Fines

The EU AI Act is now actively enforced. France's CNIL is auditing credit scoring algorithms. China fined 12 companion AI apps. The US Great American AI Act stalled in the House. Global AI regulation has split into three speeds.

EUAI ActRegulationEnforcementChina

The theoretical era of AI compliance ended on August 2, 2026. The European Union’s AI Act is now actively enforced for high-risk systems, deployer transparency duties, and general-purpose AI model obligations. The grace period that gave companies two years to prepare is over, and regulators are not treating it as a soft launch.

🔍 THE BOTTOM LINE

The global AI regulation landscape has fractured into three speeds: the EU is enforcing, China is fining, and the United States is gridlocked. Any company deploying AI in the European market now carries strict legal duties — system logs, post-market monitoring, incident reporting within 15 days. Fines reach €35 million or 7% of global annual turnover. Meanwhile, 14 different US state-level frameworks create a compliance maze for any company operating nationally.

What Actually Changed on August 2

The AI Act became generally applicable on August 2, as documented by TechGDPR. The Digital Omnibus, published in the Official Journal on July 24, brought amendments that delayed some obligations while making others immediately binding.

What is now live:

  • Transparency obligations for providers and deployers of generative and interactive AI systems
  • Bans on the riskiest AI uses (already in effect since February 2025)
  • General-purpose AI model obligations — providers of foundation models exceeding 10^25 FLOPs must submit monthly systemic risk evaluations
  • Fines: €7.5 to €35 million or 1% to 7% of worldwide annual turnover, whichever is higher

What was delayed:

  • High-risk AI systems (employment, education, administration, justice) postponed to December 2027
  • AI in regulated products (medical devices, vehicles, aviation) postponed to August 2028
  • AI content labelling postponed to December 2026

The delays sound like relief, but the transparency and GPAI obligations alone are already reshaping how companies operate in Europe.

France Moves First

The most aggressive early enforcement signal came from France. According to Cubbbix’s August regulation report, the French data protection authority (CNIL) issued formal information requests to 14 financial institutions operating credit scoring algorithms. They demanded the technical documentation required for high-risk systems. Three institutions requested extensions. CNIL denied them, citing the two-year preparation window companies had since the Act passed in 2024.

This matters because credit scoring sits squarely in the high-risk category. Even though the full high-risk obligations were delayed to December 2027, CNIL is using existing data protection authority powers to audit systems now. The message: if your AI makes decisions about people in France, you are already on notice.

China’s Companion AI Crackdown

China took a different path — vertical, precise, and fast. The Cyberspace Administration of China (CAC) activated companion AI and emotional support AI regulations on July 15. Within three weeks, the CAC issued 12 fines totalling 4.2 million RMB.

The primary violations: AI companion apps failing to label synthetic emotional responses and failing to verify the age of users interacting with persuasive AI avatars. This follows the pattern we covered when ByteDance and Alibaba pulled their AI companion features ahead of the July 15 deadline.

China’s approach targets specific use cases — generative AI, recommendation algorithms, deep synthesis, companion AI — rather than regulating the technology broadly. Each requires registration and security assessment before public release. The fines prove the rules have teeth.

The United States: Gridlocked

The US federal landscape fractured entirely. The “Great American AI Act” passed the Senate in late June with a strict federal preemption clause designed to overwrite state-level AI regulations. But in the House, a coalition of state attorneys general from California, Colorado, and New York successfully lobbied to strip the preemption clause. The bill stalled indefinitely in the House Judiciary Committee.

The result: companies operating nationally must navigate 14 different state-level AI frameworks. Colorado’s SB-205 algorithm discrimination rules are fully active. California’s Frontier AI Safety Act passed its final assembly vote and awaits the governor’s signature. A single AI hiring tool that is compliant in Texas may trigger statutory fines in Illinois and Colorado.

Corporate legal teams have abandoned hope of a unified US federal standard for 2026. The immediate strategy requires geo-fencing AI features or adopting the strictest state standard across the entire US user base — a de facto California and Colorado compliance regime.

The UK Joans the Fray

The United Kingdom’s AI Regulation and Safety Bill cleared the House of Commons in mid-August. The bill formalises the AI Safety Institute’s statutory powers, granting the legal right to inspect foundation models before deployment. Companies developing highly capable general-purpose AI must share safety test results with the government. Royal Assent is expected by October.

This brings the UK closer to the EU model than the US model — a signal that post-Brexit Britain is not using regulatory freedom to go soft on AI.

What This Means for New Zealand

New Zealand companies selling AI-powered services into Europe now face real compliance obligations. If your product uses AI to make decisions about EU residents — credit scoring, employment screening, educational assessment — you operate in a regulated industry under European law, regardless of where you are based.

The Ministry of Health’s guidance on AI in patient care and the Digital Government’s public service AI framework remain advisory rather than statutory. But as the EU and China move from theory to enforcement, the pressure on New Zealand to move from voluntary guidelines to binding rules will grow. The EU AI Act effectively sets a de facto global standard — any NZ company with international ambitions will need to meet it.

The Compliance Infrastructure Problem

The most immediate friction point is not legal interpretation but data infrastructure. The EU AI Act, the proposed Indian liability framework, and Colorado’s anti-discrimination rules all require extreme data provenance. Companies must prove what data trained their models, how it was filtered for bias, and how the model behaves in production.

If a high-risk AI system denies a loan to a consumer in France, the deployer must be able to produce the exact model weights, training data state, and decision logic active at the moment of denial. Legacy data pipelines cannot do this. MLOps teams are frantically retrofitting compliance logging into deployment pipelines — and the storage costs and latency overhead for companies processing millions of AI inferences daily are substantial.

❓ FAQ

Does the EU AI Act apply to New Zealand companies? Yes, if you deploy AI systems in the EU market or your AI outputs reach EU residents. The Act applies based on where the AI is used, not where the company is based.

What are the fines for non-compliance? Fines range from €7.5 million to €35 million, or 1% to 7% of worldwide annual turnover, whichever is higher. SMEs and startups may receive proportionate consideration.

What’s the difference between the EU and US approaches? The EU uses a risk-based classification system with binding obligations. The US has no federal AI law — instead, 14 states have their own frameworks with different requirements, creating a patchwork compliance burden.

Is China’s approach stricter than the EU’s? Different, not necessarily stricter. China targets specific use cases (companion AI, generative AI, recommendation algorithms) with registration and security assessment requirements. The EU regulates broadly by risk category. Both are now actively enforced.

🔍 THE BOTTOM LINE

The grace period is over. Three of the world’s largest economies are now enforcing AI rules — at different speeds, with different philosophies, but with real consequences. France is auditing banks. China is fining apps. The US is stuck. For any company building AI that touches human lives, compliance is no longer a future problem. It is today’s cost of doing business.

📰 Sources

— CJ Murden, editor of Singularity.Kiwi. Former digital technologies teacher, author of AI-focused books. Writing with a New Zealand focus.

Sources: Cubbbix, TechGDPR, EUR-Lex, European Commission Digital Strategy