Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

EU AI Act enforcement begins as bloc seeks digital sovereignty

The regulation took effect on 2 August with transparency rules, a beefed-up AI Office and new whistleblower tools, while Brussels fines US and Chinese platforms to assert regulatory independence.

By , Technology Editor

Published

8 min read

The European Union's AI Act became fully enforceable on 2 August 2026, marking the end of a two-year implementation period and the start of what Brussels hopes will be a new model for governing artificial intelligence. Unlike the social media era, where platforms achieved global dominance before legislators reacted, the EU is attempting to regulate generative AI while the technology is still expanding. The regulation introduces transparency rules requiring AI systems to disclose when users are interacting with them and to label synthetic content, including deepfakes. It also establishes a compliance regime backed by a significantly expanded European AI Office and new reporting channels for whistleblowers and users.

Enforcement architecture takes shape

The European AI Office, housed within the European Commission, has been reinforced with 38 new hires, according to Associated Press reporting confirmed by the Commission's own staff listings. The office now comprises technology specialists, lawyers, economists, policy experts and administrative staff organised into units ranging from Regulation and Compliance to AI for Societal Good. Their mandate covers monitoring the reporting and documentation obligations that apply to providers of general-purpose AI models and high-risk systems. Violations they will hunt for include the publication of sexually explicit synthetic material, fabricated photos and videos, and cyber threats to public infrastructure. The regulation also defines "systemic risks" broadly, encompassing chemical, biological, radiological and nuclear incidents, loss of control over autonomous systems, offensive cyber capabilities, harmful manipulation and threats to fundamental rights.

Two new digital tools accompany the staffing increase. A Whistleblower Tool allows workers at AI companies to file confidential reports of misconduct. A Compliance Tool lets users report suspected violations directly. Both are intended to supplement the Office's own supervisory capacity, which remains modest relative to the number of companies now subject to the Act. The Commission has not disclosed the Office's total budget, but the 38 additions represent a meaningful expansion for a body that was still recruiting its founding team in early 2025.

Deepfake fraud drives a detection boom

The regulatory push coincides with a measurable surge in AI-enabled fraud. Deepfake attempts are projected to exceed 334 million annually by 2028, according to industry estimates cited by the Commission in its impact assessment. A report published jointly by Biometric Update and Goode Intelligence, "The Deepfake Fraud Detection Market 2026: Securing Identity in the AI Era", forecasts that voice deepfake checks will rise from over 2.88 billion in 2026 to over 5.45 billion in 2028, while face deepfake checks will climb from over 3.16 billion to over 6.78 billion over the same period. Combined revenue for voice and face detection is expected to grow from just over $3.02 billion in 2026 to over $6.12 billion in 2028, with voice detection alone reaching $2.7 billion and face detection $3.39 billion.

These numbers reflect a market responding to necessity rather than speculation. Financial institutions, border agencies, identity-verification providers and communications platforms are all integrating deepfake detection into onboarding and authentication flows. The AI Act's labelling requirements for synthetic content create a further compliance driver: platforms that host or distribute AI-generated media must now implement detection and labelling tooling or face penalties of up to 3% of global annual turnover for non-compliance with transparency obligations.

Fines signal a harder line on digital sovereignty

In the weeks surrounding the AI Act's enforcement date, the Commission has issued a series of competition and consumer-protection fines that underscore its willingness to confront non-European platforms. Google received a $1 billion penalty for practices related to its advertising technology stack. AliExpress, the Alibaba-owned marketplace, was fined $629 million for failures linked to the sale of non-compliant products and inadequate trader verification. Temu, the Chinese-owned discount retailer, received a $230 million fine for similar violations under the Digital Services Act. The three cases are distinct in their legal bases, but together they form a pattern: Brussels is using its full regulatory toolkit, competition law, the DSA, the AI Act, to establish that access to the single market requires adherence to European rules, regardless of a company's origin.

This approach has diplomatic consequences. The United States and China have both criticised the EU's regulatory trajectory as protectionist. Washington argues that the cumulative burden of the DSA, DMA, AI Act and Data Act disproportionately affects American firms. Beijing views the scrutiny of Chinese e-commerce platforms as politically motivated. The Commission rejects both characterisations, insisting that the rules apply equally to European companies. But the reality is that the global AI market is dominated by US firms, Apple, Google, Meta, Microsoft, OpenAI, and the regulatory cost of serving 450 million European users is now substantially higher than it was three years ago.

European biometrics firms see an opening

For the European biometrics sector, the regulatory shift creates a commercial opportunity. Homegrown providers such as Regula, Innovatrics, Gataca, Signicat, Unissey and Thales are already embedded in national identity schemes, border-control systems and banking KYC processes across the bloc. The AI Act's classification of biometric identification and categorisation systems as high-risk means that any non-European vendor seeking to sell into those use cases must undergo conformity assessment, maintain technical documentation and register in an EU database. European incumbents, by contrast, have spent years navigating GDPR, eIDAS and national certification schemes. They also benefit from data-localisation preferences in public procurement and from the Commission's explicit goal of reducing strategic dependence on US and Chinese technology stacks.

The deepfake detection market is a natural extension. Several of the listed firms have already integrated synthetic-media detection into their identity-verification SDKs. Signicat, for example, offers liveness detection with deepfake defence as a module within its Digital Identity Platform. Innovatrics has added presentation-attack detection tuned for generated faces to its ABIS platform. Thales, through its Gemalto heritage, supplies biometric border-control gates to multiple member states and has been piloting generative-AI detection in airport trials. The forecast doubling of detection revenue by 2028 assumes that these and similar firms capture a significant share of the European procurement pipeline.

The sovereignty narrative and its limits

Henna Virkkunen, the Commission's Executive Vice-President for Tech Sovereignty, Security and Democracy, framed the enforcement launch in explicitly geopolitical terms. "As enforcement begins, we are taking an important step towards AI that people and businesses can understand and trust, and whose benefits are shared widely across our society," she said. The rhetoric aligns with the Commission's broader strategy of "open strategic autonomy", a phrase that has migrated from trade policy into digital regulation. The EU is negotiating trade agreements with Brazil, Australia, Kenya and others while simultaneously building regulatory bridges with like-minded partners through the EU-US Trade and Technology Council and the G7 Hiroshima AI Process.

Yet the sovereignty argument has practical limits. The most advanced foundation models, GPT-4, Claude, Gemini, Llama, are trained on infrastructure owned by US hyperscalers. European cloud capacity is a fraction of what Amazon, Microsoft and Google operate. The EU's Chips Act and IPCEI funding for microelectronics aim to close the hardware gap, but the first European exascale supercomputer, Jupiter, only came online at Forschungszentrum Jülich in 2025. Training a competitive frontier model still requires access to compute that is predominantly American. The AI Act does not address this asymmetry; it regulates deployment, not development.

What happens next

The first conformity-assessment decisions for high-risk AI systems are expected in the first quarter of 2027, once notified bodies complete audits of technical documentation submitted by providers. The AI Office will publish its first annual report on systemic-risk monitoring by late 2026. Meanwhile, the Commission is preparing delegated acts to update the list of high-risk use cases and to clarify the threshold for systemic-risk classification of general-purpose models. A review clause in Article 112 requires the Commission to assess the Act's effectiveness by August 2029, with a possible legislative proposal to follow. For European biometrics firms, the next milestone is the eIDAS 2.0 implementation deadline in 2027, which will mandate interoperable digital identity wallets across the bloc, a market where deepfake-resistant verification is a prerequisite.

Sources

  1. Biometric Update | Biometrics News, Companies and Explainers

    biometricupdate.com · 2026-08-05

People mentioned

  • Henna Virkkunen

    Executive Vice-President for Tech Sovereignty, Security and Democracy, European Commission

Organisations

European Commission · European AI Office · Biometric Update · Goode Intelligence

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.