Skip to content

Europe

Independent · Brussels & Berlin

Technology · Digital regulation

EU AI Act enforcement begins, reaching beyond European borders

Powers activated on 2 August give Brussels authority over prohibited AI practices, general-purpose models and transparency requirements, with penalties and jurisdictional reach that extend to companies outside the EU.

By , Technology Editor

Published

10 min read

On 2 August 2026, the European Union crossed a threshold that technology companies and governments around the world have been watching for months. The first substantial enforcement provisions of the AI Act took effect, giving Brussels real power over how artificial intelligence is developed, deployed and disclosed, not only inside Europe but wherever a company's output reaches an EU user.

What enforcement now covers

The provisions activated this month fall into three broad categories. The first is a set of outright prohibitions: certain AI practices are now illegal in the EU, including social scoring by governments, manipulation of human behaviour through subliminal techniques, and exploitation of vulnerabilities related to age, disability or socioeconomic situation. These bans were always part of the Act, but they lacked enforcement teeth until the Commission's AI Office and national authorities received their formal mandates.

The second category targets general-purpose AI models, the large language models and foundation systems that underpin services from chatbots to image generators. Providers of these models must now comply with requirements around transparency, copyright compliance and technical documentation. The European Commission can impose substantial financial penalties on providers that fall short, though the precise maximum fines for general-purpose model violations will depend on the company's global turnover, a structure familiar from the GDPR regime.

The third category is transparency. Any AI system that interacts with humans must now disclose that it is a machine, not a person. Deepfakes and AI-generated or manipulated content must be labelled as such. These are disclosure rules rather than restrictions on what can be built, but they carry compliance costs and, for companies that ignore them, the risk of enforcement action.

The reach beyond Europe

What makes the AI Act different from most European technology regulation is not its content but its jurisdictional scope. The law asserts authority over providers and deployers located outside the European Union when their AI systems are placed on the European market or when outputs from those systems are used within the EU. An American company building a chatbot in California, serving it to users in France, falls under these rules.

This is not novel in European law. The GDPR operates on a similar principle: if you process the personal data of EU residents, you are subject to European rules regardless of where your servers sit. The Digital Services Act and Digital Markets Act also reach beyond EU borders. But the AI Act extends the principle into a more contentious domain. Regulating data privacy is one thing. Regulating what an AI model can generate, how it is trained and what information it can provide touches directly on questions of speech, expression and the boundaries of permissible content.

The practical effect depends on whether companies choose to build separate versions of their products for different markets. Maintaining a European-compliant version and a less restricted version for the rest of the world is technically possible but expensive. Most providers have a strong financial incentive to conform their global products to European requirements rather than fragmenting their user base and engineering effort. Critics call this the Brussels Effect: the tendency of EU regulation to become a de facto global standard because the cost of non-compliance in a market of 450 million people exceeds the cost of worldwide compliance.

American objections sharpen

American critics of the Act have been vocal since the legislation was first proposed, and the start of enforcement has given their arguments new urgency. The Heartland Institute, a free-market think tank based in Illinois, published a policy study in 2025 warning that the law constitutes an extraterritorial incursion on American rights and sovereignty. The study's title made its position plain: "The European Union's Artificial Intelligence Act: An Extraterritorial Incursion on Americans' Inalienable Rights."

Jack McPherrin, a senior policy analyst and research fellow at the Heartland Institute, said the transition from proposal to enforcement changes the nature of the debate. "The EU AI Act is no longer simply a regulatory proposal whose international effects can be debated in the abstract," he said. "European authorities now have meaningful enforcement powers over rules that reach American companies and technologies. US policymakers should take that extraterritorial reach seriously and ensure that decisions governing American AI remain accountable to Americans."

Donald Kendal, director of the Heartland Institute's Socialism Research Center, went further. "The European Union should not be allowed to dictate the rules governing American artificial intelligence," he said. "The EU AI Act gives European regulators extraordinary power to influence how American companies develop their technologies, what information their models can provide, and ultimately what Americans are able to see and say online."

The language is pointed, but the underlying concern is shared more broadly across the American technology sector. Companies including OpenAI, Google and Meta have lobbied against provisions they argue will raise compliance costs, slow product development and give European regulators effective veto power over features available to users worldwide. The question of whether a European authority should influence what an American user can see or say through an AI system has become a live political issue in Washington.

What Europe gains and risks

For European policymakers, the Act represents a deliberate choice to lead rather than follow. The EU has taken a similar path before: the GDPR set a global benchmark for data protection, and the Digital Services Act has already prompted changes in how platforms moderate content worldwide. The AI Act follows the same logic. By moving first, Europe sets the terms of the debate and forces other jurisdictions to respond.

There are risks. European companies operate under constraints that competitors in less regulated markets do not face. If compliance costs are high enough, AI development could shift towards jurisdictions with lighter regulatory regimes, leaving European firms at a competitive disadvantage. The Commission's own impact assessment acknowledged this possibility, arguing that the long-term benefits of consumer trust and legal certainty would outweigh the short-term costs. That claim remains untested.

There is also a question of enforcement capacity. The AI Office within the European Commission is a new body with a limited staff. National authorities across 27 member states vary in their technical expertise and political willingness to pursue cases. The GDPR demonstrated that enforcement is uneven: some regulators are aggressive, others are not. The AI Act will face the same problem at greater complexity, because the technology it governs evolves faster than the administrative processes needed to regulate it.

What is not yet in force

The provisions activated this month are the first of several enforcement phases. The most consequential requirements, those governing high-risk AI systems used in areas such as employment, education, law enforcement and critical infrastructure, will not take effect until later. High-risk systems must meet standards around data quality, human oversight, transparency and robustness that are far more demanding than the disclosure rules now in force.

This phased approach was designed to give companies time to adapt, but it also means that the Act's full weight will not be felt for some time. Providers of general-purpose models face immediate obligations. Providers of high-risk systems face a longer runway but more onerous requirements when their deadline arrives.

The sovereignty debate

The Heartland Institute's framing, that the Act threatens American sovereignty and free expression, reflects a genuine tension in global technology regulation. When the GDPR took effect, American companies complied because the European market was too large to abandon. The same calculus now applies to AI. But the stakes are different. Data protection rules govern how information is stored and processed. AI regulation governs what information can be generated, how it is presented and whether it can be suppressed. The boundary between consumer protection and censorship is thinner, and more contested, than the boundary between data privacy and data exploitation.

European officials reject the sovereignty argument. From their perspective, any company that chooses to serve European users accepts European rules, just as any company selling physical goods in the EU must meet European product safety standards. The choice to enter the market is the company's own. If an American AI provider decides not to serve EU users, it faces no European obligations at all.

This argument is legally sound but practically incomplete. The largest AI providers are American, and their services are woven into the digital infrastructure that Europeans use daily. Withdrawing from the EU is not a realistic option for companies like Google or Microsoft, which means the Act's requirements function as mandatory rather than voluntary. Whether this constitutes regulation or coercion depends on where you stand.

Enforcement capacity and political will

Having the power to enforce is not the same as enforcing effectively. The European Commission created its AI Office to oversee general-purpose model compliance, but the office is a small institution relative to the scale of the industry it must monitor. National authorities in each member state must designate their own enforcement bodies, train staff and develop technical expertise. Some will move quickly. Others will take years.

The GDPR experience is instructive. Ireland's Data Protection Commission, which oversees most major American technology companies because their EU headquarters are in Dublin, has faced sustained criticism for moving slowly and imposing relatively modest fines. If the same pattern emerges under the AI Act, with enforcement concentrated in a single member state with limited appetite for confrontation, the law's practical impact could fall short of its ambitions.

There is also the question of political will. Regulating AI is popular in the abstract. Imposing large fines on popular companies, or requiring changes to products that consumers already use and like, is harder. The Commission will face pressure from member states worried about economic competitiveness, from companies threatening to limit services in Europe, and from users frustrated by features removed or altered for compliance reasons.

Sources

  1. The Heartland Institute

    heartland.org · 2026-08-25

People mentioned

  • Jack McPherrin

    Senior Policy Analyst and Research Fellow, The Heartland Institute

  • Donald Kendal

    Director of the Socialism Research Center, The Heartland Institute

Organisations

European Commission · The Heartland Institute

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.