Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

EU AI Act Enforcement Statistics 2026: Day 0 Compliance Data

EU AI Act enforcement statistics 2026 chart showing 9 of 27 EU member states with fully designated national authorities on Day 0 Axis Enforcement Readiness Score by EU country compared to GPAI Code of Practice signatory count, August 2, 2026

EU AI Act Enforcement Statistics 2026

By Axis Intelligence Research

Co-author: Sarah Mitchell | Last updated: August 2, 2026 | License: CC BY 4.0

Today is the date the EU AI Act’s penalty powers, transparency rules, and market surveillance authority activate. Nine of the EU’s 27 member states have fully designated the national authorities that are supposed to enforce it; six have designated none. Twenty-three companies — including every major foundation-model lab except Meta — have signed the Code of Practice that lets them demonstrate compliance without a case-by-case audit. Roughly 190 organizations signed a second, separate code covering AI-generated content labeling, most of them in the final weeks before today. Zero public fines have been issued under Article 99 or Article 101. This is what “Day 0” actually looks like, measured, sourced, and dated August 2, 2026.


Quick Answer

As of August 2, 2026, 9 of 27 EU member states (33%) have fully designated the national competent authorities required to enforce the AI Act, per the Future of Life Institute’s tracker (last updated June 17, 2026); 12 have partial designations and 6 have none. 23 organizations have signed the General-Purpose AI Code of Practice, and about 190 have signed the separate Code of Practice on AI-generated content transparency. Penalties now enforceable range from €7.5 million to €35 million, or 1% to 7% of global annual turnover, whichever is higher under Article 99 — but no public fine has been announced yet.

Key Findings

  1. According to the Future of Life Institute’s national implementation tracker, only 9 of the EU’s 27 member states had fully designated both a market surveillance authority and a notifying authority as of June 17, 2026 — the two bodies the AI Act requires for national enforcement.
  2. Axis Intelligence Research calculates a EU-27 average Axis Enforcement Readiness Score (AERS) of 68.9 out of 100 as of Day 0, driven down by the 6 member states (Austria, Belgium, Bulgaria, Croatia, Estonia, Greece) that have designated no competent authority at all.
  3. According to the European Commission, 23 organizations — including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and OpenAI — have signed the General-Purpose AI Code of Practice; Meta has not signed, and xAI has committed to only the Safety and Security chapter.
  4. According to the European Commission, roughly 190 organizations signed the separate Code of Practice on Transparency of AI-generated Content by the end of July 2026, split between 83 provider-side and 152 deployer-side signatories, just ahead of today’s marking obligations.
  5. Under Regulation (EU) 2024/1689 Article 99 and Article 101, the AI Act’s enforceable penalties as of today range from €7.5 million or 1% of global turnover (misleading information) up to €35 million or 7% of global turnover (prohibited practices) — the highest exposure ceiling in EU digital regulation, activated with zero public fines issued to date.

How Many EU Countries Are Actually Ready to Enforce the AI Act on Day 0?

The AI Act gives the European Commission’s AI Office exclusive authority over general-purpose AI models. Everything else — chatbot disclosure, biometric categorization notices, market withdrawals, on-the-ground inspections — depends on national authorities that each of the 27 member states was supposed to designate by August 2, 2025. That deadline came and went a year ago. The Future of Life Institute, which maintains the most detailed public tracker of national implementation, classifies each state’s status as Clear (both a market surveillance authority and a notifying authority formally designated), Partial clarity (draft legislation, an announcement, or one authority appointed), or Unclear (nothing formally designated).

Going into today, the split is 9 Clear, 12 Partial, 6 Unclear. Ireland, Italy, Denmark, Finland, Slovenia, Hungary, Cyprus, Malta, and Lithuania make up the Clear group; Ireland’s approach is the most built-out, with 15 sectoral bodies designated as market surveillance authorities and a National AI Office meant to go live as the central coordinator on this exact date. Germany, France, Spain, and the Netherlands — four of the bloc’s five largest economies by AI investment — sit in Partial clarity, each with draft or proposed legislation that had not cleared its national parliament as this article was being verified. Austria, Belgium, Bulgaria, Croatia, Estonia, and Greece have designated no market surveillance or notifying authority at all.

The Axis Enforcement Readiness Score (AERS) v1.0

Axis Intelligence Research built a composite score to turn this patchwork into a single comparable number per country. AERS = 0.7 × NCA_score + 0.3 × FRA_score, where NCA_score is 100 for Clear, 50 for Partial clarity, and 0 for Unclear (weighted higher because market surveillance and notifying authorities carry the actual investigation and sanction powers), and FRA_score is 100 for every member state, because the Commission’s consolidated list confirms all 27 states designated their Article 77 fundamental-rights authorities on schedule. The formula is disclosed in full so any outlet can recompute it from the same FLI table. The resulting EU-27 average is 68.9 out of 100 — a bloc where the legal deadline for enforcement has arrived everywhere, but the enforcement machinery has arrived in roughly a third of it.

Readiness tierAERS scoreMember statesCount
Full designation100.0Cyprus, Denmark, Finland, Hungary, Ireland, Italy, Lithuania, Malta, Slovenia9
Partial designation65.0Czech Republic, France, Germany, Latvia, Luxembourg, Netherlands, Poland, Portugal, Romania, Slovakia, Spain, Sweden12
No designation30.0Austria, Belgium, Bulgaria, Croatia, Estonia, Greece6

Source: Axis Intelligence Research calculation from Future of Life Institute, “Overview of all AI Act National Implementation Plans,” as of June 17, 2026. Full per-country data in the accompanying CSV.

Sarah Mitchell, AI & Machine Learning: A regulation is only as strong as the body that can knock on your door, and today twelve national doors in the EU are still half-built. That doesn’t pause the law — the AI Act applies to providers and deployers regardless of whether their national regulator has an office yet — but it does mean enforcement will be lumpy for a while. A German deployer and a Cypriot deployer are subject to the identical statute starting today; only one of their national authorities can currently act on a complaint.

How Many Companies Signed the GPAI Code of Practice?

The AI Act does not require any general-purpose AI provider to sign anything. What it requires is compliance with Articles 53 (documentation, copyright policy, training-data summaries) and, for the highest-capability models, Article 55 (systemic-risk testing and incident reporting). The Code of Practice is the voluntary shortcut: sign it, and the Commission’s enforcement focuses on monitoring adherence to the Code rather than building a case from scratch.

As of the Commission’s own current signatory list, 23 organizations have signed: Accexible, AI Studio Delta, Aleph Alpha, Almawave, Amazon, Anthropic, Black Forest Labs, Bria AI, Cohere, Domyn, Dweve, Fastweb, Google, IBM, Lawise, LINAGORA, Microsoft, Mistral AI, Open Hippo, OpenAI, Pleias, ServiceNow, and WRITER. xAI signed only the Safety and Security chapter, meaning it has committed to demonstrating transparency and copyright compliance “via alternative adequate means” rather than through the Code — a distinction the Commission has flagged for closer scrutiny. Meta has not signed any chapter.

Who actually needs to sign, and who’s opting out

The Safety and Security chapter only applies to providers of models trained above roughly 10²⁵ floating-point operations — what the Act calls systemic risk. The Future of Life Institute estimates that population at 5 to 15 companies worldwide. That’s a materially smaller group than the 23 full signatories, because most Code signatories are signing the Transparency and Copyright chapters only, which apply to every general-purpose model regardless of scale. Axis Intelligence Research is not merging these two figures into a single “compliance rate” — the systemic-risk population estimate and the full signatory count measure different populations under different obligations, and forcing them into one ratio would imply a precision neither source supports.

Sarah Mitchell, AI & Machine Learning: Twenty-three signatures sounds like consensus until you notice who’s missing. Meta staying out is the one worth watching — not because it signals defiance, exactly, but because it’s the clearest test case for what “alternative adequate means” actually costs a company willing to prove compliance the hard way, starting today.

How Many Organizations Signed the AI Content-Labeling Code Before August 2?

A second, separate Code of Practice on Transparency of AI-generated Content covers Article 50(2): machine-readable marking of AI-generated audio, image, and video. Unlike the GPAI Code, this one has two tracks — Section 1 for providers of generative systems (and of marking/detection tools), Section 2 for deployers. By the Commission’s own count, published July 31, 2026, 83 organizations signed Section 1 and 152 signed Section 2, for about 190 distinct organizations once overlap between the two sections is accounted for.

The signatory list skews toward companies most people have never heard of. Roughly half the signatories are described by the Commission itself as small or recently founded firms — a sign of who actually needs the legal certainty a Code provides, versus who can absorb the cost of proving compliance independently. Recognizable names appear on both tracks: Google, Microsoft, OpenAI, Anthropic, Meta, and Mistral signed Section 1; Getty Images, Lufthansa, Iberdrola, and Lenovo signed Section 2. Two observations follow from that split. First, Meta signed the content-labeling Code while declining the separate GPAI Code — different obligations, different calculus. Second, the marking obligation for systems already on the EU market before today doesn’t bite until December 2, 2026, so this signatory count is a snapshot of who moved early, not a measure of who’s compliant on a live deadline.

What Are the Maximum Fines Under the EU AI Act, and Which Ones Are Live Today?

Regulation (EU) 2024/1689’s penalty structure, laid out in Article 99 and Article 101, has three tiers, all enforceable now for the obligations that are themselves in force.

TierMaximum penaltyCoversEnforceable since
Article 99(3)€35,000,000 or 7% of global annual turnover, whichever higherProhibited AI practices (Article 5)February 2, 2025
Article 99(4)€15,000,000 or 3% of global annual turnover, whichever higherProvider/deployer/notified-body obligations and Article 50 transparencyAugust 2, 2026 (transparency); phased for other obligations
Article 99(5)€7,500,000 or 1% of global annual turnover, whichever higherMisleading information to authoritiesAugust 2, 2026
Article 101(1)€15,000,000 or 3% of global annual turnover, whichever higherCommission-imposed fines on GPAI model providersAugust 2, 2026

Source: European Commission, AI Act Service Desk, Articles 99 and 101, Regulation (EU) 2024/1689. Retrieved August 2, 2026.

Article 99(6) softens this for small and medium enterprises: they pay the lower of the fixed amount or the percentage, not the higher, which caps a €5 million-turnover startup’s worst-case Tier 1 exposure at €350,000 rather than €35 million. Everything in this table has been legally enforceable in some form since prohibited practices activated in February 2025; what changes today is that GPAI penalty powers, Article 50 transparency obligations, and full national market surveillance authority all switch on simultaneously.

Has the EU Issued Any AI Act Fines Yet?

No. As of this writing, the AI Office has not announced a public fine under Article 101, and no national market surveillance authority has announced one under Article 99. The Commission’s own May 2026 report on the review of prohibited practices and high-risk classifications describes enforcement rules for prohibited practices as “not yet applicable” as of that writing, and multiple national authorities — including Germany’s Federal Network Agency — have opened investigations into specific systems (automated hiring tools drew early scrutiny) without a published penalty decision attached. The AI Act Service Desk’s own FAQ confirms that GPAI penalty and market-surveillance enforcement powers only begin applying today, which is consistent with an observation-first year rather than an immediate wave of fines.

Sarah Mitchell, AI & Machine Learning: The comparison everyone reaches for is GDPR — years of quiet investigation before the first landmark fine landed. It’s not a perfect parallel; the AI Office is a single centralized body for GPAI models rather than 27 uncoordinated data-protection authorities, and it has said outright it won’t treat Code signatories as compliant without examination. But the shape of the curve — infrastructure first, headline fine later — is the same one GDPR drew, and today is closer to the infrastructure end of it than the headline end.

Methodology

Axis Intelligence Research compiled this dataset from three categories of primary source, fetched and dated between July 31 and August 2, 2026: (1) the European Commission’s own AI Act Service Desk for statutory penalty text (Articles 99 and 101) and the Commission’s Digital Strategy site for Code of Practice signatory rosters; (2) the Future of Life Institute’s national implementation tracker (last updated June 17, 2026) for member-state authority designation status, cross-checked against the Commission’s consolidated list of fundamental-rights authorities; (3) the Commission’s own July 31, 2026 announcement for the AI-generated content Code of Practice signatory counts.

The Axis Enforcement Readiness Score (AERS v1.0) is a weighted composite: AERS = 0.7 × NCA_score + 0.3 × FRA_score, where NCA_score maps the FLI’s three-way classification (Clear/Partial clarity/Unclear) to 100/50/0, and FRA_score is 100 for all 27 member states per the Commission’s confirmation that fundamental-rights authorities are fully designated bloc-wide. The 0.7/0.3 weighting reflects that market surveillance and notifying authorities hold direct investigation and sanction powers, while fundamental-rights authorities have a narrower, complaint-referral role under Article 77. This is a snapshot score, not a legal assessment of any single country’s compliance; it will be recalculated when the FLI tracker next updates or when a member state’s implementing legislation formally enters into force, whichever comes first, and any such revision will be logged as a versioned update (AERS v1.1, etc.), not a silent edit.

Limitations: The FLI tracker is independently maintained and updated on a rolling basis rather than a fixed schedule; it may lag formal legislative action by days or weeks in either direction. The GPAI Code and content-labeling Code signatory counts reflect the Commission’s published lists as retrieved on August 2, 2026 and will move as new organizations sign. This article does not merge the GPAI Code signatory count with the estimated population of systemic-risk model providers, because the two figures measure different, non-equivalent populations (see “Who actually needs to sign, and who’s opting out” above).

About This Dataset

This dataset covers EU AI Act enforcement readiness and Code of Practice participation as of August 2, 2026 — the date GPAI penalty powers, Article 50 transparency obligations, and full national market surveillance authority activate under Regulation (EU) 2024/1689. It combines European Commission statutory and administrative sources with the Future of Life Institute’s independent national-implementation tracker. Update trigger: the next FLI tracker revision, any newly announced Article 99/101 fine, or one month from publication, whichever occurs first. Licensed CC BY 4.0. Citation: Axis Intelligence Research, “EU AI Act Enforcement Statistics 2026: Day 0 Compliance Data,” 2026.

Citation formats:

  • APA: Axis Intelligence Research. (2026). EU AI Act enforcement statistics 2026: Day 0 compliance data. Axis Intelligence. https://axis-intelligence.com/eu-ai-act-enforcement-statistics/
  • MLA: Axis Intelligence Research. “EU AI Act Enforcement Statistics 2026: Day 0 Compliance Data.” Axis Intelligence, 2 Aug. 2026, axis-intelligence.com/eu-ai-act-enforcement-statistics/.
  • Chicago: Axis Intelligence Research. “EU AI Act Enforcement Statistics 2026: Day 0 Compliance Data.” Axis Intelligence. August 2, 2026. https://axis-intelligence.com/eu-ai-act-enforcement-statistics/.

Last updated: August 2, 2026 | Next scheduled review: September 2, 2026, or immediately upon the first publicly disclosed Article 99/101 penalty.

Frequently Asked Questions

What actually happens under the EU AI Act on August 2, 2026?

Three things activate simultaneously: the European Commission’s AI Office gains penalty enforcement powers over general-purpose AI models (up to €15 million or 3% of global turnover under Article 101), Article 50 transparency obligations become enforceable for systems that interact with people or generate synthetic content, and national market surveillance authorities gain full investigatory and sanction powers across all AI Act obligations, not just GPAI.

Is high-risk AI system enforcement starting today too?

No. Under the Digital Omnibus agreement reached May 7, 2026, stand-alone high-risk AI systems under Annex III (employment, credit, biometrics, and similar categories) now face a compliance deadline of December 2, 2027, not today. The obligations themselves are unchanged — only the enforcement date moved.

How many EU countries are actually ready to enforce the AI Act?

Nine of 27 member states have fully designated both required national authorities as of the Future of Life Institute’s June 17, 2026 tracker; 12 have partial designations (draft legislation or one authority appointed); 6 have designated none. This does not exempt companies in any of those 27 countries from AI Act obligations — the law applies regardless of national enforcement readiness.

Has anyone actually been fined under the EU AI Act?

Not as of this writing. No public Article 99 fine from a national authority or Article 101 fine from the AI Office has been announced, though the Commission has opened formal investigations into potential prohibited-practice violations and at least one national authority has opened an inquiry into an automated hiring tool.

Do I have to sign the GPAI Code of Practice?

No, signing is voluntary. Signatories get streamlined compliance monitoring and the Commission treats Code commitments as a mitigating factor in fine calculations. Non-signatories — Meta, for the GPAI Code — must demonstrate equivalent compliance through other means, which typically means more detailed information requests and less procedural predictability.

What is the Axis Enforcement Readiness Score?

It’s an Axis Intelligence Research composite metric, on a 0–100 scale, combining each EU member state’s national competent authority designation status (weighted 70%) with its fundamental-rights authority designation status (weighted 30%), calculated from Future of Life Institute tracking data. The full formula and per-country scores are in the Methodology section and the accompanying CSV.

What’s the maximum fine a company can face under the AI Act as of today?

€35 million or 7% of global annual worldwide turnover, whichever is higher, for prohibited AI practices under Article 5 — a threshold that has technically applied since February 2025, though enforcement infrastructure has been building since. Small and medium enterprises pay the lower of the two figures, not the higher, under Article 99(6).

Why hasn’t Meta signed the GPAI Code of Practice?

The Commission has not published Meta’s reasoning, and Axis Intelligence Research is not aware of an official statement from Meta on the record explaining the decision. What’s verifiable is the consequence: Meta must demonstrate AI Act compliance through means other than the Code, which the Commission has indicated invites more detailed scrutiny than Code adherence does.

Others Pages:

Recent Posts

IPO Statistics by Country and Exchange 2026: Rankings, Proceeds and Where Listings Actually Happen

IPO Statistics by Country 2026 By Axis Intelligence Research Co-author: Mia Scarlett (Business) | Last updated: Septembe

IPO Statistics 2026: Global Listings, Proceeds, Mega-Deals and First-Day Returns

IPO Statistics 2026 By Axis Intelligence Research Co-author: Mia Scarlett (Business) | Last updated: September 16, 2026

China Rare Earth Statistics 2026: Production, Exports, Prices and Global Market Share Ahead of the November 10 Deadline

China Rare Earth Statistics 2026 By Axis Intelligence Research Co-author: Sophie Winslow (Industrial Tech) | Last update

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.