For a year, the EU AI Act was a law with teeth on paper but no bite. That changed on August 2, 2026 — and according to the first reports, it didn't take even a week to leave its first mark.
The EU AI Act's sanctions regime isn't a single number: it's three tiers based on the severity of the infringement. The highest tier — up to €35 million or 7% of global annual turnover, whichever is higher — applies to AI practices directly prohibited under Article 5 (for example, social scoring systems or subliminal manipulation). The middle tier — up to €15 million or 3% of turnover — covers non-compliance with obligations for high-risk systems and GPAI models. The lowest tier — up to €7.5 million or 1.5% of turnover — applies to more administrative infringements, such as providing incorrect or incomplete information to an authority during an investigation.
For general-purpose (GPAI) models, the authority is the European Commission's AI Office, centralized — the same body that can request technical documentation, model access for evaluation, or demand corrective measures under Article 55. For high-risk AI systems deployed in a specific sector (hiring, credit, healthcare, etc.), oversight falls to each member state's national market surveillance authorities — the same decentralized model that already exists for product regulation in the EU.
According to reports from the first week after the regime activated on August 2, 2026, three companies received combined sanctions of €47 million for high-risk system violations: a hiring-technology platform (the single highest fine, for deploying AI-based personnel selection without the required conformity assessment documentation and without the mandatory human oversight controls — the investigation originated from complaints about opaque and allegedly discriminatory hiring decisions), a credit scoring company, and a retail chain over AI-based surveillance. These first reported cases are worth treating with caution pending further official confirmation — but the direction is clear: hiring, credit, and surveillance are, predictably, the first categories where enforcement becomes real.
The pattern in these first cases is no coincidence: hiring and credit-scoring systems are exactly the “high-risk” use cases the law's Annex III explicitly identifies, and they're also the ones that most easily generate citizen complaints — someone who wasn't hired or was denied credit has a direct incentive to ask why. It's reasonable to expect the next enforcement focus areas to follow the same pattern: chatbots that don't disclose they're AI, and unlabeled synthetic content at scale, both with transparency obligations that are relatively easy to verify from the outside.
The operational lesson from these first cases is concrete: conformity assessment documentation and human oversight controls aren't compliance checkboxes you complete once and file away — they're the first line of defense in a real investigation, and their absence was, in at least one of the reported cases, the direct cause of the highest fine. For any company using AI in decisions that affect people (hiring, credit, access to services), it's worth auditing today whether that documentation exists and is current, rather than waiting for the first complaint to arrive.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel