The EU AI Act stopped being a future deadline this month. Chatbot and AI-disclosure rules became binding on July 10, and in two weeks — August 2 — the European Commission gains the power to actually fine general-purpose AI providers for violations, retroactively, back to obligations that have technically applied since August 2025. If your risk management work touches AI in any capacity, this is the point where the framework you may have only studied in the abstract starts generating real enforcement activity.

What Changed This Month

Two things landed at once. First, the EU's Digital Omnibus package received final approval in early July, which consolidated and clarified the Act's enforcement timeline and confirmed how national authorities will coordinate with existing data protection regulators — including how the Act interacts with GDPR when an AI system processes personal data. Second, the Commission separately published its Action Plan on Cybersecurity and Artificial Intelligence, which sets up dedicated capacity to evaluate cybersecurity risk in advanced AI models before they reach the EU market, though that evaluation infrastructure won't be fully operational until 2027.

The practical effect: as of July 10, any organization deploying a chatbot, virtual assistant, or other AI system that interacts with EU users must disclose that the user is talking to AI. As of August 2, providers of general-purpose AI models become exposed to actual financial penalties for gaps in technical documentation, copyright compliance policies, training data transparency, and systemic risk assessment — obligations that have technically existed for a year, just without teeth until now.

Why this matters for AAISM: Domain 2 names the EU AI Act directly as a risk framework candidates are expected to understand. This is that framework moving from a compliance checkbox to a live enforcement mechanism — exactly the kind of judgment-under-pressure scenario the exam's risk management questions are built around.

What Risk Managers Should Actually Do

The organizations best positioned right now aren't the ones scrambling to interpret the legal text — they're the ones who already treated AI governance as an ongoing discipline rather than a one-time project. A few concrete priorities stand out:

The EU AI Act is one of several risk frameworks tested in AAISM's Domain 2. The AAISM™ Study App covers it alongside NIST AI RMF, vendor risk management, and 300 other practice scenarios — offline, once unlocked.

Explore the AAISM™ Study App — $14.99

Related Reading

For the full exam breakdown, including how Domain 2 weighs against the other two, see the AAISM Certification Study Guide.

Sources

European Commission — AI Act governance and enforcement overview
TechTimes — EU AI Act enforcement begins, chatbot disclosure live
Skycrumbs — EU AI Act enforcement in 2026: what changed