The EU AI Act stopped being a future deadline this month. Chatbot and AI-disclosure rules became binding on July 10, and in two weeks — August 2 — the European Commission gains the power to actually fine general-purpose AI providers for violations, retroactively, back to obligations that have technically applied since August 2025. If your risk management work touches AI in any capacity, this is the point where the framework you may have only studied in the abstract starts generating real enforcement activity.
What Changed This Month
Two things landed at once. First, the EU's Digital Omnibus package received final approval in early July, which consolidated and clarified the Act's enforcement timeline and confirmed how national authorities will coordinate with existing data protection regulators — including how the Act interacts with GDPR when an AI system processes personal data. Second, the Commission separately published its Action Plan on Cybersecurity and Artificial Intelligence, which sets up dedicated capacity to evaluate cybersecurity risk in advanced AI models before they reach the EU market, though that evaluation infrastructure won't be fully operational until 2027.
The practical effect: as of July 10, any organization deploying a chatbot, virtual assistant, or other AI system that interacts with EU users must disclose that the user is talking to AI. As of August 2, providers of general-purpose AI models become exposed to actual financial penalties for gaps in technical documentation, copyright compliance policies, training data transparency, and systemic risk assessment — obligations that have technically existed for a year, just without teeth until now.
What Risk Managers Should Actually Do
The organizations best positioned right now aren't the ones scrambling to interpret the legal text — they're the ones who already treated AI governance as an ongoing discipline rather than a one-time project. A few concrete priorities stand out:
- Finish the AI system inventory, if it isn't done. You can't classify risk tiers for systems you haven't catalogued. This is table-stakes and, per recent industry analysis, a majority of organizations reportedly still haven't completed it.
- Prioritize by risk category, not by convenience. Systems touching employment decisions, credit, and biometric identification are drawing the most enforcement attention early — those deserve remediation focus before lower-risk systems.
- Document proactively, not retroactively. Given the retroactive reach of August 2 penalties, contemporaneous documentation of risk assessments and mitigation decisions is far more defensible than reconstructing a paper trail after the fact.
- Watch the GPAI Code of Practice signatory list. Several major model providers have signed on, some only partially, and at least one large provider has declined entirely — worth tracking as a signal of how the compliance landscape is settling.
The EU AI Act is one of several risk frameworks tested in AAISM's Domain 2. The AAISM™ Study App covers it alongside NIST AI RMF, vendor risk management, and 300 other practice scenarios — offline, once unlocked.
Explore the AAISM™ Study App — $14.99Related Reading
For the full exam breakdown, including how Domain 2 weighs against the other two, see the AAISM Certification Study Guide.
Sources
European Commission — AI Act governance and enforcement overview
TechTimes — EU AI Act enforcement begins, chatbot disclosure live
Skycrumbs — EU AI Act enforcement in 2026: what changed