AI News

EU AI Act Enforcement Is Live Now—Here’s What Companies Miss

Timeline showing EU AI Act enforcement phases with February 2025 prohibited practices deadline highlighted

Fact-checked by the YoureNewsSource editorial team

On February 2, 2025, the first real enforcement teeth of the EU AI Act enforcement framework started biting. Most compliance teams I talk to still have 2026 circled on their calendars. They’re not wrong about the main rollout timeline, but they are dangerously late for the deadlines that already apply. The Act’s prohibited-practices ban kicked in this month, backed by the European AI Office’s authority to investigate, demand information, and pursue corrective measures right now. That’s not a soft launch; it’s live enforcement.

What makes that date so easy to miss is the mess of phased obligations. General-purpose AI model rules hit in August 2025. High-risk system obligations for most products go live in 2026, and certain legacy systems get a transitional pass until 2027. But the prohibited-practices tier doesn’t wait. Any company deploying or selling a banned AI practice, social scoring by private actors, emotion recognition in the workplace, real-time biometric categorization for most marketing purposes, is already in the enforcement window. The European Commission’s own AI Act Service Desk confirms that the AI Office has “structures for enforcement powers including requesting information, model evaluations, risk mitigation measures, and fines up to 3% of global annual turnover for GPAI providers.” That structure is not a future plan. It’s operational.

After reading this, you’ll understand which enforcement triggers are already live, how the hybrid national–EU oversight model actually creates friction, why penalty exposure can dwarf your EU revenue, and what the rarely discussed private complaint mechanism means for even small-scale users. I’ll also walk you through the August 2025 deadline most organizations aren’t tracking and the practical steps that can turn a compliance scramble into a manageable process.

Key Takeaways

  • Prohibited practices enforcement started February 2, 2025, months before many companies expect the Act to have any teeth.
  • Fines are calculated on worldwide annual turnover, not EU revenue, making non-EU firms with tiny European footprints surprisingly exposed.
  • Any affected individual can file a complaint directly with national authorities, opening a low-cost private enforcement channel most businesses ignore.
  • Member states must designate enforcement authorities and adopt penalty rules by August 2, 2025; missed deadlines will create jurisdiction-by-jurisdiction chaos.
  • The European AI Office and 27 national watchdogs operate in a hybrid model that almost guarantees inconsistent enforcement across borders.
  • Even open-source deployers and SMEs face real enforcement risk if their models touch prohibited categories or fail transparency rules.

Enforcement Has Already Begun, But Not the Way You’d Expect

The European Commission’s governance framework makes it clear: the AI Act doesn’t wait for polite announcements. The European AI Office was stood up in 2024, and its investigatory toolkit, information requests, model evaluations, corrective measures, became active the moment the prohibited-practices provision applied in February 2025. This isn’t theoretical. National market surveillance authorities received formal notification obligations under Article 99, and several member states have already begun staffing AI enforcement units.

Why 2026 Became the Fake Deadline

Most legal briefings fixate on August 2026, when the bulk of high-risk system rules become obligatory. That’s where the long lead times for conformity assessments and notified-body certifications sit. But the Act’s own structure creates a staggered implementation, and the front-loaded bans and transparency rules carry immediate consequences. The mistake companies make is treating the whole regulation as a future problem, rather than auditing which obligations already apply today.

Watch Out

If your AI system uses real-time facial recognition for customer sentiment analysis in a retail setting, you’re already covered by the prohibited-practices ban, even if the full high-risk framework isn’t in effect.

Companies operating across multiple member states face an extra layer of urgency, because different national authorities interpret their own readiness differently. Some, like France’s CNIL-adjacent AI unit, have already signaled proactive investigation agendas. Others will take months to stand up. The result: your enforcement risk in Germany may look nothing like your risk in Spain, even for the same product.

Working through an inventory of AI use cases now, before a complaint or an information request lands, is the single cheapest insurance available. It’s a more pragmatic approach than waiting for the 2026 flood, and a smarter use of resources than the typical enterprise approach of watching regulators’ first moves from the sidelines.

The Hybrid Model No One Is Modeling Correctly

Ask a typical compliance officer who enforces the AI Act, and you’ll get an oversimplified answer: the European AI Office for general-purpose AI, and national authorities for high-risk systems. The reality is messier. The European Data Protection Supervisor (EDPS) also steps in when EU institutions themselves deploy AI systems, acting as the market surveillance authority with authority to impose its own administrative fines. So we have at least 28 enforcement bodies, one central, 27 national, plus the EDPS, operating with overlapping mandates and no unified playbook.

Cross-Border Investigations: The Headache Nobody Has Solved

Here’s the cross-border problem nobody’s solved yet. Imagine a GPAI model trained by a company based in California, deployed by a subsidiary in Ireland, and generating high-risk outputs that affect users in Poland. The AI Office has jurisdiction over the GPAI provider, but the downstream deployer’s high-risk application gets watched by Polish authorities, with the Irish authority potentially involved for the subsidiary’s establishment. Coordination mechanisms exist on paper, through the European Artificial Intelligence Board, but the Board’s enforcement coordination powers are still in early development. The European Parliament’s Think Tank explicitly noted that this hybrid structure risks uneven enforcement.

Did You Know?

The AI Board includes representatives from all member states and is supposed to ensure consistent application, but it doesn’t have the power to override a national authority’s decision. It can issue opinions, not binding rulings.

For companies, this means you can’t settle enforcement strategy with a single regulator. A compliance posture acceptable in one jurisdiction could trigger an investigation in a neighboring one, and those parallel proceedings might move at very different speeds. That’s not a hypothetical. GDPR experience already shows how national data protection authorities vary wildly in enforcement appetite. This Act’s architecture replicates that pattern with even more complexity.

There’s an honest caveat here: the system is so new that we’re guessing at the friction points. But ignoring the coordination gap entirely is a gamble. Building relationships with authorities in the jurisdictions where your risk exposure concentrates is a practical hedge, something much easier to start now than after a cross-border complaint drops.

Enforcement Body Primary Scope Key Limitation
European AI Office General-purpose AI models, systemic risks Cannot impose fines; relies on Commission for penalty decisions
National Authorities High-risk AI systems, prohibited practices Varying resources, interpretation, and enforcement pace
EDPS EU institutions’ own AI systems Limited to EU bodies, not private sector
AI Board Coordination, opinions Non-binding; no direct enforcement power

Penalties That Ignore EU Revenue, And What That Really Costs

The fine numbers get quoted often: up to €35 million or 7% of worldwide annual turnover for prohibited practices, €15 million or 3% for most other violations, and €7.5 million or 1.5% for supplying incorrect information. What almost nobody explains well is the “whichever is higher” mechanism. The penalty is the greater of the fixed euro amount or the percentage of total global turnover, not EU turnover, not profits from the offending product, but the company’s entire worldwide top line.

By the Numbers

A US-based SaaS company with $200M in worldwide annual revenue and only $5M from EU customers would face a prohibited-practices fine of €14M under the 7% turnover calculation, far above the €35M fixed cap for the lower tier, but still calculated on the full $200M, not the $5M EU slice.

Small Fines Are Still Big for SMEs

For a startup with €8 million in revenue, a €7.5 million fine, under the lowest tier, is essentially a death sentence. The Act doesn’t contain a formal SME proportionality discount for penalties. The European Commission’s guidelines note that the size of the operator may be considered as a factor in penalty assessment, but nothing in the text caps fines at a percentage of EU-only income. For small businesses that inadvertently cross into a prohibited category, the exposure can be devastatingly disproportionate.

What I see in practice: Companies with modest EU revenue often underestimate the exposure until they run the global turnover calculation, then the legal budget meeting gets serious fast. The numbers don’t lie, and they don’t care about your percentage of European customers.

Pressure on GPAI providers ramps up from another direction too. The AI Act Service Desk clarifies that for GPAI models where systemic risk is identified, the Commission can impose fines up to 3% of global turnover if compliance dialogues don’t resolve the issue. That creates a scenario where an open-source foundation model with minimal direct revenue but used in millions of downstream applications could trigger enforcement that scales with the upstream provider’s unrelated business income.

Prohibited Practices: The Carveouts Nobody Talks About

The list of banned AI practices seems absolute: social scoring, biometric categorization inferring sensitive characteristics, emotion recognition at work and school, and real-time biometric identification in public spaces for law enforcement, except when it isn’t. The Act includes targeted exceptions that most summaries gloss over. Law enforcement can use real-time remote biometric identification for specific serious crimes, subject to judicial authorization. That’s not a loophole; it’s a deliberate carveout that fundamentally changes how enforcement will play out.

When “Material Distortion” Becomes a Judgment Call

The ban on AI systems that manipulate human behavior uses the threshold of “material distortion”, a phrase that’s inherently subjective. What constitutes material distortion in a marketing recommendation versus a political deepfake? The European AI Office hasn’t yet released detailed interpretive guidance, leaving national authorities to develop their own standards. A borderline system approved in Sweden might get flagged in Italy. We’ve seen this movie before with the GDPR’s “legitimate interest” balancing test.

Pro Tip

Document your internal assessments of material distortion risk now, not after a complaint. Regulators will treat contemporaneous analysis far more favorably than after-the-fact justifications.

Private actors have another advantage: the prohibited-practices list targets uses, not underlying technology. A company could develop powerful emotion-recognition algorithms and license them to non-EU clients or use them in explicitly permitted contexts, like medical diagnostics, without triggering a ban. The same technology platform might sail through enforcement while a different deployment of identical code gets blocked. That’s intentional by design, but it also means enforcement decisions will often hinge on context-specific evidence-gathering, not just a binary check against a blacklist.

Prohibited Practice Explicit Exception Enforcement Complexity
Real-time remote biometric ID Law enforcement: specific serious crimes, judicial authorization Case-by-case; authorization process varies by member state
Emotion recognition Medical or safety purposes Blurred lines between workplace “safety” and productivity monitoring
Social scoring by private actors None, but narrow definition of “social score” per Recital Interpretation of what constitutes “unrelated social context” scoring

The Private Right of Action That Could Change Everything

Most analysis of the AI Act’s enforcement reads like a top-down regulatory blueprint. The under-discussed part is bottom-up. Article 85 lets any natural or legal person whose rights are affected by a non-compliant AI system lodge a complaint with the relevant market surveillance authority. There’s no filing fee, no requirement for legal representation, and the authority must investigate and respond. This is the part that can turn a quiet compliance gap into a public enforcement action overnight.

Complaints as the Fast Track to Investigations

Unlike a whistleblower process that might get buried, a complaint from an end-user triggers a formal obligation. A job candidate rejected by an undeclared emotion-recognition tool during an interview can file a complaint. An employee subjected to constant AI-driven productivity scoring that crosses into prohibited territory can file. Each complaint forces the authority to open a dossier and examine whether the system in question violates the Act. Given the public sector’s resource constraints, that creates a powerful triage effect: investigated complaints will disproportionately target companies where evidence is easiest to collect.

By the Numbers

Under GDPR, individual complaints to data protection authorities in Europe exceeded 100,000 annually within three years of enforcement. The AI Act’s complaint mechanism is even broader, covering more rights-holders with lower barriers to entry.

Add to this the Article 86 right to explanation. When an AI system produces a decision affecting legal rights, a loan denial, a hiring rejection, a benefit termination, the affected person has a right to a meaningful explanation of the decision’s logic. That’s not just a transparency obligation; it’s a private right that, if not honored, can fuel a subsequent complaint. Companies that treat AI explainability as a nice-to-have will find out it’s a litigation magnet.

I won’t pretend this will flood the courts day one. But the architecture is in place. And the first few high-profile complaints will be covered extensively. That media dynamic alone, naming a company under investigation for AI Act violations, creates a reputational penalty that can dwarf any fine. It’s also what makes binding AI compliance into the procurement and product review process a wise move before, not after, the first complaint lands.

The August 2025 Deadline Most Companies Are Ignoring

August 2, 2025, is not a suggestion. Article 99 requires every member state to designate one or more national competent authorities responsible for AI Act enforcement, and to adopt rules on penalties applicable to infringements, and to communicate those rules to the Commission. That’s six months away from January 2025, and some countries haven’t even started passing the necessary national legislation. The consequence of a missed deadline isn’t an extension, it’s legal uncertainty and the possibility that a country’s enforcement capacity gets challenged by both companies and other member states.

Which Countries Are Actually Ready?

A patchwork of preparedness is already visible. Larger member states have staffed AI offices, drafted penalty ordinances, and begun training market surveillance bodies. Smaller jurisdictions are scrambling. For a company operating across multiple EU countries, this means your compliance posture will face different levels of scrutiny depending on where your registration or main establishment sits, and where your users are. A lagging member state doesn’t make enforcement disappear; it just shifts the burden to cross-border coordination that’s still in its infancy.

Preparedness Indicator Likely Ready by Aug 2025 At Risk
Designated authority legislation passed DE, FR, NL, IE Multiple smaller member states
National penalty rules adopted Several early movers Countries relying on generic administrative law
Staffing and training completed Larger economies Most jurisdictions

The practical takeaway is simple but uncomfortable: if you’re banking on enforcement leniency in a country that hasn’t set up its infrastructure, you’re making a bet that the AI Office and neighboring authorities won’t step into the gap. They can, and likely will, use their own powers to target the provider end, bypassing the unprepared national authority entirely.

The Scientific Panel: More Than Just Advisory

When the European Commission’s guidelines on GPAI providers were released, one organizational detail slipped through with less fanfare than it deserved. The AI Act establishes a Scientific Panel of independent experts tasked with providing technical advice to the AI Office and the AI Board. But the language isn’t purely consultative. The panel can be asked to conduct model evaluations, contribute to risk classification assessments, and flag systemic risks, inserting expert judgment directly into the enforcement pipeline.

When an Expert’s Opinion Becomes an Enforcement Trigger

If the Scientific Panel raises a concern about a GPAI model’s potential systemic risk, the AI Office can initiate a compliance dialogue with the provider, request model modifications, and escalate to the Commission for penalty consideration. This makes the panel a non-voting but influential enforcement actor. A company that thought its model fell outside high-risk classification could suddenly find itself under review because a panel member’s technical analysis says otherwise. That expert-driven friction, independent of political or business pressure, is a wildcard most risk registers are missing.

For AI developers, the implication is to treat technical documentation not just as a compliance formality but as the primary evidence that will be scrutinized by some of the sharpest technical minds in Europe. Vague model cards won’t satisfy a Scientific Panel member. Neither will broad claims about safety metrics without detailed methodology. Get your technical evidence in order before a panel review forces the conversation.

Open-Source and Small Deployers: The Enforcement Blind Spot

Open-source AI and SME deployers often assume they’ll fly below the enforcement radar. That’s half true. The Act exempts open-source models from certain obligations if they’re non-commercial and publicly available, but the exemption vanishes the moment a downstream deployer integrates the model into a high-risk system or violates a prohibited practice. Then the upstream developer can be drawn in through the enforcement chain. Small businesses face the same fine percentages, just applied to smaller absolute numbers but with proportionally higher survival risk.

The enforcement gap is that market surveillance authorities have limited resources and are likely to prioritize high-profile cases. But the private complaint mechanism changes that calculus. A single affected individual can trigger an investigation against a tiny startup just as easily as against a multinational, and the procedural obligations are identical. That makes SME exposure a game of “when, not if” for any public-facing deployment that even brushes against a prohibited category.

Transparency Rules That Already Have Real Teeth

Article 50’s transparency obligations sound soft: users must be informed when they’re interacting with an AI system, deepfakes must be labeled, and certain GPAI model providers must publish training data summaries. But what most coverage misses is how enforceably specific some of these rules already are. According to the AI Act Service Desk, for GPAI model providers, the summary of training data must be sufficiently detailed to allow an evaluation of copyright compliance and bias risks. That’s not a vague aspirational ask. It’s a hard documentation requirement that can be audited.

Did You Know?

Failure to meet transparency obligations can result in fines up to €7.5 million or 1.5% of total worldwide annual turnover, the same tier as supplying incorrect information to authorities.

Monitoring Compliance at Scale

How will the AI Office actually check transparency compliance for thousands of models? Through a combination of desk reviews, third-party research, and the same private complaint mechanism. Civil society groups are already developing tools to audit publicly accessible AI systems for transparency violations. An unreported model deployed behind a chatbot that fails to disclose its AI nature could be flagged, reported to a national authority, and trigger an information request within weeks. This isn’t a distant theory. Similar methods drove GDPR cookie consent enforcement.

The consequence for AI deployers is that transparency isn’t a passive notice buried in a terms-of-service update. It’s an active, testable condition, and the tools to test it at volume are getting better every month.

When GDPR and the AI Act Collide

One of the biggest enforcement headaches hiding in plain sight is the overlap with GDPR. The AI Act explicitly states that it’s without prejudice to existing data protection law, which means the same AI system processing personal data faces dual oversight from AI market surveillance authorities and data protection authorities. The European Data Protection Board (EDPB) has already signaled its intention to coordinate enforcement where the two regimes intersect, but the legal frameworks don’t mesh neatly.

Double Jeopardy, Double Penalties

A single training data breach could expose a company to fines under both the AI Act and GDPR. The GDPR’s maximum is up to €20 million or 4% of annual global turnover, close to, but not identical with, the AI Act’s tiers. The real risk is in separate proceedings: a data protection authority might investigate the data-processing violation while the AI authority pursues the model-compliance angle. Two separate fines, two separate orders, two separate timelines. Article 59 of the Act attempts to promote cooperation between the AI Office and data protection authorities, but coordinated enforcement is aspirational, not guaranteed.

Watch Out

Consent for data processing under GDPR doesn’t automatically satisfy an AI system’s transparency requirement under the AI Act. Each regime requires its own documented rationale.

The practical path for companies is to treat AI compliance and data protection as a unified workstream. That means your DPO needs to be in the room when AI risk assessments happen, and your AI compliance lead needs a working understanding of GDPR enforcement trends. Anything less invites parallel investigations that drain resources twice as fast.

Overlap Area GDPR Obligation AI Act Obligation Enforcement Risk
Automated decision-making Right not to be subject to solely automated decisions High-risk classification, conformity assessment Dual investigations; different fine structures
Transparency Information provision, data subject rights Article 50 disclosure, right to explanation Parallel complaints; overlapping but distinct requirements
Data minimization Only necessary data Training data summaries, bias mitigation Model documentation review by multiple authorities

Real-World Example: The Global-Recruitment Tool Trap

Consider an illustrative example: a US-based recruitment software company, HireSmart Inc., develops an AI screening tool that analyzes candidate video interviews for emotional engagement. The company’s annual global revenue is $180 million, with $3 million from EU-based clients. It doesn’t market the tool as emotion recognition, it calls it “communication analytics”, but the underlying algorithm detects and scores facial expressions linked to enthusiasm and stress.

In March 2025, a rejected EU job candidate files a complaint with their national AI authority, claiming prohibited emotion recognition in hiring. The authority opens an investigation and discovers that the tool wasn’t disclosed as AI-driven to candidates, violating Article 50 transparency rules. HireSmart’s EU subsidiary is cooperative but can’t produce a conformity assessment, because none was done. The candidate’s complaint triggers an information request that exposes the lack of proper documentation.

The national authority coordinates with the AI Office to determine whether the tool’s general-purpose underlying model also falls under GPAI obligations. The AI Office, consulting the Scientific Panel, flags the model for potential systemic risk due to bias patterns in emotion detection across demographic groups. The Commission decides to open a compliance dialogue with HireSmart, requesting model modifications and transparency upgrades.

Because the tool was deployed in an EU hiring context, the prohibition violation exposes HireSmart to a penalty. The €35 million fixed fine under the prohibited-practices tier is trumped by the 7% of worldwide turnover calculation: $180 million × 7% = $12.6 million. Even with EU revenue accounting for just 1.7% of total sales, the company faces a fine more than four times its entire EU annual revenue. The reputation hit sidelines several enterprise deals, and the total cost, including legal fees and remediation, easily exceeds $20 million.

Your Action Plan

  1. Map your AI systems against the prohibited-practices list immediately.

    Don’t wait for internal audit teams to finalize a general inventory. Identify every use case that touches emotion recognition, biometric categorization, social scoring, or manipulative patterns. Flag anything that even arguably applies; the “material distortion” threshold is a judgment call, not a bright line.

  2. Determine your entity’s role: provider, deployer, or both.

    The obligations differ dramatically. A GPAI model provider faces the AI Office directly; a downstream deployer of a high-risk system faces national surveillance authorities. Many companies are both, which means overlapping compliance requirements. Document each role clearly.

  3. Run the global-turnover penalty calculation for each AI product line.

    Use the worst-case scenario: prohibited-practices tier, 7% of total worldwide annual revenue. Compare that to the fixed euro amounts. Treat that number as your exposure baseline, not your risk-adjusted forecast. This number alone often unlocks budget for compliance.

  4. Stand up a complaint-response protocol while the channel is still theoretical.

    Designate a cross-functional team, legal, product, DPO, and communications, to handle a formal complaint under Article 85. Practice a tabletop exercise. Speed matters: the faster you respond to an authority’s initial information request, the more likely you stay on the cordial path.

  5. Prepare transparency documentation that could survive a Scientific Panel review.

    For any model touching EU users, have a clear training data summary, model card, and risk documentation. Don’t rely on marketing language. The panel’s technical experts will read this with a fine-toothed comb. Earlier versions should be dated and archived to show ongoing improvement.

  6. Engage the national authority in your primary EU jurisdiction before August 2025.

    Most authorities haven’t fleshed out their penalty rules or procedural guidelines yet. A proactive outreach, even a simple notification of your compliance plans, builds a relationship that can soften the landing when a real issue arises. This is especially valuable given how crucial time-trimmed proactive efforts are for smaller businesses.

  7. Integrate GDPR and AI Act compliance into a single governance framework.

    Data protection impact assessments (DPIAs) and AI conformity assessments share significant overlap. Combining them into one process reduces duplication and makes it much harder to overlook an intersection that could trigger dual penalties. Your DPO should be a voting member of the AI risk committee.

Learning how to start your compliance groundwork with limited resources is not unlike figuring out how to start investing with less than $500, a methodical, incremental approach beats trying to do everything at once. As AI tools themselves evolve, staying current on the regulatory curve will matter just as much as adopting the productivity tools that push the market, much like how AI productivity tools changed in 2026 forced a rethink of workflow assumptions. And when the stakes are this high, it pays to steer clear of the same preventable mistakes that trip up people when buying a used car, skipping the inspection ends up costing more every time.

Frequently Asked Questions

When does EU AI Act enforcement actually start?

Prohibited practices enforcement began February 2, 2025. GPAI model obligations take effect August 2, 2025. High-risk system rules for most new products apply from August 2, 2026, with some legacy systems phased in later.

Can a non-EU company be fined under the AI Act?

Yes. The Act applies extraterritorially to any company placing an AI system on the EU market or whose output is used in the EU. Fines are calculated on global turnover, not just EU revenue, so companies with minimal EU presence face enforcement exposure disproportionate to their EU business.

What is the role of the European AI Office in enforcement?

The AI Office oversees general-purpose AI models and systemic risks, can request information, conduct model evaluations, and order risk mitigation. It cannot impose fines directly; penalties are decided by the European Commission. For high-risk systems, national authorities take the lead.

Who can file a complaint about an AI system?

Any natural or legal person whose rights are affected by a non-compliant AI system. There’s no fee, no legal representation requirement, and the relevant market surveillance authority must investigate. This includes employees, consumers, job applicants, anyone impacted.

Are open-source models exempt from enforcement?

Only partially. Non-commercial, publicly available open-source models are exempt from certain obligations, but the exemption does not extend to downstream high-risk deployments or to any use that violates a prohibited practice. Enforcement can reach upstream developers if their model is integrated into a non-compliant system.

How do GDPR and the AI Act interact in enforcement?

They operate in parallel. The same AI system processing personal data can trigger investigations by both data protection authorities and AI market surveillance authorities. Fines can stack, and the coordination between the two regimes is not yet fully operational. Companies need unified compliance programs.

What does the Scientific Panel do in enforcement?

The Scientific Panel of independent experts provides technical advice to the AI Office and the AI Board, can evaluate models, flag systemic risks, and contribute to risk classification. Its opinions are not binding but can initiate compliance dialogues, information requests, and eventual penalty escalation.

Are there any exceptions to the prohibited-practices ban?

Yes. Real-time remote biometric identification is allowed for law enforcement in specific serious-crime situations with judicial authorization. Emotion recognition is permitted for medical and safety purposes. Private actors can also avoid the ban if their use case falls outside the narrow legal definitions.

What happens if a member state misses the August 2025 deadline?

Legal uncertainty increases. Without designated authorities and penalty rules, companies can’t know which body to report to or how fines will be calculated. Other member states or the AI Office may step in via cross-border mechanisms, potentially creating unpredictable enforcement outcomes for companies in those jurisdictions.

CB

Camila Brooks

Staff Writer

Running her family’s farm supply business in Ames, Iowa while raising two kids under seven will teach you things no MBA ever could — like why cash flow forecasting matters more than a perfect credit score. Camila took over the books from her dad in 2018 and promptly wrote ‘The Barnyard Budget,’ a self-published guide to small-business finances now available on Amazon that readers keep comparing to Dave Ramsey but with better jokes. She covers money, business basics, and the wild sport of adulting for yourenewssource.com, because if she can explain invoice factoring to a sleep-deprived parent at 11 p.m., she considers that a win.

{“@context”:”https://schema.org”,”@graph”:[{“@type”:”Organization”,”@id”:”https://yourenewssource.com/#organization”,”name”:”YoureNewsSource”,”url”:”https://yourenewssource.com”},{“@type”:”Person”,”@id”:”https://yourenewssource.com/#person-camila-brooks”,”name”:”Camila Brooks”,”description”:”Running her family’s farm supply business in Ames, Iowa while raising two kids under seven will teach you things no MBA ever could — like why cash flow forecasting matters more than a perfect credit score. Camila took over the books from her dad in 2018 and promptly wrote ‘The Barnyard Budget,’ a self-published guide to small-business finances now available on Amazon that readers keep comparing to”,”knowsAbout”:[“Technology”]},{“@type”:”Article”,”headline”:”EU AI Act Enforcement Is Live Now—Here’s What Companies Miss”,”datePublished”:”2026-07-01″,”dateModified”:”2026-07-01″,”publisher”:{“@id”:”https://yourenewssource.com/#organization”},”mainEntityOfPage”:{“@type”:”WebPage”,”@id”:”https://yourenewssource.com/eu-ai-act-enforcement-live-2025-missed-deadlines”},”inLanguage”:”en”,”author”:{“@id”:”https://yourenewssource.com/#person-camila-brooks”}},{“@type”:”FAQPage”,”mainEntity”:[{“@type”:”Question”,”name”:”When does EU AI Act enforcement actually start?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Prohibited practices enforcement began February 2, 2025. GPAI model obligations take effect August 2, 2025. High-risk system rules for most new products apply from August 2, 2026, with some legacy systems phased in later.”}},{“@type”:”Question”,”name”:”Can a non-EU company be fined under the AI Act?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Yes. The Act applies extraterritorially to any company placing an AI system on the EU market or whose output is used in the EU. Fines are calculated on global turnover, not just EU revenue, so companies with minimal EU presence face enforcement exposure disproportionate to their EU business.”}},{“@type”:”Question”,”name”:”What is the role of the European AI Office in enforcement?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”The AI Office oversees general-purpose AI models and systemic risks, can request information, conduct model evaluations, and order risk mitigation. It cannot impose fines directly; penalties are decided by the European Commission. For high-risk systems, national authorities take the lead.”}},{“@type”:”Question”,”name”:”Who can file a complaint about an AI system?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Any natural or legal person whose rights are affected by a non-compliant AI system. There’s no fee, no legal representation requirement, and the relevant market surveillance authority must investigate. This includes employees, consumers, job applicants, anyone impacted.”}},{“@type”:”Question”,”name”:”Are open-source models exempt from enforcement?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Only partially. Non-commercial, publicly available open-source models are exempt from certain obligations, but the exemption does not extend to downstream high-risk deployments or to any use that violates a prohibited practice. Enforcement can reach upstream developers if their model is integrated into a non-compliant system.”}},{“@type”:”Question”,”name”:”How do GDPR and the AI Act interact in enforcement?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”They operate in parallel. The same AI system processing personal data can trigger investigations by both data protection authorities and AI market surveillance authorities. Fines can stack, and the coordination between the two regimes is not yet fully operational. Companies need unified compliance programs.”}},{“@type”:”Question”,”name”:”What does the Scientific Panel do in enforcement?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”The Scientific Panel of independent experts provides technical advice to the AI Office and the AI Board, can evaluate models, flag systemic risks, and contribute to risk classification. Its opinions are not binding but can initiate compliance dialogues, information requests, and eventual penalty escalation.”}},{“@type”:”Question”,”name”:”Are there any exceptions to the prohibited-practices ban?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Yes. Real-time remote biometric identification is allowed for law enforcement in specific serious-crime situations with judicial authorization. Emotion recognition is permitted for medical and safety purposes. Private actors can also avoid the ban if their use case falls outside the narrow legal definitions.”}},{“@type”:”Question”,”name”:”What happens if a member state misses the August 2025 deadline?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Legal uncertainty increases. Without designated authorities and penalty rules, companies can’t know which body to report to or how fines will be calculated. Other member states or the AI Office may step in via cross-border mechanisms, potentially creating unpredictable enforcement outcomes for companies in those jurisdictions.”}}]}]}