EU AI Act Enforcement Advances as Officials Highlight Safety Needs
At a glance
- The EU AI Act applies a risk-based approach to AI regulation.
- Enforcement by the AI Office and national authorities began in August 2026.
- EU official Henna Virkkunen called for international AI safeguards in October 2026.
The European Union has implemented a regulatory framework for artificial intelligence, with enforcement underway and officials emphasizing the importance of safety measures. The approach is designed to address varying levels of risk associated with AI systems across member states.
The AI Act, which came into force on August 1, 2024, establishes a uniform set of obligations for AI systems throughout the EU. These requirements include provisions for transparency, human oversight, and cybersecurity, with obligations determined by the assessed risk level of each system.
Since August 2, 2026, the AI Office and national competent authorities have been responsible for enforcing the AI Act. The enforcement scope includes general-purpose AI models, ensuring that compliance is monitored across a broad range of technologies.
On October 9, 2026, European Commission Executive Vice-President Henna Virkkunen stated that countries hesitant to regulate artificial intelligence are likely to support safety measures in the future. She also called for the establishment of international safeguards to address the risk of serious incidents in the absence of adequate AI guardrails.
What the numbers show
- The AI Act took effect on August 1, 2024, in all EU countries.
- Enforcement activities by the AI Office and national authorities began on August 2, 2026.
- Henna Virkkunen made her statement regarding AI regulation on October 9, 2026.
The AI Act’s risk-based framework applies to all EU member states, creating consistent standards for AI system deployment and oversight. The regulation’s requirements are tailored to the potential impact of each AI application, with stricter controls for higher-risk systems.
Transparency obligations under the Act require that certain information about AI systems be made available to users and authorities. Human oversight measures are also mandated, aiming to ensure that automated decisions can be reviewed and, if necessary, corrected by people.
Cybersecurity is a key component of the regulatory requirements, with the Act specifying that AI systems must be protected against unauthorized access and manipulation. These measures are intended to reduce the likelihood of incidents resulting from security vulnerabilities.
Officials have stated that international cooperation is necessary to address the global nature of AI development and deployment. Calls for broader safeguards reflect ongoing discussions among policymakers about harmonizing safety standards beyond the EU.
* This article is based on publicly available information at the time of writing.