Fines of up to 35 million euros: The AI Act has entered into force

The grace period under the AI Act ended on August 2, 2026, when the European Commission’s AI Office and national authorities were granted actual powers to investigate and impose sanctions.

Until that date, the regulation had been in effect in parts: the bans took effect in February 2025, and the rules for GPAI models in August 2025, but without an enforcement mechanism at the EU level. Now the puzzle is complete. Violations result in fines, and the Commission has also published the specific channels through which anyone can file a report.

Who Oversees What?

Competence is divided into three levels.

AI Office is responsible for providers of GPAI models—including the most advanced ones posing systemic risk—for AI systems built by the same provider using its own model, and for AI functions in very large online platforms and search engines under the DSA. National market surveillance authorities are responsible for all other AI systems within their territory. The European Data Protection Supervisor oversees the EU institutions themselves.

The Powers of the AI Office

The tools are similar to those used in competition law. The AI Office can issue requests for information (RFIs), and providing an inaccurate or misleading response is in itself subject to a fine. For GPAI models, the agency conducts model evaluations, requires access to the model for independent experts, and, as a last resort, may request that public access to the model be restricted. For AI systems, it has the right to conduct interviews and on-site inspections at the provider’s premises.

Three Levels of Sanctions

The penalties are graded according to the severity of the violation.

  • Prohibited AI practices: up to 35 million euros or 7% of global annual revenue, whichever is higher
  • Violations of obligations regarding GPAI models: up to 15 million euros or 3% of revenue
  • False, incomplete, or misleading information in inquiries regarding AI systems: up to 7.5 million euros or 1% of turnover

The percentage of global revenue is the key factor: for a large technology group, 7% amounts to billions, so the scheme is designed to have an impact regardless of the company’s size. For small businesses, the more realistic risk is the penalties that national authorities will specify in local legislation.

What is subject to inspection as of August 2, 2026

Three sets of rules are being enforced simultaneously. Prohibited practices include systems designed to manipulate people, the exploitation of vulnerabilities, social assessment that threatens rights, and predictive policing based solely on profiling. Obligations for GPAI providers include transparency toward downstream developers, compliance with copyright laws, and security measures for models posing systemic risk. The rules under Article 50 require chatbots to be identified as AI, deepfakes to be labeled, and synthetic content to carry machine-readable markers such as SynthID.

The timeline moves forward. The bans on the non-consensual generation of intimate images and on child sexual abuse material will take effect on December 2, 2026, as part of the so-called AI Omnibus. The rules for high-risk systems under Annex III will apply starting December 2, 2027, and for AI embedded in regulated products, starting August 2, 2028.

Three Channels for Complaints and Reports

The Commission has launched three separate market monitoring tools.

  • AI Act Complaints Tool: complaints filed under Article 85 by individuals and legal entities against AI systems under the supervision of the AI Office; this channel is not anonymous and requires identification, the country where the incident occurred, and a description of the violation
  • AI Act Whistleblower Tool: an anonymous channel for individuals with a professional relationship with a provider or implementer who report violations that threaten fundamental rights or public trust
  • Channel for downstream suppliers: for developers who have integrated a third-party GPAI model into their product and are experiencing issues related to Articles 53–55, such as denied access to technical documentation

Complaints may be filed in any official EU language, including Bulgarian. For online merchants, this also works the other way around: a dissatisfied customer or competitor can file a complaint against your website just as easily.

Where Does Bulgaria Stand?

The national framework is behind schedule. According to public data from the Ministry of e-Government, the interagency working group was formally established in early 2026, but decisions regarding supervisory authorities, the sanctions regime, and the national registry of AI systems have not yet been adopted. A draft proposal designates the Bulgarian Accreditation Service Executive Agency as the notifying authority.

The absence of domestic legislation is not a loophole. The regulation is directly applicable; Bulgarian companies and citizens have been filing complaints with the AI Office since August 2; and the Commission’s sanctioning powers do not depend on Sofia.

What Businesses Should Do

It’s unlikely that an inspector will knock on the door of an average WooCommerce store tomorrow, but the audit trail is being built today. Review which AI services you actually use and what role you play (implementer in most cases), document what your providers are responsible for in terms of labeling and compliance, and describe your AI usage when drafting your terms and conditions. The regulatory burden on e-commerce is compounded by online store taxes and consumer protection laws, and the “Law and Taxes” section brings together analyses of these topics in one place.

EU Icons

The icons come in four versions: black, white, black with 50% transparency, and white with 50% transparency. You can download ZIP files containing all the icons in all versions in SVG and PNG formats.

The icons underwent user testing, and the results influenced their design. It is noteworthy that performance improved across all metrics when the main icon was accompanied by a text label (e.g., “modified”).

IconWhen is it used?Examples
Main Iconfines of up to 35 million euros: the ai act has entered into force - 1When artificial intelligence has been used to create fake content (images, audio, video) or published text, or when a personalized text label or interactive overlay has been added.A deepfake video with the text label “voices generated with,” followed by the main icon
Generated entirely by artificial intelligencefines of up to 35 million euros: the ai act has entered into force - 2When all fake content (images, audio, video) or text is generated entirely by artificial intelligence without any human input or human editorial oversight (except for prompts)Deepfake videos featuring politicians or fictional events, generated entirely by artificial intelligence; Music or art entirely composed by artificial intelligence;* News summaries generated by artificial intelligence.
Partially modified using artificial intelligencefines of up to 35 million euros: the ai act has entered into force - 3When it existed previously, the human-generated content was partially modified using artificial intelligence, turning it into deepfake text or text on topics of public interest.A person’s face in an authentic photo was replaced with that of a politician using artificial intelligence. Authentic photos of an empty apartment were generated using artificial intelligence.

*May be used with limited disclosure requirements for artistic, creative, or satirical works

The use of these EU icons is optional, but the labeling requirements under Article 50 of the Artificial Intelligence Act are not. The use of these icons alone does not establish compliance with the law. Implementers remain responsible for ensuring that any disclosure complies with the requirements of Article 50 of the Artificial Intelligence Act. Signatories to the Code of Practice on the Marking and Labeling of AI-Generated Content must duly implement the measures set forth therein.

Frequently Asked Questions

  1. What are the maximum fines under the AI Act?

    Up to 35 million euros, or 7% of global annual revenue, for prohibited practices; up to 15 million euros, or 3%, for violations related to GPAI models; and up to 7.5 million euros, or 1%, for providing false information in response to inquiries regarding AI systems.

  2. Who imposes the sanctions under the AI Act in Bulgaria?

    The national market surveillance authorities, whose designation had not yet been finalized as of mid-2026. The Commission’s AI Office directly imposes sanctions on providers of GPAI models and AI systems on very large platforms.

  3. Can a complaint under the AI Act be filed in Bulgarian?

    Yes, the AI Act Complaints Tool accepts complaints in all official EU languages, including Bulgarian, but the channel is not anonymous and requires identification.

  4. When will the rules for high-risk AI systems take effect?

    Effective December 2, 2027, for systems listed in Annex III, and effective August 2, 2028, for AI embedded in regulated products.

Share: