AI Regulation in Europe: The EU AI Act's First Real Enforcement Decisions
- Olivia Johnson

- Jun 3
- 3 min read
The European Commission opened formal enforcement proceedings against four AI providers in May 2026 for violations tied to the high-risk classification rules that became binding on February 2.
Those cases mark the first concrete application of the EU AI Act's risk-based framework. They target systems used in credit scoring, hiring, and law enforcement, where providers failed to meet transparency and risk assessment requirements.
US companies face the sharpest adjustment. Many had built compliance layers assuming lighter oversight. The new rulings now force them to embed documentation and human oversight directly into model pipelines.
The decisions also signal how regulators will interpret "systemic risk" thresholds. Providers must now disclose training data summaries and conduct impact assessments before deployment in the Union.
Next steps include a second wave of audits scheduled for July. Those reviews will cover emotion recognition tools and biometric identification systems that remain under review.
First enforcement actions target credit and hiring tools
Regulators named two US providers and one German firm in the opening cases. The actions focus on credit-scoring models that lacked required human oversight during adverse decisions.
The hiring platform cases center on resume screening systems. Authorities found insufficient documentation of training datasets and no clear process for applicants to contest automated rejections.
All four providers received notice letters requiring corrective plans within 60 days. None of the companies can deploy updates in the EU until the plans receive approval.
These categories fall under the Act's high-risk list, which applies to AI used in employment, credit, law enforcement, and critical infrastructure. The list took full effect in early 2026 after a phased rollout that began in 2024.
High-risk rules now require documented human oversight
The Act classifies systems by use case rather than model size. Providers must maintain logs that show how human reviewers can intervene when the model assigns a negative outcome.
US firms had largely relied on post-hoc review processes that sit outside the model itself. The new rulings make clear that the oversight mechanism must operate inside the decision workflow.
Companies also must publish a summary of training data sources. Several providers had treated this as optional under earlier guidance documents. The enforcement letters treat the summary as mandatory for high-risk deployments.
Fines can reach 6 percent of global turnover for repeat or systemic breaches. The opening cases stopped short of penalties but set the standard that later actions can reference.
US compliance stacks shift toward embedded controls
Major US cloud providers began rolling out new logging modules in April that capture reviewer interventions automatically. These modules tie directly to existing model serving infrastructure.
Vendors that sell resume screening tools now require customers to designate an internal reviewer before the system processes any EU applicant pool.
Several firms paused European rollouts of new features while they retrained models on smaller, documented datasets. The pause allows them to meet the data-summary requirements without rebuilding entire pipelines.
The shift has increased engineering costs, though companies have not released specific figures. The focus has instead turned to reusable compliance components that can apply across multiple product lines.
Regulators signal broader biometric reviews ahead
The Commission indicated that emotion recognition and real-time biometric identification tools will face the next round of checks. These uses sit at the top of the prohibited list with limited exceptions.
Law enforcement agencies in member states have already begun submitting impact assessments for any AI that processes live video feeds. The assessments must address false positive rates and appeal procedures.
Providers of these tools now face a tighter timeline than the general high-risk group. Documentation must be filed before any new deployment rather than after the fact.
What remains uncertain
The opening cases did not address generative AI models that power general chat interfaces. Those systems fall under a separate transparency obligation that takes effect later in 2026.
It also remains unclear how strictly regulators will interpret "substantial modification" triggers. Minor fine-tuning that changes output distribution could force fresh assessments, yet the thresholds have not been tested in practice.
Some member states have asked for additional guidance on enforcement coordination. The Commission plans a common methodology document by September, but timing could slip if political negotiations extend.
What to watch next
Watch for the July audit results on biometric systems. Those findings will test whether the same documentation standards apply when national security claims are raised.
Watch the response from the four notified providers when their corrective plans become public. The level of detail they release will indicate how much of the compliance burden they intend to shift onto customers.
Watch whether other jurisdictions reference the EU documentation requirements in their own draft rules. Early signals from Canada and the UK suggest similar data summary obligations may appear in 2027 proposals.


