The EU AI Act Enters Enforcement: Scope, Duties and Exposure for Israeli Companies

חוק הבינה המלאכותית האירופי EU AI Act, כניסה לשלב האכיפה באוגוסט 2026
August 2026 · AI Regulation

The EU AI Act Enters Enforcement: Scope, Duties and Exposure for Israeli Companies

The grace period is over. The European AI Office now holds live investigative powers, three complaint channels are open, and the transparency obligations have applied since 2 August 2026. This is no longer a draft regime. It is an operational reality carrying fines of up to 7% of global turnover.

Global AI regulation has crossed a threshold. The EU Artificial Intelligence Act, formally Regulation (EU) 2024/1689, entered into force in August 2024, and its obligations have since unfolded along a staged timeline. Two years on, the initial preparation period has ended. The European Commission, acting through the EU AI Office and the national competent authorities of the Member States, has begun enforcing the Act in practice.

For technology companies, founders, software developers and organisations in Israel that offer AI-based products, services or systems into the European market, the message is unambiguous. AI regulation is no longer a theory, a position paper or a draft awaiting adoption. It is a binding legal and operational reality, backed by supervisory powers, reporting mechanisms and substantial financial penalties.

Legislative update

On 24 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal of the European Union, and it entered into force on 27 July 2026. The Regulation postponed the application dates for the high-risk obligations, but not the bulk of the transparency obligations. Those apply from 2 August 2026, subject to a four-month extension until 2 December 2026 for content-marking in systems already placed on the market before that date.

2 Aug 2026
Transparency obligations in force
3
Active complaint channels at the AI Office
~190
Signatories to the transparency Code of Practice
7%
Maximum fine, share of global turnover
1

The regulatory timeline: what applies, and when

The EU AI Act rests on a risk-based approach, sorting AI systems into tiers that run from unacceptable risk, which is prohibited outright, down to minimal risk, which carries no dedicated obligations. Those duties are phased in along a staged timeline, most recently revised by the Omnibus Regulation that took effect in July 2026.

2 February 2025
Prohibited practices and the AI literacy duty begin to apply
An outright ban on unacceptable-risk systems, covering social scoring, cognitive manipulation and real-time remote biometric identification in public spaces for law enforcement, alongside the AI literacy duty under Article 4. The Omnibus softened that duty into an obligation to take measures promoting literacy, rather than an obligation to ensure a sufficient level of it.
2 August 2025
GPAI model obligations and the governance architecture
Obligations on providers of general-purpose AI models take effect, national competent authorities are designated, and the Member State penalty regimes are established.
2 August 2026 WE ARE HERE
Enforcement begins: the transparency obligations under Article 50
The AI Office activates its enforcement powers: investigation, document requests, evaluations, and direct access to models. In parallel, the transparency and disclosure duties begin to bind providers and deployers, and the complaint and supervision channels go live.
2 December 2026
End of the grace period for marking content in legacy systems
Content-generating AI systems placed on the market before 2 August 2026 received a four-month extension to implement the marking and detection duties under Article 50(2). The same date closes the transition period for the new prohibitions on systems generating non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM).
2 August 2027
Regulatory sandboxes
The Member States' obligation to establish national regulatory sandboxes was postponed to 2 August 2027, from the original date of 2 August 2026.
2 December 2027
Stand-alone high-risk systems (Annex III)
Stand-alone high-risk systems: recruitment and HR, credit scoring, education, law enforcement, critical infrastructure. The application date was postponed by the Omnibus Regulation from the original 2 August 2026. This is where the heavy obligations sit: a risk management system, data governance, technical documentation, human oversight, accuracy and cybersecurity.
2 August 2028
Systems embedded in regulated products (Annex I)
AI systems serving as a safety component in products governed by EU harmonisation legislation: medical devices, vehicles, machinery, aviation.
NEWThe Omnibus Regulation is no longer a proposal. On 24 July 2026 Regulation (EU) 2026/1744 was published in the Official Journal, and it entered into force on 27 July 2026. Beyond postponing the high-risk dates, it extended the AI Office's supervisory powers to AI systems supplied by providers of general-purpose models, and to systems that constitute, or are integrated into, very large online platforms and very large online search engines (VLOPs/VLOSEs) subject to the DSA.
2

The risk pyramid: where your system sits

Correct classification is the first and most consequential step. The same underlying model may fall into an entirely different tier depending on the use made of it:

Unacceptable riskProhibited · social scoring, manipulation, real-time biometric ID · fines up to 7%
High riskPermitted subject to heavy obligations · recruitment, credit, education, law enforcement · from December 2027
Transparency riskDisclosure and marking duties · chatbots, deepfakes, generated content · in force now
Minimal riskNo dedicated obligations, other than AI literacy under Article 4 · spam filters, recommendations, video games
The practical point: most Israeli companies building AI-based SaaS products will find themselves in the transparency risk tier, the layer that has just entered enforcement, alongside the outright prohibitions that have been enforceable since 2025. That is precisely why preparation is urgent even for a company confident its system is not high risk.
3

The transparency obligations, now in force

Article 50 imposes direct and detailed transparency duties, whose enforcement began in the present wave, on both providers and deployers of AI systems:

Disclosure on interactionArt. 50(1)

Any AI system that interacts directly with people, including chatbots, voice assistants and automated response systems, must make clear to the user, in a clear and distinguishable manner and no later than the first interaction, that they are dealing with an AI system rather than a human being. The exemption applies where this is obvious to a reasonably observant user, and, subject to safeguards, to systems authorised by law to detect, prevent, investigate or prosecute criminal offences.

Marking generated content and recording its provenanceArt. 50(2)

Providers must embed machine-readable markings in any text, audio, image or video generated or manipulated by AI, and offer detection mechanisms. Accepted technologies include Content Credentials (C2PA), digital watermarking such as SynthID, and cryptographic metadata.

Labelling deepfakesArt. 50(4)

A clear legal duty to disclose, visibly and audibly, any visual or audio content constituting a deepfake, meaning content that realistically depicts people, places or events. A parallel duty applies to text published on matters of public interest, unless the material has undergone substantive human editorial review.

Emotion recognition and biometric categorisationArt. 50(3)

Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to the system that it is operating, and process the personal data in accordance with the GDPR. This is particularly relevant to recruitment, customer service and security systems.

The Code of Practice on transparency of AI-generated content

On 10 June 2026 the European Commission published the Code of Practice on Transparency of AI-Generated Content, a non-binding instrument translating Article 50 into measurable technical practice. By the end of July 2026 roughly 190 companies and organisations had signed it. Signing is voluntary, but it confers a practical safe harbour: the Commission has confirmed that signatory providers and deployers may rely on its measures to demonstrate compliance with the Act. The Commission has also published a standard icon set for labelling content.

Note the distinction: this instrument is separate from the GPAI Code of Practice, published during 2025, which addresses the obligations of foundation model providers themselves. A company may be subject to both.
4

General-purpose AI models and systemic risk

The Act devotes an extensive chapter to providers of general-purpose AI models, models capable of performing a wide range of tasks and serving as infrastructure for many downstream applications:

  • Technical documentation and data transparency: GPAI model providers must supply detailed technical documentation, publish a stated copyright compliance policy, and release a sufficiently detailed publicly available summary of the training data used to build the model.
  • Transparency towards downstream providers: providers must give companies building applications on the model the information those companies need in order to meet their own obligations.

Models with systemic risk

Models of exceptionally high computational capability, or with broad market impact, are subject to an additional layer of obligations:

  • Comprehensive risk assessment and continuous monitoring of systemic risk across the model lifecycle.
  • Robustness testing and adversarial testing, including red-teaming carried out by independent external parties.
  • Stringent cybersecurity protecting the model weights and the physical and logical infrastructure surrounding them.
  • Immediate reporting to the AI Office of serious safety or security incidents and the corrective measures taken.
5

The enforcement toolkit: three active complaint channels

To make enforcement effective, the EU AI Office has formally launched a set of digital tools enabling close supervision. In practice, this creates three distinct exposure routes for every provider:

The general complaints toolArt. 85

A mechanism allowing any individual or organisation to file a formal complaint concerning infringements of the Act by providers or deployers of AI systems falling within the AI Office's exclusive competence. The complaint requires the complainant to identify themselves.

The downstream providers channelArt. 89(2)

A dedicated mechanism for companies developing applications on third-party general-purpose models. It allows them to complain where the GPAI model provider has failed to supply the technical documentation, training data summaries or safety information required under Articles 53 to 55.

The whistleblowing channelWhistleblower Tool

A secure and anonymous channel for employees and others with a professional connection to AI providers, enabling confidential reporting of internal breaches of safety and regulatory procedures that endanger fundamental rights, health or public trust.

What this means in management terms: the downstream providers channel and the whistleblowing channel redraw the risk map. Regulatory exposure no longer depends on a regulator opening an inquiry of its own motion. It can begin with a frustrated business customer or a former employee. Orderly internal documentation and demonstrable safety procedures shift from good practice to genuine legal defence.
6

The penalty tiers

The sanctions regime is graded across four levels. At each level the applicable figure is the higher of the two: a percentage of global turnover, or a fixed amount in euro.

Type of infringement Examples Maximum fine
Prohibited practicesArticle 5 Social scoring, cognitive manipulation, real-time biometric identification in public spaces, untargeted mass scraping of facial images 7%or EUR 35 million
Breach of substantive obligationsArticles 16, 26, 50 and others Failure to disclose interaction with a chatbot, absence of marking on generated content, unlabelled deepfakes, breach of high-risk system obligations 3%or EUR 15 million
GPAI provider obligationsArticle 101 Failure to supply technical documentation, failure to publish a training data summary, failure to cooperate with the AI Office 3%or EUR 15 million
Supply of incorrect informationArticle 99(5) Supplying incorrect, incomplete or misleading information to competent authorities or to notified bodies 1%or EUR 7.5 million

For small and medium-sized enterprises and start-ups, a softened mechanism applies: the fine is capped at the lower of the two components. That is a meaningful concession, and one relevant to a substantial share of the Israeli ecosystem.

7

The dual Israeli exposure: European reach and a domestic duty

Extraterritorial application

The EU AI Act has broad extraterritorial reach, following the model established by the GDPR. An Israeli company physically located in Israel, but developing, selling or operating an AI system accessible to users or businesses in the European Union, or whose output is used within the Union, is subject to the obligations of the Act that attach to its role and to the risk classification of the system. The test is not where you are established. It is where the effect lands.

Scope in practice: a company with no direct European customers may still fall within scope, for instance where it acts as a subcontractor to a European client, or where the output of its system, a report, a score, a classification, is used inside the Union. The supply chain is the exposure point companies tend to overlook.

The domestic layer: Amendment 13 and the Privacy Protection Authority guidance

Alongside the European arena, Israeli organisations are in the middle of a parallel domestic shift. Amendment 13 to the Protection of Privacy Law, in force since August 2025, substantially expanded the enforcement powers of the Privacy Protection Authority and imposed an obligation to appoint a Data Protection Officer on a wide range of entities.

The Privacy Protection Authority has also published a position stating that the Protection of Privacy Law applies to artificial intelligence systems. Its main elements include: a heightened informed consent duty covering how the system operates and the risks it carries; a duty to notify users when they are interacting with an automated bot; a determination that scraping data from the internet to train models, without consent, may constitute an unlawful invasion of privacy; and an emphasis on access and rectification rights, including correcting algorithms that have produced inaccurate information.

INSIGHTThe overlap is the opportunity. The duty to disclose that a user is interacting with a bot appears in almost identical form in both regimes, the European one under Article 50 and the Israeli one under the Authority's position. An organisation that builds a single, well-designed AI governance layer satisfies both at once. Building two separate compliance programmes means paying twice.
8

A practical readiness checklist

Eight steps every organisation exposed to the European regime should take. Tick off what is already done:

For enquiries on this subject: contact the office
Disclaimer: the above is a general and concise overview only, and does not constitute legal advice or a substitute for individual legal advice. Regulation in the field of artificial intelligence is in constant motion, and the provisions of the law, the applicable dates and their interpretation may change. Information current as of August 2026.
x
סייען נגישות
הגדלת גופן
הקטנת גופן
גופן קריא
גווני אפור
גווני מונוכרום
איפוס צבעים
הקטנת תצוגה
הגדלת תצוגה
איפוס תצוגה

אתר מונגש

אנו רואים חשיבות עליונה בהנגשת אתר האינטרנט שלנו לאנשים עם מוגבלויות, וכך לאפשר לכלל האוכלוסיה להשתמש באתרנו בקלות ובנוחות. באתר זה בוצעו מגוון פעולות להנגשת האתר, הכוללות בין השאר התקנת רכיב נגישות ייעודי.

סייגי נגישות

למרות מאמצנו להנגיש את כלל הדפים באתר באופן מלא, יתכן ויתגלו חלקים באתר שאינם נגישים. במידה ואינם מסוגלים לגלוש באתר באופן אופטימלי, אנה צרו איתנו קשר

רכיב נגישות

באתר זה הותקן רכיב נגישות מתקדם, מבית all internet - בניית אתרים.רכיב זה מסייע בהנגשת האתר עבור אנשים בעלי מוגבלויות.