The European Union's AI Office has issued its first formal sanctions under the EU AI Act, targeting three unnamed AI providers for deploying high-risk AI systems without completing mandatory conformity assessments. The penalties — totaling €15 million across the three cases — mark the transition from the regulation's grace period into active enforcement, a shift AI legal teams across the industry have been preparing for since the Act's phased rollout began in 2024. The sanctioned systems span biometric categorization, employment screening, and critical infrastructure management — all classified as high-risk under Annex III of the regulation.
The EU AI Office published a 47-page technical assessment accompanying the decisions, outlining the specific documentation failures that triggered sanctions. Chief among them: incomplete technical documentation under Article 11, absence of post-market monitoring systems required by Article 72, and failure to register systems in the EU's newly operational AI database before commercial deployment. Legal analysts note that documentation failures are the most common compliance gap, reflecting the significant operational burden the Act places on organizations deploying AI in regulated sectors.
Industry response has been mixed. The penalties are below the Act's maximum (€35M or 7% of global annual turnover for the most serious violations), suggesting the EU is calibrating initial enforcement to drive compliance rather than impose maximum penalties. However, legal advisors warn that the precedent-setting nature of the first decisions means organizations should expect escalating scrutiny. Several major US technology companies with European operations have been auditing their AI deployments since early 2025, accelerating documentation programs in anticipation of enforcement. The full prohibited AI systems list — which bans real-time public biometric surveillance and social scoring — comes into full force in August 2026.