European Union legislators have completed a two-year negotiation to finalise the enforcement mechanism for the Artificial Intelligence Act — the world's most comprehensive regulatory framework for AI systems — clearing the final bureaucratic hurdle for full implementation across all 27 member states.
The agreed mechanism establishes a tiered audit system where AI systems classified as "high risk" — including those used in hiring, criminal justice, immigration processing, and critical infrastructure — must undergo independent conformity assessments every 18 months by accredited evaluation bodies.
Companies found in violation of the Act's provisions face fines of up to 7 percent of global annual turnover or €35 million, whichever is greater. For prohibited AI practices, including real-time mass biometric surveillance and social scoring systems, penalties rise to 10 percent of global revenue.
The regulation is expected to have significant extraterritorial impact, as any company offering AI services to European consumers — regardless of where it is headquartered — must comply with the Act's transparency, safety, and human oversight requirements.
Tech industry groups have expressed concern about the compliance burden on smaller AI startups, while digital rights organisations have broadly welcomed the framework as a "global benchmark for accountable AI governance."

