Enforcement is now an operating reality

From 2 August 2026, the European Commission's AI Office and national competent authorities began exercising enforcement powers for the AI Act provisions already in application. The Commission has also highlighted routes for AI Act complaints, whistleblower reports and concerns raised by downstream providers using general-purpose AI models.

This changes the practical posture for businesses. Readiness is no longer only about completing a policy or anticipating a future audit. An organisation may need to explain a system, decision or control in response to a concern raised by a customer, employee, supplier, user or authority.

Not every report will establish non-compliance, and the relevant authority depends on the system and provision involved. But every organisation using or supplying AI should be able to locate the factual record behind its governance claims quickly.

Which rules are currently enforceable

The AI Act applies progressively. The Commission's enforcement overview identifies provisions already in play, including prohibited AI practices, obligations for providers of general-purpose AI models and transparency requirements for certain AI systems.

Other dates still matter. The Commission states that additional prohibitions concerning non-consensual intimate material and child sexual abuse material apply from 2 December 2026, while high-risk system rules follow later under the revised timetable.

Businesses should therefore maintain a provision-by-provision view rather than treating the AI Act as a single deadline. The first evidence question is always: which system, role, use and applicable obligation are involved?

Complaints expose weak ownership before weak paperwork

When a concern arrives, the first failure is often uncertainty about ownership. Customer support may see the issue first, while product, legal, compliance, security and a third-party model provider each hold part of the answer.

Create a documented intake route for AI-related complaints and concerns. It should identify who triages the report, who can preserve evidence, who assesses severity, when senior leaders are informed and how legal or regulatory escalation is decided.

Connect that route to the AI system inventory. A report should be traceable to the relevant system owner, intended purpose, deployment version, model or supplier, applicable controls and previous risk assessment.

Prepare an evidence response pack before it is needed

For each material AI system, maintain a compact response pack: system description, intended purpose, regulatory role view, risk classification, data and supplier map, testing summary, human oversight design, transparency evidence, incident history and change record.

The pack should distinguish evidence that existed at the time of the decision from analysis created afterwards. Contemporaneous approvals, test results, interface captures and release records generally provide a clearer account than a retrospective narrative assembled under pressure.

Access also matters. Preserve confidentiality and privilege where appropriate, but avoid creating a process where no authorised person can assemble the relevant record within a sensible timeframe.

Downstream-provider concerns require supplier traceability

The Commission specifically identifies a complaints channel for downstream providers using general-purpose AI models. That reinforces a wider procurement lesson: organisations need a reliable way to raise issues through the AI supply chain and understand how upstream providers will respond.

Record model dependencies, contractual contacts, incident-notification commitments and the evidence a provider has agreed to supply. Where a model or service changes materially, reassess whether prior testing and transparency measures remain valid.

A supplier assurance statement without escalation routes, version information or change evidence is unlikely to be enough when a real concern arises.

A practical 30-day readiness agenda

In week one, confirm the inventory and owners for customer-facing, employee-facing and general-purpose AI-dependent systems. In week two, test the complaint and escalation route using a realistic scenario. In week three, assemble evidence packs for the highest-exposure systems. In week four, close ownership gaps and brief support, product, procurement and leadership teams.

The goal is not to predict every complaint. It is to make sure the organisation can understand a concern, preserve the record, involve the right people and provide an evidence-based response.

AI Act Ready helps teams connect system inventories, supplier records, controls and decision evidence into a living assurance pack. This article is practical guidance rather than legal advice; organisations should obtain legal input for specific regulatory matters.