AI Act Enforcement and Frontier Controls
Coverage from Duschka, Davis Wright Tremaine, and others

AI governance is moving from voluntary principles toward enforceable controls for frontier models and autonomous agents.
EU AI Act enforcement, formal information requests, and cross-border obligations are converging with reported containment failures and weak internal safeguards, while the United States and other jurisdictions pursue more fragmented or voluntary approaches.
The story now has clearer evidence of active EU enforcement: the AI Office reportedly sent formal information requests to more than 30 developers. It also highlights implementation uncertainty and reframes compliance as an operational, market-access, and supply-chain requirement.
The story has moved from anticipated EU enforcement to active regulatory information-gathering and compliance assessment. It also broadens beyond AI regulators as cybersecurity and privacy agencies address agentic-system risks and data controls.
The story shifts from broad regulatory readiness toward operational accountability, with new evidence that frontier-model controls remain incomplete and sector-specific deployments are creating concrete liability and appeal questions.
The story shifts from phased EU implementation toward reported full applicability and active enforcement on August 2, 2026, with explicit penalty exposure. It also broadens through proposed oversight of frontier AI infrastructure and new findings on Hong Kong organizations’ privacy controls.
- The EU AI Act reportedly became fully applicable on August 2, 2026.
- Potential EU penalties may reach €35 million or 7% of global revenue.
- Frontier-model oversight proposals now encompass data centers and semiconductor supply chains.
- Hong Kong checks identified weaker retention practices and declining board-level AI policy discussions.
- U.S. federal opposition is now an explicit counterweight to state-level AI regulation.
The European Union is moving the AI Act from implementation toward enforcement while expanding transparency, cybersecurity, and high-risk system obligations. Reported OpenAI and Anthropic model incidents have intensified attention on evaluations, sandbox controls, incident response, and safeguards for advanced AI. The Act is also influencing companies outside Europe, while employers and privacy regulators in the United States, China, and Hong Kong continue to operate under more fragmented or sector-specific requirements.
