
On 2 August, the European Union's AI Act became fully enforceable, and its Article 50 transparency obligations came into force alongside it. In the fortnight since, a specific claim has circulated widely in trade press and on social media: that the EU AI Office has already fined three companies a combined €47 million. CNBC has separately reported that Anthropic and OpenAI are facing new scrutiny under the Act's enforcement powers. Something is clearly happening. But checking the European Commission's own enforcement material against the specific fine figures being repeated turns up no match, and that gap is worth understanding before anyone treats the €47 million number as fact.
For Australian organisations working out what this enforcement era actually means for them, the temptation is to anchor on the most dramatic number circulating. The more useful exercise is separating what the regulator has actually confirmed from what is still unverified chatter.
What the European Commission Has Actually Confirmed
The Commission's own published enforcement framework confirms that the AI Office's investigative and sanctioning powers became active on 2 August 2026. Those powers are genuinely substantial: requests for information, model evaluations and requests for access to GPAI models, interviews of relevant individuals and inspections of provider premises. On the sanctioning side, infringements involving prohibited AI practices carry penalties of up to €35 million or 7 percent of global turnover, whichever is higher, with other breaches of GPAI obligations capped at €15 million or 3 percent, and breaches related to AI systems capped at €7.5 million or 1 percent.
The Commission also confirms three new tools now live: an AI Act Complaint Tool for the public, a Whistleblower Tool for individuals connected to a provider in a professional capacity, and a complaints channel for downstream providers using general purpose AI models. Nowhere in this material, as of publication, does the Commission name a fined company or confirm any penalty amount.
The €47 Million Figure Nobody Can Actually Source
The specific claim in circulation, three companies fined a combined €47 million across hiring, credit scoring and retail biometric use cases, traces back to unofficial aggregator sites rather than the Commission or any national market surveillance authority. One of the more widely shared versions of this claim is internally inconsistent, citing different figures for the same company in its own headline and body text. That is a reasonable signal the underlying reporting has not been properly verified, and it is a pattern worth being sceptical of generally in the early weeks of any new enforcement regime, when speculation tends to circulate faster than confirmation.
Until an official Commission statement, a published decision, or credible primary reporting actually confirms a fine and names the company involved, the €47 million figure should be treated as unverified rather than repeated as settled fact.
What Is Actually Verified Beyond the Rumour
Separating the unverified fine figure from the rest of the picture still leaves genuine developments worth taking seriously. CNBC reported on 3 August that Anthropic and OpenAI are facing new scrutiny under the Act's enforcement powers, a credible outlet naming real organisations in the context of active oversight rather than a settled penalty. There are also reports that national market surveillance authorities in Germany, France and the Netherlands have opened formal inquiries, though these have not been confirmed by name in official Commission material and should be read as reported activity rather than established fact.
Reporting also suggests the AI Office's preferred first tool is what has been described as a technical compliance dialogue, a process of engagement and clarification with a provider before any sanction is considered. That is a more measured picture than a headline fine figure, and it is also a more typical way for a new enforcement regime to actually begin.
Why the Distinction Between Confirmed and Rumoured Actually Matters
Regulatory rumour cycles like this one create a specific risk for compliance teams. Some organisations will overreact, assuming fines are already flying and treating every AI system as an emergency. Others will dismiss the whole development as noise once a headline figure turns out to be unverifiable. Neither response is well calibrated. What is actually confirmed, genuine investigative powers, real scrutiny of frontier AI providers, and public complaint and whistleblower tools now live, is serious enough on its own without needing an unverified fine figure to make the point.
What Australian Organisations Should Actually Do
The practical response does not depend on whether the €47 million figure is ever substantiated. The AI Office's confirmed powers, requests for information, inspections, and a whistleblower tool now open to anyone professionally connected to a provider, are reason enough to have an honest inventory of which AI systems interact with people in the EU, and whether the Article 50 disclosure, labelling and machine readable mark requirements are actually being met.
What This Means for Your Organisation
What we see across the organisations we work with is that regulatory rumour cycles like this one are common in the early weeks of a new enforcement regime, and the organisations that get caught out are rarely the ones who reacted to the wrong headline. They are the ones who did not check what was actually confirmed either way, and were unprepared regardless of which version of the story turned out to be true.
Key Takeaways
- The EU AI Act's enforcement powers and its Article 50 transparency obligations became active on 2 August 2026, confirmed directly in the European Commission's own published enforcement framework.
- A widely circulated claim that three companies were fined a combined €47 million does not appear in any Commission material and traces only to unofficial sources with internally inconsistent figures.
- CNBC has reported that Anthropic and OpenAI are facing new scrutiny under the Act's enforcement powers, and national market surveillance authorities in several member states are reported to have opened formal inquiries.
- The AI Office's confirmed powers include requests for information, model evaluations, inspections and fines of up to €35 million or 7 percent of global turnover for the most serious breaches.
- Organisations should act on the confirmed powers and the newly available complaint and whistleblower tools now, rather than waiting to see whether the rumoured fine figure is ever substantiated.
How Trusenta Can Help
AI Governance registers which AI systems interact with EU based users so exposure to confirmed obligations like Article 50 can be identified before a regulator asks.
Compliance Management tracks obligations across the EU AI Act alongside Australian frameworks in a single view as enforcement activity accelerates globally.
AI Governance Enterprise builds the disclosure and labelling controls this post describes quickly, for organisations with AI systems reaching EU based users.
Conclusion
The EU AI Act's enforcement era is real, regardless of whether the €47 million figure currently circulating is ever confirmed. Genuine investigative powers, real reported scrutiny of frontier AI providers, and a live whistleblower tool are already in effect. Australian organisations with any AI system reaching people in the EU do not need a confirmed fine to know it is time to check where they actually stand.
