On 2 August 2026, the European Commission's AI Office acquired full enforcement powers over General-Purpose AI (GPAI) model providers under the EU AI Act. The date had been circled in compliance calendars across the technology industry for months. It marked the end of what practitioners had called the "paper compliance" phase — the period since August 2025 when GPAI obligations were technically in force but enforcement powers had not yet been activated. From 2 August 2026, the AI Office can compel documentation, conduct technical evaluations, mandate corrective measures, and impose fines of up to €15 million or 3% of global annual turnover for non-compliance.
The milestone is significant not merely as a regulatory event but as a signal of where the global AI governance landscape is heading. The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. Its full applicability — achieved in stages over two years — represents the most ambitious attempt yet to subject AI development and deployment to systematic legal oversight. How it performs in its enforcement phase will shape AI governance debates far beyond Europe's borders.
The Architecture of the Act: A Risk-Based Framework
The EU AI Act organises AI systems into four risk tiers, each carrying different obligations. At the apex are AI practices deemed to pose unacceptable risk — social scoring systems, real-time biometric surveillance in public spaces, subliminal manipulation — which are prohibited outright. These prohibitions entered into force on 2 February 2025, along with AI literacy obligations requiring organisations to ensure their staff have sufficient understanding of AI systems to use them appropriately.
High-Risk Systems: The Compliance Burden
High-risk AI systems — those used in biometric identification, critical infrastructure, education, employment, migration, and the administration of justice — carry the most extensive compliance obligations: mandatory risk assessments, data governance requirements, technical documentation, human oversight mechanisms, and pre-market conformity assessments by designated "notified bodies." These obligations will apply from 2 December 2027 for systems in sensitive sectors, and from 2 August 2028 for high-risk AI embedded in regulated products such as medical devices, toys, and industrial machinery.
The phased timeline reflects a deliberate choice to allow industry time to adapt, but it also means that the most consequential applications of AI — those with the greatest potential to affect fundamental rights — will not be subject to full enforcement for another two years. Critics have argued that this creates a window of regulatory arbitrage during which high-risk deployments can proceed without the oversight the Act is designed to provide.
Transparency Requirements: The August 2026 Additions
The August 2026 full applicability date brought with it new transparency requirements that apply across a broader range of AI systems. Chatbots must now disclose their artificial nature to users. AI-generated content — including deepfakes and synthetic media — must be labelled in a machine-readable format. These requirements address a gap that had become increasingly visible as generative AI proliferated: the absence of any systematic mechanism for users to know when they were interacting with AI-generated content.
The machine-readable labelling requirement aligns with the technical standards being developed by the Coalition for Content Provenance and Authenticity (C2PA), which has been working on cryptographic content credentials that allow the origin and modification history of digital content to be verified. The Act does not mandate a specific technical standard, leaving room for the market to develop solutions — but it creates the regulatory demand that makes investment in those solutions commercially rational.
The GPAI Code of Practice is voluntary, but its strategic logic is compelling: signatories gain a presumption of conformity that significantly reduces the administrative burden of proving compliance through alternative, more complex means.
GPAI Models: The Frontier of Enforcement
The most novel and contested aspect of the EU AI Act is its treatment of General-Purpose AI models — large foundation models such as GPT-4, Gemini, Claude, and their successors, which are trained on vast datasets and deployed across a wide range of applications. The Act distinguishes between GPAI models generally and those that pose "systemic risk" — defined as models trained above a computational threshold of 10^25 floating-point operations (FLOPs).
The GPAI Code of Practice is voluntary, but its strategic logic is compelling: signatories gain a presumption of conformity that significantly reduces the administrative burden of proving compliance through alternative, more complex means.
The Code of Practice: Voluntary Compliance with Strategic Logic
The GPAI Code of Practice, published on 10 July 2025 and endorsed by the European Commission and the AI Board, is the primary mechanism through which GPAI providers can demonstrate compliance with the Act. It is explicitly voluntary — but its strategic logic is compelling. Signatories gain a "presumption of conformity" that significantly reduces the administrative burden of proving compliance through alternative means. Providers who do not sign must demonstrate compliance through "other adequate means," which involves a higher burden of proof and increased scrutiny from the AI Office.
As of 31 July 2026, the list of signatories includes Amazon, Google, Microsoft, OpenAI, Anthropic, IBM, Cohere, Aleph Alpha, Mistral AI, and a range of European and specialised AI firms. The Code consists of three chapters: Transparency (mandatory for all GPAI providers, requiring standardised documentation on model architecture, training data, and energy usage); Copyright (mandatory for all GPAI providers, requiring policies to respect EU copyright law including machine-readable opt-outs); and Safety and Security (applying only to systemic-risk models, requiring rigorous risk management, red-teaming, and incident reporting).
One notable exception is xAI, which has signed specifically for the Safety and Security chapter but not for Transparency and Copyright — meaning it must prove compliance with those obligations through other means. This selective participation illustrates the flexibility of the Code's architecture, but also its potential for strategic gaming: providers can choose the chapters that impose the least additional burden relative to their existing practices.
Systemic Risk: The High-Stakes Tier
Providers of GPAI models with systemic risk — those trained above the 10^25 FLOPs threshold — face significantly more stringent requirements. They must notify the AI Office of their models, conduct mandatory risk assessments, implement adversarial testing (red-teaming), and report serious incidents. The rationale is that models of this scale have the potential to cause harms that extend beyond individual users or applications — harms to critical infrastructure, democratic processes, or public safety that require proactive oversight rather than reactive enforcement.
The identification of the 10^25 FLOPs threshold as the boundary for systemic risk has been criticised as both arbitrary and potentially obsolete. Computational efficiency improvements mean that models with capabilities equivalent to those trained at 10^25 FLOPs in 2024 may be achievable at significantly lower computational cost by 2026 or 2027. A threshold defined in terms of training compute may not remain a reliable proxy for capability or risk as the technology evolves. The Act includes a mechanism for the Commission to adjust the threshold by delegated act, but the political and technical process for doing so is slow relative to the pace of model development.
The Enforcement Challenge: From Rules to Reality
The AI Office must evaluate the compliance of models trained on datasets of unprecedented scale, using techniques that are not fully understood even by their creators. The gap between regulatory ambition and technical capacity is real and must be closed.
The activation of enforcement powers on 2 August 2026 raises an immediate practical question: does the AI Office have the capacity to exercise them effectively? The Office was established in February 2024 with a mandate to oversee GPAI models and coordinate AI governance across the EU. It has recruited technical staff, established a Scientific Panel of independent experts, and developed the procedural infrastructure for investigations and enforcement actions. But the scale of the task is formidable.
The AI Office must evaluate the compliance of models trained on datasets of unprecedented scale, using techniques that are not fully understood even by their creators. The gap between regulatory ambition and technical capacity is real and must be closed.
Technical Capacity and the Evaluation Problem
Evaluating the compliance of a large language model with the Act's requirements is not a straightforward audit task. It requires assessing the composition and provenance of training data (for copyright compliance), the adequacy of risk management processes (for systemic-risk models), and the accuracy of technical documentation (for transparency). These assessments require deep technical expertise and access to information that model providers may be reluctant to share — particularly training data, which is commercially sensitive and may itself contain proprietary information.
The Act grants the AI Office the power to compel documentation and conduct technical evaluations, including through independent experts and the Scientific Panel. But the evaluation methodologies for assessing the properties of large AI models — their capabilities, their failure modes, their potential for misuse — are still being developed by the research community. The AI Office is being asked to enforce rules about systems whose behaviour is not fully understood even by their creators. This is not an argument against enforcement; it is an argument for investing heavily in the technical capacity needed to make enforcement meaningful.
Supply Chain Compliance: The Downstream Problem
The compliance obligations of the EU AI Act do not fall only on model providers. Downstream enterprises that deploy GPAI models in their products and services have their own obligations — and their compliance posture is directly affected by the compliance posture of their model vendors. If a model provider faces regulatory restrictions or is required to withdraw a model from the market, businesses that have built applications on that model may be forced to rebuild or migrate their systems.
This supply chain interdependency creates a new category of business risk that many enterprises are only beginning to assess. The compliance due diligence required before selecting a GPAI model provider now includes not only technical evaluation but regulatory risk assessment: Is this provider compliant with the Act? Have they signed the Code of Practice? Are they subject to systemic-risk obligations? What is their track record with the AI Office? These questions are becoming standard elements of enterprise AI procurement.
The Digital Omnibus Deferral
The "Digital Omnibus" regulation, adopted in 2026, deferred the application deadlines for high-risk AI systems in several categories — pushing the December 2027 and August 2028 dates back by approximately six months. The deferral was justified on the grounds that industry needed additional time to develop the technical standards and conformity assessment infrastructure required for compliance. Critics argued that it reflected successful lobbying by technology companies and that it would delay the protection of fundamental rights in high-stakes AI applications.
The EU AI Act is not merely a European regulatory event. Through the Brussels Effect, it is shaping AI governance practices worldwide — and the compliance choices made by major model providers in response to it will define the norms of the global AI industry.
Notably, the Digital Omnibus did not alter the enforcement timeline for GPAI models. The August 2026 enforcement activation proceeded as scheduled, and models placed on the market before August 2025 must be brought into full compliance by August 2027. The asymmetry — stricter timelines for GPAI models than for high-risk applications — reflects the political priority given to governing the most powerful AI systems, even at the cost of consistency in the overall regulatory architecture.
Global Implications: The Brussels Effect in AI Governance
The EU AI Act is not merely a European regulatory event. Through what scholars call the "Brussels Effect" — the tendency of EU regulations to become de facto global standards because multinational companies find it more efficient to comply globally than to maintain separate compliance regimes — the Act is shaping AI governance practices worldwide. Companies that have signed the GPAI Code of Practice to comply with EU requirements are implementing transparency, copyright, and safety practices that affect their global operations.
The Act's influence is also visible in the regulatory initiatives of other jurisdictions. The United Kingdom's AI Safety Institute, Canada's proposed Artificial Intelligence and Data Act, and the emerging AI governance frameworks of Singapore, Japan, and South Korea all reflect, to varying degrees, the risk-based approach and the emphasis on transparency and human oversight that characterise the EU Act. The United States remains the significant outlier — federal AI legislation has not advanced, and the regulatory landscape is fragmented across sector-specific agencies — but the pressure from trading partners and the compliance requirements of multinational companies are creating de facto convergence in some areas.
The EU AI Act is not merely a European regulatory event. Through the Brussels Effect, it is shaping AI governance practices worldwide — and the compliance choices made by major model providers in response to it will define the norms of the global AI industry.
What Adequate Enforcement Would Require
The activation of enforcement powers is a necessary but not sufficient condition for effective AI governance. Several additional elements are required to translate regulatory authority into meaningful oversight.
First, the AI Office needs sustained investment in technical capacity — the ability to evaluate AI systems independently, rather than relying solely on documentation provided by the systems' creators. The Scientific Panel is a step in this direction, but its resources are limited relative to the scale of the task. Public investment in AI evaluation infrastructure — analogous to the investment in financial audit capacity that followed the 2008 financial crisis — is needed.
Second, the enforcement regime needs to demonstrate credibility through early action. Regulatory frameworks that are never enforced lose their deterrent effect. The AI Office's first enforcement actions — the cases it chooses to pursue, the fines it imposes, the corrective measures it mandates — will signal to the industry whether the Act is a serious constraint or a compliance exercise. The choice of cases matters as much as the legal authority to bring them.
Third, the international dimension of AI governance requires active engagement. The Brussels Effect creates convergence pressure, but it is not a substitute for genuine international coordination. The AI Safety Summits initiated in 2023 and the OECD's AI Policy Observatory provide forums for coordination, but they lack the binding authority needed to address the most significant governance gaps — particularly around systemic-risk models developed and deployed by non-EU providers.
The EU AI Act represents the most serious attempt yet to govern artificial intelligence through law. Its full applicability in August 2026 is a genuine milestone. Whether it proves to be a turning point in AI governance — or a well-intentioned framework that is outpaced by the technology it seeks to regulate — depends on the enforcement choices made in the months and years ahead. The rules are now in place. The harder work of making them real has just begun.





