EU AI Act Enforcement Is Live. The Grace Period Is Over

The EU AI Act's enforcement powers went live August 2. The Commission can now inspect models, demand evaluations, and fine providers up to 3% of global revenue.

EU AI Act Enforcement Is Live. The Grace Period Is Over

The EU AI Act just got teeth. Enforcement powers over general-purpose AI models went live on August 2.

The European Commission can now do what it couldn’t do for a year: demand model evaluations, restrict market access, and fine providers up to €15 million or 3% of global annual turnover.

The obligations under Chapter V of the AI Act technically applied since August 2025. What changed Sunday is that they’re finally enforceable. The grace period is over, and every frontier lab selling into Europe is now on the regulator’s clock.

What the AI Act enforcement powers actually do

The AI Office, the Commission’s enforcement arm, can now send requests for information to any provider of a general-purpose AI model. It can run its own model evaluations, or appoint independent experts to do it. It can demand corrective measures.

If a provider stalls, the fines start at €15 million or 3% of worldwide annual turnover, whichever is higher. Prohibited practices carry up to €35 million or 7%.

The scope is the part US labs should read twice. The powers apply to any company offering a general-purpose AI model in the EU, regardless of where it’s headquartered.

Non-EU providers must appoint an EU-based authorized representative as the regulator’s point of contact. A US address doesn’t put a lab outside the EU regulator’s reach.

Even the process violations are finable on their own. Refusing an information request, giving misleading answers, or blocking a model evaluation is a fine, separate from whatever the underlying model did wrong.

That detail matters. The AI Act enforcement machinery doesn’t need to prove a model caused harm to make life expensive for a lab that stonewalls.

The Commission has also said it will focus enforcement on providers that signed the GPAI Code of Practice, the voluntary framework that operationalizes the AI Act’s obligations.

Signatories get monitored, not investigated. Everyone else is a candidate for the full toolkit.

Why this lands right now

The timing isn’t a coincidence. The Commission is in talks with OpenAI and Anthropic after recent cyber incidents involving their models.

CNBC reported on the outreach to both labs.

Brussels had chased access to Anthropic’s Mythos model for months before the company agreed to share it in June. Now the Commission has a legal lever it didn’t have during those negotiations.

This is the same regulatory muscle that fined Google $1 billion in July under Digital Markets Act rules. Trump responded by threatening substantial tariffs on the bloc.

The AI Act gives Brussels another lever against American tech, and the two governments are already on opposite sides of a trade fight.

Who signed up, who didn’t

The GPAI Code of Practice is the compliance fast lane. Amazon, Anthropic, Google, Microsoft, Mistral AI, and OpenAI signed it. X signed only the safety and security chapter. Meta hasn’t signed at all.

Those absences are going to be the first enforcement questions, because the Commission has said code signatories get lighter-touch monitoring.

The Commission also published a list of more than 180 organizations that signed the transparency code for AI-generated content. That’s the companion set of rules that went live the same day: chatbots have to say they’re AI, deepfakes need labels, and synthetic content gets machine-readable marks.

I covered the labeling side in my EU AI labels piece.

What this means for builders

If you build on top of a frontier model, the obligations sit with the provider, not with you. But they still matter.

Your supplier now has real incentives to keep technical documentation current, honor EU copyright rules, and publish training data summaries. If your model vendor is cutting corners on the AI Act, enforcement makes that a business risk for them, which makes it a reliability question for you.

There’s a downstream angle too. The AI Act gives downstream providers a complaints channel when a model supplier won’t hand over the documentation they’re owed. That’s a new stick for every startup building on a frontier API.

The first months are likely to be dialogue, not fines. A Commission official told Tech Policy Press the AI Office wants to keep a constructive dialogue with providers while monitoring the market.

The real test is whether the AI Act becomes an accountability framework or stays a set of obligations on paper.

Here’s the bigger picture. American labs now face two governments demanding pre-release review from opposite sides of the Atlantic. The White House finished its own classified framework this week, and the EU AI Act enforcement powers are the European version of that same gate. Each side has its own thresholds, timelines, and penalties.

The AI Act enforcement powers went live the same weekend the White House completed its framework. The companies that built models to serve the world are discovering the world wants to approve them first. That’s the new normal for every frontier lab, and the grace period for getting comfortable is over.

Tony Simons

Reviewed & Written By

Tony Simons

Independent tech reviewer and creator of Tony Reviews Things. 14 years of hands-on testing, software auditing, and workflow automation. I test the gear so you don't waste your money on junk.

Submit a Take

Your email address will not be published. Required fields are marked *