EU AI Act Enforcement Begins for General-Purpose AI Models
The EU AI Act's enforcement powers over general-purpose AI model providers became operational on 2 August 2026, with the AI Office issuing its first information requests to providers within days.
The European Commission's enforcement powers over general-purpose AI model providers became operational on 2 August 2026, the date on which the EU AI Act's rules for GPAI models and transparency obligations took effect simultaneously. The AI Office issued its first round of information requests to AI providers covering safety, security, and copyright obligations within days of the enforcement window opening.
Providers found in breach of GPAI rules face fines of up to 3% of global annual turnover, while the highest tier of penalty — for banned practices — stands at €35 million or 7% of worldwide turnover. The AI Office is treating technical compliance dialogues as its preferred initial tool before moving to formal enforcement decisions.
The Commission also published the AI Act complaints mechanism on 2 August 2026, allowing public submissions directly to the AI Office — opening a channel for civil society, researchers, and competitors to flag potential violations of the regulation's requirements on any GPAI provider operating in the EU market.
Why it matters for business: Any company that provides a general-purpose AI model accessible in the EU — including through API access or embedded in downstream products — is now subject to active regulatory oversight with significant financial penalties. The information requests being issued are the template for what compliance documentation the AI Office expects; providers who cannot respond comprehensively face formal investigations. Building the compliance infrastructure retrospectively under regulatory pressure is more expensive than building it before the first request arrives.
Source: European Commission / CDT Europe AI Bulletin, August 2026, https://cdt.org/insights/cdt-europes-ai-bulletin-september-2026/