Skip to content

The EU Can Now Pull an AI Model Out of Europe. Those Powers Went Live Sunday.

DS
LDS Team
Let's Data Science
8 min
On August 2 the European Commission's AI Office gained the authority to demand model evaluations, restrict market access, and fine general-purpose AI providers up to 15 million euros or 3 percent of global annual turnover. The same day, every chatbot serving European users became legally required to say it is a chatbot. About 190 organisations signed the transparency code that operationalises the rules before it took effect.

The fine that lawyers are pointing at is not the one for building a dangerous model.

"What's rarely appreciated is that GPAI liability isn't limited to substantive breaches," Elisabetta Righini, a partner at the law firm Sidley Austin, told CNBC. "Refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own."

That became true on Sunday. On August 2, 2026, the European Commission's AI Office, working with national authorities, began enforcing the Artificial Intelligence Act against providers of general-purpose AI models. The powers that switched on are not advisory. The Commission can now request documentation, run its own technical evaluations of a model, order compliance and risk-mitigation measures, restrict or withdraw a model from the European market, and issue fines of up to 15 million euros or 3 percent of global annual turnover, whichever is higher.

The rules apply to every company that makes a general-purpose AI model available in the EU, regardless of where that company is headquartered. OpenAI, Anthropic, and Google are all inside the perimeter.

The Obligations Are Documentation Obligations First

Most of what providers now owe Brussels is paperwork, which is exactly why the procedural fines matter.

ObligationWho It BindsWhat It Requires
Technical documentationAll GPAI providersMaintain specified model information and share it with authorities and downstream providers on request
Copyright policyAll GPAI providersPut a policy in place for complying with EU copyright law
Training data summaryAll GPAI providersPublish a summary of the content used to train the model
Systemic risk measuresModels the Act classifies as posing systemic riskAdditional obligations covering large-scale harms, including cybersecurity threats and risks to fundamental rights
Local representativeProviders headquartered outside the EUDesignate a contact in the EU through whom regulators can reach the company

Righini flagged the last row as the one non-EU companies overlook. Without a designated representative, a regulator's first contact attempt becomes a compliance failure before anyone has read a line of the model card.

Models already on the market before August 2, 2025 get a longer runway. They have until August 2, 2027 to come into full compliance.

Every Chatbot in Europe Now Has to Introduce Itself

The transparency rules that started the same day reach further into ordinary product work than the GPAI regime does, because they bind anyone shipping an interface, not just anyone shipping a model.

Three things changed on August 2:

  • Interactive AI systems must disclose that they are AI. Chatbots and similar systems have to tell users they are dealing with a machine, not a human, unless that is obvious from context.
  • Deepfakes must be labelled. Images, video, and audio generated or edited with AI have to be identified as such.
  • AI-generated or altered content must carry machine-readable marks so it can be detected automatically rather than by eye.

The Commission is not enforcing this cold. Alongside the press release it published the list of organisations that have signed the Code of Practice on transparency of AI-generated content, the voluntary instrument that spells out how to satisfy the rules in practice. About 190 organisations had signed by the end of July: 83 to the section covering providers of generative AI systems, 152 to the section covering deployers, with many signing both. OpenAI, Anthropic, Google, Meta, Microsoft, Mistral and Cohere are all on the provider section. About half of the signatories are small or recently founded companies.

Signing is the cheapest available demonstration of good faith, and the list is public.

For anyone maintaining a product with a text box and a model behind it, that is the actionable part of this week. The disclosure requirement is not scoped to frontier labs. It is scoped to systems that interact with people.

Brussels Spent Months Building Toward This, and Blinked Once

The AI Act was never going to arrive all at once, and it did not.

MAY 7, 2026
Council and Parliament agree to simplify the rules
The two institutions reach political agreement on a package streamlining the AI Act and extending several deadlines.
JUNE 29, 2026
Council gives final approval to the Digital Omnibus on AI
The package that defers the AI Act's high-risk obligations clears its last hurdle.
JULY 24, 2026
Regulation (EU) 2026/1744 published in the Official Journal
The deferral becomes law, entering into force three days later on July 27.
JULY 31, 2026
Commission publishes the enforcement announcement
The press release lands two days ahead of the date, alongside the list of transparency code signatories.
AUGUST 2, 2026
Enforcement powers and transparency rules take effect
The AI Office can now evaluate, restrict, withdraw, and fine. Chatbot and deepfake disclosure become binding.

The blink is in the middle of that sequence. August 2, 2026 was originally the date the AI Act's high-risk obligations were supposed to bite. They did not. Under the Digital Omnibus on AI, stand-alone high-risk systems listed in Annex III now face their obligations from December 2, 2027, and high-risk AI embedded in regulated products under Annex I from August 2, 2028.

So the day arrived, and the heaviest part of the law was not on it.

The Labs Sound Cooperative. The Backstory Is Less Comfortable.

Henna Virkkunen, executive vice-president for tech sovereignty, security and democracy at the European Commission, framed the moment in terms of scale.

"Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale." — Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, European Commission

OpenAI's response was conciliatory. "We've collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age," said Tom Gordon, the company's VP of EMEA policy. A Google spokesperson said the company remains committed to meeting all applicable rules.

The cooperation has been more contested than those statements suggest. Anthropic agreed to give ENISA, the EU's cybersecurity agency, access to its Mythos model only after senior Commission officials flew to San Francisco to press the company's leadership directly, following an earlier arrangement in which OpenAI offered the bloc access to a cyber-focused variant of GPT-5.5. Brussels has also opened discussions with both OpenAI and Anthropic in the wake of cyber attacks linked to their models, according to CNBC, including the incident where Anthropic's own testing led to three real companies being breached.

Model access has been the friction point in this relationship for a year. Now the friction has a fine attached to it.

The Other Side of the Argument Comes From Both Directions

The Act is being attacked from opposite ends, which is a reasonable sign it landed somewhere in the middle.

Civil society read the Digital Omnibus as a retreat. The digital rights group Liberties argued the final agreement weakens several safeguards in the original text and described the postponement of high-risk obligations as a delay to fundamental rights protections that were supposed to take effect in August 2026. The European Data Protection Board and the European Data Protection Supervisor raised similar concerns about what the later dates mean for those protections.

Industry read it as overdue relief. DIGITALEUROPE, among the loudest critics of the Act's original compliance costs and timeline, broadly welcomed the simplification package.

The practical objection sits underneath both: enforcement now has to be demonstrated in practice across 27 member states with 27 sets of national authorities, and nobody has seen the AI Office run a model evaluation at scale. A power that exists on paper and a power that gets exercised consistently are different things. The first test case will tell you which one this is.

Contrast that with the United States, where AI rules are being written state by state. Illinois turned a set of industry-backed commitments into binding law in July, and Brussels has separately used competition law to force open Android AI assistant access for ChatGPT and Claude. Europe now has one regulator with cross-border withdrawal powers. America has fifty legislatures and a draft federal framework.

If You Ship to European Users

Check three things this week. Does every AI-facing interface disclose that it is AI? Does AI-generated media in your product carry machine-readable provenance marks? If you are a non-EU company distributing a general-purpose model, have you designated an EU representative? The third one is the cheapest to fix and the easiest to forget.

The Bottom Line

For two years the AI Act was a compliance calendar. As of Sunday it is a regulator with a complaints tool, a whistleblower channel, a dedicated channel for downstream providers, and the authority to take a model off the European market.

What it does not yet have is a track record. The heaviest obligations got pushed to late 2027, the largest providers have all said the right things in public, and no company has been fined a euro. The most consequential sentence written about this week may turn out to be Righini's: the exposure is not only in building something dangerous, it is in being slow to answer the phone.

Brussels wrote the first serious enforcement regime for general-purpose AI models. The next twelve months decide whether that sentence describes a law or a letter.

Sources

Practice interview problems based on real data

1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.

Try 250 free problems