The fine that lawyers are pointing at is not the one for building a dangerous model.
"What's rarely appreciated is that GPAI liability isn't limited to substantive breaches," Elisabetta Righini, a partner at the law firm Sidley Austin, told CNBC. "Refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own."
That became true on Sunday. On August 2, 2026, the European Commission's AI Office, working with national authorities, began enforcing the Artificial Intelligence Act against providers of general-purpose AI models. The powers that switched on are not advisory. The Commission can now request documentation, run its own technical evaluations of a model, order compliance and risk-mitigation measures, restrict or withdraw a model from the European market, and issue fines of up to 15 million euros or 3 percent of global annual turnover, whichever is higher.
The rules apply to every company that makes a general-purpose AI model available in the EU, regardless of where that company is headquartered. OpenAI, Anthropic, and Google are all inside the perimeter.
The Obligations Are Documentation Obligations First
Most of what providers now owe Brussels is paperwork, which is exactly why the procedural fines matter.
| Obligation | Who It Binds | What It Requires |
|---|---|---|
| Technical documentation | All GPAI providers | Maintain specified model information and share it with authorities and downstream providers on request |
| Copyright policy | All GPAI providers | Put a policy in place for complying with EU copyright law |
| Training data summary | All GPAI providers | Publish a summary of the content used to train the model |
| Systemic risk measures | Models the Act classifies as posing systemic risk | Additional obligations covering large-scale harms, including cybersecurity threats and risks to fundamental rights |
| Local representative | Providers headquartered outside the EU | Designate a contact in the EU through whom regulators can reach the company |
Righini flagged the last row as the one non-EU companies overlook. Without a designated representative, a regulator's first contact attempt becomes a compliance failure before anyone has read a line of the model card.
Models already on the market before August 2, 2025 get a longer runway. They have until August 2, 2027 to come into full compliance.
Every Chatbot in Europe Now Has to Introduce Itself
The transparency rules that started the same day reach further into ordinary product work than the GPAI regime does, because they bind anyone shipping an interface, not just anyone shipping a model.
Three things changed on August 2:
- Interactive AI systems must disclose that they are AI. Chatbots and similar systems have to tell users they are dealing with a machine, not a human, unless that is obvious from context.
- Deepfakes must be labelled. Images, video, and audio generated or edited with AI have to be identified as such.
- AI-generated or altered content must carry machine-readable marks so it can be detected automatically rather than by eye.
The Commission is not enforcing this cold. Alongside the press release it published the list of organisations that have signed the Code of Practice on transparency of AI-generated content, the voluntary instrument that spells out how to satisfy the rules in practice. About 190 organisations had signed by the end of July: 83 to the section covering providers of generative AI systems, 152 to the section covering deployers, with many signing both. OpenAI, Anthropic, Google, Meta, Microsoft, Mistral and Cohere are all on the provider section. About half of the signatories are small or recently founded companies.
Signing is the cheapest available demonstration of good faith, and the list is public.
For anyone maintaining a product with a text box and a model behind it, that is the actionable part of this week. The disclosure requirement is not scoped to frontier labs. It is scoped to systems that interact with people.
Brussels Spent Months Building Toward This, and Blinked Once
The AI Act was never going to arrive all at once, and it did not.
The blink is in the middle of that sequence. August 2, 2026 was originally the date the AI Act's high-risk obligations were supposed to bite. They did not. Under the Digital Omnibus on AI, stand-alone high-risk systems listed in Annex III now face their obligations from December 2, 2027, and high-risk AI embedded in regulated products under Annex I from August 2, 2028.
So the day arrived, and the heaviest part of the law was not on it.
The Labs Sound Cooperative. The Backstory Is Less Comfortable.
Henna Virkkunen, executive vice-president for tech sovereignty, security and democracy at the European Commission, framed the moment in terms of scale.
"Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale." — Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, European Commission
OpenAI's response was conciliatory. "We've collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age," said Tom Gordon, the company's VP of EMEA policy. A Google spokesperson said the company remains committed to meeting all applicable rules.
The cooperation has been more contested than those statements suggest. Anthropic agreed to give ENISA, the EU's cybersecurity agency, access to its Mythos model only after senior Commission officials flew to San Francisco to press the company's leadership directly, following an earlier arrangement in which OpenAI offered the bloc access to a cyber-focused variant of GPT-5.5. Brussels has also opened discussions with both OpenAI and Anthropic in the wake of cyber attacks linked to their models, according to CNBC, including the incident where Anthropic's own testing led to three real companies being breached.
Model access has been the friction point in this relationship for a year. Now the friction has a fine attached to it.
The Other Side of the Argument Comes From Both Directions
The Act is being attacked from opposite ends, which is a reasonable sign it landed somewhere in the middle.
Civil society read the Digital Omnibus as a retreat. The digital rights group Liberties argued the final agreement weakens several safeguards in the original text and described the postponement of high-risk obligations as a delay to fundamental rights protections that were supposed to take effect in August 2026. The European Data Protection Board and the European Data Protection Supervisor raised similar concerns about what the later dates mean for those protections.
Industry read it as overdue relief. DIGITALEUROPE, among the loudest critics of the Act's original compliance costs and timeline, broadly welcomed the simplification package.
The practical objection sits underneath both: enforcement now has to be demonstrated in practice across 27 member states with 27 sets of national authorities, and nobody has seen the AI Office run a model evaluation at scale. A power that exists on paper and a power that gets exercised consistently are different things. The first test case will tell you which one this is.
Contrast that with the United States, where AI rules are being written state by state. Illinois turned a set of industry-backed commitments into binding law in July, and Brussels has separately used competition law to force open Android AI assistant access for ChatGPT and Claude. Europe now has one regulator with cross-border withdrawal powers. America has fifty legislatures and a draft federal framework.
Check three things this week. Does every AI-facing interface disclose that it is AI? Does AI-generated media in your product carry machine-readable provenance marks? If you are a non-EU company distributing a general-purpose model, have you designated an EU representative? The third one is the cheapest to fix and the easiest to forget.
The Bottom Line
For two years the AI Act was a compliance calendar. As of Sunday it is a regulator with a complaints tool, a whistleblower channel, a dedicated channel for downstream providers, and the authority to take a model off the European market.
What it does not yet have is a track record. The heaviest obligations got pushed to late 2027, the largest providers have all said the right things in public, and no company has been fined a euro. The most consequential sentence written about this week may turn out to be Righini's: the exposure is not only in building something dangerous, it is in being slow to answer the phone.
Brussels wrote the first serious enforcement regime for general-purpose AI models. The next twelve months decide whether that sentence describes a law or a letter.
Sources
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission press release (July 31, 2026)
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — Shaping Europe's Digital Future (July 31, 2026)
- E.U. activated new powers to fine or restrict AI models from Anthropic, OpenAI, and Google — Quartz (August 3, 2026)
- EU AI Act enforcement powers — CNBC (August 3, 2026)
- Code of Practice on transparency of AI-generated content — European Commission
- Enforcement of the AI Act — European Commission
- Artificial intelligence: Council and Parliament agree to simplify and streamline rules — Council of the EU (May 7, 2026)
- EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn (2026)
- AI Act rules on high-risk AI delayed as AI Digital Omnibus agreed — Winston Taylor (2026)
- Digital Omnibus on AI: The EU's AI Act simplification and new AI Office powers — Digital Watch Observatory (2026)
- Enforcement of Chapter V under the EU AI Act — EU Artificial Intelligence Act (2026)