Skip to content
Predictive Systems
PSI Daily

The EU's AI Act Grows Teeth: Brussels Begins Policing the World's Frontier Model Makers

PrivacyRobert Voltaire L. Javier

The European Commission on August 2 activated its enforcement powers over general-purpose AI model providers, ending a year in which the AI Act's rules for frontier models existed on paper but carried no penalty.

robot under investigation

The European Commission on August 2 activated its enforcement powers over general-purpose AI model providers, ending a year in which the AI Act's rules for frontier models existed on paper but carried no penalty. For the organisations that build, buy, or depend on these models, the question of who controls them now has a second answer: their vendors, and Brussels.

Enforcement Powers Arrive, a Year After the Rules

Obligations for general-purpose AI (GPAI) providers under Chapter V of the AI Act took effect in August 2025, but until this month the Commission had no power to act on them. That changed on August 2, 2026, when, as the Commission announced on July 31, its AI Office and national authorities began enforcing the Act against model providers and other regulated entities.

The Commission holds exclusive enforcement authority over GPAI providers. It can demand technical documentation, conduct evaluations of models directly, order corrective measures up to market restrictions and recalls, and impose fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher, according to the AI Act's Chapter V enforcement provisions. Providers must maintain technical documentation, publish summaries of training data, adopt copyright compliance policies, supply downstream deployers with the information they need, and, for models designated as posing systemic risk, assess and report on large-scale harms.

New transparency obligations under Article 50 took effect the same day: chatbots must disclose that users are talking to a machine, deepfakes must be labelled, and AI-generated content must carry machine-readable marks. The Commission says more than 180 organisations have signed the Code of Practice on transparency of AI-generated content. The Act's high-risk system rules, by contrast, were pushed back roughly a year by the EU's digital omnibus, agreed by Parliament and Council in June 2026: obligations for standalone high-risk systems moved from August 2026 to December 2027, and those for high-risk AI in regulated products moved to August 2028, per Help Net Security and Secure Privacy. The omnibus left the August 2026 dates for GPAI enforcement and transparency untouched; the delay does not reach the powers that activated this week.

Jurisdiction Over Models Built Elsewhere

The strategic weight of this moment is jurisdictional. Nearly every frontier model that matters to European enterprises is built outside Europe, yet the Commission now claims the power to inspect those models, demand their documentation, and fine their makers a share of global revenue. This is the most direct assertion of regulatory control over foundation models attempted by any jurisdiction to date, and it converts Europe's market size into leverage over infrastructure it does not own.

The provider landscape reflects that tension. According to TechPolicy.Press, Amazon, Anthropic, Google, Microsoft, Mistral AI, and OpenAI signed the voluntary GPAI Code of Practice that serves as the presumptive compliance pathway; Meta declined, and X signed only the safety and security chapter. The same reporting notes the AI Office's enforcement unit numbers roughly 34 staff, a thin line for supervising the world's most capitalised technology companies, and that Washington has criticised EU digital enforcement as targeting American firms. Whether a 34-person team can meaningfully audit frontier labs is the open question on which the Act's credibility rests; that staffing figure and the political friction are drawn from a single outlet and should be read as reported rather than confirmed.

There is also upside in the fine print. The enforcement regime opens complaint channels for downstream users of GPAI models, which for the first time gives European deployers a formal lever against their model suppliers. Documentation duties flow information down the stack: enterprises gain a right to know more about the models they build on than vendor discretion previously allowed.

Compliance Posture Becomes a Procurement Question

For organisations that care about ownership and control, the practical consequences arrive through procurement and architecture. A vendor's standing with the AI Office is now a supply chain risk factor: a model provider facing corrective measures, or in the extreme a market restriction, is a dependency that can be impaired by regulatory action outside the buyer's control. Contracts should secure the documentation and transparency artefacts the Act obliges providers to produce, because those artefacts are how deployers demonstrate their own compliance.

The rules also sharpen the case for optionality. Models placed on the market before August 2025 have until August 2027 to reach full compliance, so the coming year will reveal which providers treat European obligations as a design constraint and which treat them as a negotiation. Organisations running open-weight models on their own infrastructure inherit fewer of these vendor dependencies, though transparency obligations for deployed systems, such as chatbot disclosure and content marking, apply regardless of where the model runs.

Regulatory Leverage Is Now a Market Fact

The AI Act's enforcement phase makes external control over frontier models a live variable rather than a hypothetical: any organisation whose operations depend on a handful of foreign model providers now shares its dependency with a regulator empowered to inspect, correct, and fine them. Sovereignty planning that ignores this second axis of control is incomplete.

Sources

Primary source: European Commission announcement, published 31 July 2026, confirming enforcement and transparency obligations from 2 August 2026. Cross-checked against the EU AI Act explorer on Chapter V enforcement (dates, powers, fine levels) and Help Net Security, 4 August 2026 (transparency requirements, revised high-risk timeline). The digital omnibus delay was verified against Secure Privacy and AI Act Blog, both confirming that only the high-risk timelines moved and that the August 2026 GPAI enforcement and transparency dates were unchanged. Code of Practice signatories, AI Office staffing, and US political reaction are reported by TechPolicy.Press, 30 July 2026 and are labelled as single-source above.

Source: European Commission