EU AI Act Enforcement Begins: What the Commission Can Now Do
The European Commission has begun applying the European Union's AI Act to general-purpose AI models — the systems behind chatbots, AI agents and other generative tools. The provisions took effect on 2 August, giving the Commission's AI Office the authority to request information from developers, evaluate models before they reach the EU market and restrict access to the bloc when the rules are breached. The obligations cover all providers, including OpenAI, Google and Anthropic, and apply regardless of where a company is registered.
Providers offering AI models in the EU must now appoint an official representative in the Union. They also have to document how their models are trained, implement a copyright-compliance policy and publish sufficiently detailed information about the data used in training. Models judged capable of creating systemic risk face additional requirements on risk management, covering areas such as cybersecurity, chemical, biological and nuclear threats, manipulation of people and loss of human control.
Alongside these powers, new transparency rules begin to apply. Chatbots must clearly tell users they are interacting with AI, and AI-generated or AI-edited images, video and audio — including deepfakes — must be labelled in a way that allows automatic recognition. Companies that fail to comply can be fined up to €15 million or 3% of their annual global turnover, and sanctions are available even for refusing to provide information, giving misleading answers or obstructing checks.
The move comes as the EU seeks to strengthen its technological sovereignty and reduce its dependence on American AI companies. With the new enforcement powers, Brussels now has a direct regulatory lever over the biggest AI developers at a time when transatlantic tensions over digital rules are already elevated.
How the AI Office Will Police Frontier Models
What the AI Office Can Actually Do
Before 2 August, the Commission's general-purpose AI rules were largely a legal framework awaiting application. They are now enforceable: the AI Office can demand internal information, run evaluations and assess models before launch. The decisive change is that EU market access becomes a conditional privilege rather than an automatic right — a violation can lead to a model being restricted or blocked in the bloc.
The Fine Structure Is Designed for the Biggest Players
The penalty ceiling of €15 million or 3% of annual global turnover matters most for frontier labs with billion-dollar revenues. A turnover-based fine is what gives the regime bite: for OpenAI, Google or Anthropic, a fixed €15 million penalty alone would be proportionally small, while a percentage of global revenue is far more consequential. Equally important, the Commission can sanction companies for procedural failures — refusing to provide information, misleading answers or obstructing checks — which makes delaying tactics risky.
Why Brussels Is Acting Now
The EU has tied the new powers to its goal of technological sovereignty and to reducing reliance on US AI companies. Enforcement changes the balance in ongoing dealings: Brussels has already fined Google, opened various investigations and held security talks with OpenAI and Anthropic. Those conversations now happen under a formal regulatory umbrella, which shifts negotiating leverage toward the Commission. That does not mean US providers will be pushed out, but it does mean their European market position becomes more conditional on compliance.
Systemic Risk Rules Target the Frontier
The additional duties for models that can create systemic risk point explicitly at cybersecurity, chemical, biological and nuclear threats, manipulation and loss of human control. That language is aimed at the most capable foundation models rather than at the wider software market. Providers will need to assess their own models against this threshold and, where it applies, build safety measures into development instead of adding them after deployment.
The Transatlantic Pressure Point
Because the rules apply to any company offering AI in the EU, wherever it is registered, the Commission now has a direct regulatory lever over US-based AI firms. The likely short-term consequences are more detailed disclosure, earlier pre-market dialogue with the AI Office and more systematic labelling of AI-generated content across European digital services.
What AI Providers Must Do Before the EU Comes Knocking
For AI providers and their compliance teams:
- Appoint an official EU representative if your company offers general-purpose AI models in the bloc — the obligation applies to every provider regardless of where it is registered.
- Build the documentation trail now: training methods, training-data sources and copyright-compliance policies all have to be disclosed to the AI Office on request.
- Determine whether any model qualifies as a systemic-risk model and prepare additional risk-management safeguards covering cybersecurity and chemical, biological and nuclear risks.
- Update chatbot interfaces to state clearly that users are talking to AI, and ensure AI-generated or edited images, video and audio carry machine-readable labels.
- Plan financial and legal exposure for a worst case of up to €15 million or 3% of annual global turnover, plus potential restriction of EU market access.
Risk & Opportunity Assessment
| Commercial Risk | High | Fines can reach €15 million or 3% of annual global turnover, and the AI Office can restrict or block a model's access to the EU market — a direct revenue risk for OpenAI, Google and Anthropic. |
| Competitive Risk | Medium | Documentation and compliance costs fall disproportionately on smaller AI developers, potentially strengthening large incumbents with dedicated regulatory resources. |
| Regulatory Risk | High | The AI Office can request information, evaluate models before market entry and impose sanctions for obstruction or misleading answers, and the rules apply extraterritorially. |
| Reputation Risk | Medium | Mandatory disclosure of training data, copyright policies and AI-content labelling keeps major providers under public scrutiny; Brussels has already fined Google and opened investigations. |
| Technology Disruption | Medium | Systemic-risk models face new design and testing requirements covering cybersecurity and chemical, biological and nuclear threats, which may force changes to development practices for frontier systems. |
| Commercial Opportunity | Medium | Providers that demonstrate strong transparency and risk management may win smoother EU market access and credibility with European customers as enforcement begins. |
Comments 0