EU AI regulation

Brussels Gains Real Teeth Over Frontier AI Models, But Has Yet to Use Them

EU Commission enforcement powers over general-purpose AI providers, including fines up to 3% of turnover, took effect August 2, 2026.

GPAI Enforcement Arrives in Brussels People of Internet Research · EU 3% or €15M Maximum GPAI fine Whichever is higher, per Article 1… 12 months Grace period before enforcement GPAI obligations applied from Aug.… 180+ Signers of transparency code Organizations signed the Commissio… peopleofinternet.com
GPAI Enforcement Arrives in Brussels People of Internet Research · EU 3% or €15M Maximum GPAI fine 12 months Grace period before enforceme… 180+ Signers of transparency code peopleofinternet.com

Key Takeaways

A one-year grace period just ended

Since August 2, 2025, providers of general-purpose AI (GPAI) models — the foundation models underpinning everything from ChatGPT to Gemini to Llama — have been legally bound by transparency, copyright, and systemic-risk obligations under Articles 53 and 55 of the EU AI Act. For a full year, those obligations existed largely on paper. The European Commission's AI Office could ask questions and encourage adoption of its voluntary Code of Practice, but it could not compel anything.

That changed on August 2, 2026. Under Articles 91–93 and 101 of the AI Act, the Commission's supervision and enforcement powers over GPAI providers came into force — the same day the Commission confirmed it was beginning to enforce the Act's broader transparency rules, including labelling requirements for chatbots and AI-generated media.

What the AI Office can now do

The new powers are not symbolic. The Commission can:

As of this writing, no fines have been issued. The regime is live, but untested.

The steelman: why this oversight is defensible

The case for giving Brussels compulsion powers, not just persuasion, is stronger than critics of EU tech regulation usually credit. Frontier models are now embedded in critical infrastructure, financial services, and information ecosystems reaching hundreds of millions of Europeans, yet the internal workings of the largest models remain opaque even to sophisticated regulators. A voluntary code works only as well as the incentive to comply with it, and a regime with no binding backstop cannot credibly claim to manage systemic risk — the kind that, by definition, one company's board is poorly positioned to weigh against the public interest alone. The one-year lag between obligation and enforcement was itself a reasonable concession to industry, giving providers time to build compliance infrastructure before penalties attached.

Where the design still cuts against innovation

The steelman only goes so far. "Systemic risk" under the AI Act is defined partly by a training-compute threshold and partly by Commission discretion — a standard flexible enough to invite exactly the kind of case-by-case unpredictability that chills investment more than a bright-line rule would. The Commission's own compliance shortcut, the GPAI Code of Practice, has already fractured on this point: Meta refused to sign it in February 2025, with chief global affairs officer Joel Kaplan calling it a source of legal uncertainty that goes beyond the Act's own text, while xAI signed only the safety chapter. Firms that decline the Code aren't breaking the law, but they now carry the full evidentiary burden of proving compliance through bespoke documentation — a heavier, less predictable lift than following a Commission-endorsed template, and precisely the kind of asymmetry that pushes global model developers to treat EU deployment as a distinct, costlier release track rather than a default one.

That asymmetry matters because the Commission's fining power is not narrow. A 3%-of-global-turnover ceiling, applied to a company whose GPAI product is a small fraction of overall revenue, is a lever sized for deterrence, not proportionality — and the Act gives the Commission latitude to invoke it for process failures (a missed documentation request, a contested evaluation) as readily as for a demonstrated harm. Regulators asking hard questions about frontier models is legitimate; regulators holding a company's entire global revenue hostage over a documentation dispute is a different order of instrument, and one Brussels has not yet had to justify in a contested case.

What to watch

The next twelve months will show whether this regime matures into predictable, proportionate oversight or becomes another wedge between EU and non-EU AI deployment. Two signals will tell the story: whether the Commission's first enforcement actions target genuine systemic-risk failures rather than paperwork gaps, and whether holdouts like Meta face a compliance path that's merely more burdensome than the Code — or effectively foreclosed. Over 180 organizations have already signed onto the Commission's separate transparency code for AI-generated content, suggesting industry will comply where the ask is concrete. Systemic-risk enforcement, with its vaguer triggers, is the harder test — and it starts now.

Sources & Citations

  1. Commission: enforcement begins Aug. 2
  2. EU AI Act regulatory framework overview
  3. Enforcement of Chapter V (Articles 91-101)
  4. Tech Policy Press: US firms and the GPAI Code