What Took Effect August 2
The second major compliance milestone of the European Union (EU) Artificial Intelligence (AI) Act came into force on August 2, 2025. <cite index="9-4">On that date, AI Act obligations for providers of General-Purpose AI (GPAI) models entered into application, and Member States were required to designate national competent authorities and adopt national laws on penalties.</cite> The regulation itself <cite index="5-14">was published in the Official Journal of the European Union on 12 July 2024, entered into force on 1 August 2024, and has been applying in phases ever since.</cite>
The August 2 milestone followed an earlier phase in which <cite index="1-9">prohibited AI systems had to be discontinued and AI literacy obligations took effect for all organisations deploying AI systems in the European Union as of 2 February 2025.</cite>
What GPAI Providers Must Now Do
<cite index="10-2">The EU AI Act introduces obligations for providers of GPAI models, including those with systemic risk, defining GPAI models as AI capable of performing a wide range of tasks and requiring integration into downstream systems.</cite> Under Article 53, <cite index="14-7,14-8,14-9">baseline obligations apply to all GPAI model providers regardless of whether the model presents systemic risk, with providers required to draw up and keep up to date technical documentation of the GPAI model, including its training and testing process and the results of its evaluation.</cite> Providers must also <cite index="12-13,12-14">publish a training data summary using an AI Office template and maintain a copyright compliance policy.</cite>
Systemic Risk: The Higher Bar
Models that exceed a compute threshold face additional scrutiny. <cite index="22-2">A GPAI model is presumed to have high-impact capabilities when the cumulative amount of computation used for its training, measured in floating-point operations (FLOPs), is greater than 10²⁵.</cite> <cite index="24-3">Providers must notify the European Commission within two weeks of reasonably foreseeing or reaching the 10²⁵ FLOPs threshold.</cite>
<cite index="11-1">Providers of GPAI models that pose systemic risk must comply with an additional set of obligations under Article 55, which include the performance of model evaluations to assess the model's capabilities and effects; the assessment and mitigation of systemic risks; the report of serious incidents to relevant authorities; the adoption of corrective measures; and the implementation of an appropriate level of cybersecurity for the model and its physical infrastructure.</cite>
Fines and Enforcement Timeline
<cite index="10-1">The Act, effective from August 2, 2025, with a grace period for fines until August 2, 2026, grants the European Commission exclusive enforcement powers, including fines up to 3% of annual worldwide turnover or €15 million.</cite> <cite index="14-4,14-5">The AI Office, established within the European Commission, has exclusive competence to supervise and enforce GPAI model obligations — a centralised enforcement model that differs from the decentralised approach used for high-risk AI systems, where national market surveillance authorities play the primary role.</cite>
<cite index="12-1">While obligations kicked in on 2 August 2025, the AI Office does not have full enforcement powers until 2 August 2026, by which time it may request information, order model recalls, mandate mitigations, or impose fines.</cite>
The GPAI Code of Practice
To assist providers, <cite index="32-1">the European Commission released the General-Purpose AI Code of Practice (GPAI CoP) on 10 July 2025 as a compliance tool to support compliance with the AI Act.</cite> <cite index="32-3">The Code is organised into three chapters covering Transparency, Copyright, and Safety and Security, and outlines how providers can meet the Act's relevant obligations.</cite> <cite index="35-6,35-7,35-8">The Commission and the AI Board have confirmed that the Code is an adequate voluntary tool for providers of GPAI models to demonstrate compliance with the AI Act, giving signatories more legal certainty and reduced administrative burden than if they proved compliance through other methods.</cite>
<cite index="29-1">As of August 4, 2025, several GPAI model providers, including OpenAI, Google, Anthropic, Microsoft, and Mistral, signed the voluntary Code of Practice.</cite> <cite index="32-5">xAI signed only the Safety and Security chapter.</cite> <cite index="31-7">Meta publicly stated in July 2025 that it would not sign the Code.</cite>
What Comes Next
<cite index="9-5">On 2 August 2026, the majority of rules of the AI Act come into force and enforcement starts, including rules for high-risk AI systems in Annex III, transparency rules under Article 50, and enforcement at national and EU-level.</cite> <cite index="3-3">Obligations for providers and deployers of high-risk AI systems will now apply from 2 December 2027 for standalone AI systems and 2 August 2028 for AI systems embedded in a product.</cite>