8/22/2026, 1:03:00 PM · evaluation-safety

EU AI Act Enforcement Enters Active Phase as GPAI Obligations Take Effect and Fines of Up to €15M Loom

The European Union's landmark AI regulation shifts from theoretical compliance to operational enforcement, with binding obligations now in force for general-purpose AI model providers and European Commission fine powers set to fully activate in August 2026.

Background

The European Union Artificial Intelligence Act (EU AI Act), formally designated Regulation 2024/1689, entered into force on 1 August 2024 as the world's first comprehensive binding AI regulation. Its provisions have rolled out on a staggered timeline designed to give industry time to adapt.

Current Enforcement Milestone

The most significant threshold to date was reached on 2 August 2025, when obligations for providers of General-Purpose AI (GPAI) models — commonly referred to as foundation models or large language models (LLMs) — became legally applicable. Any new foundation model introduced to the EU market after that date must comply with the Act's transparency, safety, and copyright requirements.

The governance infrastructure underpinning enforcement, including the European AI Office (AI Office) operating within the European Commission, also became operational on that date. The AI Office holds exclusive competence to supervise and enforce GPAI model obligations, a centralised model that differs from the decentralised approach applied to high-risk AI systems more broadly, where national market surveillance authorities play the primary role.

What GPAI Providers Must Now Do

All GPAI model providers face baseline obligations under Article 53 of the Act: they must prepare technical documentation per Annex XI, maintain a copyright compliance policy consistent with EU Directive 2019/790, and publish summaries of training data using an AI Office-mandated template.

For the most advanced frontier models — those whose training compute exceeds 10²⁵ floating-point operations (FLOPs) — additional systemic-risk obligations apply under Article 55. These include conducting model evaluations, performing and documenting adversarial testing, assessing and mitigating systemic risks, tracking and reporting serious incidents to the Commission without undue delay, and maintaining adequate cybersecurity protections. Models currently understood to fall within this category include GPT-4 class systems, Gemini Ultra, Claude 3 Opus and later versions, and Meta Llama 3 405B, though Commission review of individual designations is ongoing.

Providers must notify the Commission within two weeks of reaching or foreseeably reaching the 10²⁵ FLOPs threshold and may contest a systemic-risk classification by submitting benchmark or scaling-law evidence. Obligations remain in effect throughout any review period.

Code of Practice

On 10 July 2025, the AI Office published the final General-Purpose AI Code of Practice (CoP), a voluntary compliance tool covering three chapters: Transparency, Copyright, and Safety and Security. The European Commission and AI Board confirmed that the CoP adequately covers obligations under Articles 53 and 55, meaning signatories gain a presumption of conformity with those articles from 2 August 2026. Providers that do not sign must separately report their compliance approach to the AI Office.

The Safety and Security chapter, which applies exclusively to systemic-risk GPAI providers, requires development of a comprehensive Safety and Security Framework before model release, ongoing risk monitoring, adversarial testing, and publication of summarised model reports.

Penalty Exposure and Key Deadlines

Full enforcement powers for the European Commission — including the ability to impose fines — activate on 2 August 2026. Fines for GPAI-related infringements can reach up to 3% of global annual turnover or €15 million, whichever is higher. Providers of GPAI models already on the EU market before 2 August 2025 have a transitional period until 2 August 2027 to achieve full compliance.

Separately, broader high-risk AI system obligations for Annex III applications — spanning recruitment, credit scoring, law enforcement, and similar domains — are currently scheduled to apply from December 2027 following the EU AI Act Omnibus provisional political agreement of May 2026, which deferred that earlier deadline.

Industry Context

The GPAI systemic-risk designation is currently estimated to apply to a small group of five to fifteen companies worldwide. Frontier model developers including those behind systems such as OpenAI's o3, Anthropic's Claude 4 Opus, and Google's Gemini 2.5 Pro are explicitly cited in the official Code of Practice documentation as examples of models subject to the Safety and Security chapter's strictest requirements. Industry groups have urged further delays and additional interpretive guidance, while EU officials have maintained that the framework balances regulatory clarity with technological pragmatism.

Cross-references

Sources

  1. [1]
    EU AI Act Update 2025 | TTMS
  2. [2]
    Latest wave of obligations under the EU AI Act take effect: Key considerations | DLA Piper
  3. [3]
    EU AI Act 2026 Updates: Compliance Requirements and Business Risks
  4. [4]
    EU AI Act Compliance Guide: Updated June 2026
  5. [5]
    Artificial Intelligence Act | Freshfields
  6. [6]
    EU AI Act 2025-2026: deadlines, fines & what to expect | Practical Guide | EU AI Act | aiactblog.nl
  7. [7]
    What Is the EU AI Act? Risk Tiers, Deadlines & Compliance | Snowflake
  8. [8]
    Implementation Timeline | EU Artificial Intelligence Act
  9. [9]
    High-level summary of the AI Act | EU Artificial Intelligence Act
  10. [10]
    EU: Obligations on providers of GPAI models under the EU AI Act | Stephenson Harwood
  11. [11]
    EU AI Act Brief – Pt. 5, General-Purpose AI Models - Center for Democracy and Technology
  12. [12]
    Overview of Guidelines for GPAI Models | EU Artificial Intelligence Act
  13. [13]
    EU AI Act: Risk-Classifications of the AI Regulation
  14. [14]
    Frequently Asked Questions | AI Act Service Desk
  15. [15]
    EU AI Act GPAI Rules: What Providers Need to Know
  16. [16]
    AI Risk Classification: Guide to EU AI Act Risk Categories - GDPR Local
  17. [17]
    GPAI & Foundation Model Compliance Under the EU AI Act: Transparency & Systemic-Risk Obligations
  18. [18]
    EU AI Act Risk Levels: How to Classify AI System Correctly
  19. [19]
    EU AI Act omnibus: the new high-risk deadlines explained
  20. [20]
    The AI Act’s New Guidelines on General-Purpose AI Models (GPAI) | Cranium
  21. [21]
    reuters.com,2025:newsml L8N3TE1P0:0 ai models with systemic risks given pointers on how to comply with eu ai rules
  22. [22]
    82770 nl
  23. [23]
    EU AI Act: GPAI Model Obligations in Force and Final GPAI Code of Practice in Place
  24. [24]
    Overview of the Code of Practice | EU Artificial Intelligence Act
  25. [25]
    Guidelines for providers of general-purpose AI models | Shaping Europe’s digital future
  26. [26]
    AI Systemic Risk Assessment Under EU AI Act: GPAI Model Provider Obligations
  27. [27]
    EU AI Act: General-Purpose AI Code of Practice · Final Version
  28. [28]
    An Introduction to the Code of Practice for General-Purpose AI | EU Artificial Intelligence Act
  29. [29]
    EU AI Act: A Quick Guide to the GPAI Code of Practice (2026 Update) – eyreACT: AI Compliance Automation Platform