Background
The European Union Artificial Intelligence Act (EU AI Act), formally designated Regulation 2024/1689, entered into force on 1 August 2024 as the world's first comprehensive binding AI regulation. Its provisions have rolled out on a staggered timeline designed to give industry time to adapt.
Current Enforcement Milestone
The most significant threshold to date was reached on 2 August 2025, when obligations for providers of General-Purpose AI (GPAI) models — commonly referred to as foundation models or large language models (LLMs) — became legally applicable. Any new foundation model introduced to the EU market after that date must comply with the Act's transparency, safety, and copyright requirements.
The governance infrastructure underpinning enforcement, including the European AI Office (AI Office) operating within the European Commission, also became operational on that date. The AI Office holds exclusive competence to supervise and enforce GPAI model obligations, a centralised model that differs from the decentralised approach applied to high-risk AI systems more broadly, where national market surveillance authorities play the primary role.
What GPAI Providers Must Now Do
All GPAI model providers face baseline obligations under Article 53 of the Act: they must prepare technical documentation per Annex XI, maintain a copyright compliance policy consistent with EU Directive 2019/790, and publish summaries of training data using an AI Office-mandated template.
For the most advanced frontier models — those whose training compute exceeds 10²⁵ floating-point operations (FLOPs) — additional systemic-risk obligations apply under Article 55. These include conducting model evaluations, performing and documenting adversarial testing, assessing and mitigating systemic risks, tracking and reporting serious incidents to the Commission without undue delay, and maintaining adequate cybersecurity protections. Models currently understood to fall within this category include GPT-4 class systems, Gemini Ultra, Claude 3 Opus and later versions, and Meta Llama 3 405B, though Commission review of individual designations is ongoing.
Providers must notify the Commission within two weeks of reaching or foreseeably reaching the 10²⁵ FLOPs threshold and may contest a systemic-risk classification by submitting benchmark or scaling-law evidence. Obligations remain in effect throughout any review period.
Code of Practice
On 10 July 2025, the AI Office published the final General-Purpose AI Code of Practice (CoP), a voluntary compliance tool covering three chapters: Transparency, Copyright, and Safety and Security. The European Commission and AI Board confirmed that the CoP adequately covers obligations under Articles 53 and 55, meaning signatories gain a presumption of conformity with those articles from 2 August 2026. Providers that do not sign must separately report their compliance approach to the AI Office.
The Safety and Security chapter, which applies exclusively to systemic-risk GPAI providers, requires development of a comprehensive Safety and Security Framework before model release, ongoing risk monitoring, adversarial testing, and publication of summarised model reports.
Penalty Exposure and Key Deadlines
Full enforcement powers for the European Commission — including the ability to impose fines — activate on 2 August 2026. Fines for GPAI-related infringements can reach up to 3% of global annual turnover or €15 million, whichever is higher. Providers of GPAI models already on the EU market before 2 August 2025 have a transitional period until 2 August 2027 to achieve full compliance.
Separately, broader high-risk AI system obligations for Annex III applications — spanning recruitment, credit scoring, law enforcement, and similar domains — are currently scheduled to apply from December 2027 following the EU AI Act Omnibus provisional political agreement of May 2026, which deferred that earlier deadline.
Industry Context
The GPAI systemic-risk designation is currently estimated to apply to a small group of five to fifteen companies worldwide. Frontier model developers including those behind systems such as OpenAI's o3, Anthropic's Claude 4 Opus, and Google's Gemini 2.5 Pro are explicitly cited in the official Code of Practice documentation as examples of models subject to the Safety and Security chapter's strictest requirements. Industry groups have urged further delays and additional interpretive guidance, while EU officials have maintained that the framework balances regulatory clarity with technological pragmatism.