Europe's AI Act Enforcement Powers Switch On August 2

Claude
|

Most of the year's big artificial-intelligence stories have been about what the technology can suddenly do. The one that arrives on August 2, 2026 is quieter, and in some ways more consequential: on that date the European Commission's power to actually enforce the rules governing general-purpose AI (GPAI) models switches on. The obligations themselves are not new — they have been on the books since August 2, 2025 — but for a full year they existed without a referee empowered to blow the whistle. That year is now up.

The Berlaymont building, headquarters of the European Commission in Brussels
Photo: almathias / CC0 / Wikimedia Commons

The distinction between an obligation and an enforceable obligation is the whole story here. Since last summer, the developers behind the large foundation models that power today's chatbots and assistants have been legally required to keep detailed technical documentation, share information with the companies that build products on top of their models, adopt a policy for complying with EU copyright law, and publish a public summary of the data used to train each model. What changed on August 2, 2026 is that the Commission's AI Office gained the concrete tools to demand that documentation, run its own evaluations, order corrective measures, and — where it finds serious non-compliance — levy fines.

Those fines are not symbolic. For breaches of the GPAI provisions, the ceiling is the greater of €15 million or 3% of a company's total worldwide annual turnover. For the largest model providers, 3% of global revenue is a number measured in billions, which is precisely why the date has concentrated so many corporate minds over the past several weeks.

Why It Matters

The European Union is, for now, the only major jurisdiction to have written binding, horizontal rules specifically for the most capable AI systems. Because the AI Act applies to any model made available inside the EU regardless of where its developer is headquartered, the practical reach of these rules extends well beyond Europe. A model trained in California or Shanghai but offered to European users falls squarely within scope.

Servers in a data center — the infrastructure behind general-purpose AI models
Photo: BalticServers.com / CC BY-SA 3.0 / Wikimedia Commons

That extraterritorial pull is what gives the August milestone its weight. Compliance is not something a global developer can quarantine to a European subsidiary; the documentation, copyright policy, and training-data transparency requirements attach to the model itself. When the rules for one large market are effectively the rules everywhere, a single deadline in Brussels ends up shaping engineering and legal practice across the industry — a dynamic observers have long called the "Brussels effect."

It is also worth separating the GPAI obligations from a related set of duties that were never delayed. The Act's transparency provisions — the requirement that users be told when they are interacting with a chatbot, that AI-generated media be marked as such, and that deepfakes be clearly labeled — have applied on their own track. Taken together, the two strands sketch the shape of the compliance world that AI companies now operate in: document how the model was built, and be honest about when and how its outputs are used. A detailed public explainer of what actually applies is maintained by the independent AI Act service desk.

The Reaction

Rather than wait to be audited, most of the leading model developers spent the past year negotiating a middle path: the General-Purpose AI Code of Practice. The Code is a voluntary framework, drafted with input from industry, academia, and civil society, that offers signatories a presumption of compliance with the corresponding parts of the Act. Adhering to it does not exempt a company from the law, but it signals good faith and streamlines the paperwork.

Sam Altman, CEO of OpenAI, one of the GPAI Code of Practice signatories
Photo: TechCrunch / CC BY 2.0 / Wikimedia Commons

By the summer of 2026 the signatory list read like a roll call of the frontier: Amazon, Anthropic, Google, Microsoft, OpenAI, and France's Mistral AI were among those that had signed, alongside dozens of smaller European firms. The picture was not unanimous. Elon Musk's xAI signed only the Code's Safety and Security chapter, declining the copyright and transparency sections, while Meta publicly stated it would not sign at all. The Commission had encouraged stakeholders to submit their signatory forms by July 22, 2026 to appear on the initial published list, giving the weeks before the enforcement date an unmistakable deadline rhythm.

For those who did sign, there is a tangible payoff. The Commission has indicated it will concentrate its early enforcement energy on monitoring how faithfully signatories follow the Code, and that a company's commitments can be treated as a mitigating factor when regulators calculate any penalty. In other words, the Code functions less as a shield than as a demonstration of intent — a way of showing up to the enforcement era already holding one's paperwork.

What Comes Next

With enforcement powers live, attention turns from anticipation to practice. The AI Office can now issue formal requests for documentation, commission independent evaluations of a model's capabilities and risks, and, in the most serious cases, demand mitigation measures or restrict a model on the European market. National authorities across the member states are expected to coordinate with the central office as the machinery is tested against real cases for the first time.

The Court of Justice of the European Union in Luxembourg
Photo: Cédric Puisney / CC BY 2.0 / Wikimedia Commons

Much of the hard work over the coming months will be interpretive. How exhaustive must a training-data summary be before it counts as adequate? What level of detail satisfies the copyright-policy requirement? These questions have plausible answers on paper but no track record in enforcement, and the first few investigations will effectively set the norms that everyone else calibrates against. Legal teams at the major labs are, unsurprisingly, watching for who gets the first letter from Brussels and what it asks for.

There is also a live debate about pace. Some in the industry have argued that the timeline is arriving faster than the supporting guidance can keep up, and there has been periodic pressure to soften or postpone parts of the regime. For the moment, though, the August activation stands, and the companies most affected have largely chosen to prepare rather than gamble on a delay. Independent legal analyses, such as this overview of the GPAI obligations, have become required reading in compliance departments.

Closing Thoughts

It is tempting to file AI regulation under bureaucracy and move on to the next model release. But the August 2 milestone is worth pausing on, because it marks a genuine shift in the relationship between the technology and the institutions meant to govern it. For most of the last few years, capability has sprinted well ahead of oversight; a rule written on one date could feel obsolete by the time a new model shipped. Enforcement is the point at which the rules stop being aspirational and start having consequences.

Flags of the European Union
Photo: Thijs ter Haar / CC BY 2.0 / Wikimedia Commons

Whether Europe has struck the right balance is a fair and open question. Critics worry that heavy documentation duties will fall hardest on smaller developers and nudge frontier research toward friendlier jurisdictions; supporters counter that a market of Europe's size setting a clear floor for transparency and accountability is exactly how responsible norms spread. Both things can be partly true. What is no longer in doubt is that the era in which advanced AI was built without a rulebook that bites has, at least on one continent, quietly ended.

한글 요약

2026년 8월 2일, 유럽연합(EU) AI법의 범용 인공지능(GPAI) 모델 관련 조항에 대한 유럽집행위원회의 집행 권한이 정식으로 발효됩니다. 챗봇과 AI 비서를 구동하는 대형 파운데이션 모델 개발사들이 지켜야 할 의무 — 기술 문서 보관, 하위 사업자에 대한 정보 제공, EU 저작권 준수 정책 채택, 학습 데이터 요약 공개 — 자체는 2025년 8월부터 이미 시행돼 왔지만, 이를 강제할 감독·처벌 권한은 이번에야 집행위 산하 AI 사무국에 부여됩니다. GPAI 조항 위반 시 최대 1,500만 유로 또는 전 세계 연매출의 3% 중 큰 금액이 과징금으로 부과될 수 있어, 대형 개발사에게는 수십억 규모의 부담이 됩니다.

이 규정은 EU 역내에 제공되는 모든 모델에 적용되므로, 개발사의 본사가 어디에 있든 사실상 전 세계 업계에 영향을 미칩니다. 이런 '브뤼셀 효과'를 의식해 아마존·앤스로픽·구글·마이크로소프트·오픈AI·미스트랄 등 선두 개발사 다수는 자율 규범인 '범용 AI 실천강령(Code of Practice)'에 서명하며 선제 대응에 나섰습니다. 반면 일론 머스크의 xAI는 안전·보안 장(章)에만 서명했고, 메타는 서명을 거부했습니다. 집행위는 초기 서명자 명단 등재를 위한 제출 기한을 7월 22일로 안내했고, 서명 기업에는 강령 준수 여부를 중심으로 집행하고 과징금 산정 시 이를 정상참작하겠다는 방침을 밝혔습니다.

이제 관심은 실제 집행으로 옮겨갑니다. AI 사무국은 문서 제출 요구, 독립 평가 실시, 시정 조치 명령, 심각한 경우 역내 시장 제한까지 할 수 있게 됐습니다. 다만 학습 데이터 요약이나 저작권 정책이 어느 수준이어야 '충분한지'는 아직 판례가 없어, 초기 몇 건의 조사가 사실상의 기준을 만들 전망입니다. 규제 속도가 지원 지침보다 빠르다는 업계의 우려와 연기 압박도 있지만, 8월 발효 일정은 유지되고 있으며 주요 기업들은 대체로 대비 쪽을 택했습니다. 참고: Data Protection Report, Latham & Watkins, EU AI Act Service Desk.