The EU Begins Enforcing Its AI Act in Earnest: Strict Duties for the Highest-Risk General-Purpose Models
The European Union has moved from drafting rules to enforcing them. On 2 August 2026, the majority of the AI Actās applicable provisions entered their enforcement phase, including transparency requirements, AI literacy duties, prohibitions and European-level supervision of general-purpose AI (GPAI) models.[1] The date does not mean that every obligation for every high-risk system is already active. It does mean that providers of powerful, widely usable models can no longer treat compliance as a distant preparation exercise.
Ā
The EUās approach is built around risk. A model that can write text, generate images, analyse code or power an AI agent may be used in thousands of different products. The regulation therefore places a layer of duties on the model provider itself, before downstream developers integrate the model into specific applications. The most demanding layer applies to GPAI models that may create systemic riskāthe small group of highly capable or widely influential models whose failures could affect public safety, fundamental rights or society at large.[2]
Ā

What changed on 2 August 2026?
The AI Act entered into force on 1 August 2024, but its provisions were deliberately phased. The first general rules and prohibitions began applying in February 2025. The dedicated GPAI rules followed in August 2025, while the August 2026 date brought most of the Actās operational enforcement architecture into play.[1]
Ā
Date | Practical effect |
1 August 2024 | The regulation entered into force. |
2 February 2025 | General provisions, AI literacy requirements and most prohibitions began to apply. |
2 August 2025 | GPAI obligations applied; national authorities and EU governance structures were required. |
2 August 2026 | Article 50 transparency rules and enforcement for applicable GPAI, transparency, prohibition and literacy duties began. |
2 December 2027 | Rules for many high-risk systems listed in Annex III are scheduled to apply. |
2 August 2028 | Rules for high-risk AI embedded in regulated products under Annex I are scheduled to apply. |
This distinction matters for businesses. The EU is already enforcing duties that apply to GPAI providers and transparency obligations, while many obligations for high-risk use casesāsuch as recruitment, credit access, education, law enforcement and certain critical infrastructure applicationsāremain tied to later dates under the current implementation timetable.[1][2]
Ā
The baseline duties for GPAI providers
GPAI providers must supply enough information for downstream users to understand what a model can do, how it was developed and how it should be integrated responsibly. The framework addresses transparency and copyright for all providers covered by the GPAI chapter. It also requires providers to maintain a policy for complying with EU copyright law, including the treatment of rights reservations in training data.[3]
Ā
Providers must prepare technical documentation and make relevant information available to the AI Office and to developers who place the model into other AI systems. The purpose is not to force companies to publish every trade secret or every line of training code. It is to create a usable compliance record: the modelās capabilities, limitations, evaluation methods, intended use conditions and the information needed by downstream operators to meet their own obligations.
Ā
The European Commissionās voluntary GPAI Code of Practice provides a practical route for demonstrating compliance. Published on 10 July 2025, it contains separate chapters on transparency, copyright, and safety and security. The first two chapters address the obligations applicable to GPAI providers generally. The safety and security chapter is aimed at providers of GPAI models with systemic risk.[3]
Ā
Signing the code is voluntary, but the legal duties are not. The Commission and the AI Board have described the code as an adequate voluntary tool. Providers that follow it can reduce administrative work and gain greater legal certainty, although a non-signatory must still demonstrate compliance through other adequate means.[3]
Ā
Why the highest-risk models face a tougher regime
The systemic-risk category recognises that capability and scale can change the nature of harm. A general-purpose model used by a small research team presents one set of risks. A frontier model integrated into search, office software, customer service, coding tools and autonomous agents can produce failures across many sectors at once.
Ā
For these models, Article 55 adds duties beyond ordinary documentation and copyright policies. Providers must perform model evaluations, assess and mitigate systemic risks, conduct adversarial testing, track and report serious incidents, and maintain appropriate levels of cybersecurity. They must also keep the AI Office informed when a model reaches the relevant threshold or is otherwise identified as presenting systemic risk.[2][3]
Ā
The regulatory logic is preventive. Authorities do not need to wait for a catastrophic incident before asking whether a provider tested dangerous capabilities, maintained safeguards or had a process for responding to severe failures. A providerās internal evidenceāevaluations, red-team results, risk controls and incident recordsābecomes part of the compliance picture.
Ā
The framework also creates a supervisory relationship at EU level. The AI Office is responsible for GPAI models under its remit, while national market-surveillance authorities enforce rules within their areas. The European Data Protection Supervisor has a specific role when EU institutions are providers or deployers.[1]
Ā
Transparency reaches the user interface
The August 2026 enforcement phase is also visible to ordinary users. Certain AI-generated or manipulated images, audio and videos that resemble real people, objects, places, entities or events must be clearly labelled and carry machine-readable marks. This covers deepfake-style content. Users must also be told when they are interacting with an AI system, such as a chatbot, AI agent or avatar.[4]
Ā
The rules cover additional situations, including certain public-interest text produced without human review or editorial control, as well as systems for emotion recognition and biometric categorisation.[4] The policy goal is straightforward: people should be able to distinguish an automated interaction or synthetic media from human-created and authentic material before making decisions based on it.
Ā
The Commissionās enforcement notice states that companies can face fines of up to ā¬15 million or 3% of global annual turnover for breaches of the transparency rules. EU institutions can face penalties of up to ā¬750,000, with proportionality considered for small and medium-sized enterprises and small mid-cap companies.[4]
Ā
āThe goal is simple: more transparency, so you know when AI is involved.ā ā European Commission Audiovisual Service[5]
Ā
What companies should do now
For model providers, the immediate priority is to map every GPAI obligation to evidence that can be produced quickly and consistently. That means maintaining a current model card or equivalent technical record, a documented copyright policy, training-data governance records, evaluation results and an incident-response process. Providers whose models may present systemic risk should treat adversarial testing and security controls as continuing operations rather than one-time certification steps.
Ā
For downstream developers and deployers, the key task is different. They must determine whether a GPAI model is being used inside a regulated high-risk system, whether the resulting service triggers transparency duties, and what information they need from the model provider. A model itself is not automatically a high-risk use case merely because it is powerful. Risk depends on the systemās role and context, while systemic-risk duties apply to a narrower class of GPAI providers.
Ā
Procurement teams should therefore ask for more than a general statement that a model is āAI Act compliant.ā They should request the modelās intended-use restrictions, documentation package, update policy, incident-notification terms, transparency mechanisms and evidence that the provider has addressed copyright and security obligations. Contractual clarity will be especially important when a model is updated frequently or when several suppliers share responsibility for one deployed system.
Ā

Enforcement will test the Actās credibility
The EU now faces the difficult part: applying a complex, technology-neutral regulation to models that change faster than ordinary product cycles. Regulators will need to decide how to interpret capability thresholds, systemic risk evidence, open-source arrangements, model modifications and responsibility across the supply chain. Providers, in turn, will need to show that their claims are supported by records rather than marketing language.
Ā
The Actās success will depend on proportional supervision. Excessively vague demands could burden smaller developers without improving safety. Weak scrutiny of frontier providers could leave the most consequential systems under-supervised. The Code of Practice is intended to narrow that gap by translating legal duties into operational practices, but it does not remove the need for case-by-case judgment.[3]
Ā
The next major pressure point is the later application of high-risk system rules. From December 2027, many Annex III systems will face requirements covering risk management, data quality, logging, documentation, human oversight, accuracy, robustness and cybersecurity.[1][2] Those duties will affect organisations that use AI in employment, education, essential services, biometrics, migration, justice and democratic processes. The August 2026 enforcement phase is therefore the beginning of a longer compliance cycle, not its endpoint.
Ā
A visible new standard for AI accountability
Europeās message to model providers is now concrete: broad capability brings broad responsibility, and the highest-risk models must be able to demonstrate how they identify and reduce systemic dangers. The immediate obligations concern documentation, copyright, transparency, evaluation, reporting and security. The wider effect is cultural. AI companies are being pushed to treat governance as part of product design, not as paperwork added after launch.
Ā
For users, the first visible result will be clearer disclosure. For developers, it will be a more demanding information and procurement environment. For frontier model providers, it will be sustained scrutiny from a dedicated European supervisor. Whether this produces safer and more trustworthy AI will depend on enforcement quality, technical evidence and cooperation across the supply chain. But as of August 2026, the EU has made one point unmistakable: the rulebook is no longer waiting on the sidelines.
References
[1]: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act āAI Act Service Desk, Timeline for the Implementation of the EU AI Act.ā
[2]: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai āEuropean Commission, AI Act | Shaping Europeās digital future.ā
[3]: https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai āEuropean Commission, The General-Purpose AI Code of Practice.ā
[4]: https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en āEuropean Commission, Safer and more transparent AI, 2 August 2026.ā
[5]: https://audiovisual.ec.europa.eu/en/media/video/I-293312 āEuropean Commission Audiovisual Service, How You'll Know When It's AI, 31 July 2026.ā





Comments