EU AI Act enforcement powers over general-purpose AI models take full effect from 2 August 2026, with fines of up to €35 million or 7% of global turnover for prohibited practices
The EU AI Act, adopted in 2024, reached a pivotal enforcement milestone on 2 August 2026 as the European Commission gained direct powers to enforce obligations on providers of general-purpose AI (GPAI) models, which are powerful AI systems capable of performing a wide range of tasks. From this date, the European Commission's AI Office can assess GPAI models, conduct investigations, require companies to supply documents and information, grant regulators access to models for evaluation, and in some cases examine a model before it is released on the European market. Companies can be ordered to take corrective action, and models can be restricted or withdrawn from the EU market. New transparency requirements also came into force on 2 August. Providers and users of certain AI systems must now make it clear when material has been artificially generated or manipulated. AI-generated content must carry electronic markings that allow it to be detected. Organisations publishing deepfakes (highly realistic manipulated images, audio, or video) must disclose the manipulation. AI-generated or manipulated text published to inform the public on matters of public interest must generally be labelled, with exemptions where content has undergone human editorial review and a responsible person accepts accountability for it. Penalties are tiered by severity. Companies using (such as indiscriminate facial recognition databases or AI systems exploiting vulnerabilities linked to age, disability, or economic circumstances) face fines of up to , whichever is higher. Breaches of other requirements carry fines of up to . Smaller companies face proportionate penalties. Systems placed on the EU market before 2 August have until to comply with some technical marking and detection requirements. Stricter rules for high-risk AI in healthcare, employment, education, migration, and security will not apply until , and AI embedded in regulated products such as medical devices and machinery takes effect in . The enforcement expansion is particularly significant for non-European companies, including US-headquartered GPAI developers such as , whose models are deployed across Europe. Providers of the most advanced models posing what the Act calls a systemic risk face additional requirements: safety assessments, cybersecurity protections, incident reporting, and harm mitigation measures. GPAI providers must also maintain technical documentation, publish information about training data, and establish policies to comply with EU copyright law.