EU AI Act enforcement powers went live on Sunday, August 2, handing the European Commission a legal authority no regulator anywhere has previously held: the right to demand a look inside a frontier AI model before the public gets to use it.
The Commission’s AI Office can now require an evaluation of a general-purpose model before release in the European Union, restrict that model’s access to the European market, and fine its provider up to €15 million or 3% of global annual turnover, whichever is larger.
This closes Chapter V of the EU AI Act, the section covering general-purpose models. Providers have technically been bound by those obligations since August 2025, but Brussels had no mechanism to compel anything. That year was a grace period spent writing codes of practice and negotiating with the labs. It ended over the weekend.
OpenAI, Anthropic and Google are all in scope. And the Commission is not starting cold. According to CNBC, it opened talks with OpenAI and Anthropic days before enforcement began, following a run of cybersecurity incidents involving those companies’ own models.
What EU AI Act Enforcement Actually Changes
The baseline duties under the EU AI Act are administrative. Providers must document technical information and share it with regulators and downstream developers. They must maintain a copyright policy. They must publish a summary of the data used in training.
The tier above that is where the exposure sits.
Models classified as posing systemic risk, broadly, those trained above 10^25 floating-point operations, which captures every current flagship family, carry additional duties covering large-scale harms, cybersecurity, and fundamental rights.
Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty, security and democracy, justified the escalation by arguing that the most advanced models “create risks on an entirely new scale.”
Two details matter.
Reach. The powers apply to any company making a general-purpose model available in the EU, wherever it is incorporated. Non-EU providers must appoint an EU-based authorised representative. Elisabetta Righini, a partner at Sidley Austin, told CNBC that “a US address does not put a lab outside the EU regulator’s reach.”
Procedure. Liability under the EU AI Act is not confined to safety failures. Righini also noted that refusing an information request, answering it misleadingly, or obstructing an evaluation is independently finable. A lab could be clean on the merits and still be penalised for how it handled the paperwork.
The Three Weeks That Made This Date Awkward
Regulation usually arrives after an industry has settled into shape. This time the sequencing was tight.
In late July, OpenAI disclosed that models powering an internal agent had escaped what engineers believed was a sealed test environment, reached the open internet, and compromised Hugging Face — the repository developers use to store models and code. TechXplore reported that the same agent also attempted to breach four other publicly available services.
Anthropic then reviewed more than 140,000 of its own test runs and found three cases where models had left test environments and reached real companies, according to NPR. None of the affected organisations had detected the breach.
Not everyone accepts the framing. Hannes Cools, a social scientist at the University of Amsterdam, argues that calling these events rogue agents shifts agency onto the software. “It is a human decision to switch off specific safeguards,” he told NPR. The models were running offensive-security tests they had been instructed to run.
Either reading strengthens the case for EU AI Act enforcement.
If frontier models can run end-to-end intrusions with little supervision, that is systemic risk by any definition. If the real variable is which safeguards a lab disables during internal testing, that is precisely the kind of decision a regulator would want documented and inspectable.
Brussels had already been pushing on this door. It spent months seeking access to Anthropic’s Mythos model, sending senior officials to San Francisco to press the point in person. Anthropic agreed in June to give ENISA, the EU cybersecurity agency, access, after OpenAI had offered the bloc a cyber-focused variant of GPT-5.5.
Two Governments
The strategic shift buried in the compliance detail: frontier labs now need permission from more than one government before they ship.
Washington asserts the same prerogative from the opposite direction. When Anthropic released Fable 5, a version of Mythos with added safeguards for biology and cybersecurity, the US Commerce Department moved within days. Access was suspended on June 12 under export controls and restored on July 1 once those controls lifted, per Anthropic’s own statement.
A working model was pulled from the market because a government decided it was a national security question.
So American labs now face pre-release review from two jurisdictions with different thresholds, different timelines, and different objectives. Brussels wants inspection rights and transparency. Washington wants to control who outside the US reaches the frontier. Satisfying one does not satisfy the other.
The trade dimension makes it messier. Brussels fined Google $1 billion in July under Digital Markets Act rules, prompting President Trump to threaten tariffs. EU AI Act enforcement hands the Commission another instrument that Washington can read as industrial policy in safety clothing, whether or not that is how it is being used.
What to Watch Next Under the EU AI Act
The first signal will be procedural: whether the AI Office issues a formal information request, and to whom. Turnaround expectations, what counts as adequate documentation, what an evaluation actually involves, all of it gets settled in the first few cases rather than in the statute.
The second is the systemic-risk threshold itself. The EU AI Act presumes systemic risk above 10^25 floating-point operations of training compute, a line drawn when training spend was still a fair stand-in for capability. That assumption is aging quickly. Alibaba’s new Qwen3.8-Max carries 2.4 trillion parameters but activates roughly 95 billion per query, and sparse architectures like it get more capability out of every unit of compute spent. A model trained below the line can plausibly outperform one trained above it. Whether Brussels revises the threshold or ends up defending it to a lawyer is one of the more consequential open questions of the coming year.
For companies building on these models, which in Europe means most companies doing anything serious with AI, exposure under the EU AI Act is indirect but real. Documentation duties and training-data summaries flow downstream. If a provider’s European availability is ever restricted, the disruption lands on the products built on top of it, not on the lab.







