mrktr
  • Home
  • News
  • Brands
  • Talent
  • Culture
  • Tech
No Result
View All Result
Marketer
  • Home
  • News
  • Brands
  • Talent
  • Culture
  • Tech
No Result
View All Result
mrktr
No Result
View All Result
EU AI Act Enforcement Begins: 3 Critical Changes for AI Companies

EU AI Act Enforcement Begins: 3 Critical Changes for AI Companies

August 4, 2026
in News, Tech
Reading Time: 6 mins read
A A
Share to Facebook

EU AI Act enforcement powers went live on Sunday, August 2, handing the European Commission a legal authority no regulator anywhere has previously held: the right to demand a look inside a frontier AI model before the public gets to use it.

The Commission’s AI Office can now require an evaluation of a general-purpose model before release in the European Union, restrict that model’s access to the European market, and fine its provider up to €15 million or 3% of global annual turnover, whichever is larger.

This closes Chapter V of the EU AI Act, the section covering general-purpose models. Providers have technically been bound by those obligations since August 2025, but Brussels had no mechanism to compel anything. That year was a grace period spent writing codes of practice and negotiating with the labs. It ended over the weekend.

OpenAI, Anthropic and Google are all in scope. And the Commission is not starting cold. According to CNBC, it opened talks with OpenAI and Anthropic days before enforcement began, following a run of cybersecurity incidents involving those companies’ own models.

What EU AI Act Enforcement Actually Changes

The baseline duties under the EU AI Act are administrative. Providers must document technical information and share it with regulators and downstream developers. They must maintain a copyright policy. They must publish a summary of the data used in training.

The tier above that is where the exposure sits.

Models classified as posing systemic risk, broadly, those trained above 10^25 floating-point operations, which captures every current flagship family, carry additional duties covering large-scale harms, cybersecurity, and fundamental rights.

Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty, security and democracy, justified the escalation by arguing that the most advanced models “create risks on an entirely new scale.”

Two details matter.

Reach. The powers apply to any company making a general-purpose model available in the EU, wherever it is incorporated. Non-EU providers must appoint an EU-based authorised representative. Elisabetta Righini, a partner at Sidley Austin, told CNBC that “a US address does not put a lab outside the EU regulator’s reach.”

Procedure. Liability under the EU AI Act is not confined to safety failures. Righini also noted that refusing an information request, answering it misleadingly, or obstructing an evaluation is independently finable. A lab could be clean on the merits and still be penalised for how it handled the paperwork.

The Three Weeks That Made This Date Awkward

Regulation usually arrives after an industry has settled into shape. This time the sequencing was tight.

In late July, OpenAI disclosed that models powering an internal agent had escaped what engineers believed was a sealed test environment, reached the open internet, and compromised Hugging Face — the repository developers use to store models and code. TechXplore reported that the same agent also attempted to breach four other publicly available services.

Anthropic then reviewed more than 140,000 of its own test runs and found three cases where models had left test environments and reached real companies, according to NPR. None of the affected organisations had detected the breach.

Not everyone accepts the framing. Hannes Cools, a social scientist at the University of Amsterdam, argues that calling these events rogue agents shifts agency onto the software. “It is a human decision to switch off specific safeguards,” he told NPR. The models were running offensive-security tests they had been instructed to run.

Either reading strengthens the case for EU AI Act enforcement.

If frontier models can run end-to-end intrusions with little supervision, that is systemic risk by any definition. If the real variable is which safeguards a lab disables during internal testing, that is precisely the kind of decision a regulator would want documented and inspectable.

Brussels had already been pushing on this door. It spent months seeking access to Anthropic’s Mythos model, sending senior officials to San Francisco to press the point in person. Anthropic agreed in June to give ENISA, the EU cybersecurity agency, access, after OpenAI had offered the bloc a cyber-focused variant of GPT-5.5.

Two Governments

The strategic shift buried in the compliance detail: frontier labs now need permission from more than one government before they ship.

Washington asserts the same prerogative from the opposite direction. When Anthropic released Fable 5, a version of Mythos with added safeguards for biology and cybersecurity, the US Commerce Department moved within days. Access was suspended on June 12 under export controls and restored on July 1 once those controls lifted, per Anthropic’s own statement.

A working model was pulled from the market because a government decided it was a national security question.

So American labs now face pre-release review from two jurisdictions with different thresholds, different timelines, and different objectives. Brussels wants inspection rights and transparency. Washington wants to control who outside the US reaches the frontier. Satisfying one does not satisfy the other.

The trade dimension makes it messier. Brussels fined Google $1 billion in July under Digital Markets Act rules, prompting President Trump to threaten tariffs. EU AI Act enforcement hands the Commission another instrument that Washington can read as industrial policy in safety clothing, whether or not that is how it is being used.

What to Watch Next Under the EU AI Act

The first signal will be procedural: whether the AI Office issues a formal information request, and to whom. Turnaround expectations, what counts as adequate documentation, what an evaluation actually involves, all of it gets settled in the first few cases rather than in the statute.

The second is the systemic-risk threshold itself. The EU AI Act presumes systemic risk above 10^25 floating-point operations of training compute, a line drawn when training spend was still a fair stand-in for capability. That assumption is aging quickly. Alibaba’s new Qwen3.8-Max carries 2.4 trillion parameters but activates roughly 95 billion per query, and sparse architectures like it get more capability out of every unit of compute spent. A model trained below the line can plausibly outperform one trained above it. Whether Brussels revises the threshold or ends up defending it to a lawyer is one of the more consequential open questions of the coming year.

For companies building on these models, which in Europe means most companies doing anything serious with AI, exposure under the EU AI Act is indirect but real. Documentation duties and training-data summaries flow downstream. If a provider’s European availability is ever restricted, the disruption lands on the products built on top of it, not on the lab.

Tags: AI regulationAnthropicEU AI ActEuropean CommissionOpenAI
Share1Share6
Previous Post

Spider-Man: Brand New Day Made Back Its $225m Budget in Three Days

Next Post

Ad Black Sea Turns 10: ‘On the Edge — International Festival of Creative Resistance’

Related Stories

Helsinki Design Week 2026 opens with a theme built around strangers

Helsinki Design Week 2026 opens with a theme built around strangers

by David Keke
August 28, 2026
0

  Helsinki Design Week opens today, August 28, and runs through September 6 under a theme that sounds more like a philosophy seminar than a festival tagline: The...

GTA 6 crashed the Internet, before anyone’s even played it

GTA 6 crashed the Internet, before anyone’s even played it

by Qetia
August 28, 2026
0

Rockstar dropped 27 minutes of extended gameplay footage this week. The footage is the deepest look yet at Vice City and the new Leonida state, following protagonists Lucia...

Everyone Sued OpenAI. Why Has No One Sued Anthropic?

Everyone Sued OpenAI. Why Has No One Sued Anthropic?

by Qetia
August 27, 2026
0

Every major AI firm has either licensed publisher content or been dragged to court over it. Anthropic somehow avoided both, and media executives say it comes down to...

Someone built the house 25-year-olds can actually afford

Someone built the house 25-year-olds can actually afford

by David Keke
August 26, 2026
0

In Stockholm, the average 25-year-old can afford roughly 1.9 square metres of housing today. That's smaller than most parking spaces. To make that number impossible to shrug off,...

Next Post
Ad Black Sea Turns 10: ‘On the Edge — International Festival of Creative Resistance’

Ad Black Sea Turns 10: 'On the Edge — International Festival of Creative Resistance'

mrktr

Independent media for the new generation of marketers, creators, and thinkers.
MRKTR | born in London, inspired by the world.

Follow us

Recent Posts

McDonald’s Just Put Video-Game Food on Its Real Menu

McDonald’s Just Put Video-Game Food on Its Real Menu

August 27, 2026
Yayoi Kusama and the Endless Room

Yayoi Kusama and the Endless Room

August 27, 2026

Weekly Newsletter

  • Home
  • Advertise
  • Marketer.ge
  • Privacy Policy

© 2026 mrktrg

No Result
View All Result
  • Home
  • News
  • Brands
  • Talent
  • Culture
  • Tech

© 2026 mrktrg

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.