
- The switchGPAI obligations have applied since August 2, 2025. What starts on August 2, 2026 is the European Commission's power to enforce them.
- The stickFines reach 3% of global annual turnover or €15 million, whichever is higher, with four separate legal routes to a penalty.
- Already insideEvery general-purpose model placed on the EU market since August 2, 2025 is liable now. Older models have until August 2, 2027.
- Limited shelterSigning the GPAI Code of Practice softens fine calculations and buys good-faith treatment. It does not block enforcement.
In ten days, the European Commission stops asking nicely. On August 2, 2026, its AI Office gains the power to audit general-purpose AI models, order corrections, restrict their availability in Europe, and fine the companies behind them. The obligations themselves are not new. The consequences are.
That one-sentence distinction is doing a lot of work, and most of the coverage misses it. Providers of general-purpose AI (GPAI) models have been legally bound since August 2, 2025 to publish training-content summaries, respect copyright, document their systems, and manage systemic risk. For twelve months, though, nobody in Brussels could compel any of it. The European Commission's own timeline held supervision back a full year so providers and the AI Office could build the machinery. That grace period ends in August.
What actually switches on
Chapter V of the AI Act reads like a dormant toolkit that is about to be plugged in. From August 2, the AI Office can demand documentation proving a model complies with its transparency and copyright duties under Articles 53 and 55. It can run its own technical evaluations of a model, with outside experts if it chooses. It can order a provider to fix a compliance gap, mitigate a systemic risk, or — at the far end — pull a model off the EU market entirely.
None of this requires a court case to begin. The enforcement structure of Chapter V hands these levers directly to the Commission, and it layers on inputs from outside: any person or organization can lodge a complaint under Article 85, and the Act's Scientific Panel can issue qualified alerts when it sees a concrete risk in a specific model.
For a sense of how the same law treats AI agents that talk to people, TECHi's earlier reporting on the EU's agent disclosure requirements covers the transparency side of the same August 2 deadline. This piece is about the other half: what happens to the companies that build the models underneath.
Four ways a provider gets fined
Article 101 gives the Commission four distinct routes to a penalty, and each stands on its own. A provider can be fined for breaking the substantive GPAI rules. It can be fined for ignoring a documentation request. It can be fined for refusing to grant model access for an evaluation. And it can be fined for failing to carry out an ordered corrective measure.
The ceiling is the same for each: 3% of total worldwide annual turnover for the prior year, or €15 million, whichever is higher. For a large model provider, the turnover figure is the one that matters, because the percentage attaches to the whole company's revenue, not the revenue of the model in question. On a business earning $10 billion a year, the arithmetic tops out at $300 million per violation — and the four routes are independent, so a provider that ignores a documentation request about a non-compliant model has opened two doors, not one.
There is one recognized softener. Companies that signed the GPAI Code of Practice — the voluntary compliance framework finalized in July 2025 — get their commitments weighed when a fine is calculated, and Latham & Watkins' analysis of the Code notes the AI Office said it would treat signatories as acting in good faith through the transition. The same analysis is blunt about the limit of that shelter: the Office intends to fully enforce the GPAI requirements from August 2, 2026, signatures or not. Providers can also sign some chapters of the Code and skip others, which makes "we signed the Code" a claim worth reading closely rather than taking at face value.
Which models are already inside the net
The timeline creates two very different populations of models, and the difference is worth money.
Any GPAI model placed on the EU market on or after August 2, 2025 has been subject to the full obligations from day one, with no grace period. That covers essentially every frontier release of the past year — the current generation of flagship language models, their fine-tuned enterprise variants, and newly launched open-weight models alike. When enforcement powers arrive in August, these models are immediately auditable.
Models that were already on the market before August 2, 2025 get a longer runway: their providers must reach compliance by August 2, 2027. That split means a provider's exposure depends partly on release timing — and it gives the AI Office a clean early docket of post-2025 models to examine first. It also creates a quieter risk inside product teams: a version upgrade that swaps an early-2025 model for its late-2025 successor silently moves the application from the protected population to the enforceable one, with no contract change and no announcement.
Two more tripwires sit alongside the calendar. A model whose training run exceeded 10^25 floating-point operations is presumed to carry systemic risk, which activates the Act's heavier assessment and mitigation duties, and a provider whose model crosses the threshold must notify the Commission within two weeks. And providers based outside the EU must appoint an authorized representative inside it before placing a model on the market, unless the model is genuinely free and open-source. For US and Chinese labs, that representative is the address where enforcement letters land.
How the first months are likely to play out
What the AI Office will do with its new powers is the open question, but its own guidance sketches the shape. The Commission has said that for Code signatories whose commitments it deems adequate, enforcement will focus on monitoring adherence to the Code. Read plainly: signatories get supervised through paperwork they already agreed to produce, while non-signatories face the full statutory checklist without an agreed template.
From there, the economics of enforcement point in one direction. Documentation requests under Article 91 cost the Office almost nothing to send and create immediate legal jeopardy for providers that respond poorly — non-response is itself a finable offense. Full technical evaluations require expert capacity the Office is still building. Market withdrawal is the tool of last resort against a major provider, with obvious diplomatic weight. The cheap, scalable move is the letter asking a provider to prove what it has claimed. That is analysis, not an announcement; the Office has not published an enforcement priority list, and its first-year posture may prove more or less aggressive than its guidance implies.
The complaints channel adds unpredictability. Article 85 lets rights holders, competitors, and civil-society groups put specific models in front of regulators — and copyright disputes around training data are the most obvious first wave, given the publishing and media industries' long-running objections to how training corpora were assembled.
What builders and buyers should check before August 2
For companies that build on top of these models rather than train them, the enforcement switch changes procurement questions more than engineering ones. Five checks are worth running now.
Verify which chapters of the Code of Practice a model provider actually signed, not just whether it signed. The chapter-by-chapter option means transparency commitments and safety commitments travel separately.
Establish when each model in production was placed on the EU market. A model from early 2025 lives under the 2027 runway; its successor from late 2025 is enforceable now.
Ask providers for the compliance artifacts the law already requires — the training-content summary is a published obligation, and documentation prepared for Article 53 exists to be shown. A provider that cannot produce these for its own regulator will not produce them for a customer audit either. Teams that already keep structured release records for AI changes will recognize the pattern: the record either exists before the request arrives, or it does not exist at all.
Re-read indemnification and regulatory-change clauses in model contracts. If a model is restricted or withdrawn from the EU market under Article 93, downstream products inherit the disruption overnight.
Finally, price in substitution. Agent stacks with runtime control hooks can swap an underlying model with less rework than hard-wired integrations, and that difference now has a regulatory price attached. The question to ask an architecture review is simple: if this model left the EU market in thirty days, what breaks, and for how long?
What stays unsettled
The honest caveat is that nobody has seen this machine run. No GPAI fine has ever been calculated, so the gap between the 3% ceiling and actual penalties is guesswork. The EU's broader digital-omnibus process has reshuffled other AI Act deadlines — high-risk system rules now land in phases through December 2027 and August 2028 — while leaving the GPAI enforcement date untouched, a combination that has bred a steady supply of confident but wrong compliance advice. And the Commission's guidelines, including the good-faith assurances the industry is leaning on, are not binding law; the Court of Justice will have the final word on what Chapter V actually requires.
What is not in doubt is the direction. A year of voluntary preparation ends on August 2. After that, the question shifts from whether a model provider chose to comply to whether it can prove it did — on demand, to a regulator holding a percentage of global revenue in its other hand.
FAQ
Frequently asked questions
When does EU AI Act enforcement start for GPAI models?
The European Commission's enforcement powers over general-purpose AI model providers apply from August 2, 2026. The underlying GPAI obligations have applied since August 2, 2025; what changes in 2026 is the ability to compel compliance and impose fines.
What powers does the EU AI Office gain on August 2, 2026?
Under Chapter V of the AI Act, the AI Office can request compliance documentation, conduct technical evaluations of models, order corrective and risk-mitigation measures, restrict or withdraw a model from the EU market, and impose fines.
How large are GPAI fines under the EU AI Act?
Up to 3% of a provider's total worldwide annual turnover for the preceding year or €15 million, whichever is higher, under Article 101. Non-compliance with documentation requests, evaluations, or ordered measures are each independent grounds for a fine.
Are models released before August 2025 exempt?
Not exempt, but on a longer runway: providers of GPAI models placed on the EU market before August 2, 2025 must be compliant by August 2, 2027. Models placed on the market on or after August 2, 2025 are subject to the obligations with no grace period.
Does signing the GPAI Code of Practice protect a company from fines?
No. The AI Office weighs Code commitments when calculating fines and has said it will treat signatories as acting in good faith, but it has also said it will fully enforce GPAI requirements from August 2, 2026. Companies can also sign only some chapters of the Code.
About the Author
Saba Javed handles TECHi's daily market coverage: the movers, the earnings beats and misses, and the pre-market headlines that set the tone for the session. She writes to a tight window, working from SEC 8-K filings, company press releases, and exchange status feeds rather than second-hand recaps. Her goal is clarity within the first 20 minutes of a story breaking, without the summary-of-summary recycling that dominates breaking-news coverage.


