// blog · analysis · policy2026-08-06source: European Commission and legal analysis

The regulator can now ask for the model

Not documents about the model. The model. That is a categorically different oversight power from anything else operating in this field, and it went live on 2 August.

From 2 August the EU AI Office may obtain access to models for evaluation, require corrective measures, and fine providers up to €15 million or 3% of worldwide turnover. The obligations landed a year earlier; the enforcement powers were deliberately held back for an adjustment period that has now ended.

Why access for evaluation is the whole story

A regulator that can only read documents is dependent on the accuracy of those documents. Every claim it assesses is a claim the provider chose to make, in language the provider chose. That is disclosure regulation, and it works about as well as the incentives of the disclosing party allow.

A regulator that can obtain the model and test it can check a claim independently. That is a categorically different capability, it is rare anywhere in technology regulation, and it is the reason this milestone matters more than the fine schedule attached to it.

The deadline was honoured, which is itself information

GPAI obligations came into force August 2025. Enforcement powers activated August 2026, exactly as scheduled. Regulatory timelines in this field slip often enough that arriving on time is a signal about how seriously the regime is being run.

The contrast is now unavoidable

In the same week, the US convened a voluntary meeting with three labs after their incidents became public, on top of a federal frontier-model framework that was finalised and then withheld from publication.

One regime publishes its rules and takes the power to inspect. The other holds meetings and keeps the criteria private. Both are described as AI governance and they are not the same activity.

The one genuinely interesting American move

Filing frontier model capability under cybersecurity rather than content policy is a small drafting decision with large consequences. It routes the question to agencies that already run vulnerability disclosure, incident reporting and classified assessment — machinery that exists and works, rather than machinery that would have to be built.

It also fits the evidence. The recent incidents were models reaching production infrastructure through weak credentials, not misuse of a chat box. That is a cyber incident by any ordinary definition.

The cost is that cyber regimes default to non-disclosure for defensible reasons, and a governance framework inheriting those norms gets harder to observe from outside. Which is precisely the tension already visible in a framework that was completed and then classified.

European Commission — The enforcement framework of the AI Act → · Wilson Sonsini — EU AI Act enforcement phase begins → · Wiley — New AI executive order addresses frontier models and cybersecurity vulnerabilities →