The EU AI Office can now investigate and enforce against model providers
From 2 August the European Commission, acting through its AI Office, holds formal investigation and enforcement powers over providers of general-purpose AI models. Chatbots must identify themselves, deepfakes must be labelled, and generated content must carry machine-readable marks. Penalties reach €15 million or 3% of worldwide turnover.
Obligations on GPAI providers came into force a year earlier, in August 2025. The enforcement powers were deliberately withheld for a twelve-month adjustment period that has now expired exactly on schedule — which, in a field where regulatory timelines slip routinely, is itself information about how this one is being run.
The power that separates this from ordinary disclosure regulation is access for evaluation. A regulator that can only read documents depends on the accuracy of those documents. A regulator that can obtain a model and test it can check a claim independently, and very few technology regimes anywhere hold that authority.
Watch the first investigation rather than the first compliance statement. Obligations describe what should happen; enforcement decides whether any of it is real, and nothing about the first year of GPAI duties tells you which way that will go.
European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August → · Help Net Security — EU begins enforcing AI Act, putting AI models under the microscope → · Wilson Sonsini — EU AI Act enforcement phase begins →