The one-year grace period is over
When the EU AI Act's rules for general-purpose AI (GPAI) models took effect on August 2, 2025, there was a catch: Brussels could set the rules, but it could not enforce them. The European Commission's own timeline deliberately held back its supervision powers for twelve months, giving model providers and the newly formed AI Office time to prepare.
That grace period ends on August 2, 2026. From that day, the AI Office can demand documentation proving a model meets its transparency and copyright obligations under Chapter V of the AI Act, run its own technical evaluations — with outside experts if it chooses — and order providers to fix compliance gaps, mitigate systemic risks, or pull a model from the EU market entirely. None of this requires a court case first.
If you are a European business that uses ChatGPT, Claude, Gemini, Mistral, or any other foundation model in your products, this is not a distant regulatory abstraction. It is a supply-chain risk that lands in ten days, and the question is simple: what happens to your product if your model provider gets a letter from Brussels?
What the AI Office can actually do
The enforcement toolkit is broader than most people realise. Under Article 91, the AI Office can request the technical documentation providers were already supposed to have prepared — and supplying "incorrect, incomplete or misleading information" is itself a finable offence. Under Article 92, it can demand access to a model for its own evaluation. Under Article 93, it can order corrective measures, risk mitigation, or — at the far end — a full market withdrawal.
And then there is the complaints channel. Under Article 85, any person or organisation — a competitor, a rights holder, a civil-society group — can lodge a complaint about a specific model. Copyright disputes around training data are widely expected to be the first wave, given publishing and media industries' long-running objections to how training corpora were assembled. A single credible complaint can put a model in front of regulators.
The fine print: four ways to get fined
Article 101 gives the Commission four separate legal routes to a penalty, and they stack. A provider can be fined for breaking the substantive GPAI rules. It can be fined for ignoring a documentation request. It can be fined for refusing access for an evaluation. And it can be fined for failing to carry out an ordered fix.
The ceiling for each is the same: 3% of total worldwide annual turnover for the preceding year, or €15 million, whichever is higher. For context, on a company earning €10 billion a year, the arithmetic tops out at €300 million per violation — and the four routes are independent. As the law firm Latham & Watkins notes, a provider that ignores a documentation request about a non-compliant model has opened two doors, not one.
No GPAI fine has ever been calculated, so the gap between the ceiling and actual penalties is guesswork. But the structure is clear: non-cooperation can be as expensive as non-compliance.
Which models are already in the net
The timeline creates two populations of models, and the difference matters. Any GPAI model placed on the EU market on or after August 2, 2025 has been subject to full obligations from day one — no grace period, no excuses. That covers essentially every frontier release of the past year: the current generation of flagship language models from OpenAI, Google, Anthropic, Meta, and Mistral, plus fine-tuned enterprise variants and newly launched open-weight models. When enforcement powers arrive, these models are immediately auditable.
Models that were already on the market before August 2, 2025 get a longer runway: their providers must reach compliance by August 2, 2027. That split gives the AI Office a clean early docket of post-2025 models to examine first.
There is a quiet risk here for product teams. A version upgrade that swaps an early-2025 model for its late-2025 successor silently moves the application from the protected population to the enforceable one — no contract change, no announcement, just a shift in regulatory exposure.
Two more tripwires sit alongside the calendar. A model whose training run exceeded 1025 FLOP (floating-point operations) is presumed to carry systemic risk, which triggers heavier assessment and mitigation duties. The provider must notify the Commission within two weeks of crossing the threshold. And providers based outside the EU — including every major US and Chinese AI lab — must appoint an authorised representative inside the Union before placing a model on the market, unless the model is genuinely free and open-source. That representative is the address where enforcement letters land.
The Code of Practice: a cushion, not a shield
The GPAI Code of Practice, finalised in July 2025, is the voluntary compliance framework that many providers have signed. It covers three chapters: transparency, copyright, and safety and security for models with systemic risk. Signing it matters — the AI Office has said it will weigh Code commitments when calculating fines and treat signatories as acting in good faith through the transition.
But the same AI Office has been blunt about the limit of that shelter: it intends to fully enforce the GPAI requirements from August 2, 2026, signatures or not. And providers can sign some chapters and skip others — so "we signed the Code" is a claim worth reading closely rather than taking at face value. The Commission's guidance says that for signatories whose commitments it deems adequate, enforcement will focus on monitoring adherence to what they already agreed to produce. For non-signatories, the full statutory checklist applies without an agreed template.
What European businesses should check before August 2
If your company builds on top of AI models rather than training them, the enforcement switch changes procurement questions more than engineering ones. Here are five practical checks:
1. Which chapters did your provider actually sign? The chapter-by-chapter option means transparency commitments and safety commitments travel separately. A provider that signed the copyright chapter but not the safety chapter is making a specific choice you should understand.
2. When was each model in your stack placed on the EU market? A model from early 2025 lives under the 2027 runway; its successor from late 2025 is enforceable from August 2. Map your model versions to the timeline.
3. Ask for the compliance artefacts. The training-content summary is a published legal obligation. Documentation prepared for Article 53 exists to be shown to regulators — and to you. A provider that cannot produce these for its own regulator will not produce them for a customer audit either.
4. Re-read your indemnification and regulatory-change clauses. If a model is restricted or withdrawn from the EU market under Article 93, downstream products inherit the disruption overnight. Do your contracts account for this?
5. Price in substitution. If your architecture can swap the underlying model with reasonable effort, that flexibility now carries a clear regulatory advantage. The question to ask your engineering team: if this model left the EU market in thirty days, what breaks, and for how long?
What this means in practice for European users
For the average European citizen, the AI Act enforcement deadline is not something you will feel on August 3. No chatbot will go dark overnight. But the direction of travel matters. The AI Office now has the tools to demand transparency from the companies that build the models underpinning everything from customer-service chatbots to medical diagnostic tools. If a model provider cannot document what training data it used, how it tested for bias, or what safety measures it built in, there is now a regulator that can ask — with consequences attached.
For businesses, the practical message is: your AI supply chain is no longer a pure engineering decision. It is a regulatory one too. The model you chose last year may have a different compliance status than the one you are planning to upgrade to next month. And the contract you signed with your provider may not say what you need it to say about what happens when Brussels comes asking.
Ten days. That is how long European businesses have to check whether their AI stack is ready for a regulator that is finally ready to regulate.
Does the AI Act ban any AI models outright?
No. The GPAI rules do not ban models. They require transparency, copyright compliance, and — for the most powerful models — systemic risk management. Bans apply only to specific prohibited practices (such as social scoring or untargeted facial recognition scraping), which took effect in February 2025. What starts on August 2, 2026 is enforcement of the obligations that models already have, not new prohibitions.
What if my provider is based outside the EU?
The AI Act applies to any GPAI model placed on the EU market, regardless of where the provider is headquartered. Non-EU providers must appoint an authorised representative inside the Union. If a US or Chinese lab places its model on the European market — directly or through integration into an AI system sold in the EU — it is within the AI Office's reach.
Will this affect the price of AI services in Europe?
Potentially, but indirectly. Compliance costs — documentation, evaluation, authorised representatives, legal fees — add to the cost of serving the European market. Whether providers absorb those costs or pass them on through API pricing or subscription fees remains to be seen. What is certain is that the regulatory bar for operating in Europe has risen, and that will be reflected in business decisions about which markets to prioritise.