Logo
FrontierNews.ai

EU AI Act Enforcement Is Now Live: What Companies Need to Know Right Now

The EU AI Act's enforcement powers for general-purpose AI (GPAI) models are no longer theoretical; they are now actively enforced by the European Commission and AI Office as of August 2, 2026. This means companies developing, fine-tuning, or deploying broad-capability AI systems like large language models (LLMs) must immediately assess their compliance status or risk significant penalties, including fines up to 3% of total worldwide annual turnover or 15 million euros, whichever is higher.

What Exactly Is a General-Purpose AI Model Under EU Rules?

The EU AI Act distinguishes between AI systems (the finished products users interact with) and GPAI models (the underlying technology that powers multiple applications). A GPAI model is broadly capable, meaning it can competently perform a wide range of distinct tasks and be integrated into various downstream systems. Large language models like those powering chatbots and coding assistants are the primary example.

The Commission uses an indicative training-compute threshold of 10^23 FLOP (floating-point operations) to identify GPAI models. Models exceeding 10^25 FLOP are presumed to carry systemic risk and face additional obligations including state-of-the-art evaluations, adversarial testing, and serious-incident reporting to the AI Office.

Who Must Comply, and Does Location Matter?

The rules apply extraterritorially. Any entity that develops a GPAI model or has one developed and places it on the EU market under its own name or trademark must comply, regardless of whether the company is based in the EU or a third country. This includes distribution through physical channels, virtual platforms, application programming interfaces (APIs), and downloads in the course of commercial activity.

A company can also become a GPAI provider by significantly modifying a third-party model. If the additional training compute amounts to at least one-third of the original training compute, the modifying company assumes responsibility for the elements under its control.

Third-country providers must appoint an EU authorized representative in writing before placing a GPAI model on the Union market. This representative verifies technical documentation, retains copies for ten years, responds to AI Office requests, and must terminate the mandate and inform authorities if the provider breaches the rules.

What Are the Core Compliance Obligations?

GPAI providers face four main requirements under Article 53 of the EU AI Act:

  • Technical Documentation: Providers must prepare and maintain detailed technical documentation following the official template in Annex XI, covering model architecture, training data, and capabilities.
  • Information for Downstream Providers: Companies must supply information under Annex XII to any organization integrating the model into an AI system, enabling them to understand the model's capabilities and limitations.
  • Copyright Compliance Policy: Providers must establish a copyright compliance policy that includes mechanisms for opting out of copyright-protected content used in training, in line with the EU Digital Single Market Directive.
  • Training-Content Summary Publication: Providers must publish a summary of the training content using the official AI Office template, making information about training data publicly available.

Models released under a free and open-source license with publicly available parameters are exempt from the first two requirements, though this exemption does not apply to models with systemic risk.

What Enforcement Powers Do Regulators Now Have?

Since August 2, 2026, the Commission and AI Office possess dedicated enforcement mechanisms that include requesting documents and information, demanding access to APIs or source code for model evaluations, and requiring compliance with core obligations. The Commission can also require risk-mitigation measures where evaluations raise serious concerns about systemic risk at the Union level, and may restrict, withdraw, or recall a model from the market.

The AI Office may first open a structured dialogue with providers; commitments offered during this process can be made binding by formal decision. Any correspondence from the AI Office should be treated as a formal regulatory matter, not a routine business communication. Companies should activate a regulatory response protocol, involve EU counsel if past deadlines may have been missed, and communicate cooperatively with authorities.

How Should Companies Prepare for Compliance?

Automotive companies and other organizations using, integrating, fine-tuning, or developing broadly capable models should take immediate action. The practical message is clear: enforcement is now live, yet many companies remain unaware of their status or misjudge their obligations.

  • Assess Your Role: Determine whether your organization is a GPAI provider (developing or significantly modifying models), a downstream provider (integrating models into AI systems), or a supplier. This classification determines which obligations apply to you.
  • Review Documentation: If you are a provider, audit your technical documentation against Annex XI requirements and prepare information for downstream providers under Annex XII. Ensure your copyright compliance policy covers opt-out mechanisms.
  • Evaluate Supply-Chain Arrangements: For suppliers and downstream providers, the Article 53(1)(b) information duties become commercially critical. Ensure contractual documentation, warranties, and indemnities reflect your compliance responsibilities and clearly allocate obligations between parties.
  • Consider Market-Access Strategies: If you are uncertain whether your model is placed on the EU market, consider risk mitigation measures such as geoblocking and offering only non-EU-language versions pending further regulatory guidance on targeting factors.

Providers of GPAI models placed on the market before August 2, 2025, have until August 2, 2027, to achieve full compliance. However, since enforcement powers are now active, the Commission and AI Office can begin investigations and take action immediately.

The EU AI Act's enforcement regime represents a significant shift in how artificial intelligence is regulated globally. Unlike previous technology regulations that often lagged behind innovation, this framework applies enforcement powers to models already on the market, making immediate compliance assessment essential for any organization involved in developing, modifying, or deploying general-purpose AI systems in Europe.