The Clock Is Ticking for General-Purpose AI Providers

Seven weeks from now, on August 2, 2026, the EU AI Act's enforcement regime clicks into its next gear. The EU AI Office — the bloc's new regulator for frontier AI — will gain the legal authority to verify compliance, demand information, and issue corrective measures against providers of general-purpose AI (GPAI) models. For OpenAI, Google, Anthropic, Meta, and every other company whose models are placed on the EU market, the countdown is real.

The August 2 date is not the start of GPAI obligations. Those kicked in a year earlier, on August 2, 2025, when the AI Act's Title VIII rules on GPAI models became legally applicable. What changes this summer is enforcement: the AI Office goes from a body that has been watching and preparing to one with formal powers to act. Companies that have been slow-walking compliance will have nowhere left to hide.

What GPAI Providers Must Already Be Doing

Under Article 53 of the AI Act, all GPAI model providers — defined as companies releasing models capable of a wide range of tasks, including large language models — face a set of baseline transparency and copyright obligations.

The most visible of these is the requirement to publish a structured public summary of training data using a template issued by the EU AI Office on July 24, 2025. The template is not a check-the-box form. It requires providers to disclose the types of content used to train their models, data sources, and collection methods. The level of required detail varies depending on the source: publicly available datasets require more granular disclosure than licensed or proprietary data. Crucially, providers must update these summaries at least every six months, or whenever material changes — such as additional training runs or fine-tuning — occur to the training data.

Copyright compliance is equally central. Providers must implement a policy for respecting rightsholders' opt-outs under the EU's text and data mining (TDM) exception framework. They must also take "proportionate safeguards" to mitigate the risk of infringing outputs, designate a point of contact for rightsholders, and establish a functioning complaints mechanism. As David Botero, a Westin Fellow at the IAPP, has noted, the AI Act's transparency requirements for training data are explicitly designed "to empower rightsholders to exercise their rights" — linking the GPAI chapter firmly to EU copyright law.

The Penalty Structure

Non-compliance with GPAI obligations is expensive. Article 99 of the AI Act establishes a tiered fine structure tied to the severity of the violation:

- Prohibited AI practices: up to €35 million or 7% of global annual turnover, whichever is higher. - GPAI violations and other Article 53/55 breaches: up to €15 million or 3% of global annual turnover, whichever is higher. - Providing incorrect or misleading information to regulators: up to €7.5 million or 1% of global annual turnover, whichever is higher.

For SMEs and startups, fines are capped at whichever figure is lower — a deliberate carve-out to avoid crushing smaller players. For hyperscalers, however, 3% of global turnover is a number that concentrates minds: for a company with $100 billion in annual revenue, that ceiling approaches $3 billion.

The GPAI Code of Practice: Voluntary, but Consequential

In parallel with the legally binding rules, the EU developed a voluntary GPAI Code of Practice — finalized on July 10, 2025 after a multistakeholder process involving nearly 1,000 participants. Signing it grants providers a presumption of conformity with their obligations under Articles 53–55, substantially reducing regulatory scrutiny and administrative burden.

The signatory list is substantial. Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, OpenAI, Cohere, and Aleph Alpha have all signed or committed to signing. Elon Musk's xAI signed only the safety and security sections. The notable holdout is Meta.

In July 2025, Meta's chief global affairs officer Joel Kaplan declared the company would not sign, arguing the Code "introduces a number of legal uncertainties for model developers, as well as measures which go far beyond the scope of the AI Act." Meta warned the obligations would stifle innovation and give European regulators excessive reach into model development decisions.

The stance is not without consequences. Non-signatories must still comply with the underlying legal requirements — they simply cannot rely on the Code's safe harbor. They will also face closer scrutiny from the AI Office when enforcement begins in earnest, since the Office will have no pre-certified compliance framework to reference.

What the August 2 Date Actually Changes

To be precise: August 2, 2026 does not introduce new substantive obligations on GPAI providers. What it activates is the AI Office's enforcement toolkit — the ability to initiate investigations, request documents, conduct audits, and impose fines. Think of it as the difference between a law existing on the books and a regulator having the authority and mandate to prosecute violations.

There is one important caveat. The EU's Digital Omnibus package, currently in trilogue, proposes extending the compliance deadline for high-risk AI system obligations from August 2, 2026 to December 2, 2027. However, that delay applies to Annex III high-risk systems, not to GPAI-specific rules under Title VIII. Unless the Omnibus explicitly carves out GPAI enforcement — which current drafts do not appear to do — August 2, 2026 remains the operative date for GPAI providers.

Providers of models placed on the EU market before August 2, 2025 (the original application date) have a grace period: they must comply with training data summary requirements by August 2, 2027. But any model that entered the EU market on or after August 2, 2025 must already be compliant — and will be subject to AI Office oversight as of next month.

What to Watch

The next eight weeks will be telling. Watch for:

- First enforcement signals from the EU AI Office. The Office is likely to send information requests to major non-compliant or non-signatory providers shortly after August 2 to establish its authority. - Meta's next move. Having declined the Code, the company must still comply with Articles 53–55. How it demonstrates that compliance — and whether the AI Office accepts it — will set an important precedent for non-signatory providers. - Training data summary quality. The published summaries from major providers will draw immediate scrutiny from rightsholders, journalists, and regulators. Vague or incomplete filings will invite complaints and potentially formal action. - Digital Omnibus trilogue outcomes. If negotiators broaden the delay provisions to cover GPAI enforcement, the August 2 milestone could shift — but that outcome remains uncertain as of mid-June 2026.

For a regime that has been building for three years, August 2 is less a starting gun than the moment the starter's pistol finally loads.

"This Code introduces a number of legal uncertainties for model developers, as well as measures which go far beyond the scope of the AI Act."
- Joel Kaplan, Chief Global Affairs Officer, Meta
Aug 2, 2026
EU AI Office gains GPAI enforcement power
15M / 3%
Max GPAI fine (euro or global turnover)
35M / 7%
Max fine for prohibited practices