The day the rulebook gets teeth
For a year, the European Union's AI Act has been a law that mostly asked. On August 2, 2026, it starts to demand. That is the date, fixed in Article 113 of Regulation (EU) 2024/1689, when the bulk of the Act reaches general application and, more consequentially, when the European Commission's power to investigate and fine providers of general-purpose AI (GPAI) models switches on. The obligations themselves have technically bound frontier model makers since August 2, 2025. What was missing was the enforcer with a checkbook. On Sunday, that arrives.
"There is no stop the clock, there is no grace period, there is no pause," a Commission spokesperson said earlier this year, batting down a months-long lobbying campaign to freeze the timeline. Brussels has held that line into the summer.
What precisely becomes enforceable
The distinction between 2025 and 2026 matters, and it is widely muddled. Since August 2025, providers placing new GPAI models on the EU market have had to publish training-data summaries, maintain technical documentation, respect a copyright policy, and — for the handful of "systemic-risk" models trained above the 10^25 FLOP threshold — run model evaluations, assess and mitigate systemic risk, report serious incidents, and secure their models.
But the AI Office and the Commission could not yet wield their supervisory teeth. From August 2, 2026, they can. Under the Act, the Commission gains the power to request documentation and information, conduct its own model evaluations, demand corrective measures including risk mitigation, recall or market withdrawal, and impose fines. National competent authorities, which member states were required to designate, likewise move into active enforcement of the broader regime.
The penalty architecture is tiered. Prohibited AI practices carry the ceiling: up to €35 million or 7% of worldwide annual turnover, whichever is higher. Most other breaches top out at €15 million or 3%. GPAI-specific violations, governed by Article 101, are capped at €15 million or 3% of global turnover.
The Code of Practice and who signed
The compliance on-ramp is the voluntary General-Purpose AI Code of Practice, published July 10, 2025, and structured in three chapters: Transparency, Copyright, and Safety and Security. The first two apply to all GPAI providers; the third targets only systemic-risk models. Signing does not create legal immunity, but the Commission has said adherence reduces administrative burden and offers greater legal certainty than proving compliance by other means.
The signatory list tracks the industry's fault lines. Amazon, Anthropic, Google, IBM, Microsoft, and OpenAI signed all three chapters, joined by Europe's Mistral AI and Aleph Alpha. Elon Musk's xAI signed only the Safety and Security chapter. Meta, notably, declined to sign at all, as did major Chinese labs including Alibaba, Baidu, and DeepSeek — meaning the Commission's first enforcement year will play out against a field where some of the largest providers have opted for the harder, self-documented path.
Compliance burden and the transatlantic split
The divergence with Washington is now stark. The US has leaned toward light-touch, innovation-first federal signals, while the EU is switching on a binding, extraterritorial regime that reaches any model offered in the single market. For US labs, August 2 is less a European problem than a global-product-design problem: the training-summary and copyright disclosures are hard to geofence.
That burden fueled a fierce "stop the clock" push. Executives from ASML, Airbus, SAP, Siemens, Ericsson, Nokia, and even signatory Mistral warned Europe was regulating itself out of the AI race. Brussels refused a blanket freeze — but it did blink selectively. Through the Digital Omnibus, agreed in provisional form earlier in 2026, the EU deferred the heaviest high-risk obligations: stand-alone Annex III systems slip to December 2, 2027, and AI embedded in regulated products to August 2, 2028. GPAI oversight, transparency, and the August 2 enforcement machinery were pointedly left untouched.
What to watch next
Expect the AI Office to move cautiously but visibly. Early activity will likely center on information requests to non-signatories rather than headline fines, as the Office builds evidentiary records and evaluation capacity. That capacity is itself a live project: the Commission's July 7, 2026 Action Plan on Cybersecurity and Artificial Intelligence pledged to stand up an EU model-evaluation capability and a secure AI-testing platform with ENISA and the Joint Research Centre — the technical muscle enforcement will require.
The questions for the autumn: Will the Office name a first target? Does Meta's holdout provoke a documentation demand? And can Brussels enforce a systemic-risk regime it is still, in July 2026, building the tools to police? August 2 starts the clock. It does not answer them.
"There is no stop the clock, there is no grace period, there is no pause."— European Commission spokesperson, on rejecting calls to freeze the AI Act timeline