Three weeks ago, on 2 August, the European Commission's AI Office acquired the legal power to compel the world's largest AI labs to hand over training documentation, grant its experts access to frontier models, and — if it finds an intentional or negligent breach — fine them up to €15 million or 3% of worldwide annual turnover, whichever is higher. For Alphabet, 3% would clear €9 billion.

As of this writing, it has issued no fines, opened no formal proceedings, and named no company. That is not a scandal. It is the story.

What actually switched on

The obligations themselves are not new. Providers of general-purpose AI models have been bound by Articles 53 and 55 — technical documentation, downstream transparency, a copyright policy, a public summary of training content, plus safety and security duties for models with systemic risk — since 2 August 2025. What they got was a one-year grace period in which the AI Office could ask nicely but could not compel. It ended on 2 August 2026.

Three powers came alive at once. Article 91 lets the AI Office issue requests for information, informally or by Commission decision; incomplete or misleading answers are themselves finable. Article 92 lets it run model evaluations and demand access. Article 93 lets it require corrective measures and, in extremis, restrict a model's availability in the EU, withdraw it, or recall it — or accept binding commitments that close an investigation without an infringement finding, a mechanism lifted from EU competition practice.

The same date brought Article 50's transparency rules into application, with Commission guidelines adopted on 20 July. Chatbots must tell users they are not human. Generative systems must embed machine-readable markings and offer a detection mechanism. Deployers must disclose deepfakes and AI-generated text on public-interest matters, unless a named human took editorial responsibility. Content published before 2 August needs no retroactive labelling, and systems already on the market have until 2 December 2026 to meet the marking requirement. Breaches carry the same €15 million / 3% ceiling; prohibited practices top out at €35 million or 7%.

Enforcement is split three ways. The AI Office covers GPAI providers, systems built by the same provider or corporate group as the underlying model, and systems inside DSA-designated very large platforms. National authorities cover everything else; the European Data Protection Supervisor covers EU institutions.

The Commission's own asterisk

The 31 July press release is unusually candid about the weak link. "Effective enforcement will also depend on Member States ensuring that national competent authorities are properly designated and adequately resourced," it reads — a line that only appears in Commission text when someone has been counting.

They have reason to. Article 70 required every member state to designate a market surveillance authority, a notifying authority and a single point of contact by 2 August 2025. Only eight of 27 met that deadline, and as of March 2026 the Commission's list of notified contact points still stood at eight. France (DGCCRF), Germany (Bundesnetzagentur), Spain (AESIA) and Ireland are the functioning exceptions. The Act is a directly applicable regulation, so companies are bound regardless — but the map of who enforces what, where, remains mostly blank.

Executive Vice-President Henna Virkkunen framed the moment differently: "With the AI Act, we established a clear, risk-based and durable framework for trustworthy AI — one that gives innovators legal certainty while protecting the public interest."

Powers on paper, headcount in question

The unit inside the AI Office that evaluates frontier models employs 36 people. The office added 38 staff on 31 July, bringing the total to roughly 165, named Oxford's Alessandro Abate as Lead Scientific Adviser, and stood up a 60-member Scientific Panel that has met once. The NGO Pour Demain argues the GPAI supervisory function alone needs at least 160 staff by 2030 — roughly the entire current AI Office, on one workstream.

Five MEPs from across the political groups — Brando Benifei, Sergey Lagodinsky, Kim van Sparrentak, Axel Voss and Kristian Vigenin — wrote to the Commission on 18 May warning that "the resourcing trajectory of the AI Office does not appear aligned with the scale and complexity of its foreseen tasks."

Capacity is not the only constraint. The AI Office and its external evaluators have reportedly struggled to get access to some frontier models, including Anthropic's Mythos. And the political weather runs the other way: Regulation (EU) 2026/1744 — the AI Omnibus — entered into force on 27 July, pushing Annex III high-risk obligations to 2 December 2027 and product-embedded rules to 2 August 2028. EDRi, Access Now, ECNL and Amnesty International called it "a vehicle for deregulation" and urged Parliament to reject it; it passed anyway. Washington's posture and US industry lobbying have made "simplification" the safer word in Brussels.

The Code of Practice landscape shows where the leverage sits. Amazon, Anthropic, Google, Microsoft, Mistral and OpenAI signed the GPAI Code; Meta declined outright, citing "legal uncertainties"; xAI signed only the Safety and Security chapter. Separately, more than 180 organisations have signed the Code of Practice on Transparency of AI-Generated Content. Signatories get a lighter enforcement posture; non-signatories are told to expect more information requests. That asymmetry is only real if someone sends them.

What to watch

The Digital Services Act is the template: the Commission opened formal proceedings against X within months of the VLOP obligations applying, issued no fines in year one, and still changed behaviour. The tell here is whether the AI Office moves beyond what it calls technical compliance dialogues and issues its first Article 91 request by decision — to a Code signatory as routine supervision, or to Meta as a pointed exception. Watch, too, the 2 December 2026 double deadline: the marking transition expires and the new prohibitions on AI-generated non-consensual intimate imagery and CSAM begin to apply, both landing on an office that will still be hiring.

"Companies should be taking preventive action, not merely corrective action after harm has occurred," says Risto Uuk, head of European policy and research at the Future of Life Institute. The same is now true of the regulator. Three weeks in, the tools are unpacked. Nobody has picked one up.

“the resourcing trajectory of the AI Office does not appear aligned with the scale and complexity of its foreseen tasks”
— Benifei, Lagodinsky, van Sparrentak, Voss and Vigenin, Members of the European Parliament, letter to the Commission
€15M or 3%
Maximum GPAI penalty
36
Staff in the evaluation unit
8 of 27
States with notified contact points
2 Dec 2027
New high-risk obligations deadline