The European Union crossed a threshold on August 2, 2026 that AI companies have been bracing for since the bloc’s landmark AI Act became law two years ago: Brussels can now formally investigate and penalize the makers of general-purpose AI models. The European Commission confirmed the European AI Office’s enforcement powers took effect that day, alongside a fresh set of transparency rules requiring AI systems to disclose when users are talking to a machine, according to the Commission’s own press release and reporting from Help Net Security.
What Changed on August 2
Before this month, the AI Act’s obligations for general-purpose AI, or GPAI, model providers existed on paper but lacked teeth. Now the AI Office can request internal documentation, demand access to models for direct evaluation, order corrective or risk-mitigation measures, and impose fines reaching the higher of €15 million or 3 percent of a company’s global annual turnover, per the Commission’s announcement carried on the EU’s digital-strategy site. The new transparency requirements are just as consequential for everyday users: chatbots must now identify themselves as automated systems, AI-generated deepfakes require a visible label, and machine-generated or edited content must carry machine-readable markers.
How We Got Here
The EU AI Act passed in 2024 as the world’s first comprehensive AI law, phasing in obligations over several years to give companies time to prepare. Wilson Sonsini’s legal analysis notes the Act deliberately built in a roughly two-year runway before enforcement began, precisely so providers of high-risk and general-purpose systems could get their compliance documentation in order. That runway is now over. The Act’s risk-tiered structure means the heaviest obligations fall on GPAI model providers, such as OpenAI, Google, Meta, and Anthropic, and on “high-risk” applications like credit scoring and hiring algorithms.
The First Enforcement Shots Are Already Being Fired
Regulators didn’t wait long to test their new authority. On August 4, France’s data protection authority, the CNIL, sent formal information requests to 14 financial institutions running credit-scoring algorithms, demanding the Article 11 technical documentation required for high-risk AI systems. According to reporting synthesized from the AI Journal and related coverage, three of those institutions asked for extensions, and CNIL denied all three, pointing out that companies have had the full two-year preparation window since the law passed. That swift, no-extensions response is being read across the industry as a signal that European regulators intend to enforce aggressively rather than phase in expectations gently.
Industry Split on Compliance Costs
Reaction from industry has been predictably divided. Compliance-minded firms point to the Commission’s release of a list of more than 180 organizations that have voluntarily signed the Code of Practice on transparency of AI-generated content, framing it as evidence the market is adapting constructively. Critics within the tech industry, however, argue the compliance burden disproportionately hits smaller AI startups that lack the legal and engineering staff of a Google or Microsoft, potentially entrenching the market position of the very giants the Act was partly designed to constrain. Some U.S. policymakers have separately criticized the Act as a de facto tax on American AI exports to Europe, while EU officials counter that predictable rules are what will let European businesses adopt AI with confidence.
What Comes Next
With enforcement powers now live, the next few months will reveal how aggressively the AI Office wields fines versus corrective orders. Financial services, given the CNIL’s opening move, looks likely to be an early enforcement battleground, and companies operating chatbots or generative content tools across the EU need to have disclosure labels in place now, not eventually. For global AI labs, the practical effect is that European compliance can no longer be treated as a future problem — model documentation, risk assessments, and content labeling built for the EU market will increasingly shape how products are designed everywhere, given how costly it is to maintain separate compliant and non-compliant versions of the same AI system. Legal advisers at firms like Wilson Sonsini are already fielding a surge of client questions about how the Article 11 documentation demands sent to French banks might extend to other high-risk sectors, including hiring software, insurance underwriting, and healthcare diagnostics tools, all of which fall under the same high-risk tier as credit scoring. Whether the AI Office reaches for its maximum fines quickly or opts first for corrective orders will likely shape how other regulators, including the UK’s data protection authority and various U.S. state regulators, calibrate their own emerging AI rules in the months ahead.