The EU AI Act moved from obligation to enforcement on August 2, 2026. The rules for general-purpose AI models had applied since August 2025, with a one-year adjustment period; that period is over.
What the Commission can now do
The Commission and its AI Office can request documentation, run technical evaluations of models, demand compliance and risk-mitigation measures, and restrict or withdraw a model from the EU market.
Fines reach 3% of global annual turnover or EUR 15 million, whichever is higher. Refusing or stalling on a request is itself a finable offence — so non-cooperation is not a strategy.
What providers must have
General-purpose model providers need technical documentation, a copyright policy, and a public summary of the content used for training. Models judged to carry systemic risk carry additional safety and security duties.
The training-data summary is the provision with teeth for the content industry: it exists specifically so rights holders can see whether their work was used and act on it. Obligations apply to models offered in the EU regardless of where training happened.
Labelling
Article 50 requires AI-generated content to be labelled and machine-readable. That is the regulatory context for the provenance work vendors have been shipping — Anthropic published its text watermarking approach in August, and image credentials have been spreading for longer. Those are not only goodwill gestures.
Why it matters
For most teams building on these models, nothing changes directly — the obligations sit with providers, not with everyone who calls an API. What changes is the risk that a model you depend on becomes unavailable in the EU, or that its terms shift to satisfy a regulator.
Providers of models released before August 2, 2025 have until August 2, 2027 to comply, so the older end of the market has another year. The practical takeaway is the same as for pricing: avoid architectures that assume one specific model will always be there.