Picture a courtroom where the judge has spent a year watching the accused, taking careful notes, building the file, but was legally barred from issuing any verdict. That year ended on August 2, 2026. The EU AI Act entered its enforcement era on that date, and the European Commission's AI Office, together with national market surveillance authorities across EU member states, activated its full enforcement powers. The significance is not procedural theater. The difference is that the Commission could not issue fines during that first year; it can, retroactively, starting this month. For OpenAI, Google, Anthropic, Mistral, and every other provider whose models touch European users, the compliance dialogues they have been having are now backed by something real: a fine of up to 3 percent of their annual total worldwide turnover in the preceding financial year, or 15 million euros, whichever is higher.
To understand why no penalty has landed yet, you need to understand the architecture of the enforcement sequence. The act gives the AI Office three enforcement powers designed to escalate in sequence: the first is the power to request documentation and information under Article 91, which can require any GPAI model provider to hand over technical documentation, training data summaries, and model reports; providers that fail to respond, or that supply incomplete or misleading information, face fines under Article 101; this power is the foundation of the enforcement architecture. Step two is direct model evaluation under Article 92, and step three is compelled corrective action or market withdrawal. The AI Office's preferred opening move is what it calls "technical compliance dialogues," structured conversations with model providers and deployers to assess compliance status and clarify grey areas before formal proceedings begin. That is not weakness; it is exactly how the European Commission approached early Digital Services Act enforcement, using the threat of fines to extract cooperation before the first penalty notice ever went out. The choices it makes in its first months of enforcement will shape whether GPAI providers treat the Code of Practice as a serious compliance framework or a voluntary gesture, and whether the EU's AI governance model is taken seriously by regulators elsewhere.
The stakes are structural, and the Digital Omnibus made them sharper by contrast. The Digital Omnibus, signed into EU law as Regulation 2026/1744 on July 27, extended the conformity assessment deadline for high-risk AI to December 2, 2027, a significant concession to industry, particularly smaller AI vendors who argued the original August 2026 deadline was unworkable. The Digital Omnibus delayed high-risk deadlines but explicitly left the GPAI date and Article 50 transparency obligations untouched. That was a deliberate political choice, a message that the concession to industry on high-risk systems had a price: the frontier-model obligations would hold. The eight foundation models that exceed the 10^25 FLOPs compute threshold are already submitting monthly systemic risk evaluations, and those providers have been under GPAI obligations since August 2025. OpenAI, Anthropic, and Google have each submitted documentation to the AI Office, but the adequacy of those submissions is under active review, and the AI Office has indicated it expects ongoing cooperation and updated disclosures as models are modified.
The skeptics have a serious point, and it centers on one uncomfortable number. Brussels gained powers to demand frontier model access from August 2, days after a high-profile AI security incident, but the model evaluation unit has just 36 staff. The European AI Office currently employs more than 125 staff across all its functions, only a portion of whom work on general-purpose AI supervision; a Pour Demain recommendation cited in Lawfare calls for scaling that GPAI supervisory capacity to at least 160 staff by 2030, having judged the current level insufficient. Hiring has been slow, with the AI Office struggling to recruit for its safety unit, as rigid EU pay scales and slow bureaucracy make it hard to attract scarce frontier-AI talent. Significant uncertainty remains regarding the efficacy of this staffing level, as the AI Office must manage a vast and technically complex landscape of providers. There is also a precedent gap: the EU AI Office launched its first formal inquiry into GPAI model providers under Article 51 of the EU AI Act, probing whether frontier model providers are complying with transparency and documentation requirements; that marks the first enforcement action under the EU AI Act, with the outcome still ongoing and no penalties imposed yet.
None of that changes the basic legal reality for the labs. The AI Office can compel a provider to hand over technical documentation under Article 91, require risk-mitigation measures under Article 93, and demand model access to conduct evaluations under Article 92; refusing or stalling on any of those is itself a finable offense. The GPAI Code of Practice, signed by Amazon, Anthropic, Google, Mistral AI, OpenAI, and others, can demonstrate compliance and serves as a mitigating factor in enforcement actions, but it does not substitute for the statutory obligations. The organizations most exposed are not only the frontier laboratories, which have been engaged with the AI Office for a year, but the mid-market companies that fine-tune, rebrand, or build on GPAI models and have not yet asked whether they are, in law, providers. For a company the size of OpenAI, 3 percent of global turnover is an eye-watering sum; for a mid-sized European startup that quietly wrapped GPT-5 in its own brand name and forgot to publish a training-data summary, the math is even more alarming relative to their balance sheet. "As enforcement begins, we are taking an important step towards AI that people and businesses can understand and trust," said Henna Virkkunen, executive vice-president of the European Commission for tech sovereignty, security and democracy. The first Commission decision to actually impose a fine will be quoted in boardrooms from San Francisco to Seoul for years.
When the AI Office sends its first formal Article 91 documentation request and the recipient's lawyers begin calculating whether to cooperate or litigate, the era of purely voluntary AI governance, everywhere on Earth, will be measurably closer to over.