The European Union's AI Act enters its most consequential enforcement phase on August 2, giving Brussels real power — fines up to €35 million or seven percent of global revenue — to police how the world's largest AI providers label, disclose, and document their systems3. ANALYSIS The question is no longer whether the EU will regulate AI, but whether its enforcement apparatus can keep pace with an industry that has spent two years preparing — or not — for this moment.
Why it matters
This is the first time a major jurisdiction can penalize AI companies for failing transparency obligations at scale. Starting Sunday, chatbots must disclose their AI identity to users, deepfakes must carry labels and machine-readable markings, and providers of general-purpose AI models face documentation and copyright-compliance requirements1,2. The rules apply instantly to all AI systems in scope, regardless of when they were placed on the market. ◆ That retroactive reach means every chatbot already deployed in Europe — from customer-service portals to recruitment screeners — is now in the enforcement window.
The big picture
The AI Act, adopted in 2024, has been rolling out in stages. Sunday's phase activates Article 50's transparency mandate and hands the EU AI Office power to supervise providers of general-purpose AI models, particularly advanced systems that may present systemic risks. The AI Office will be staffed by dozens of tech experts, lawyers, and economists13. National authorities will enforce rules for smaller AI systems, while the AI Office, national regulators, and the European Data Protection Supervisor share responsibility for compliance oversight.
The enforcement toolkit is substantial. The EU can demand access to models, restrict a model's deployment within the bloc if concerns go unaddressed, and in some cases demand access before a model is placed on the market. "As enforcement begins, we are taking an important step towards AI that people and businesses can understand and trust, and whose benefits are shared widely across our society," said Henna Virkkunen, the EU chief for tech sovereignty.
The penalty structure is tiered. The stiffest fines — up to seven percent of a company's annual worldwide turnover or €35 million, whichever is higher — apply to the most serious violations. For other violations, companies could be fined up to three percent of global annual revenue or €15 million. Companies may also be fined for hindering or failing to cooperate with EU probes.
Between the lines
OpenAI has published a detailed compliance framework built around four pillars — safety, security, transparency, and provenance — that map directly to the Act's requirements for high-risk AI systems, including general-purpose models11,15. The company's framework represents ongoing work to support "responsible AI governance in Europe," according to its statement. ANALYSIS The timing of OpenAI's disclosure — ahead of Sunday's deadline — positions the company as a willing compliance partner, a posture that contrasts with the friction Brussels has encountered elsewhere. The EU struggled this year to get access to Anthropic's Mythos model, an episode that illustrates the tension between enforcement ambition and practical access to frontier systems.
More than 180 organizations have joined a voluntary code of practice aimed at supporting compliance with the transparency requirements. ◆ That voluntary uptake suggests significant industry engagement, but voluntary codes and binding enforcement are different instruments — Sunday is when the binding instrument activates.
The Act also bans specific AI practices outright: predictive policing, emotion recognition in workplaces or schools, and AI that manipulates human behavior. From December, there will be a ban on AI systems generating sexualized deepfakes. Existing AI systems have until December 2 to adapt to the new rules, and there are exemptions for artistic or satirical content.
ANALYSIS The phased timeline reveals a deliberate regulatory strategy: lock in transparency and disclosure obligations now, defer the more complex high-risk system requirements. Stand-alone high-risk AI systems face rules from December 2027, and AI tools embedded in other products from August 2028.
What's next
The AI Office can test the most advanced general-purpose AI models, such as chatbots, to ensure they comply with the law. The EU can also restrict a model's deployment within the bloc if it has concerns that the provider does not address, and can force companies to take action to remedy breaches. ◆ The distinction the Act draws between providers and deployers — a media company publishing AI-generated articles, a bank running a third-party chatbot — distributes compliance obligations across the value chain, meaning enforcement actions could target companies that did not build the AI but chose to deploy it. More rules under the AI Act will be enforceable later this year and beyond. Existing AI systems have until December 2 to adapt to the new rules. How Brussels wields its first enforcement actions — whether to set examples or negotiate quietly — will shape how seriously the global AI industry treats the Act's expanding obligations.