Europe has turned its AI rulebook into a watchdog, and the world’s biggest AI companies are about to find out what that means.
Last August 2, the European Union entered the active enforcement stage of its AI Act. This stage grants its AI Office the authority to investigate providers of General Purpose AI models, require technical documentation, order corrective measures, and impose penalties for violations.
That effectively shifts the previously existing law from a largely legislative framework into an active regulatory regime overseeing companies behind systems such as ChatGPT, Gemini, Claude, Llama, and other foundation models operating within the bloc.
The enforcement phase also introduces tougher transparency and safety expectations for advanced AI systems, particularly those considered capable of posing “systemic risks,” according to the European Commission’s statement.
What the EU can now enforce
The AI Act entered into force in August 2024, but its requirements have been introduced in stages. Obligations for providers of general-purpose AI models began applying in August 2025, while the Commission’s authority to enforce those requirements and impose fines took effect August 2, 2026.
The European AI Office can request information and access to qualifying models, conduct evaluations, and require providers to address compliance problems. It can also seek restrictions on a model’s public availability when necessary.
The most advanced general-purpose AI models face additional safety and security requirements intended to reduce systemic risks, including large-scale cyberattacks, harmful manipulation, loss-of-control scenarios, and chemical, biological, radiological, or nuclear threats.
Enforcement is shared across several authorities. The AI Office supervises general-purpose AI models and certain related systems, national authorities oversee other AI systems, and the European Data Protection Supervisor handles systems used by EU institutions.
What enforcement means for AI vendors and partners
For AI companies:
For AI developers, the era of relying primarily on voluntary safety commitments is narrowing.
Companies building AI models in the EU will increasingly need to treat regulatory compliance as part of the development process, alongside engineering and security.
The implications may stretch beyond dedicated AI firms. Many technology companies now embed third-party AI models within their products and services. As AI becomes a standard enterprise feature, businesses integrating these systems may also face greater pressure to understand how their services comply with these new requirements.
For governments:
The EU is once again positioning itself as an early mover in technology regulation, much as it did with the GDPR. Whether the AI Act proves effective — or overly burdensome — will likely influence how other governments design their own AI governance frameworks in the coming years.
Countries that have so far favored voluntary guidelines over binding regulation will be watching closely. If Europe’s approach succeeds in improving accountability without significantly slowing innovation, these countries may adopt the EU’s style. If it introduces compliance burdens without clear public benefits, it may reinforce arguments for lighter-touch oversight.
For EU residents:
For people living in the EU, the immediate effects may be less dramatic but more noticeable over time. Users are likely to encounter clearer disclosures when interacting with AI-generated content, including certain deepfakes and synthetic media.
More broadly, the enforcement framework provides residents with additional channels to report suspected violations and regulators with stronger powers to investigate companies whose AI systems may pose unacceptable risks.
A plausible third could be the withdrawal of some AI services from the bloc.
While these measures cannot eliminate all harmful uses of AI, they are intended to make companies more accountable for how advanced systems are developed and deployed in the European market.
Read more: UK businesses are accelerating AI adoption, but compliance and security risks continue to grow.





