The European Commission stops asking nicely on August 2, 2026. Its AI Office gains the power to audit, fine, and restrict general-purpose AI models in the EU market on that date. The obligations themselves have existed since August 2025. What changes is the enforcement. The AI Office can demand documentation, run technical evaluations, order model corrections, and levy fines up to 3% of global annual turnover or EUR 15 million, whichever is higher.
This is not a hypothetical. The EU called this date two years ago. It is arriving in 10 days. Every AI founder serving European users needs to understand what actually changes and where their exposure sits.
What Actually Changes on August 2
The key distinction most coverage misses: GPAI obligations have been in force since August 2, 2025. What starts now is the ability to enforce them. For the past 12 months, the rules existed on paper. From August 2, the AI Office can act on them without a court case.
Here is what the AI Office can do starting August 2:
- Demand documentation proving compliance with transparency and copyright duties under Articles 53 and 55 of the AI Act. This includes training content summaries, copyright policies, and systemic risk management documentation.
- Run independent technical evaluations of models, either internally or with external experts. The provider must grant model access for these evaluations or face penalties.
- Issue qualified alerts through the Act's Scientific Panel when a model presents systemic risk. Any person or organization can also lodge a complaint under Article 85, effectively crowd-sourcing enforcement triggers.
- Restrict or remove models from the EU market if they refuse to comply with orders. The AI Office can limit availability, demand corrective actions, or suspend model access entirely.
The fine structure has four independent routes to a penalty. A provider can be fined for violating the substantive GPAI rules, ignoring a documentation request, refusing to grant model access for evaluation, or failing to provide adequate information on model capabilities and limitations. Each route carries the same ceiling: 3% of total worldwide annual turnover or EUR 15 million.
Who Is Most at Risk
Not every AI company faces the same exposure. The AI Act's enforcement targets providers of general-purpose AI models broadly, but the real risk concentrates in specific profiles.
The highest-risk group: companies training and deploying frontier GPAI models in the EU. These are the obvious targets. If you trained a model with significant compute and distribute it in Europe, the AI Office will want to see your documentation. A provider that has not prepared training content summaries, copyright documentation, or systemic risk assessments over the past year is exposed to both fines and market restrictions starting day one.
Medium-risk: companies fine-tuning or adapting GPAI models for commercial use. The rules apply most directly to the original model provider, but downstream deployers also bear obligations. If you serve European users through a model that was not compliant with EU rules, you share some of the liability. This is the category most AI startups fall into.
Lowest-risk: companies using closed API models from compliant providers. If Anthropic, OpenAI, Google, and Mistral are already compliant (and they all prepared for this), most API-based applications inherit that compliance. The risk here is narrower: documentation of your own AI system deployment.
The EU also created a transition period for models placed on the market before 2025, giving them until August 2027. That grandfather clause does not cover newer models.
What This Means for Founders
If you are building or deploying AI models for European users, the next 10 days are not for panic. They are for documentation. The AI Office will not audit every company on August 3. But the ones that get flagged will face an enforcement process that is designed to move fast.
Start with three things this week. First, confirm your model provider's compliance status. If you rely on a GPAI foundation model, ask for their transparency documentation. If they do not have it, start evaluating alternatives. Second, document your own training data and copyright posture. Even if you are a fine-tuner, you need records of what data went into your model and how you handled copyright. Third, review your product for any EU-specific user base that might trigger direct obligations under the AI Act.
The smartest move is to do the work before the AI Office asks for it. The fine structure rewards compliance, not evasion. A documented, good-faith effort to meet the rules will matter in any enforcement proceeding. An empty file cabinet will not.

